AI acceptable use policy template
Short answer: a good AI acceptable use policy says which AI tools are approved, which data may go into them, that a person reviews and owns every result, that AI never makes decisions about people, that AI acting on your systems uses the employee's own access, and that AI use is logged as a record. Below is a complete template you can edit: replace each [bracket], have your attorney and HR review it, and approve it.
Written for towns, counties, special districts, schools and small organizations. Pair it with the plain-language employee handbook section for staff.
Artificial Intelligence (AI) Acceptable Use Policy
[Organization] · Policy number [###] · Effective [date] · Owner: [IT Director / CIO] · Review: every 12 months
1. Purpose
AI tools can help [Organization] staff write, summarize, research and serve the public faster. This policy sets out how to use them so that the information we hold stays protected, the work we publish stays accurate, and every decision stays with a person.
2. Scope
This policy applies to all employees, contractors, interns and volunteers of [Organization], and to anyone using [Organization] devices, accounts, networks or data with any AI tool, at work or remotely.
3. Definitions
- AI tool: any software that generates text, images, audio, video or code, answers questions, or takes actions using a machine learning model. This includes chat assistants, AI features built into other software, browser extensions and AI agents connected to other systems.
- Approved AI tool: an AI tool listed on the [Organization] approved list maintained by [IT].
- Public data: information already released, or meant for release, to the public.
- Internal data: information for staff use that is not confidential.
- Confidential data: personal information about residents, students, patients or employees; health, financial, criminal justice and student records; legal matters; security details such as passwords, keys and network information; and anything protected by law, contract or [Organization] policy.
4. Approved tools
- [IT] keeps a list of approved AI tools and the highest data level each may be used with.
- Use [Organization] accounts for approved AI tools, never personal accounts, so the work and its records belong to [Organization].
- Public AI tools that are not on the approved list may be used with public data only.
- Request a new AI tool, plug-in, browser extension or AI feature through [IT] before using it with anything other than public data. [IT] reviews where the data goes, how long it is kept, and who can see it.
5. Data rules
- Never enter confidential data into an AI tool that is not approved for it.
- An AI tool may only see what you are allowed to see. AI tools connected to [Organization] systems, such as file shares, email, HR or finance, must act with your own access, not a shared or administrator account.
- Do not use AI tools to get around access controls, or to find, combine or infer information you would not otherwise be allowed to see.
- Remove personal details from text before using it with an AI tool whenever the task allows.
6. Using AI output
- You are responsible for anything you produce with AI. Review it for accuracy, bias, tone and completeness before you use or share it.
- AI tools can be confidently wrong. Check facts, figures, citations, legal references and code against a trusted source.
- Say when AI generated a substantial part of public-facing material, following [Organization] communications guidance.
- Decisions about a person's rights, benefits, services, employment or discipline are made by a person. AI may assist with research and drafting but may not make the decision.
- Do not use AI to impersonate anyone, create misleading images, audio or video, or produce content that is harassing or discriminatory.
- Respect copyright and licenses. Do not enter material [Organization] has no right to share, and check AI output before reusing it as original work.
7. Actions, not just answers
- AI tools that can take actions (send email, change records, run commands, approve payments) may only do so through an approved, logged connection, with the same approvals the action would need if a person did it by hand.
- Changes to systems, money or records made with AI require human review before they take effect, as set by [IT] and the system owner.
8. Records, monitoring and transparency
- Prompts, outputs and AI actions made for [Organization] business may be public records and may be subject to disclosure and to the [Organization] records retention schedule.
- Use of approved AI tools on [Organization] systems is logged: who used which tool, what was asked, what the tool did and what it returned. Logs are kept and reviewed for security, compliance and records purposes.
9. Security
- Report to [IT] at once if confidential data was entered into a tool not approved for it, if an AI tool behaved unexpectedly, or if content you gave an AI tool appeared to give it instructions (for example a document telling the AI to send data somewhere).
- Do not install AI applications, plug-ins or browser extensions on [Organization] devices without [IT] approval.
10. Training
Staff complete AI awareness training before using approved AI tools with internal or confidential data, and when this policy changes.
11. Compliance
Violations of this policy may lead to loss of AI tool access and to disciplinary action under [Organization] personnel policies. Questions go to [IT contact] or [HR contact].
12. Review
[IT] and [HR] review this policy at least every 12 months and when laws, regulations or AI capabilities change.
Approval
Approved by: ____________________ Title: ____________________ Date: __________
This template is a starting point, not legal advice. Check it against your state's public records and privacy laws and any rules that cover your data (for example CJIS, HIPAA or FERPA), and have your attorney and HR review it before adoption.
Making the policy real: enforce it, don't just sign it
A signed policy tells people the rules. These controls make the rules hold even on a busy day:
- Section 5, "an AI tool may only see what you are allowed to see": connect AI tools through a gateway that runs every action with the person's own access, so file shares, HR and finance apply their own permissions. See how to stop AI from seeing files a user can't open.
- Section 5, confidential data: keep it in tools approved for it, ideally a model running on your own hardware, and redact card numbers, Social Security numbers and secrets before text reaches any model.
- Section 7, actions: rules that let reads through and hold changes for an approver, as the person who asked.
- Section 8, records: a per-action audit trail streamed to your SIEM. See MCP audit logging to your SIEM.
The full clause-by-clause mapping is in how to enforce an AI acceptable-use policy.
Turn the policy into controls
Acutis Gate enforces sections 5, 7 and 8 for you: every AI action runs as the employee, under rules you set, recorded in full.
Start a 14-day trial Tour the live GateFrequently asked questions
What should an AI acceptable use policy include?
Scope, definitions, the approved tools and the data each may handle, rules for confidential data, human review of AI output, no AI decisions about people, rules for AI that takes actions, records and logging, security reporting, training and consequences.
Can staff use ChatGPT or other public AI tools at work?
Under this template, public AI tools that are not on the approved list may be used with public data only. Anything internal or confidential goes into tools IT has approved for that data level.
Are AI prompts public records?
They can be. Prompts, outputs and AI actions made for government business may fall under public records law and your retention schedule, so the policy says so and AI use should be logged.
Who should own the AI policy?
Usually IT or the CIO, with HR for the personnel side and legal review before adoption. Review it at least every 12 months.
Acutis