AI Governance Gap Check

AI acceptable use policy: what to put in it, and what to leave out

This is the document customers ask for most often and the cheapest one to produce. It is also the one most companies get wrong, by writing something so broad that nobody can follow it.

What an AI acceptable use policy is

An AI acceptable use policy states which AI tools staff may use, what information they may put into those tools, and what must be checked before AI output is relied on.

That is the whole job. Three questions, answered specifically enough that someone can follow the policy without asking anyone. A policy that says "use AI responsibly" answers none of them and protects nobody.

The seven sections it needs

1. Which tools are approved

Name them. Not categories, actual product names, and the version or tier if that matters (a free consumer account and a business account often have completely different data handling). Include how someone requests a tool that is not on the list, because otherwise they will simply use it and not tell you.

2. What may never be entered

This is the section that earns the policy its keep. Be concrete. Typical lines include customer personal data, anything covered by a confidentiality agreement, unreleased financial information, credentials or keys, and complete source code where the terms allow training on inputs.

Write it as examples rather than principles. "Do not paste a customer contract into a chat assistant" is followed. "Exercise appropriate care with confidential information" is not.

3. What must be checked before output is used

Say who checks, and what they check for. Anything going to a customer, anything going into a legal or financial document, and anything published in the company name should have a named human check. State the check plainly: facts verified against a source, figures recalculated, quotes confirmed to exist.

4. Where AI output must be disclosed

Cover whether AI involvement is disclosed to customers, in published content, and in work delivered to clients. Some client contracts now prohibit AI assistance outright, so the policy should say that contract terms override the general rule.

5. What is prohibited entirely

Common ones: using AI to make a final decision about a person without human review, generating content that impersonates a real individual, and using AI to produce anything the company would not be willing to stand behind publicly.

6. Who to tell when something goes wrong

One named role and one route. If somebody pastes something they should not have, you want to hear about it in ten minutes, not never. Say explicitly that reporting a mistake promptly will not be treated as a disciplinary matter, or you will not hear about mistakes at all.

7. When the policy is reviewed

A date and an owner. AI tools change monthly. A policy written a year ago and never revisited describes a world that no longer exists, and an assessor will spot that immediately.

What to leave out

Leave out long explanations of how AI works. Leave out predictions about where the technology is going. Leave out anything you have no way of detecting or enforcing, because an unenforceable rule teaches staff that the rest of the policy is optional too.

Leave out legal language you have not had checked. A policy written in confident legal-sounding prose that is subtly wrong is worse than a plain one that is right.

The mistake that undoes all of it

A policy that has been written but never communicated changes nobody's behaviour. Assessors probe this first, and it is the most common gap.

Sending it once in an email is not communication. People need to have seen it, and you need to be able to show that they did. A short acknowledgement, dated, is enough. Without it, the honest answer to "do your staff follow your AI policy" is that you do not know.

How this fits the wider picture

The acceptable use policy is one of eleven documents an AI management system is expected to hold under ISO/IEC 42001. It is the most visible and the most requested, but on its own it does not cover the inventory of what you actually use, who is accountable, or how risk gets assessed.

Find out which of the eleven you are missing

Nine questions, about three minutes. Your result appears on screen, no email needed.

Start the check