Writing an AI Acceptable-Use Policy That People Follow
A usable AI acceptable-use policy fits on one page, names approved tools, lists data that must never be entered, and offers a sanctioned alternative, because outright bans fail, with 45–46% of workers finding workarounds (Unseen Security, 2025).
Why “just ban it” policies fail
Bans fail because demand for AI outpaces enforcement: 45–46% of workers find workarounds for blocked tools, and in some environments employees reinstall revoked apps over 1,000 times a year (Unseen Security, 2025). Prohibition drives usage underground, not away.
The data is unambiguous: providing an approved alternative reduces unauthorized AI use by up to 89%, while a pure ban leaves you with 59% shadow-AI usage you cannot see (Unseen Security, 2025). A good policy channels behavior; it does not pretend it can stop it.
What a one-page policy must include
A functional policy covers five things: approved tools, prohibited data types, disclosure requirements, human-review triggers, and consequences. Anything longer than a page rarely gets read, let alone followed.
- Approved tools list, the specific AI products staff may use, and the default answer (“ask first”) for anything not on it.
- Prohibited data, client PII, health records, financials, source code, and anything under NDA never go into an unapproved model.
- Disclosure, when AI-generated content must be labeled internally or to clients.
- Human review triggers, which outputs require sign-off before use (legal, medical, financial, hiring, public statements).
- Consequences, what happens on violation, stated plainly.
Tie the approved-tools list to your AI inventory so it updates as tools change. A policy that names “ChatGPT” and nothing else is obsolete the moment a team adopts a new copilot.
Frequently asked questions.
What should an AI acceptable-use policy include?
Five essentials: a list of approved AI tools, prohibited data types (PII, health, financial, NDA material), disclosure rules, human-review triggers for high-stakes outputs, and clear consequences for violations, all on one page so it actually gets read.
Should we ban AI tools like ChatGPT at work?
Outright bans backfire: 45–46% of employees find workarounds. A sanctioned alternative works far better, cutting unauthorized use by up to 89% (Unseen Security, 2025). Provide an approved, safe path rather than prohibiting the category.