AI Acceptable Use Policy
Effective Date: [DATE] Owner: [POLICY OWNER, e.g. CISO, IT Director] Review Cycle: Annual
1. Purpose
This policy establishes how [COMPANY NAME] employees and contractors may use generative AI tools (including ChatGPT, Claude, Gemini, Microsoft Copilot, GitHub Copilot, and similar services) in connection with their work. It protects [COMPANY NAME]'s sensitive data, customer information, and intellectual property while enabling productive use of approved AI tools.
2. Scope
This policy applies to:
- All employees, contractors, and authorized agents of [COMPANY NAME]
- All [COMPANY NAME]-owned devices and accounts
- Use of personal devices or accounts when accessing [COMPANY NAME] data
- Both web-based and desktop AI applications
3. Definitions
- Approved AI Tool: An AI service that has completed [COMPANY NAME]'s vendor security review and has an executed Data Processing Agreement (DPA) covering the relevant data categories.
- Sensitive Data: Customer personal data, employee data, financial records, source code, credentials, contracts, board materials, and any data classified as Confidential or Restricted under [COMPANY NAME]'s data classification policy.
- Regulated Data: Data subject to HIPAA, GDPR, PCI-DSS, or other regulatory regimes applicable to [COMPANY NAME].
4. Approved AI Tools
The following tools are approved for use, subject to the data restrictions in Section 5:
| Tool | Approved For | DPA on File |
|---|---|---|
| [e.g. Microsoft Copilot for M365] | [e.g. Internal documents only] | Yes |
| [e.g. GitHub Copilot Business] | [e.g. Code assistance] | Yes |
| [e.g. ChatGPT Enterprise] | [e.g. General productivity] | Yes |
All other AI tools are considered Unapproved and must not be used with any [COMPANY NAME] data.
5. Prohibited Data
The following data must never be submitted to any AI tool, approved or otherwise, without prior written approval from [POLICY OWNER]:
- Personally identifiable information (PII) of customers, prospects, employees, or any third party
- Protected health information (PHI)
- Payment card data (PAN, CVV)
- Authentication credentials (passwords, API keys, tokens, connection strings)
- Source code marked Confidential or higher
- Materially non-public information (MNPI), including pre-announcement financial results, M&A activity, or product roadmaps
- Privileged communications (legal advice, attorney-client matter)
- Contract terms marked Confidential
- Personal data of EU residents (any category) unless a Data Processing Agreement covers the specific AI tool and use case
6. Permitted Use
Employees may use Approved AI Tools for:
- General productivity (drafting emails, summarizing public content)
- Code assistance (with non-confidential code)
- Research using publicly available information
- Internal brainstorming with non-sensitive content
7. Personal Accounts
Use of personal accounts on AI tools while performing [COMPANY NAME] work is prohibited. All AI use must be through [COMPANY NAME]-provisioned accounts on Approved Tools.
8. Monitoring
[COMPANY NAME] monitors AI tool usage on [COMPANY NAME]-managed devices. This includes:
- Detection of AI tool access (which tools, which users, when)
- Classification of content submitted (without storing content)
- Audit logs of policy violations
Employees are expected to acknowledge this monitoring as part of their employment agreement.
9. Violations
Suspected violations should be reported to [POLICY OWNER] or the IT helpdesk. Violations may result in:
- Required completion of additional AI training
- Restriction of AI tool access
- Disciplinary action up to and including termination, depending on severity and intent
- Notification to affected parties and regulators where required by law
10. Exception Requests
If an Approved Tool does not exist for a needed use case, employees may submit an exception request to [POLICY OWNER]. Requests will be evaluated within 5 business days and may result in an expedited vendor review.
11. Review and Updates
This policy is reviewed annually, or more frequently as the AI vendor landscape evolves. Material changes will be communicated to all employees.
12. Acknowledgement
I acknowledge that I have read, understood, and agree to comply with this AI Acceptable Use Policy.
Employee Name: ____________________________ Signature: ____________________________ Date: ____________________________
This template was published by ShadowLock and may be freely used, modified, and adapted to your organization. ShadowLock does not provide legal advice; have your counsel review this template before adopting it.