AI Policy Template: The 12 Sections You Need - Step-by-step guide for Blog

AI Policy Template: The 12 Sections You Need

By Mark FershteynPublished 11 min read

A free AI policy template broken into the 12 sections every workplace AI policy needs, with sample clause language for each and the mistake companies make.


Most AI policy templates hand you a generic document and leave you to work out which half applies. This one goes the other way. Here are the twelve sections a workplace AI policy needs, the clause language for each, and the mistake companies make in that section.

Take what fits. If you'd rather not edit at all, the AI acceptable use policy generator assembles these sections from ten questions about your company — free, and readable in full before you give an email. There's also a ready-made template PDF if you just want the finished document.

One caveat before any of it: this is not legal advice. Laws differ by jurisdiction and change fast. Have a qualified lawyer review your policy before you adopt it, and check it against your actual customer contracts.

1. Purpose and scope

States why the policy exists and who it binds. "Who" needs to include contractors and personal devices, or you've written a policy that covers roughly half the people using AI on your behalf.

This policy applies to all employees, contractors, interns, and temporary staff, and covers any use of AI tools for company work — on company devices or personal ones, whether or not the company pays for the tool.

Common mistake: limiting scope to "employees using company software." Most shadow AI use happens in a personal account on a personal laptop.

2. Approved tools

Names the tools people may use, and says what to do about everything else. A list beats a principle here — "use good judgment" is not an answer anyone can act on.

The following tools are approved for work use: [list]. Use company accounts, not personal ones. Anything not on this list is not approved — that means it has not been reviewed yet, not that the answer is no.

Common mistake: writing a list and never updating it. A stale list is what drives people to stop asking.

3. Permitted use

Says what people are encouraged to do. Most policies skip this and open with prohibitions, which is why most policies get read once and ignored.

You are encouraged to use approved AI tools to draft and edit written material, research unfamiliar areas, write and review code, analyse data you are already authorised to see, and prepare for meetings.

Common mistake: being all stick and no carrot. If the policy never says yes to anything, people assume the real answer is no and route around it.

4. Prohibited use

The hard lines. Keep this short enough that people remember it — a list of thirty prohibitions is a list nobody retains.

You may not use AI tools to enter data this policy does not permit, produce misleading or discriminatory material, impersonate a real person, circumvent a security control, or make a final decision about someone's employment, credit, health, or legal position without human review.

Common mistake: prohibiting things you cannot detect. Rules you will never enforce teach people that the rest are optional too.

5. Data handling

The clause that matters most, and the one companies most often get vague. Pick a tier and state it plainly: public only, internal fine, customer data in approved tools, or regulated data under controls.

Internal company information may be entered into approved tools using a company account. Customer data, personal data about identifiable individuals, credentials, and anything covered by a confidentiality obligation to a third party may not.

Common mistake: writing "do not enter sensitive information." Nobody thinks their own paste is the sensitive one. Name the categories.

6. Human review and accountability

Names who is responsible for AI output. Without this the policy has no teeth — everything else is a rule with no owner.

Anything that leaves the company must be reviewed by a person before it goes out. The reviewer is accountable for the content as though they had written it themselves.

Common mistake: requiring review of everything. A rule that doubles everyone's workload gets quietly dropped in week three. Scope it to what actually carries risk.

7. Disclosure

Says where AI use must be declared — client deliverables, published content, code, hiring. It's fine to require none, as long as that's a decision rather than an omission.

Where AI has materially contributed to a client deliverable, say so. Check the engagement terms first — some clients prohibit AI use outright, and that overrides this policy.

Common mistake: ignoring what your customer contracts already say. Several will have an AI clause you haven't read.

8. Intellectual property

Covers both directions: what you may not own in AI output, and whose rights you might infringe with it.

AI-generated material may not be protectable by copyright in every jurisdiction. Where exclusivity matters — a logo, a product name, a signature asset — involve a person and keep a record of the human contribution.

Common mistake: assuming generated output is yours to license exclusively. It often isn't.

9. Security

Credentials, prompt injection, and any agent that can take an action rather than just produce text.

Never enter passwords, API keys, or tokens into an AI tool, including inside a code snippet or error log. Treat content a model reads from email or the web as untrusted input.

Common mistake: writing this section for chatbots only, then having no answer when someone connects an agent to the CRM.

10. Regulatory compliance

Ties the policy to the obligations you already have. If you operate in the EU, the AI Act adds real duties, including an AI literacy requirement for anyone working with these systems.

Using an AI tool does not change any obligation we already have. Where this policy and a customer contract disagree, the contract wins — tell us so we can fix the policy.

Common mistake: copying a US template while operating in the EU, or the reverse. The clauses are genuinely different.

11. Approval process

How someone gets a new tool added. Give it a deadline — an approval process with no SLA is a decline with extra steps.

Submit the tool, what data it will touch, and whether something we already have could do the job. You will get an answer within ten working days.

Common mistake: no stated turnaround. People stop asking and start using it anyway.

12. Training, violations, and review

Acknowledgement, consequences, and how often the policy gets revisited. In this area, annually is the floor.

If you think you have made a mistake, say so immediately. Reporting a problem promptly and in good faith will be treated as the right call. Concealing one will not.

Common mistake: punishing self-reporting. Do that once and you'll never hear about the next incident until a customer does.

The part the policy can't do

A policy tells people what not to do. It doesn't make anyone good at the tools.

That matters more than it sounds, because the most common cause of a policy breach isn't defiance — it's someone not knowing there was a compliant way to do the task. They had a deadline, the approved tool didn't obviously solve it, and the unapproved one did. Every policy that gets ignored was competing with a faster path.

So the fastest way to make a policy stick is to make the safe path the fast path. Write the document, then teach people to do their actual jobs with the tools you approved.

Next: build your policy from ten questions, or download the ready-made template.

Ready to Master AI?

Join our self-paced AI course and learn ChatGPT, Claude, and Claude Code with hands-on training.

  • Live instruction
  • Hands-on practice
  • 12-month community access

Frequently Asked Questions

What is an AI policy template?

A starting document that sets out how a company allows AI tools to be used at work — which tools are approved, what data may go into them, who reviews the output, and what happens when the rules are broken. A template saves you writing from scratch, but it has to be adapted: the clauses a regulated healthcare company needs are not the ones a ten-person agency needs.

Is a free AI policy template good enough?

As a starting point, yes. As a finished document, no. Free templates are generic by design, so the work is in cutting the clauses that do not apply and adding the ones specific to your contracts, your regulators, and the tools your team actually uses. Have a lawyer review it before you adopt it.

What should an AI policy include?

Twelve sections cover it: purpose and scope, approved tools, permitted use, prohibited use, data handling, human review and accountability, disclosure, intellectual property, security, regulatory compliance, the approval process for new tools, and training plus violations plus review cadence.

How long should an AI policy be?

Two to four pages for most companies. Long enough to be specific about data and accountability, short enough that people actually read it. If yours runs past six pages, the detail probably belongs in a separate procedure document.

Who should own the AI policy?

One named person, usually in operations, legal, or IT depending on your size. The most common reason a policy goes stale is that it was written by a committee and owned by nobody. Put the owner and the next review date on the document itself.

Do small companies need an AI policy?

If anyone is pasting work into an AI tool, yes — and small companies are usually further along than they think. The document can be short. What matters is that the data rules are written down somewhere other than one person's head, because that is what your first enterprise customer security questionnaire will ask for.

BONUS RESOURCE

Finished reading?
Take it with you.

Get a downloadable checklist summarizing the key points from AI Policy Template: The 12 Sections You Need, plus weekly AI tips.

Printable quick-reference guide
Step-by-step action items
Weekly AI insights newsletter

Guide Checklist

PDF + Email Series

No spam. Unsubscribe anytime.