Business • Free Template

Free AI Acceptable Use Policy Template

Set clear staff rules for approved AI tools, prohibited data and human review.

Free template • No registration required • Google Docs users can also download a copy as a Word file
Template Document
AI Acceptable Use Policy
Data boundaries
Human review
Incident steps

Set the boundary

Establish clear rules distinguishing approved company AI accounts from unapproved public tools.

Protect company data

Prevent accidental leaks of customer data, PII, intellectual property, or proprietary source code.

Create an audit trail

Define a straightforward incident reporting flow and policy ownership for annual review cycles.

AHAI Recommendation & Review

This template is a starting point, not legal advice. Ask the person responsible for data protection to review it before adoption. Seek legal advice where your client contracts, regulatory duties or use cases require it.

What's included in the template

Approved-tools register: Tool, account type, permitted data, owner, and review date tracking.
Data categories: Rules for public, internal, confidential, personal, special-category, and restricted data.
Human review: Validation rules requiring human review before use, prior to sending or file entry.
Copyright and IP rules: Boundaries to prevent unauthorised uploads of third-party materials.
Incident response workflow: Reporting procedures, contact logs, and escalation timelines for leaks.
Governance & review logs: Version tables, sign-offs, review triggers, and policy ownership definitions.

What this policy template covers

This editable template helps UK organisations set a clear boundary for staff use of generative AI tools. It covers approved accounts, prohibited data, human review, incident reporting, policy ownership and review dates.

It is designed for organisations using AI tools such as Gemini within Google Workspace, alongside clear rules for personal and unapproved AI accounts. It is not a substitute for checking client contracts, data-processing arrangements or sector-specific duties.

How to use the template

1

Review placeholder sections: Open the Word document and check the highlighted placeholders in brackets (e.g., [Company Name]).

2

Customise your register: Adapt the data rules, list of approved tools, and client contract boundaries to match your actual setup.

3

Submit for validation: Pass the custom document to your Data Protection Officer or information lead for final approval before roll-out.

Template preview

Template preview

1. Purpose and Scope

This policy defines the authorised and secure use of generative Artificial Intelligence (AI) tools and Large Language Models (LLMs) at [Company Name].

This policy applies to all systems that process company-owned text, images, code, or spreadsheet data. It covers both company-purchased accounts (e.g., Google Workspace Gemini Business) and public, consumer-facing tools (e.g., ChatGPT Free, Gemini Basic).

2. Approved vs. Prohibited Systems

Employees may only enter company data into tools that the organisation has approved for the specific data type and use case. The level of data protection depends entirely on the service model and licensing tier.

Tool status Permitted information Examples
Approved organisation-managed AI tools Only information permitted in the approved-tools register. Check the supplier terms, account type, configuration and data-processing arrangements before use. Your managed Google Workspace Gemini service
Unapproved or personal AI tools Public, non-confidential information only, if the policy permits it. Not approved for company confidential information, personal data, client data, source code or internal documents. Personal accounts and unapproved third-party tools

The full template includes six complete policy sections, available in two formats:

Frequently asked questions

Is this AI acceptable-use policy template free?

Yes. You can download and edit it for internal use.

Does the template make an organisation UK GDPR compliant?

No. It provides a starting point for staff rules. Your organisation must still review its lawful basis, processor arrangements, client contracts and security controls.

What should staff never enter into an unapproved AI tool?

Client confidential information, personal data, passwords, source code, internal documents and commercially sensitive material.

Who should approve the policy?

The person responsible for data protection should review it. Seek legal advice where the organisation's contracts or regulatory obligations require it.

Related guidance