Free AI Acceptable Use Policy Template
Set clear staff rules for approved AI tools, prohibited data and human review.
Set the boundary
Establish clear rules distinguishing approved company AI accounts from unapproved public tools.
Protect company data
Prevent accidental leaks of customer data, PII, intellectual property, or proprietary source code.
Create an audit trail
Define a straightforward incident reporting flow and policy ownership for annual review cycles.
This template is a starting point, not legal advice. Ask the person responsible for data protection to review it before adoption. Seek legal advice where your client contracts, regulatory duties or use cases require it.
What's included in the template
What this policy template covers
This editable template helps UK organisations set a clear boundary for staff use of generative AI tools. It covers approved accounts, prohibited data, human review, incident reporting, policy ownership and review dates.
It is designed for organisations using AI tools such as Gemini within Google Workspace, alongside clear rules for personal and unapproved AI accounts. It is not a substitute for checking client contracts, data-processing arrangements or sector-specific duties.
How to use the template
Review placeholder sections: Open the Word document and check the highlighted placeholders in brackets (e.g., [Company Name]).
Customise your register: Adapt the data rules, list of approved tools, and client contract boundaries to match your actual setup.
Submit for validation: Pass the custom document to your Data Protection Officer or information lead for final approval before roll-out.
Template preview
1. Purpose and Scope
This policy defines the authorised and secure use of generative Artificial Intelligence (AI) tools and Large Language Models (LLMs) at [Company Name].
This policy applies to all systems that process company-owned text, images, code, or spreadsheet data. It covers both company-purchased accounts (e.g., Google Workspace Gemini Business) and public, consumer-facing tools (e.g., ChatGPT Free, Gemini Basic).
2. Approved vs. Prohibited Systems
Employees may only enter company data into tools that the organisation has approved for the specific data type and use case. The level of data protection depends entirely on the service model and licensing tier.
| Tool status | Permitted information | Examples |
|---|---|---|
| Approved organisation-managed AI tools | Only information permitted in the approved-tools register. Check the supplier terms, account type, configuration and data-processing arrangements before use. | Your managed Google Workspace Gemini service |
| Unapproved or personal AI tools | Public, non-confidential information only, if the policy permits it. Not approved for company confidential information, personal data, client data, source code or internal documents. | Personal accounts and unapproved third-party tools |
Frequently asked questions
Is this AI acceptable-use policy template free?
Yes. You can download and edit it for internal use.
Does the template make an organisation UK GDPR compliant?
No. It provides a starting point for staff rules. Your organisation must still review its lawful basis, processor arrangements, client contracts and security controls.
What should staff never enter into an unapproved AI tool?
Client confidential information, personal data, passwords, source code, internal documents and commercially sensitive material.
Who should approve the policy?
The person responsible for data protection should review it. Seek legal advice where the organisation's contracts or regulatory obligations require it.