Runs entirely on your device · nothing is uploaded
Get started

Build an AI Use Policy

Answer a short set of questions and download a ready-to-adopt AI Use Policy in Word or PDF. To be successful:

  • Have a list of approved tools
  • Have a list of prohibited actions
  • Have a list of high risk activities and responsible parties

A blue box like this one sits at the top of every step. It explains what that step does and, where it helps, lists example wording you can copy or adapt. Examples only ever appear in the blue box — nothing is pre-filled or pre-ticked for you, so the policy says exactly what you decide it says.

Everything you type stays in your browser — nothing is uploaded or sent anywhere. You can edit every word of the finished policy in Word after you download it.

This template policy is provided for informational purposes only and is not legal, regulatory, or professional advice. You are solely responsible for reviewing, modifying, approving, implementing, and maintaining your AI Use Policy, and for ensuring it is accurate, appropriate for your business, and compliant with all applicable laws, regulations, industry standards, and contractual obligations, both now and as they evolve in the future. By using this tool, you acknowledge that responsibility for the content, adequacy, and compliance of any resulting policy rests entirely with you.
Step 1 of 6 · Organization

The basics

These details fill the cover block of the policy. Every field starts blank — anything you skip becomes an editable placeholder in the downloaded document, so you can come back to it later.

Examples:
  • Organization name — Summit IT Solutions
  • Policy owner — Jake Rivera, Service Desk Manager
  • Incident reporting — email security@summitit.com, or open a ticket marked "AI incident"
  • Escalation — the Policy Owner, or any member of leadership

Calculated from the effective date and cadence above. Clear it to recalculate.

Step 2 of 6 · Approved tools

Which AI tools are approved for use?

Check the tools the team is allowed to use — nothing is ticked for you. They become the Approved Tools list — the heart of the policy. Anything not on this list is not approved.

Exercise due care. A tool earns its place on this list the same way any other software does: through the company's existing supply chain and vendor due diligence process. Only select tools that have been properly vetted and approved by your company.

Only check tools used through a company-provided business or corporate account. The policy already prohibits personal or free accounts for work, and bars pasting sensitive data into consumer chat.

Other tools allows you to add other approved tools that have not been listed below.

General-purpose AI assistants— business / enterprise accounts
Specialized & creative AI
AI agent & automation builders— tools you configure to build agents/workflows
AI platforms & APIs— for automations / agents you build
Step 3 of 6 · Prohibited Actions

What must never go into any AI tool

These are your Prohibited Actions — a list the company creates of use cases, data or materials that are not to be used in or with AI. The list is absolute: whatever you add here stays out of every AI tool, approved or not, regardless of account type. The list starts empty — add each item in your own words. For example, you may want to prohibit particular categories of data, or outcomes that should not be AI generated.

If you handle regulated data (health, financial, government, education), your existing policies for that data — HIPAA, GLBA, FERPA, and similar — still govern it. This AI policy doesn't replace them.

Step 4 of 6 · Human in the lead

High-risk use cases

These are your high-risk use cases. Use this section if you have specific defined controls or processes for certain use cases within the business. You can provide more detail and also designate a person who is responsible for such use cases.

Expect increasing regulatory and contractual pressure to define your high-risk activities and use cases — regulators, insurers, and customer contracts are already asking for them. Being able to point to this list, and speak to the escalation controls behind each entry, is fast becoming table stakes.

Examples you can copy:
  • Customer-facing output — Emails, proposals, contracts, reports, social posts.
  • Money decisions — Pricing, billing, refunds, payments, contract terms.
  • People decisions — Hiring, performance, discipline, terminations.
  • Security decisions — Access, configuration, permission changes, incident response calls.
  • Critical infrastructure — Systems affecting operational safety, utilities, or essential services.
  • Legal decisions — Legally privileged topics, legal positions, regulatory or compliance calls.
Step 5 of 6 · Review

The policy

Every section below is in your final document. Core sections — responsible-AI principles, output verification, and training & acknowledgment — are built in for every policy. To remove or reword anything, edit the Word file after download.

Step 6 of 6 · Finish

You've got a solid policy 🎉

Your AI Use Policy is complete and ready to review. A few steps to make it yours and make it official:
  • Make it yours — tweak any wording in the Word file, and fill in the few [bracketed] spots (like the approver's name).
  • Confirm the tool list with your team so nothing in use is missing.
  • Have it reviewed by legal / HR / compliance — this is a strong starting template, not legal advice, so a quick review keeps you covered.
  • Connect it up — make sure your other policies (HIPAA, incident response, acceptable use) reference AI too.
  • Make it official — sign, date, circulate, and hold to the review date.
Prototype · single self-contained file · no internet connection required · built for Pax8 Academy