ARTIFICIAL INTELLIGENCE (AI) ACCEPTABLE USE POLICY [Organization] · Policy number [###] · Effective [date] · Owner: [IT Director / CIO] · Review: every 12 months 1. Purpose AI tools can help [Organization] staff write, summarize, research and serve the public faster. This policy sets out how to use them so that the information we hold stays protected, the work we publish stays accurate, and every decision stays with a person. 2. Scope This policy applies to all employees, contractors, interns and volunteers of [Organization], and to anyone using [Organization] devices, accounts, networks or data with any AI tool, at work or remotely. 3. Definitions - AI tool: any software that generates text, images, audio, video or code, answers questions, or takes actions using a machine learning model. This includes chat assistants, AI features built into other software, browser extensions and AI agents connected to other systems. - Approved AI tool: an AI tool listed on the [Organization] approved list maintained by [IT]. - Public data: information already released, or meant for release, to the public. - Internal data: information for staff use that is not confidential. - Confidential data: personal information about residents, students, patients or employees; health, financial, criminal justice and student records; legal matters; security details such as passwords, keys and network information; and anything protected by law, contract or [Organization] policy. 4. Approved tools - [IT] keeps a list of approved AI tools and the highest data level each may be used with. - Use [Organization] accounts for approved AI tools, never personal accounts, so the work and its records belong to [Organization]. - Public AI tools that are not on the approved list may be used with public data only. - Request a new AI tool, plug-in, browser extension or AI feature through [IT] before using it with anything other than public data. [IT] reviews where the data goes, how long it is kept, and who can see it. 5. Data rules - Never enter confidential data into an AI tool that is not approved for it. - An AI tool may only see what you are allowed to see. AI tools connected to [Organization] systems, such as file shares, email, HR or finance, must act with your own access, not a shared or administrator account. - Do not use AI tools to get around access controls, or to find, combine or infer information you would not otherwise be allowed to see. - Remove personal details from text before using it with an AI tool whenever the task allows. 6. Using AI output - You are responsible for anything you produce with AI. Review it for accuracy, bias, tone and completeness before you use or share it. - AI tools can be confidently wrong. Check facts, figures, citations, legal references and code against a trusted source. - Say when AI generated a substantial part of public-facing material, following [Organization] communications guidance. - Decisions about a person's rights, benefits, services, employment or discipline are made by a person. AI may assist with research and drafting but may not make the decision. - Do not use AI to impersonate anyone, create misleading images, audio or video, or produce content that is harassing or discriminatory. - Respect copyright and licenses. Do not enter material [Organization] has no right to share, and check AI output before reusing it as original work. 7. Actions, not just answers - AI tools that can take actions (send email, change records, run commands, approve payments) may only do so through an approved, logged connection, with the same approvals the action would need if a person did it by hand. - Changes to systems, money or records made with AI require human review before they take effect, as set by [IT] and the system owner. 8. Records, monitoring and transparency - Prompts, outputs and AI actions made for [Organization] business may be public records and may be subject to disclosure and to the [Organization] records retention schedule. - Use of approved AI tools on [Organization] systems is logged: who used which tool, what was asked, what the tool did and what it returned. Logs are kept and reviewed for security, compliance and records purposes. 9. Security - Report to [IT] at once if confidential data was entered into a tool not approved for it, if an AI tool behaved unexpectedly, or if content you gave an AI tool appeared to give it instructions (for example a document telling the AI to send data somewhere). - Do not install AI applications, plug-ins or browser extensions on [Organization] devices without [IT] approval. 10. Training Staff complete AI awareness training before using approved AI tools with internal or confidential data, and when this policy changes. 11. Compliance Violations of this policy may lead to loss of AI tool access and to disciplinary action under [Organization] personnel policies. Questions go to [IT contact] or [HR contact]. 12. Review [IT] and [HR] review this policy at least every 12 months and when laws, regulations or AI capabilities change. Approval Approved by: ____________________ Title: ____________________ Date: __________