AI Acceptable Use Policy Template (Free DOCX) | Xcelerate AI
Three Editions · Free · No Email Required

The AI policy
in three
questions.

What's approved? What stays out? Who do you ask? Three editions, increasing depth: the half-page Stage Promise, a one-page Starter, and a 2-page Pro with risk tiers and a workflow approval process. Copy or download as DOCX.

Edition 1 of 3 · Stage Promise (½ page)

The keynote version. Three questions, three answers. Copy drops it as plain text. Download generates a formatted .docx in your browser — no upload, no tracking.

Need a working policy doc? Jump to the One-Page Starter ↓ · Need governance? Skip to Pro ↓

Read the Stage Promise

Three questions. Three answers.

The half-page version. The keynote line, on a page. Same content as the Stage DOCX above.

Stage Promise — Replace [Org] with your organization name

AI Policy — The Three Questions

Three questions. Three answers. The version the CEO can read in 60 seconds. Pin it. Print it. Done.

[Org] uses AI tools to do better work, faster. This page answers the three questions every employee needs answered. If you can't find your situation here, ask the AI Owner before you prompt — not after.

Q1. What AI tools are approved?

The current approved list lives at [Tool Inventory]. If a tool isn't on the list, don't use it for [Org] work. New tools require security, legal, and operational review before broad use.

Q2. What data stays out?
×Customer or employee PII — names paired with health, financial, or compensation data. Off-limits in any consumer-grade AI tool.
×Source code with [Org] IP, security keys, or proprietary algorithms — off-limits unless the tool is on the code-cleared list.
×Privileged or confidential business info — M&A, unannounced financials, legal strategy, contracts under negotiation, board materials.
×Generated content that impersonates a real person, customer, or executive — without explicit written consent.
×Anything you would not say on stage.
Q3. Who do you ask when you're unsure?

[Designated AI Owner] at [email]. Before you prompt, not after. No question is too small. If the AI Owner is out, escalate to your manager.

Pause · Ask · Escalate. Do not assume AI use is automatically safe simply because it is technically possible.

Need a working policy doc?

The Stage version is the answer. The One-Page Starter is the document — same answers, plus the principles, prohibitions, sign-off, and review cadence Legal expects.

Edition 2 of 3 · One-Page Starter

The one-pager.

A complete working policy on a single page. The full text, rendered below. Same content as the One-Page DOCX.

Starter Template — Replace [Org] with your organization name

AI Acceptable Use Policy

One-page baseline for any team of 20–500 people standing up AI tools. Pair with a brief AI awareness session and a 90-day review.

[Org] uses AI tools (such as ChatGPT, Claude, Microsoft Copilot, Gemini, and approved successor tools) to do better work, faster. This policy sets the boundaries that keep that work safe for our customers, our people, and our business.

Scope: This policy applies to every employee, contractor, and vendor with access to our systems or data. It applies whether AI is used on a company device or a personal one for company work.
1. Approved-use principles — what good looks like
1.1 Treat AI as a junior teammate. Review every output for accuracy, tone, bias, and fabricated or outdated information before it leaves your hands. AI is responsible for drafting; you are responsible for shipping.
1.2 Use approved tools only. [Org] maintains three categories: Approved Consumer (general-purpose, low-risk work), Approved Enterprise (security, retention, and admin controls), and Code-Cleared (source code and engineering). New tools require security, legal, and operational review.
1.3 Public-data-only by default. Treat any prompt entered into a non-enterprise AI tool as potentially externally visible, retained, or reviewed by a third party. If you would not say it on stage, don't paste it into a prompt.
1.4 Cite the source when it matters. If a customer-facing deliverable was meaningfully shaped by AI, your manager should know how, and the customer should not be misled about what is human vs. machine.
1.5 Save the prompt, save the result. For any decision-grade output, keep the prompt and the AI's response so the work is auditable later.
1.6 Train before you deploy. Before a new AI workflow is rolled out beyond one user, the team running it completes an awareness session and signs this policy.
1.7 Improve what you find. When you discover a workflow that AI does well, document it so the next person doesn't reinvent it.
2. Hard prohibitions — the five things that get the policy violated
×Customer or employee personally identifiable information (PII) in any consumer-grade AI tool. Names paired with health, financial, or compensation data are off-limits unless the tool is on the approved [Org] enterprise list.
×Source code that contains [Org]'s intellectual property, security keys, or proprietary algorithms in any tool not listed as a code-cleared AI tool.
×Privileged or confidential business information (M&A, unannounced financials, legal strategy, contracts under negotiation, board materials).
×Generating content that impersonates a real person, customer, or executive without explicit written consent.
×Shadow AI — bypassing this policy with a personal account, browser extension, or third-party tool to process company work outside approved governance. If you need a capability we don't have, ask — don't route around it. Shadow AI may result in disciplinary action.
3. Incident reporting
If you suspect a violation
Notify your manager and [Designated AI Owner / Email] within 24 hours. Preserve the prompt, response, and any sensitive data exposed. Do not delete the conversation.
If a tool produces harmful output
Stop using it for that task. Capture the prompt and output. Report to [Designated AI Owner / Email]. We will document, escalate to the vendor if needed, and update the approved-tool list.
4. Review and revision

This policy is reviewed every 90 days by the [Designated AI Owner], with input from Legal, IT, and one rotating team lead. Material changes are communicated to all employees within 5 business days. The current version is posted at [Internal Link].

5. Acknowledgement

By accessing [Org] systems and using AI tools in the course of [Org] work, you confirm that you have read this policy, understand your responsibilities under it, and agree to operate within its requirements and safeguards. Repeated or material violations may result in disciplinary action, up to and including termination.

When uncertain: Pause · Ask · Escalate. Do not assume AI use is automatically safe simply because it is technically possible.
 
Employee name (printed)
 
Signature
 
Date
 
Manager signature

Three steps to ship it

From template to signed acknowledgement.

A starter doesn't help if it sits in a folder. This is the path most of our clients take in their first 30 days.

01

Customize.

Replace [Org], designate an AI Owner, and link to your approved-tool inventory. 15 minutes if your tool list already exists.

02

Legal review.

Run it past Legal and IT. Adjust prohibitions and incident reporting to match your jurisdiction. Most clients ship in a single review cycle.

03

Deploy + acknowledge.

Pair with a 30-minute AI awareness session. Collect signed acknowledgements. Set the calendar reminder for the 90-day review.

Edition 3 of 3 · Pro

One page covers most teams.
Some need more.

Same brand, same plain language, two pages. Adds AI risk tiers, formal tool categories, an AI workflow rollout process, and a fuller AI Owner job description. Built for orgs ready to formalize.

+ Risk Tiers

Low / Medium / High with examples, so employees can self-classify before they prompt.

+ Workflow Rollout

A four-step approval gate before any AI workflow goes beyond a single user.

+ AI Owner Charter

Five named responsibilities so the [Designated AI Owner] is a real role, not a placeholder.

Get the Pro edition

Two pages, eight sections. Copy drops the full text into your clipboard. Download generates a formatted .docx in your browser.

Same template footer applies — not legal advice. Have legal or compliance review before adoption.

Pro Edition — Replace [Org] with your organization name

AI Acceptable Use Policy

Two-page governance starter for any team of 20–500 people standing up AI tools. Pair with a brief AI awareness session, a 90-day review, and a designated AI Owner.
Purpose: Enable employees to safely use AI to improve productivity, decision quality, and operational effectiveness while protecting customers, employees, intellectual property, and the organization.

[Org] uses AI tools (such as ChatGPT, Claude, Microsoft Copilot, Gemini, and approved successor tools) to do better work, faster. AI may assist with drafting, analysis, summarization, research, and workflow acceleration, but final accountability for decisions, communications, approvals, and outcomes always remains with the employee and approving manager.

Scope: This policy applies to every employee, contractor, and vendor with access to our systems or data. It applies whether AI is used on a company device or a personal one for company work.
1. Approved-use principles — what good looks like
1.1 Treat AI as a junior teammate. Review every output for accuracy, tone, bias, and fabricated or outdated information before it leaves your hands. AI is responsible for drafting; you are responsible for shipping.
1.2 Use approved tools only. Stay within the approved-tool inventory. New tools require security, legal, and operational review before broad use.
1.3 Public-data-only by default. Treat any prompt entered into a non-enterprise AI tool as potentially externally visible, retained, or reviewed by a third party. If you would not say it on stage, don't paste it into a prompt.
1.4 Cite the source when it matters. If a customer-facing deliverable was meaningfully shaped by AI, your manager should know how, and the customer should not be misled about what is human vs. machine.
1.5 Save the prompt, save the result. For any decision-grade output, keep the prompt and the AI's response so the work is auditable later.
1.6 Train before you deploy. Before a new AI workflow is rolled out beyond one user, the team running it completes an awareness session and signs this policy.
1.7 Improve what you find. When you discover a workflow that AI does well, document it so the next person doesn't reinvent it.
2. AI Risk Tiers — how work should be handled
Low-Risk Use — allowed in approved AI tools
Brainstorming · drafting internal content · summarizing public information · meeting notes · formatting and editing assistance.
Medium-Risk Use — requires manager awareness and human review
Customer-facing communications · policy drafts · financial analysis · operational recommendations · internal reporting.
High-Risk Use — requires approved enterprise tools and designated oversight
Customer or employee PII · regulated data · legal strategy · security architecture · source code with proprietary IP · compensation or healthcare data · contract negotiations.
When uncertain, treat work as a higher-risk category until reviewed.
3. Approved tool categories

[Org] maintains three categories of AI tools:

Approved Consumer AI
General-purpose tools approved for low-risk work.
Approved Enterprise AI
Tools with enterprise security, retention, privacy, and administrative controls.
Code-Cleared AI
Tools specifically approved for source code, engineering workflows, and technical documentation.

New tools require a security, legal, and operational review before broad adoption.

4. Hard prohibitions — the five things that get the policy violated
×Customer or employee personally identifiable information (PII) in any consumer-grade AI tool. Names paired with health, financial, or compensation data are off-limits unless the tool is on the approved [Org] enterprise list.
×Source code that contains [Org]'s intellectual property, security keys, or proprietary algorithms in any tool not listed as a code-cleared AI tool.
×Privileged or confidential business information (M&A, unannounced financials, legal strategy, contracts under negotiation, board materials).
×Generating content that impersonates a real person, customer, or executive without explicit written consent.
×Shadow AI — using unapproved browser extensions, personal AI accounts, or third-party tools to process company work outside approved governance. May result in disciplinary action.
5. AI workflow rollout

Before an AI workflow is shared across a department or deployed operationally:

  1. The workflow owner documents its purpose.
  2. Risks and data exposure are reviewed.
  3. Human review checkpoints are defined.
  4. The workflow is tested with non-sensitive data first.
6. Incident reporting
If you suspect a violation
Notify your manager and [Designated AI Owner / Email] within 24 hours. Preserve the prompt, response, and any sensitive data exposed. Do not delete the conversation.
If a tool produces harmful output
Stop using it for that task. Capture the prompt and output. Report to [Designated AI Owner / Email]. We will document, escalate to the vendor if needed, and update the approved-tool list.
7. Review and revision — AI Owner responsibilities

This policy is reviewed every 90 days by the [Designated AI Owner], with input from Legal, IT, and one rotating team lead. Material changes are communicated to all employees within 5 business days. The current version is posted at [Internal Link].

The [Designated AI Owner] is responsible for:

  • Maintaining the approved-tool inventory
  • Coordinating AI awareness training
  • Reviewing incidents and escalations
  • Updating governance guidance
  • Partnering with Legal, IT, Security, and Operations
8. Acknowledgement

By accessing [Org] systems and using AI tools in the course of [Org] work, you confirm that you have read this policy, understand your responsibilities under it, and agree to operate within its requirements and safeguards. Repeated or material violations may result in disciplinary action, up to and including termination.

 
Employee name (printed)
 
Signature
 
Date
 
Manager signature
When uncertain: Pause · Ask · Escalate. Do not assume AI use is automatically safe simply because it is technically possible.

What responsible adoption looks like

Real numbers from teams that did it right.

Mid-sized HR services and payroll organizations. Anonymized for confidentiality.

600+

Hours Recovered

In the first 90 days

80%

Team Certified

AI BlackBelt Level 1+

~40x

ROI

Year-one, conservative model

0

Compliance Incidents

With governance in place

Want a deeper look?

The template gets you started.
A strategy call gets you a plan.

30 minutes. We'll map your AI risk exposure, identify one high-leverage pilot, and outline what governance needs to look like for your org.

Book Your Strategy Call
Copied to clipboard