AI Best Practices: What to Include in an AI Acceptable Use Policy

AI tools like ChatGPT, Claude, Gemini, and Grok can save your team a lot of time. But without clear rules, employees may paste confidential data into public tools, trust AI output that turns out to be wrong, or use AI in ways that put your compliance at risk.

That's why one of the most important AI best practices is to implement an AI Acceptable Use Policy before you roll out AI across your organization. This is part two of our four-part AI best practices series. Here's what your policy should include.

1. Purpose and Scope

Start by defining what your organization will use AI for and who the policy applies to. This sets expectations and gives employees a clear reference point for everything that follows.

2. Approved Tools List

There are many AI tools and large language models (LLMs) out there. Your policy should spell out which LLMs and AI tools employees are allowed to use, such as Claude, ChatGPT, Gemini, or Grok, and make clear that anything not on the list is off-limits until it's reviewed and approved.

3. Data Classification and Handling Rules

This is one of the most critical sections. Define which types of data can and cannot be entered into an AI tool. For example:

  • Never enter highly confidential information or intellectual property into an LLM.
  • Redact any sensitive information before using it with an AI tool.
  • Tie these rules to your existing data classification levels so employees know exactly what's allowed.

4. Identity, Access, and Technical Controls

Decide who is allowed to use AI tools and what technical controls you'll put in place to enforce the policy. This becomes even more important with agentic AI, which can take actions on its own. We cover our recommendations for securing AI agents in part four of this series.

5. Prohibited Uses and Human Oversight

List the ways AI must not be used. The biggest one: never take the output of any LLM or AI engine at face value.

AI is known to hallucinate and can get things very, very wrong. Every piece of AI-generated content must be reviewed by a human and checked for accuracy before it's used or sent out. Nothing should go out the door without human oversight.

6. Confidentiality, Intellectual Property, and Third-Party Data

Explain how employees must protect confidential information, your company's intellectual property, and any third-party data you're responsible for, such as client or vendor information, when using AI tools.

7. Compliance Mapping

If your organization must comply with regulations such as CUI/CMMC, PCI, or HIPAA, your policy should map those requirements to AI use. Spell out the scenarios where AI can be used and the scenarios where it cannot.

8. Incident Reporting

See something, say something, do something. If something seems off, or an employee accidentally uploads sensitive data like financial information, they need to report it right away.

Make it clear that reporting a mistake is always better than hiding it. Ignoring a problem and hoping no one notices is a really bad idea.

9. Training and Acknowledgment

AI is a wonderful tool, but it's a double-edged sword. Used incorrectly, it can be dangerous. Make sure every employee is trained on the policy and signs an acknowledgment that they've read and understand it.

10. Governance and Review

Decide who is responsible for monitoring AI use, how you'll keep a log of activity, and how often the policy will be reviewed and updated as AI tools continue to change.

11. Enforcement

Finally, define what happens if someone doesn't follow the policy. Will they lose access to AI tools? Receive a written warning? Clear consequences help make the policy stick.

The Bottom Line

A solid AI Acceptable Use Policy should cover:

  • Purpose and scope
  • Approved tools list
  • Data classification and handling rules
  • Identity, access, and technical controls
  • Prohibited uses and human oversight
  • Confidentiality, IP, and third-party data
  • Compliance mapping (CUI/CMMC, PCI, HIPAA)
  • Incident reporting
  • Training and acknowledgment
  • Governance and review
  • Enforcement

Have an acceptable use policy in place before you implement any AI.

Need Help Creating an AI Acceptable Use Policy?

ADS Consulting Group can customize an AI Acceptable Use Policy for your company, including the compliance requirements that apply to your industry. Email us at info@adscon.com or book a free discovery call.

Prefer video? Watch the full discussion on our YouTube channel.

Ai

Get updated on the latest Information Technology news, Cybersecurity, Information Technology Trends, and recent real-world troubleshooting experiences.

SUBSCRIBE NOW!