An AI acceptable use policy gives employees clear rules without preventing sensible experimentation.
Define the policy scope
Specify who the policy covers, which tools are approved and whether the rules apply to personal devices, free accounts and third-party integrations.
Set information-handling boundaries
Explain which categories of customer, employee and confidential data may be entered into approved systems, and who can authorise exceptions.
Require human review
Make clear that employees remain accountable for the accuracy, fairness and appropriateness of AI-assisted work. Introduce additional checks for legal, financial, HR or customer-impacting outputs.
Address security and supplier risks
Require appropriate access controls, MFA where supported, procurement review and reporting of suspected data exposure or malicious AI output.
Review and train
Assign a policy owner, communicate changes and review the policy when tools, contracts, laws or business processes change.
Book cybersecurity and AI training
Learn these skills with Matthew Southgate in our combined full-day course. View and book upcoming training events, or register interest in the online training course.