Writing an AI Acceptable Use Policy Your Team Will Actually Follow

How to write a one-page AI acceptable use policy people will actually follow: what to encourage, what to prohibit, the data line, approved tools, and keeping it live.

An AI acceptable use policy tells your people what is fine, what is not, and where the sensitive data must never go. Done well it is one page, written in plain English, and it speeds teams up because nobody is guessing. Done badly it is a legalistic document nobody reads, which is the same as having none.

Here is how to write one people will actually follow.

Why you need one

Your staff are already using AI tools, almost certainly through free accounts, ahead of any rules. The choice is not whether AI is used, it is whether that use sits inside a boundary you have set or in personal accounts you cannot see. A short policy pulls it into the open, which is safer and, honestly, more productive.

What it should cover

What is encouraged. Say clearly that using approved AI tools for drafting, research and routine work is fine and welcome. A policy that only says no gets ignored.

What is off limits. The specific things not to do: putting personal data, customer data, credentials or commercially sensitive information into public tools; using AI output for decisions about individuals without a human check; presenting AI output as fact without verifying it.

Which tools are approved. A short list of tools people can use freely, and how to ask about a new one, so the answer to “can I use this” is quick rather than a shrug.

The data line. The single most important rule, stated plainly: what data must never be pasted into a tool that is not approved for it.

Who to ask. A named person or channel for the grey areas, so people have somewhere to go instead of guessing.

Keep it short and human

One to two pages, in the language your team actually speaks, beats a policy suite nobody opens. If it needs a lawyer to read it, it will not change behaviour. The test is whether a new starter could read it in five minutes and know what to do.

Make it live

A policy on its own is a document, not a control. Pair it with a named owner, a quick route to approve new tools, and a light check on the riskier uses. And revisit it, because the tools move fast. That is the difference between a policy that shapes behaviour and one that gathers dust.

Where ScaleAround fits

Our free AI Governance Starter Kit includes an acceptable use policy template you can adapt in an afternoon, and our AI governance advisory helps where you need more depth.

Our founder, Oliver Smith, established and ran an AI and machine learning function at a UK lender and facilitates sessions at the CDO Financial Services Exchange on the data challenges specific to machine learning. He is a Fellow of the British Computer Society. Our engagements are led by senior practitioners with at least 15 years of relevant experience.

Frequently asked questions

What should an AI acceptable use policy include? What is encouraged, what is off limits, which tools are approved, a clear data line, and who to ask about grey areas, all in plain English.

How long should it be? One to two pages. If it is longer or legalistic, people will not read it and it will not change behaviour.

Should we just ban AI to be safe? No. Banning pushes use into personal accounts you cannot see. A clear boundary is safer and more productive.

What is the single most important rule? The data line: what must never be pasted into a tool that is not approved for it.

Is a policy enough on its own? No. Pair it with a named owner, a fast approval route for new tools, and a light check on riskier uses.


Want a policy your team will actually follow? Start with the template in our free AI Governance Starter Kit, and our AI governance advisory if you need more. Book a 30-minute scoping call to talk it through.