Home/Blog/AI governance
AI governance · 5 October 2026 · 7 min read

Building an AI Acceptable Use Policy

A practical template for SMEs

AI Acceptable Use Policy
If your organisation doesn’t have a documented AI acceptable use policy yet, you’re not alone, and you’re not as far behind as it might feel.What you are though is exposed, but in a very specific and fixable way. It needs to be assumed that your staff are already using AI tools, (with or without your permission), and governance bodies and insurers are watching this space. They will all start with the same question: is there a clear, practical AI acceptable use policy in place?

The good news is that this is one of the fastest wins available to any organisation without a full-time CISO. You don’t need a hundred-page document. You need something short enough that people will actually read, clear enough that they know what to do, and specific enough to hold up if something goes wrong. Here’s how to build an AI acceptable use policy.

Why this is the right place to start

The NCSC’s recent guidance on managing shadow AI risk in UK organisations makes a point worth building your whole approach around: the goal isn’t to restrict AI use into hiding, it’s to understand why staff are reaching for these tools and give them a sanctioned way to do it.

Organisations that respond to shadow AI with a flat ban will find usage continuing anyway. Just like the US Government found with prohibition, it will be pushed underground. An AI acceptable use policy that offers a clear, approved path has a far greater chance of actually getting followed.

The mindset to bring into drafting this: not “how do we stop people using their shadow AI tools,” but “how do we make it obvious what’s safe, what isn’t, and what are we going to offer up instead as a viable, low friction option instead.”

AI Acceptable Use Policy: The practical template

Here’s a skeleton you can adapt. Each section should be a paragraph or two, at most. Remember, the goal is a policy people will actually read, not a legal document that sits in a folder unopened.

1. Purpose and scope. One short paragraph. State plainly that this policy governs how employees may use AI tools (including public tools like ChatGPT, Claude, and Copilot, and any AI features built into existing software) in connection with their work, and that it applies to all staff, contractors, and third parties working on company systems or data.

2. Approved tools. List, by name, which AI tools are sanctioned for use, and for what. If your organisation has licensed an enterprise AI product with proper data protections, name it here and make clear it’s the preferred option. If nothing is currently approved, say so honestly, and give a route for staff to request evaluation of a tool rather than leaving them with no legitimate option, this is a step most policies skip, and it’s the one that determines whether shadow AI use actually reduces.

3. Data classification: what can and can’t go in. This is the section that does the real work. Be explicit and concrete rather than abstract. Typically, no client or customer personal data, no employee personal data, no confidential commercial information (e.g. contracts, pricing, strategy, M&A intelligence), no source code or credentials, and no regulated data (health, financial, or otherwise sensitive categories) should ever be entered into a public or unapproved AI tool. Give two or three real examples relevant to your business, people will follow these far better than abstract rules. For instance: “Don’t paste a client contract into ChatGPT to summarize it. Use the approved internal tool [X], or summarize it yourself” reads very differently to staff than an abstract line about “confidential information,” and is far more likely to actually change behaviour at the point it matters.

4. Human review and accountability. State that AI-generated output, whether text, code, analysis, or a decision recommendation must be reviewed by a human before it’s relied upon, sent externally, or used in a decision affecting a customer, employee, or candidate. Make clear that using an AI tool doesn’t transfer accountability for the output away from the employee who used it.

5. Prohibited uses. A short, specific list: no use of AI tools to make final hiring, credit, or disciplinary decisions without human review; no use for anything that would breach a client confidentiality agreement; no bypassing of company security tools to access unapproved AI services; no use of AI to generate content that misrepresents the company or impersonates real individuals.

6. Vendor and third-party AI. A brief note that new software purchases or renewals involving embedded AI features should be flagged to whoever owns AI governance internally, so the same data-handling standards get applied to vendor tools as to tools staff choose themselves.

7. Reporting and incidents. One clear line: if someone realizes they’ve put sensitive data into an AI tool, entered something they shouldn’t have, or spotted a colleague doing so, they should report it immediately, without fear of blame, to a named contact. The point of this section is to surface problems early, not to punish people for coming forward.

8. Training and acknowledgement. State that all staff will receive training on this policy, and that acknowledgement of understanding will be recorded. This record is exactly what a cyber insurer or a regulator will ask to see if something goes wrong.

9. Review cycle. Name a specific interval. Six months is sensible given how fast both the tools and the regulatory landscape are moving and who owns keeping it current.

Making it stick

A policy that exists only as a document nobody’s read isn’t governance, it’s paperwork. Three things turn this template into something real:

First, keep it short enough that a new starter can read the whole thing in five minutes. Length is the single biggest reason policies go unread.

Second, pair it with at least one approved alternative to the tools people are already using informally; a policy that says “don’t” without offering a “do instead” will simply get ignored.

Third, revisit it on a fixed schedule rather than leaving it to gather dust. The tools your staff are using today are not the ones they’ll be using in a year, and a stale policy is barely better than no policy when it’s tested.

It’s also worth deciding, before you roll this out, who actually owns it day to day. A policy with no named owner tends to drift out of date within a couple of review cycles, because nobody’s job depends on keeping it current. That doesn’t need to mean a new hire, it’s exactly the kind of ongoing accountability a vCISO is built to hold, alongside everything else sitting in the wider AI governance programme.

The bottom line

An AI acceptable use policy is genuinely one of the highest-value, lowest-effort steps an organisation without a full-time CISO can take right now. It’s the first thing insurers ask for, the first thing regulators expect to see, and the first real control most organisations are missing. Use the template above as a starting draft, adapt the specifics to how your business actually uses AI, and you’ll have something functional far faster than you’d expect.

CyberKainos helps organisations without a full-time CISO turn a policy template into a governance programme that actually holds up; written, trained on, and reviewed on a schedule. If you’d like a second pair of eyes on your draft AI acceptable use policy, or don’t know where to start, let’s talk.

Keep reading

More insights

View all posts →

Talk to a vCISO

Need help turning these insights into action? Talk to our team.