The good news is that this is one of the fastest wins available to any organisation without a full-time CISO. You don’t need a hundred-page document. You need something short enough that people will actually read, clear enough that they know what to do, and specific enough to hold up if something goes wrong. Here’s how to build an AI acceptable use policy.
Why this is the right place to start
The NCSC’s recent guidance on managing shadow AI risk in UK organisations makes a point worth building your whole approach around: the goal isn’t to restrict AI use into hiding, it’s to understand why staff are reaching for these tools and give them a sanctioned way to do it.
Organisations that respond to shadow AI with a flat ban will find usage continuing anyway. Just like the US Government found with prohibition, it will be pushed underground. An AI acceptable use policy that offers a clear, approved path has a far greater chance of actually getting followed.
The mindset to bring into drafting this: not “how do we stop people using their shadow AI tools,” but “how do we make it obvious what’s safe, what isn’t, and what are we going to offer up instead as a viable, low friction option instead.”
AI Acceptable Use Policy: The practical template
Here’s a skeleton you can adapt. Each section should be a paragraph or two, at most. Remember, the goal is a policy people will actually read, not a legal document that sits in a folder unopened.
1. Purpose and scope. One short paragraph. State plainly that this policy governs how employees may use AI tools (including public tools like ChatGPT, Claude, and Copilot, and any AI features built into existing software) in connection with their work, and that it applies to all staff, contractors, and third parties working on company systems or data.
2. Approved tools. List, by name, which AI tools are sanctioned for use, and for what. If your organisation has licensed an enterprise AI product with proper data protections, name it here and make clear it’s the preferred option. If nothing is currently approved, say so honestly, and give a route for staff to request evaluation of a tool rather than leaving them with no legitimate option, this is a step most policies skip, and it’s the one that determines whether shadow AI use actually reduces.
3. Data classification: what can and can’t go in. This is the section that does the real work. Be explicit and concrete rather than abstract. Typically, no client or customer personal data, no employee personal data, no confidential commercial information (e.g. contracts, pricing, strategy, M&A intelligence), no source code or credentials, and no regulated data (health, financial, or otherwise sensitive categories) should ever be entered into a public or unapproved AI tool. Give two or three real examples relevant to your business, people will follow these far better than abstract rules. For instance: “Don’t paste a client contract into ChatGPT to summarize it. Use the approved internal tool [X], or summarize it yourself” reads very differently to staff than an abstract line about “confidential information,” and is far more likely to actually change behaviour at the point it matters.
4. Human review and accountability. State that AI-generated output, whether text, code, analysis, or a decision recommendation must be reviewed by a human before it’s relied upon, sent externally, or used in a decision affecting a customer, employee, or candidate. Make clear that using an AI tool doesn’t transfer accountability for the output away from the employee who used it.
5. Prohibited uses. A short, specific list: no use of AI tools to make final hiring, credit, or disciplinary decisions without human review; no use for anything that would breach a client confidentiality agreement; no bypassing of company security tools to access unapproved AI services; no use of AI to generate content that misrepresents the company or impersonates real individuals.
6. Vendor and third-party AI. A brief note that new software purchases or renewals involving embedded AI features should be flagged to whoever owns AI governance internally, so the same data-handling standards get applied to vendor tools as to tools staff choose themselves.
7. Reporting and incidents. One clear line: if someone realizes they’ve put sensitive data into an AI tool, entered something they shouldn’t have, or spotted a colleague doing so, they should report it immediately, without fear of blame, to a named contact. The point of this section is to surface problems early, not to punish people for coming forward.
8. Training and acknowledgement. State that all staff will receive training on this policy, and that acknowledgement of understanding will be recorded. This record is exactly what a cyber insurer or a regulator will ask to see if something goes wrong.
9. Review cycle. Name a specific interval. Six months is sensible given how fast both the tools and the regulatory landscape are moving and who owns keeping it current.
Making it stick
A policy that exists only as a document nobody’s read isn’t governance, it’s paperwork. Three things turn this template into something real:
First, keep it short enough that a new starter can read the whole thing in five minutes. Length is the single biggest reason policies go unread.
Second, pair it with at least one approved alternative to the tools people are already using informally; a policy that says “don’t” without offering a “do instead” will simply get ignored.
Third, revisit it on a fixed schedule rather than leaving it to gather dust. The tools your staff are using today are not the ones they’ll be using in a year, and a stale policy is barely better than no policy when it’s tested.
It’s also worth deciding, before you roll this out, who actually owns it day to day. A policy with no named owner tends to drift out of date within a couple of review cycles, because nobody’s job depends on keeping it current. That doesn’t need to mean a new hire, it’s exactly the kind of ongoing accountability a vCISO is built to hold, alongside everything else sitting in the wider AI governance programme.
The bottom line
An AI acceptable use policy is genuinely one of the highest-value, lowest-effort steps an organisation without a full-time CISO can take right now. It’s the first thing insurers ask for, the first thing regulators expect to see, and the first real control most organisations are missing. Use the template above as a starting draft, adapt the specifics to how your business actually uses AI, and you’ll have something functional far faster than you’d expect.
CyberKainos helps organisations without a full-time CISO turn a policy template into a governance programme that actually holds up; written, trained on, and reviewed on a schedule. If you’d like a second pair of eyes on your draft AI acceptable use policy, or don’t know where to start, let’s talk.



