Governance & Compliance

AI acceptable-use policy (AUP)

An AI acceptable-use policy sets the rules for AI at work: approved tools, prohibited data, verification duties, and consequences — the written half of AI governance.

An AI AUP tells employees what they may do with AI: which tools are approved at which tiers, what data classes may never enter a prompt, when outputs must be verified, and how to request new tools. Good ones are written for a busy day — short rules, concrete examples — rather than as legal boilerplate.

A policy alone changes little; the pairing that works is policy plus enforcement at the moment of use, so the rule about client data fires as a nudge at the paste, not as a finding in the post-incident review.

Where this shows up

Related terms

See it in your own organization.

Sanitized AI inventories the AI tools in use and redacts sensitive data from prompts before it leaves.

Get a demo