Skip to content

What should an AI acceptable-use policy say?

Short answer

Keep it short enough that people read it. It should name the approved AI tools, list the information that never goes into any AI tool, require a person to review anything AI produces before it reaches a client, and say who to ask about a new tool. Review it at least yearly, because the tools change quickly.

Draft · pending expert review

A good AI policy is closer to one page than twenty. Its job is to make the safe choice the easy one.

What to include

  • Approved tools. Name them, and say how people get access. If the approved option is hard to reach, people will use something else.
  • Data that never goes in. Passwords, client financial records, health information, personal identifiers, and anything covered by an NDA or regulation.
  • Human review. A person checks AI output before it goes to a client, a regulator, or into a system of record.
  • AI features inside other software. Vendors are adding AI to existing products. Someone should decide whether each one is switched on.
  • Tools people build. Apps and scripts built with AI get reviewed before they touch real data.
  • Who to ask. One named person or team for questions and new-tool requests.

Industry rules still apply

HIPAA, SEC and FINRA recordkeeping, and CMMC don't have AI exceptions. If a tool will see regulated information, it needs the same agreements and controls as any other system that does.

Talk to a person, not a ticket

Tell us what's going on. We'll listen, ask good questions, and give you a straight answer about whether we can help.

Call us