Answer a short set of questions and download a ready-to-adopt AI Use Policy in Word or PDF. To be successful:
A blue box like this one sits at the top of every step. It explains what that step does and, where it helps, lists example wording you can copy or adapt. Examples only ever appear in the blue box — nothing is pre-filled or pre-ticked for you, so the policy says exactly what you decide it says.
Everything you type stays in your browser — nothing is uploaded or sent anywhere. You can edit every word of the finished policy in Word after you download it.
These details fill the cover block of the policy. Every field starts blank — anything you skip becomes an editable placeholder in the downloaded document, so you can come back to it later.
Examples:Calculated from the effective date and cadence above. Clear it to recalculate.
Tick the tools the team is allowed to use — nothing is ticked for you. They become the Approved Tools list — the heart of the policy. Anything not on this list is not approved.
Exercise due care. A tool earns its place on this list the same way any other software does: through the company's existing supply chain and vendor due diligence process. Only select tools that have been properly vetted and approved by your company.
Only check tools used through a company-provided business or corporate account. The policy already prohibits personal or free accounts for work, and bars pasting sensitive data into consumer chat.
Other tools allows you to add other approved tools that have not been listed below.
These are your Prohibited Actions — a list the company creates of use cases, data or materials that are not to be used in or with AI. The list is absolute: whatever you add here stays out of every AI tool, approved or not, regardless of account type. The list starts empty — add each item in your own words. For example, you may want to prohibit particular categories of data, or outcomes that should not be AI generated.
If you handle regulated data (health, financial, government, education), your existing policies for that data — HIPAA, GLBA, FERPA, and similar — still govern it. This AI policy doesn't replace them.
These are your high-risk use cases. Use this section if you have specific defined controls or processes for certain use cases within the business. You can provide more detail and also designate a person who is responsible for such use cases.
Expect increasing regulatory and contractual pressure to define your high-risk activities and use cases — regulators, insurers, and customer contracts are already asking for them. Being able to point to this list, and speak to the escalation controls behind each entry, is fast becoming table stakes.
Examples you can copy: