Seed-stage B2B SaaS startup
Sample for a fictional organisation · 2,636 words[Company] AI Acceptable Use Policy
- Version: 1.0
- Owner: CTO
- Approved by: CEO
- Effective date: [Effective date]
- Next review date: [Review date]
1. Purpose and Scope
This policy sets the rules for using artificial intelligence (AI) tools in [Company]'s work: which tools may be used, what information may be entered into them, how their output is checked, and which uses need approval or are never allowed. It sits beneath [Company]'s information security policy, and where another [Company] policy covers the same subject, both apply and the stricter rule applies. [Company] wants AI tools to be used where they help its work, and this policy sets out how that is done safely.
This policy applies to everyone who is given access to [Company]'s systems, accounts or information: employees, contractors and anyone else working on its behalf. This policy calls them staff. It applies to every AI tool used for company work, on any device and whether or not [Company] pays for the tool.
- AI tool: software or a service that uses artificial intelligence to produce text, code, images, audio or video, to transcribe or translate, or to take actions for a person. It includes a chat assistant, a coding assistant, a meeting note-taker, an AI feature inside software [Company] already uses, a browser extension that uses AI, and an AI agent.
- AI agent: an AI tool that can take actions in other systems for a person, such as sending messages, changing records or running commands.
- Register: the list of AI tools approved for company work, which section 3 describes.
- Customer data: information that [Company] holds for or about its customers.
3. Approved AI Tools
- Staff must use an AI tool for company work only where it is on the register, and only with the kinds of information the register allows for it.
- Staff must use an AI tool that is on the register only through an account that [Company] provides or that the register names, and must never use a personal account with an AI tool for company work.
- An AI feature that is added to or switched on in software [Company] already uses, and a connector, plug-in or browser extension that gives an AI tool access to other systems, each count as an AI tool of their own and must be on the register before they are used.
- Staff ask for an AI tool to be added to the register by writing to the CTO with what the tool is, what it would be used for and what information would be entered into it, and the CTO makes sure each request is answered within 10 working days.
- Before approving an AI tool, the CTO makes sure its supplier's terms have been checked for whether the supplier may use what staff enter, or what the tool produces, to train its models, for how long the supplier keeps that information, and for where the supplier processes it.
- The CTO approves an AI tool for personal data or customer data only where its supplier's terms do not let the supplier use that information to train its models.
- The CTO makes sure the register records, for each AI tool, what it is, the account or plan it is approved on, the kinds of information that may be entered into it, each use approved under section 5 and the date of approval. The register may be kept as part of a wider inventory of [Company]'s AI systems.
- The CTO makes sure the register is available to all staff, is reviewed at least every 6 months and whenever a supplier changes its terms, and no longer lists a tool that does not meet this policy.
4. What May Be Entered into an AI Tool
The table shows what information may be entered into an AI tool.
| Kind of information | Where it may be entered |
|---|---|
| Information [Company] has made public, and any other information that is not in a row below | Any AI tool on the register |
| Confidential information, personal data and customer data | Only an AI tool that the register shows as approved for that kind of information |
| Information that a contract or other agreement says must not be used with AI | No AI tool |
Entering information includes typing or pasting it, uploading a file, speaking it to a tool, and connecting a tool to an account, a folder or a system that holds it. Where information fits more than one row, the stricter row applies. Confidential information is anything [Company] has not made public whose release could harm [Company] or anyone it works with or for. A use that involves personal data or customer data also needs approval under section 5, which may be given for a kind of use.
Read the full example
[Company] AI Acceptable Use Policy
- Version: 1.0
- Owner: CTO
- Approved by: CEO
- Effective date: [Effective date]
- Next review date: [Review date]
1. Purpose and Scope
This policy sets the rules for using artificial intelligence (AI) tools in [Company]'s work: which tools may be used, what information may be entered into them, how their output is checked, and which uses need approval or are never allowed. It sits beneath [Company]'s information security policy, and where another [Company] policy covers the same subject, both apply and the stricter rule applies. [Company] wants AI tools to be used where they help its work, and this policy sets out how that is done safely.
This policy applies to everyone who is given access to [Company]'s systems, accounts or information: employees, contractors and anyone else working on its behalf. This policy calls them staff. It applies to every AI tool used for company work, on any device and whether or not [Company] pays for the tool.
- AI tool: software or a service that uses artificial intelligence to produce text, code, images, audio or video, to transcribe or translate, or to take actions for a person. It includes a chat assistant, a coding assistant, a meeting note-taker, an AI feature inside software [Company] already uses, a browser extension that uses AI, and an AI agent.
- AI agent: an AI tool that can take actions in other systems for a person, such as sending messages, changing records or running commands.
- Register: the list of AI tools approved for company work, which section 3 describes.
- Customer data: information that [Company] holds for or about its customers.
2. Roles and Responsibilities
- The CTO: keeps this policy and reviews it under section 14; approves AI tools and makes sure the register is kept under section 3; decides or passes on requests under section 5; approves connections and AI agents under section 9; approves tests of [Company]'s security under section 10; approves, or designates a senior manager to approve, each review under section 11; decides under section 12 whether a report is a security incident; and approves exceptions under section 14.
- All staff: follow this policy whenever they use an AI tool for company work, check and remain responsible for what they produce with one, and report problems under section 12.
3. Approved AI Tools
- Staff must use an AI tool for company work only where it is on the register, and only with the kinds of information the register allows for it.
- Staff must use an AI tool that is on the register only through an account that [Company] provides or that the register names, and must never use a personal account with an AI tool for company work.
- An AI feature that is added to or switched on in software [Company] already uses, and a connector, plug-in or browser extension that gives an AI tool access to other systems, each count as an AI tool of their own and must be on the register before they are used.
- Staff ask for an AI tool to be added to the register by writing to the CTO with what the tool is, what it would be used for and what information would be entered into it, and the CTO makes sure each request is answered within 10 working days.
- Before approving an AI tool, the CTO makes sure its supplier's terms have been checked for whether the supplier may use what staff enter, or what the tool produces, to train its models, for how long the supplier keeps that information, and for where the supplier processes it.
- The CTO approves an AI tool for personal data or customer data only where its supplier's terms do not let the supplier use that information to train its models.
- The CTO makes sure the register records, for each AI tool, what it is, the account or plan it is approved on, the kinds of information that may be entered into it, each use approved under section 5 and the date of approval. The register may be kept as part of a wider inventory of [Company]'s AI systems.
- The CTO makes sure the register is available to all staff, is reviewed at least every 6 months and whenever a supplier changes its terms, and no longer lists a tool that does not meet this policy.
4. What May Be Entered into an AI Tool
The table shows what information may be entered into an AI tool.
| Kind of information | Where it may be entered |
|---|---|
| Information [Company] has made public, and any other information that is not in a row below | Any AI tool on the register |
| Confidential information, personal data and customer data | Only an AI tool that the register shows as approved for that kind of information |
| Information that a contract or other agreement says must not be used with AI | No AI tool |
Entering information includes typing or pasting it, uploading a file, speaking it to a tool, and connecting a tool to an account, a folder or a system that holds it. Where information fits more than one row, the stricter row applies. Confidential information is anything [Company] has not made public whose release could harm [Company] or anyone it works with or for. A use that involves personal data or customer data also needs approval under section 5, which may be given for a kind of use.
5. Uses That Need Approval First
- A use of an AI tool that affects customers, staff or the public, or that involves personal data or customer data, needs approval under this section before it starts, even where the tool is on the register.
- The person who wants to start a use that needs this approval sends the CTO a short description of the use, of who it could affect and of how.
- The CTO decides each request for this approval, or passes it to a more senior role or a group of senior roles where [Company] has given that decision to one, and makes sure the decision is recorded in the register.
- An approval under this section may cover a kind of use, such as drafting replies to support requests, for a team or for all staff.
- Staff must not use an AI tool to make or recommend a decision that has a legal or similarly significant effect on a person, such as a decision on hiring, pay, promotion, discipline or dismissal, unless the use is approved under this section and a person with the authority and knowledge to overrule the tool reviews each case and can change the outcome.
- A person who reviews a case in which an AI tool was used must not simply approve what the tool produced.
- Any other use of an AI tool that is on the register, such as drafting a summary of a public document, needs no approval under this section.
6. Checking AI Output
- Staff remain responsible for the work they produce with an AI tool, as they are for any other work.
- Staff must check AI output for accuracy before relying on it or sending it outside [Company], including its facts, figures, names, quotations and references.
- Staff must not use AI output in a contract, in legal or financial advice, or in a statement about [Company]'s security or compliance until a person qualified to judge it has reviewed it.
- Staff must not use AI output that they know or suspect copies someone else's text, images, code or other protected work without permission to use that work.
- Staff must review and test code that an AI tool writes as they would code written by a person, and must not merge code they cannot explain.
- Staff must not turn off or work around [Company]'s code review, testing or security checks in order to use an AI tool.
7. Saying When AI Was Used
- Staff must not present material made with an AI tool and sent outside [Company] as unaided human work where that would mislead the person who receives it.
- Staff must answer truthfully when anyone asks whether an AI tool was used in a piece of work.
- Staff who share a summary, a transcript or a translation that an AI tool made must say that an AI tool made it.
- The person who makes a decision about someone with the help of an AI tool makes sure that person is told that AI was used, without waiting to be asked.
- Staff need not say that an AI tool was used for routine help, such as correcting spelling, grammar or wording.
8. AI in Meetings
- Staff must use only an AI tool that is on the register to record or transcribe a meeting or a call, or to write notes of one.
- Before recording or transcription starts, the person who starts it must tell everyone in the meeting or call that an AI tool is in use, and must not use it where anyone objects.
- Staff must follow any further requirement that the law of the place where a participant is sets for recording a conversation.
- The person hosting a meeting must remove an AI tool that is not on the register, or ask the participant who brought it to turn it off.
- Staff must not use an AI tool to record, transcribe or take notes of a meeting about a named person's health, pay, performance or discipline, or a meeting in which legal advice is given, unless that use is approved under section 5.
- Staff must check notes made by an AI tool before relying on them or sharing them, and must delete a recording or transcript when it is no longer needed for company work.
9. AI Agents and Connected Tools
- Staff must not connect an AI tool to [Company]'s email, files or other systems, or let an AI agent act for them, unless the CTO has approved it and the register records it.
- Each approved AI agent has a named person who is responsible for what it does.
- The CTO approves a connection or an AI agent only with the least access it needs, and with read-only access where that is enough.
- A person must approve each action before an AI agent sends a message outside [Company], makes or approves a payment, deletes records or changes anyone's access, unless the CTO has approved that kind of action for that AI agent and the register records it.
- The person responsible for an AI agent must stop it, and report under section 12, where it does something it was not approved to do.
10. Uses That Are Never Allowed
No exception under section 14 is given to a rule in this section.
- Staff must not type, paste or upload a password, an access key or any other credential into an AI tool.
- Staff must not use an AI tool to impersonate a real person, or to make audio, images or video that show a real person saying or doing something they did not say or do, without that person's agreement.
- Staff must not use an AI tool to get around a security control or to write malicious software.
- Staff must not use an AI tool to harass, deceive or discriminate against anyone.
The rules in this section on getting around a security control, writing malicious software and deceiving anyone, but not the rule on impersonating or depicting a real person, do not apply to a test of [Company]'s own security that the CTO has approved in writing.
11. Monitoring of AI Use
[Company] may monitor the use of AI tools on its systems and accounts, including which tools are used, by whom and how often, and may block access to AI tools that are not on the register.
[Company] reviews what a person has entered into an AI tool, or what a tool has produced for them, only where there is a specific reason, such as continuing work when someone is away or has left, investigating a security incident, or a suspected breach of this policy or the law. Each review is approved by the CTO or a senior manager the CTO has designated, and the reason is recorded.
Where the law of the place where a member of staff works requires [Company] to give notice, to consult employee representatives or to take any other step before it monitors the use of AI tools, [Company] takes that step first.
12. Reporting Problems
Staff must report each of the following to [Security contact email] immediately, and in any case within 24 hours.
- Information has been entered into an AI tool that section 4 does not allow to be entered there.
- An AI tool or an AI agent has done something it was not approved to do.
- AI output that was wrong or harmful has been sent outside [Company], or has been relied on for a decision about a person or about [Company]'s security or finances.
- An AI tool that is not on the register is being used for company work.
Staff who report promptly and in good faith are not penalized for reporting, and hiding a mistake is itself a breach of this policy. The CTO decides whether a report is a security incident, and [Company]'s incident reporting process then applies. Staff may raise any other concern about how AI is used at [Company] with the CTO or through any other route [Company] gives for concerns about AI.
13. Training and Awareness
- Everyone in scope reads and acknowledges this policy when it takes effect or when they join, before they use an AI tool for company work, and again after any material change and at least every 12 months.
- [Company] keeps a record of who has acknowledged this policy, with the date and the policy version.
- [Company] gives staff who use an AI tool for company work training in using AI tools safely that suits their role and the people their use of AI affects, when they start to use one and at least every 12 months, and keeps a record of who has completed it.
14. Exceptions, Breaches and Review
An exception to this policy, other than to section 10, is requested from and approved in writing by the CTO, with the reason and any conditions recorded, and lasts no longer than 12 months unless the CTO renews it.
A breach of this policy may lead to access to AI tools or to other company systems being restricted or removed, and to disciplinary action up to dismissal, in line with [Company]'s disciplinary process and the employment law of the country where the person works; for contractors and other non-employees it may lead to the engagement ending.
The CTO reviews this policy at least every 12 months and after any significant change, such as a new kind of AI tool, a change in a supplier's terms, a change in the law or a security incident, and each change is approved by the CEO.
Disclaimer
This document is provided for informational purposes only and does not constitute legal advice. It is provided "as is", without warranty of any kind, express or implied, and no liability is accepted for any loss or damage arising from its use. It is used at your own discretion. Review it with a qualified adviser before adopting it.