Information Security

AI Acceptable Use Policy

A ai acceptable use policy template defining what staff may and may not do with generative AI tools, covering approved tools, data restrictions and output verification, aligned to ISO 27001, NIST CSF, GDPR.

14-20 pages|Updated 2026-09-12|3 frameworks

What's Included

1. Purpose & Scope

Objective and tools covered.

Policy ObjectiveTools in ScopeRoles and Responsibilities

2. Approved Tools

Which AI services may be used at all.

Approved ListApproval ProcessProhibited ServicesEnterprise vs Consumer Accounts

3. Data Restrictions

What may never be entered into a prompt.

Prohibited Data ClassesCustomer DataPersonal DataSource Code and SecretsConfidential Business Information

4. Output Verification

Treating output as a draft, not an answer.

Human Review RequirementFactual VerificationCitation CheckingProhibited Unreviewed Uses

5. Disclosure & Attribution

Being honest about AI involvement.

Internal DisclosureCustomer-Facing DisclosureIntellectual Property Considerations

6. Monitoring & Enforcement

How compliance is checked.

Usage VisibilityIncident HandlingDisciplinary Interface

7. Records & Review

Evidence and cadence, given how fast this area moves.

Approved Tool RegisterIncident RecordsQuarterly Policy Review

Frequently Asked Questions

What should a ai acceptable use policy include?

A comprehensive ai acceptable use policy should include purpose & scope, approved tools, data restrictions, output verification, and more. This template covers 7 key sections aligned to ISO 27001, NIST CSF, GDPR requirements.

Which frameworks require a information security policy?

Major frameworks requiring information security policies include ISO 27001, NIST CSF, GDPR. This template maps directly to their control requirements, making it easier to demonstrate compliance across multiple standards.

How often should a ai acceptable use policy be reviewed?

Best practice is to review your ai acceptable use policy at least annually, or whenever significant changes occur in your organisation, technology environment, or regulatory landscape. Most frameworks including ISO 27001 and NIST CSF require documented policy review cycles.

Build Your Compliance Programme

Pair this policy template with our compliance platform to map controls across 686+ frameworks, run self-assessments, and get AI-powered compliance advisory.

Get Started Free →

Free forever — no credit card required