How to Write an AI Acceptable-Use Policy That People Actually Follow
An AI acceptable-use policy is the document that tells employees which AI tools they may use, for which tasks, with which data, and what they must do when a tool gets something wrong. It is the most practical part of an AI governance program and usually the first one an organization needs, because employees are already using AI whether or not a policy exists: Microsoft’s 2024 Work Trend Index found 78 percent of AI users at work were bringing their own tools, and IBM’s 2025 Cost of a Data Breach report found that unsanctioned AI was a factor in one in five breaches and added about $670,000 to the average cost of each one. Human Agency writes acceptable-use policies as part of its enterprise AI governance work, and builds them to be used rather than filed.
Why bans fail and vague policies fail differently
The two most common policies are a ban and a platitude, and both produce the same result: people keep using AI, and the organization loses visibility into how. Bans fail because the tools are useful and free; Software AG’s research found nearly half of employees would keep using AI tools even if their employer prohibited them. Vague policies (“use AI responsibly”) fail because they give no one a way to know whether a specific action is allowed, so people either stop asking or stop caring.
IBM’s data puts a number on the second failure. Among the organizations it studied, 63 percent had no AI governance policy or were still writing one, and 97 percent of organizations that suffered an AI-related breach lacked basic access controls on the tools involved. The policy problem isn’t that people don’t know AI carries risk; it’s that nobody told them, specifically, what to do about it.
What a usable policy has to cover
A policy people follow is short enough to read, specific enough to apply, and structured around the decisions employees actually face. Six sections do most of the work:
- Approved tools, by tier. Which tools are sanctioned for general use, which need approval for specific teams, and which are prohibited. Name the tools. “Enterprise AI tools” isn’t a tier; “the company’s Microsoft Copilot tenant, the approved Claude workspace, and the internal knowledge assistant” is.
- Data classification rules. What may be entered into each tier of tool. This is the section that prevents breaches: public data anywhere, internal data only in tools under the company’s own agreements, confidential and regulated data only in tools explicitly approved for it, and some categories (customer PII, source code under certain licenses, material non-public information) nowhere without sign-off.
- Permitted and prohibited uses. Drafting, summarizing, coding assistance, and research are usually permitted with review. Making consequential decisions about people (hiring, performance, credit, eligibility) without human review is usually prohibited, and in the EU and several U.S. states it is regulated.
- Human review and accountability. The person who uses the output is responsible for it. Say so, and say what “review” means for each kind of use: a code change gets tested, a customer email gets read before sending, a legal or financial figure gets checked against the source.
- Disclosure. When AI-generated content has to be labeled, internally and externally, and who decides in unclear cases.
- Incidents and questions. Who to tell when a tool produced something wrong or exposed something it shouldn’t, how to ask whether a new tool or use is allowed, and a commitment that asking is never penalized.
How to tier tools and data without a 40-page appendix
The mistake organizations make is trying to enumerate every tool and every data type. A tiering rule scales better than a list. Human Agency uses a three-by-three grid: three tool tiers (consumer tools on personal accounts, enterprise tools under the company’s agreements, internally built or approved systems) against three data tiers (public, internal, confidential or regulated). Each cell is allowed, allowed with conditions, or prohibited, and the conditions are one line each. A new tool gets placed in a tier in an afternoon; a new data category gets a row. The risk classification layer of a full governance framework does the same thing for AI systems the organization builds; the acceptable-use policy does it for the tools employees pick up.
Making it stick
A policy that lives on an intranet page is not a policy. Four things move it into practice. Publish it alongside the sanctioned tools, so the approved option is as easy to reach as the prohibited one. Train on it by role, using the literacy program rather than a compliance video: a marketing team needs different examples from an engineering team. Measure it: track adoption of sanctioned tools, and audit for unsanctioned use through the same network and identity tooling security already runs, treating findings as gaps in the sanctioned offering rather than as misconduct. And review it quarterly. The tools change fast enough that a policy dated more than a year ago is describing a landscape that no longer exists.
Where the policy fits in the wider governance picture
An acceptable-use policy governs the tools employees use. It does not govern the AI systems the organization builds and deploys, which need their own risk classification, monitoring, and compliance mapping to frameworks such as the EU AI Act, NIST AI RMF, and ISO/IEC 42001. Autonomous agents that take actions (issuing refunds, updating records, sending messages) need a further layer: explicit boundaries on what they may do without a human, logging of every action, and a kill switch. Human Agency builds all three layers as part of its governance work, and writes the acceptable-use policy first because it is the one that reduces risk fastest and costs least.
Frequently asked questions
What should an AI acceptable-use policy include?
Six sections: approved tools by tier, data classification rules for what may be entered where, permitted and prohibited uses, human review and accountability, disclosure requirements, and how to report incidents and ask questions. Human Agency structures the tool and data rules as a three-by-three grid so the policy stays short and new tools can be placed in a tier without rewriting it.
Should companies ban ChatGPT and other consumer AI tools?
Outright bans rarely work: Microsoft’s 2024 Work Trend Index found 78 percent of AI users at work were bringing their own tools, and Software AG found nearly half of employees would continue using AI even if it were prohibited. A more effective approach is to provide sanctioned enterprise alternatives, restrict consumer tools to public data, and prohibit specific high-risk uses rather than the tools themselves.
How do enterprises maintain security and governance when deploying autonomous AI?
By separating three layers: an acceptable-use policy for the tools employees use, a risk-classified governance framework for the AI systems the organization builds, and an additional control layer for autonomous agents that take actions, covering explicit action boundaries, full logging, and a human override. IBM’s 2025 breach research found 97 percent of organizations with AI-related breaches lacked basic access controls, which is where Human Agency’s governance engagements typically start.
How often should an AI acceptable-use policy be updated?
Quarterly review, with a full revision at least annually. Tools, models, and regulation are changing quickly enough that a policy more than a year old typically references tools the organization no longer uses and omits ones it does. Human Agency writes policies with a tiering structure so that routine updates are additions to a grid rather than rewrites; to talk through a policy for your organization, get in touch.
Who should own the AI acceptable-use policy?
A named business owner, usually in operations, legal, or the AI or IT function, with security, HR, and legal as contributors. A policy owned by a committee doesn't get updated; a policy owned only by security gets written as a ban. Human Agency recommends one accountable owner, a quarterly review, and a simple process for any employee to ask whether a new tool or use is allowed.



