GLOSSARY · LEADERSHIP & GRC

AI acceptable use policy

An AI acceptable use policy is an internal policy that defines which AI tools employees may use, for what tasks, and with what categories of data.

Good policies name approved tools, prohibit pasting sensitive data into unapproved ones, and explain how to request a new tool. They work best paired with technical controls such as an AI gateway, since policy alone does not stop copy and paste.

The difference between a policy people follow and one they ignore is usually specificity. “Use AI responsibly” tells an employee nothing they can act on at the moment they are deciding whether to paste a customer contract into a chatbot. A usable policy names the tools by name, maps them to your existing data classification so the rule reads as “client-confidential material may go into A but not B”, and says what to do when the answer is unclear. People generally want to comply; most violations are ambiguity rather than defiance.

The second thing that determines success is whether the approval path works. Every acceptable use policy implicitly promises that if the approved tools do not cover a real need, there is a way to get a new one considered. If that route takes a quarter, the policy has taught people that the rules do not fit the work, and you have created shadow AI with a signed document attached.

Keep it short, keep it current, and pair it with something that enforces. The list of approved tools will change every few months, so a policy that hardcodes it into a twelve-page document nobody reprints is already out of date. A one-page policy pointing at a maintained list ages considerably better, and the technical controls do the work the prose cannot.