Skip to main content
Phyllogic AI

Free AI acceptable use policy template for small businesses

Set clear AI rules

Your team is probably already using AI. This free template gives them clear rules: which tools are approved, what data never goes in, and when a person has to review the output. Read it below, or download an editable copy.
Download the template

Editable .rtf file. Opens in Word, Google Docs, or Pages.

How to use this template

  • This is a starting point, not legal advice. Have your attorney or HR advisor review it before you adopt it, especially if you handle regulated data such as health, financial, or legal records.
  • Replace every [bracketed placeholder] with your own details, and delete any line that doesn't fit how your business works.
  • Keep it short and plain. A policy your team actually reads beats a longer one nobody opens.
  • Walk your team through it in person, collect a signed acknowledgment from each employee, and set a date to review it.

The template: AI Acceptable Use Policy

1. Purpose and scope

[Company Name] uses AI tools to help our people work faster and better, not to replace their judgment. This policy explains which AI tools we use, what information may and may not go into them, and when a person must review AI output.

This policy applies to all employees, contractors, and interns who use AI tools for [Company Name] work, on any device, including personal phones and home computers.

2. Approved tools

Only the following AI tools may be used for company work, and only through company-provided accounts:

  • [Approved Tool 1] (company account) for [approved uses, e.g. drafting emails, summarizing documents]
  • [Approved Tool 2] (company account) for [approved uses]
  • AI features built into [Approved Software, e.g. our email, accounting, or document software], using company accounts
  • To request a new tool, email [Policy Owner] with the tool name, what you want to use it for, and what data it would touch. Do not use it for work until it's approved.
  • [Policy Owner] reviews the vendor's current terms (data use for training, retention, admin controls, access management) before approving, and keeps this list current.

3. Data that must never go into AI tools

Never enter the following into any AI tool, including approved ones, unless [Policy Owner] has approved a specific process in writing:

  • Social Security numbers, driver's license numbers, passport numbers, or other government ID numbers
  • Bank account, routing, or credit card numbers
  • Passwords, PINs, security questions and answers, API keys, or other login credentials
  • Health or medical information about anyone
  • Employee records, including pay, performance reviews, disciplinary notes, or background checks
  • [Other restricted data specific to your business, e.g. trade secrets, pending deal terms]

4. Data allowed only in approved business tools

The following may be used only in approved tools with company accounts, never in personal or free accounts:

  • Client and customer names, contact details, and correspondence
  • Internal documents, procedures, and non-public company information
  • Confidential client files, contracts, or financials, only when our agreement with that client allows it
  • Remove or replace names and numbers with placeholders ("Client A," "[Amount]") whenever the task doesn't need the real details.
  • Share only what the task needs. Don't upload a whole file when a paragraph will do.

5. Human review

AI drafts; people decide. A person must review and approve AI output before it is used in any of these areas:

  • Anything sent to customers, clients, vendors, or the public
  • Financial figures, invoices, reports, or anything used to make a financial decision
  • Anything with legal effect, such as contracts, terms, or compliance statements
  • HR matters, including job postings, hiring, performance, or discipline
  • The person who sends or uses AI-assisted work is responsible for it, just as if they wrote it themselves.

6. Accuracy and attribution

  • AI tools can be confidently wrong. Check facts, figures, names, dates, and citations before relying on them.
  • Don't present AI output as a verified fact, a professional opinion, or another person's words without checking it.
  • Don't use AI to create content that copies someone else's work, imitates a real person, or could mislead a customer.
  • [Optional: Note when content was AI-assisted, e.g. "Tell clients when a deliverable was drafted with AI, if asked."]

7. Confidentiality and client consent

  • Our confidentiality obligations to clients apply to AI tools the same way they apply to email or file sharing.
  • If a client contract limits how their information may be used or shared, follow that contract. When in doubt, ask [Policy Owner] before using AI on that client's work.
  • [If applicable: Get client consent before using AI tools on their confidential information, and record it in [Location].]

8. Accounts and access

  • Use only company-provided accounts for work. Never use personal or free AI accounts for company or client information.
  • Turn on multi-factor authentication (MFA) for every AI tool account.
  • Don't share your AI account with anyone else.
  • When connecting AI tools to email, files, or other systems, grant only the access the task needs.
  • When someone leaves [Company Name] or changes roles, [Policy Owner or IT Contact] removes or updates their AI tool access on their last day.

9. Reporting mistakes and incidents

  • If you put restricted information into an AI tool, or notice AI output that is wrong, inappropriate, or contains information it shouldn't, tell [Policy Owner] right away at [Contact Email or Phone].
  • Report it even if you're not sure it matters. Fast reporting lets us limit any harm.
  • We treat honest mistakes, reported promptly, as a chance to improve, not as grounds for blame.

10. Training

  • Everyone covered by this policy completes AI training before using AI tools for work, and a refresher [annually / when tools change].
  • Training covers our approved tools, the never-enter list, redaction habits, and human review.
  • Questions about using AI well are welcome any time. Ask [Policy Owner].

11. Policy owner and review

  • Policy owner: [Policy Owner Name, Title]
  • Effective date: [Date]
  • This policy is reviewed at least every [6 / 12] months, and whenever we add a new AI tool or our tools' terms change.
  • Violations of this policy may lead to loss of AI tool access and other action under [Company Name]'s existing workplace policies.

12. Employee acknowledgment

I have read and understand the [Company Name] AI Acceptable Use Policy, and I agree to follow it.

Name: ____________________ Signature: ____________________ Date: __________

Want help choosing tools and training your team on the policy? See Team AI Training, or read Is ChatGPT safe for client data?

Questions about AI policies

Find your lost hours

Book a free 30-minute discovery call. We'll talk through where your team's time goes and whether AI can help. No pitch, no pressure.