Back to Home

Free Tool

Draft your AI acceptable-use policy

Six questions, one working draft, written for how AI is actually used at work, ready for counsel to adapt. No email gate; your answers never leave this page.

01

Your industry

02

Your default posture on AI tools

03

Tools you approve

Select all that apply

04

Data that must never enter an AI tool

Select all that apply

05

Personal AI accounts for work content

06

Uploading work files to AI tools

Your draft

Answer the six questions and your draft appears here, live.

DRAFT: for internal review

Acceptable Use of AI Tools

Purpose

This policy lets our people use AI tools productively while keeping client, customer, and company data under our control. It is written to be followed on a busy day, not just filed.

Scope

This policy applies to everyone who works here, including employees, contractors, and students, on any device where work content is handled. "AI tools" means any external service that takes a prompt, file, or query: chatbots, coding assistants, transcription services, and AI features inside other products.

Personal AI accounts must not be used for work content of any kind.

Approved tools

The following tools are approved for work use:

  • ChatGPT
  • Microsoft Copilot

Other AI tools may be used provided the data rules below are followed and usage remains visible to the organization.

Data that must never enter an AI tool

Regardless of tool, the following must never be typed, pasted, or uploaded into an AI service:

  • Personal identifiers: names tied to client, customer, or employee records; government IDs; dates of birth.
  • Contact details: personal or client emails, phone numbers, home addresses.
  • Financial data: card and account numbers, payroll, client returns, valuations.
  • Health information: diagnoses, health card numbers, clinical or intake notes.
  • Credentials: API keys, passwords, access tokens, connection strings.
  • Intellectual property: source code, designs, draft patent material, deal data.

When in doubt, leave it out, or replace specifics with placeholders before prompting.

File uploads

Work files (documents, spreadsheets, presentations, PDFs) must not be uploaded to AI tools.

What we expect in the moment

Look at what's in the prompt before sending. Prefer placeholder versions of real data. If a prompt is stopped, read the reason. The explanation is training, not punishment. Unsure whether something is sensitive? Ask before sending.

Enforcement

Prompts are checked at submission; restricted data is redacted automatically where possible, and policy events are logged for governance, not for reading conversations. Repeated deliberate circumvention is handled under existing conduct policies.

A note on realism: the data rules above only work if something checks the prompt at the moment of submission. If enforcement is manual, treat that as this policy's open gap.

If something slips

If you suspect sensitive data entered an AI tool, tell [POLICY OWNER] immediately, and include what was submitted, where, and when. Fast, blame-free reporting is the difference between an incident record and a breach investigation.

Ownership and review

This policy is owned by [POLICY OWNER] and reviewed every six months, because AI tooling changes faster than annual cycles. Last reviewed: [DATE].

Generated with the Sanitized Ai policy tool as a starting draft. It is not legal advice. Have counsel adapt it to your jurisdiction and obligations.