AI acceptable use policy
The staff-facing rules: what people may use, what they may not put into a tool, and what has to be checked before AI-assisted work goes out.
An AI acceptable use policy sets the everyday rules for staff: approved and unapproved tools, what may not be entered into a tool, and what must be reviewed before release.
An acceptable use policy is the part of an AI policy your staff actually read, so it has to be plain and specific. Where a use touches personal data or the EU AI Act's literacy duty it carries its article, but most of it is your organisation's own rules for its own tools.
What does an acceptable use policy cover?
Four things, in plain language: which tools are approved and which are not, what can and cannot be put into a tool, what has to be reviewed before AI-assisted work reaches anyone outside the team, and where to report a problem. It is the everyday half of the wider policy, so it should fit on a page or two.
Terms like an employee AI policy or a ChatGPT policy for employees describe the same thing. There is no need for a separate document for each phrasing; one acceptable use policy covers them.
What do staff actually need told?
The rule that matters most is what never goes into an external tool. The NCSC on the risk of public large language models is clear that sensitive information should not be entered into public large language models, and that providers can retain and access what is submitted, so name the categories that are off limits for your organisation.
After that: which tool to use for what, that AI-assisted work going to a customer needs a human review first, and who to ask when something is unclear. Keep it to what a person needs to do their job without getting it wrong.
Approved and unapproved tools
Keep a live list of approved tools and a route to get a new one approved. The list is the useful artefact: it tells staff what they may use today, and it gives you something to keep current as tools change.
Be explicit about what is unapproved and why, so the boundary is a decision rather than a silence people fill for themselves. A route to request a new tool is what stops the unapproved list from being ignored.
What about accounts people already have?
Most organisations already have staff using consumer AI accounts they signed up for themselves. Say plainly whether those may be used for work, what may never be entered into them, and how someone moves their use onto an approved tool.
Pretending the accounts are not there does not remove them; it just moves the use out of sight. That is shadow AI, and the shadow AI guide covers why banning it outright rarely works and what to do instead.
How does it connect to the AI literacy duty?
The policy is one of the ways you meet the EU AI Act's duty to support the development of AI literacy for staff dealing with AI (Article 4, in force). Travers Smith on the AI literacy requirement notes the duty reaches both providers and deployers and can extend to contractors, with no duty to test anyone's literacy but a clear reason to document the training you give.
The AI literacy guide covers the duty in full. Tying the acceptable use policy to it means the same document that tells people what is allowed also helps you show you supported their understanding of it. The generator drafts the acceptable use sections around your answers, and the policy skeleton gives you the headings to start from.