Free AI Acceptable Use Policy Builder
What should an AI acceptable use policy include?
Most AI policies fail the same test: an employee at four in the afternoon cannot tell from them whether the thing they are about to do is allowed. A page of prohibitions is not followed. A page of aspirations decides nothing. This one names a tool, forbids six specific things, and encourages the rest.
No email, no download gate, nothing stored. The text appears on the page and you copy it.
Six answers, then the document
Clauses attach only when your answer makes them apply, because a policy full of duties that do not apply to you teaches people to skim it. Nothing is stored or sent anywhere.
What makes a policy people follow
It names a permitted path
A policy that only forbids gives people nowhere to go, so they go to a personal account where you have no contract, no logs and no visibility. Naming one approved tool and answering approval requests quickly does more for your exposure than any prohibition.
Its prohibitions are specific
"Do not enter confidential information" is not a rule, it is a mood. Credentials, special category data, customer personal data, HR records, anything under an NDA and anything price sensitive is a list a person can actually check themselves against.
It puts accountability on the human, in writing
The single most useful sentence in any AI policy is that using the output makes it yours. It settles arguments before they happen and it is the sentence a regulator, a client or a court will look for.
Reporting a mistake is safe
The damage from a bad paste is almost entirely a function of how long it takes you to find out. A no-blame reporting line is not softness, it is the control that shortens that clock, and a policy without one guarantees you learn late.
Questions people ask
What should an AI acceptable use policy include?
At minimum: which tool is approved and that personal accounts are not work tools, a specific list of what must never be entered, a specific list of what is encouraged, a statement that the human remains accountable for the output, and a no-blame route for reporting mistakes fast. The common failure is a policy of prohibitions with no permitted path, which is not followed and therefore documents nothing. The second failure is aspiration with no decisions in it, which cannot answer whether a particular action is allowed.
Is an AI policy legally required?
No law requires a document called an AI policy. What the law requires are outcomes: a lawful basis and a processor agreement before personal data is processed, non-discrimination in employment decisions, sector rules where they apply, and in the EU measures that support AI literacy under Article 4 of the EU AI Act. A policy is the cheapest way to produce evidence that those decisions were made deliberately rather than improvised.
How do we stop employees using AI we have not approved?
By making the approved path faster than the workaround. Shadow AI is not defiance, it is what happens when the sanctioned tool is missing, slow, or forbids the work people actually have to do. Name a good tool, answer approval requests quickly, forbid a short and specific list rather than everything, and make reporting a mistake safe. A stricter ban mainly moves the activity to a personal account where you can see nothing.
Can we just say no AI at work?
You can write it, and you will not get it. People will use these tools on personal devices and personal accounts to hit deadlines, which is the same activity with none of the visibility, none of the contractual protection and no record. A blanket ban converts a manageable risk into an invisible one, which is why the policy generated here forbids six specific categories and encourages the rest.
Does the EU AI Act require AI training for employees?
Article 4 requires providers and deployers to take measures supporting the development of AI literacy among staff and others operating AI on their behalf. Since the Digital Omnibus amended it in July 2026 the European Commission has been explicit that no specific level is mandated, no format is prescribed, no certificate is required and there is no obligation to measure employee knowledge. It is an obligation of effort, so what matters is that you took reasonable measures and can show it.
The two pages that go with this
The Paste Test is where the prohibition list above comes from, category by category, with what actually happens to each one. Whether any law requires you to train staff answers the question your board asks next.
The generated document is a starting draft, not legal advice, and having a policy is not the same as complying with anything. Have it read by someone qualified where you operate, and change whatever does not describe how your organisation actually works.