AI Acceptable Use Policy Template (2026): Rules for ChatGPT and AI Tools at Work
ai-acceptable-use-policy ai-policy-template hr-documents workplace-ai employee-handbook

AI Acceptable Use Policy Template (2026): Rules for ChatGPT and AI Tools at Work

A free AI acceptable use policy template for employees using ChatGPT, Gemini and other AI tools at work — approved tools, confidential data limits, and output review, explained.

James James · Content Manager September 23, 2026 11 min read

AI Acceptable Use Policy Template (2026): Rules for ChatGPT and AI Tools at Work

Your employees are already using ChatGPT, Gemini, or Copilot to draft emails, summarize meetings, and debug code — whether or not you've approved it. Most of them have never been told what they can and can't paste into a chat window, so customer names, contract terms, and unreleased product details end up on a server your company doesn't control. If you're an HR or ops lead who suspects this is happening but has nothing written down to point to when it does, you don't have a training problem yet — you have a documentation problem. This guide covers what a written AI acceptable use policy needs to include, a template you can adapt this afternoon, and how to roll it out so people actually follow it instead of ignoring another attachment.

Quick Answer

  • An AI acceptable use policy tells employees which AI tools are approved, what data can never be pasted into them, and when a human has to review AI-assisted work before it goes out the door.
  • At minimum, cover five things: an approved tools list, prohibited data categories, a disclosure-and-review rule, who owns AI-generated output, and an accuracy/liability caveat.
  • Don't ban AI outright — employees without an approved option often use one on a personal phone instead, where you have zero visibility.
  • Get every employee to sign an acknowledgment. A policy nobody signed is hard to enforce after the fact.
  • AiDocX can draft a policy tailored to your company's actual tools and industry, then collect a signed acknowledgment from every employee automatically.

Why You Need One in 2026

AI adoption inside companies outran the policies meant to govern it. Microsoft and LinkedIn's 2024 Work Trend Index found that 78% of AI users at work bring their own AI tools rather than using anything the company issued or approved — often called "shadow AI." That means the tools are already in daily use at your company even if IT never signed off on them.

The risk isn't theoretical. In 2023, Samsung banned ChatGPT and other generative AI tools company-wide after engineers pasted proprietary source code, a transcribed internal meeting, and confidential chip test-sequence data into ChatGPT within about three weeks. Once that information left the building, Samsung had no way to retrieve or delete it from the vendor's servers. Most companies won't end up in a headline, but the same behavior — pasting whatever's on screen into a chat box — happens in nearly every department, from a support agent pasting a customer's contact details into a "make this nicer" prompt to an analyst summarizing an unreleased earnings draft.

A written policy also answers the questions that surface the moment something goes wrong. Who's responsible if an AI tool inserts a wrong number into a client-facing proposal? Does the company own the copyright on a blog post or contract clause an AI drafted? Can a manager use an AI tool to screen job applicants without telling them? None of these get settled by good intentions alone — they get settled by a document employees actually read and signed beforehand.

This is a narrower, more universal problem than AI regulatory compliance for a specific use case like contract review — see our guide to EU AI Act contract review obligations if that's what you need. What's covered here applies regardless of jurisdiction or industry: rules for the ordinary act of an employee opening an AI chat window at their desk.

What to Cover in an AI Acceptable Use Policy

A usable policy is specific enough that an employee can apply it without calling you to ask. Five things need to be in writing:

  1. An approved tools list. Name the specific tools employees may use — for example, "ChatGPT Enterprise, Google Gemini for Workspace, GitHub Copilot" — instead of banning "AI" as a category. A named list is something people can actually follow; a ban on "artificial intelligence" isn't, because most employees can't tell a spell-checker's AI feature from an actual chatbot.
  2. Confidential and customer data restrictions. Spell out, with examples, what can never go into a non-approved tool: customer contact details, unreleased financials, source code, anything under an NDA, health or payment information. The word "confidential" alone doesn't mean much to someone trying to close a ticket at 4:45 on a Friday — a short list of concrete examples does.
  3. Disclosure and human review. Anything AI helps produce — a contract clause, a client email, a financial summary — needs a named human who reviewed it before it's sent, signed, or published. Require employees to flag AI involvement to their manager for anything client-facing or legally binding, even when the final output carries no external "AI-assisted" label.
  4. Who owns the output. State plainly that anything generated with a company-approved AI tool, on company time, for company purposes, belongs to the company the same way any other work product does. This matters more than most people assume: the US Copyright Office has said since March 2023 that a work generated entirely by AI, without meaningful human authorship, isn't copyrightable at all — so treat heavily AI-assisted drafts the way you'd treat a first draft from a new hire: reviewed, edited, and owned by the business, not shipped as-is.
  5. Accuracy and liability. AI tools produce wrong answers in a confident tone. State that AI output is a draft, not a verified fact, and that the employee who sends or publishes it is responsible for checking it — the same standard as if they'd written it themselves. This matters even more once AI touches an actual contract; see our guide on whether an AI-generated contract is legally binding for how that liability plays out after a document gets signed.

AI Acceptable Use Policy Template (Copy This)

This covers the core clauses a small business needs. Fill in the bracketed sections for your actual tools, industry, and any specific rules that apply to your business, then have someone with legal training review it before you roll it out.

AI ACCEPTABLE USE POLICY

Effective date: [DATE]
Applies to: All employees, contractors, and interns who use AI tools on company
devices, company accounts, or for company-related work, regardless of location.

1. APPROVED TOOLS
Only the following AI tools are approved for company use: [LIST TOOLS, e.g.,
ChatGPT Enterprise, Google Gemini for Workspace, GitHub Copilot, AiDocX]. Using
an unapproved AI tool for company work requires written sign-off from
[MANAGER / IT / DEPARTMENT].

2. PROHIBITED DATA
Never enter the following into an AI tool that isn't on the approved list above,
even for a quick question:
 - Customer or employee personal data (names, contact details, ID numbers,
   health or payment information)
 - Unreleased financial results or forecasts
 - Source code, credentials, or system architecture details
 - Contract terms covered by an NDA or confidentiality clause
 - Anything marked "Internal" or "Confidential" in company systems

3. DISCLOSURE AND HUMAN REVIEW
Any AI-assisted work product — client emails, contract language, marketing
copy, financial summaries, code — must be reviewed by the employee before it
is sent, signed, or published. Flag AI involvement to your manager for
anything client-facing or legally binding. AI output is a draft, never a
final answer.

4. OWNERSHIP
Work generated using an approved AI tool, on company time, for company
purposes, is company property, the same as any other work product created
during employment.

5. ACCURACY
AI tools can produce incorrect, outdated, or fabricated information. The
employee submitting, sending, or publishing AI-assisted work is responsible
for verifying its accuracy, not the AI tool or its vendor.

6. VIOLATIONS
Violating this policy may result in disciplinary action up to and including
termination, particularly where a violation involves confidential or personal
data. Report accidental disclosures (e.g., pasting confidential data into an
unapproved tool) to [CONTACT] immediately.

ACKNOWLEDGMENT
I have read and understood this AI Acceptable Use Policy and agree to
follow it.

Employee name: _______________________
Signature: _______________________
Date: _______________________

Rolling It Out Without Employees Ignoring It

A policy that lives in an onboarding PDF nobody reopens doesn't change behavior. Three things separate a policy people follow from one they route around.

Train, don't just distribute. A 20-minute walkthrough — what's approved, what's off-limits, and a real example like the Samsung case above — sticks better than an email with an attachment. Let people ask the awkward questions out loud — like whether they can paste a client's contract into ChatGPT to summarize it. Almost always no, unless the tool is approved and the contract doesn't restrict third-party disclosure.

Give one approved list instead of a ban. Employees who hear "no AI" don't stop using AI — they just stop telling you about it, on a personal laptop where you have zero visibility and zero audit trail. A short, named list of approved tools gives people a fast, legitimate option, which is the only thing that competes with the tool already open in another browser tab.

Track acknowledgment like any other required signature. If your handbook software or e-signature tool can show you who has and hasn't signed the AI policy, use it — a policy three people never opened doesn't protect you if one of them causes a data incident. This policy can live as a standalone document or as a new section inside a broader employee handbook template, whichever fits how your company already ships policy updates.

Worked Example

Dana runs HR at Fleetwire, a 40-person logistics software company. In August, a sales rep pasted a prospect's entire pricing negotiation thread into ChatGPT to draft a follow-up, and Dana only found out because the rep mentioned it in passing during a team meeting. There was no policy to point to, and no record of who else might be doing the same thing.

Dana wrote a one-page AI acceptable use policy over a weekend: three approved tools (ChatGPT Enterprise, Gemini for Workspace, and the company's AiDocX account for contracts), a short list of data that could never leave those tools, and a rule that any AI-drafted client communication needed a second set of eyes before sending. Fleetwire already had a signed remote work policy on file for its hybrid staff, so Dana reused the same acknowledgment workflow: upload the document, route it to all 40 employees, track who had signed.

Within a week, 38 of 40 had signed. The two holdouts hadn't read it rather than objected to it — a five-minute follow-up conversation closed both out. Dana now reviews the tool list twice a year and re-sends the policy for a fresh signature whenever it changes.

Writing this policy from scratch is the same problem AiDocX solves for every other internal document: you know roughly what needs to be in it, but turning that into something properly structured takes longer than it should. Describe your company's tools, industry, and the kinds of data you handle in plain language, and AiDocX drafts an AI acceptable use policy built around them — then routes it to every employee for an e-signed acknowledgment, so you get an actual record of who agreed to it instead of a PDF sitting in a shared drive nobody opened. Start drafting yours at app.aidocx.ai — it's free to start.

FAQ

Does this policy replace our data privacy or IT security policy?

No, it works alongside them. Your IT security policy covers device and network access; this policy covers a specific behavior — what employees paste into third-party AI tools — that most existing IT policies don't name directly.

Can we just ban AI tools instead of writing a policy?

You can try, but it rarely holds. Employees who can't use AI at work with company tools tend to use it anyway on a personal device, where you have no visibility. An approved-tools list is easier to enforce than a ban nobody follows.

Do contractors and freelancers need to sign this too?

Yes, if they touch company data or systems. Contractors often have less context on what counts as confidential, and they're using their own devices and accounts by default — both good reasons to have them sign the same acknowledgment as employees.

How often should we update the policy?

Review it at least twice a year, or any time you add a new AI tool to your stack. AI vendors change their data-handling terms more often than most software contracts, so a list that was accurate in January can be out of date by summer.

Is a written AI policy legally required?

There's no single federal US law requiring one for general workplace AI use; requirements vary by jurisdiction, industry, and the data you handle. Even where nothing specifically mandates it, a written policy is one of the clearest ways to show reasonable care if a data-handling question comes up.

This guide is general information, not legal advice. AI governance obligations vary by jurisdiction, industry and the specific tools in use — consult a licensed attorney before adopting a policy for your organization.

Ready to automate your documents with AI?

Start free with AiDocX — AI contract drafting, meeting minutes, consultation notes, e-signatures, and more in one platform.

Get Started Free