Free tool · Runs in your browser
AI policy generator
An AI policy tells your team which AI tools they may use, what data may go into them, what a person must check, and who to ask. Answer the questions below and you get a nine-section policy you can copy, edit and adopt.
It is a starting structure for small organisations, not legal advice. Nothing you enter leaves your browser.
Last checked 24 September 2026
A name or a role. This person approves new tools and keeps the training record.
Your policy
1. Purpose and scope
This policy sets out how people at [Organisation] use AI tools at work. It applies to employees, freelancers and interns, on company and personal devices, whenever the work is for [Organisation].
2. Approved tools
Only these tools may be used for work: ChatGPT, Claude.
Any other AI tool needs approval from [name or role] before first use.
3. Data
Personal data, customer data and confidential business information may only be entered into approved tools used through a business account covered by a data processing agreement. Never into a personal or free account.
Special categories of personal data (health, religion, union membership and similar) never go into any AI tool.
4. Human review
AI output is a draft. A person checks it before it is used for:
- texts that leave the organisation (emails, offers, posts, documents)
- code before it is deployed
- anything that feeds a decision about a person (hiring, performance, pay, termination)
The person who uses the output is responsible for it, not the tool.
5. Transparency
When a customer or the public interacts with an AI system on our behalf, for example a chatbot, we say so. Content that is substantially generated by AI and published as fact is labelled as such.
6. Not permitted
- Using AI to infer the emotions of colleagues or applicants at the workplace.
- Entering passwords, access keys or payment data into any AI tool.
- Letting an AI tool send, publish or sign anything on behalf of the organisation without a person approving it.
7. Training and record
Everyone who uses AI tools for work completes a short training before first use and a refresher when the approved tools change.
[Organisation] keeps a record of who was trained, when, and on what. The record is kept by [name or role].
8. Questions and incidents
Questions go to [name or role]. If personal or confidential data went into a tool by mistake, report it to [name or role] the same day. Reporting early is expected and is not held against anyone.
9. Review
This policy is reviewed every 12 months, and sooner when a new tool is approved.
Template
AI policy template: a complete sample
This is the full text the generator produces for a small company with ChatGPT and Claude approved, the business-account data rule, and every review box ticked. Change the answers above and it rewrites itself.
1. Purpose and scope
This policy sets out how people at Example Ltd use AI tools at work. It applies to employees, freelancers and interns, on company and personal devices, whenever the work is for Example Ltd.
2. Approved tools
Only these tools may be used for work: ChatGPT, Claude.
Any other AI tool needs approval from the operations lead before first use.
3. Data
Personal data, customer data and confidential business information may only be entered into approved tools used through a business account covered by a data processing agreement. Never into a personal or free account.
Special categories of personal data (health, religion, union membership and similar) never go into any AI tool.
4. Human review
AI output is a draft. A person checks it before it is used for:
- texts that leave the organisation (emails, offers, posts, documents)
- code before it is deployed
- anything that feeds a decision about a person (hiring, performance, pay, termination)
The person who uses the output is responsible for it, not the tool.
5. Transparency
When a customer or the public interacts with an AI system on our behalf, for example a chatbot, we say so. Content that is substantially generated by AI and published as fact is labelled as such.
6. Not permitted
- Using AI to infer the emotions of colleagues or applicants at the workplace.
- Entering passwords, access keys or payment data into any AI tool.
- Letting an AI tool send, publish or sign anything on behalf of the organisation without a person approving it.
7. Training and record
Everyone who uses AI tools for work completes a short training before first use and a refresher when the approved tools change.
Example Ltd keeps a record of who was trained, when, and on what. The record is kept by the operations lead.
8. Questions and incidents
Questions go to the operations lead. If personal or confidential data went into a tool by mistake, report it to the operations lead the same day. Reporting early is expected and is not held against anyone.
9. Review
This policy is reviewed every 12 months, and sooner when a new tool is approved.
Checklist
What an AI acceptable use policy has to cover
An acceptable use policy answers the questions people otherwise answer differently each time. These nine are the ones that come up in practice:
| Section | What it decides | Often missing because |
|---|---|---|
| Scope | Who the rules apply to, and on which devices | Freelancers and personal phones get forgotten |
| Approved tools | Which tools are allowed, and who approves a new one | No one owns the approval |
| Data | What may go into a tool, and through which account | Free personal accounts feel harmless |
| Human review | Which outputs a person checks before use | Drafts quietly become final |
| Transparency | When customers are told AI is involved | It only matters once someone asks |
| Not permitted | Uses that are off the table entirely | Written as vague principles instead of cases |
| Training and record | Who is trained, and how that is documented | Training happens, the record does not |
| Incidents | What to do when data went in by mistake | People hide mistakes they expect to be blamed for |
| Review | When the policy is looked at again | Tools change faster than the document |
Data rule
Strict rule or business-account rule?
The generator offers two data rules, because the right one depends on the accounts you pay for.
| Strict | Business accounts only | |
|---|---|---|
| Personal and customer data | Never in any AI tool | Only in approved tools on a business account with a data processing agreement |
| Special categories (health, religion and similar) | Never | Never |
| Suits | Teams on free or personal accounts, or just starting | Teams on business or team plans that signed a data processing agreement |
| Cost of the rule | People anonymise by hand | Paid accounts and an agreement per provider |
EU AI Act
An AI policy and the EU AI Act in 2026
Article 4 of the EU AI Act is about the AI literacy of the people who use AI systems at work. According to the European Commission's Q&A, the amendment that entered into force in mid-July 2026 keeps AI literacy an obligation for providers and deployers but no longer mandates a specific or "sufficient" level.
The same Q&A says there is no need for a certificate, and that organisations can keep an internal record of their trainings. Section 7 of the policy and the record template below are that record.
Separately, using AI to infer the emotions of people at the workplace is among the practices the Act prohibits, which applies since 2 February 2025. That is why it is listed under "Not permitted" in every version of the policy.
Record
AI training record template
A record needs five columns and nothing more. One row per person per training, kept by whoever the policy names as contact:
| Name | Date | Tools covered | Content | Format and length |
|---|---|---|---|---|
| [Name] | [Date] | ChatGPT, Claude | This policy, data rule, human review | Internal session, 45 minutes |
| [Name] | [Date] | Claude Code | Approved uses, what stays out of prompts | Online course, 2 hours |
Keep it where the policy lives. When someone asks how your staff learned to use the tools, this table is the answer.
Rollout
How to introduce an AI policy in five steps
- 1Ask the team which AI tools they already use. The honest list is always longer than the official one.
- 2Decide the approved tools and the data rule, then generate the policy above.
- 3Name one contact who approves new tools and keeps the training record.
- 4Walk everyone through the policy in one short session, and record it in the table as the first training.
- 5Put the review date in the calendar and revisit the policy when a new tool arrives.
Sectors
Adapting the template: agencies, nonprofits, law firms, schools
Agencies
Client material is the risk. Add a line on whether client data may go into any tool at all, and check what your client contracts already say about subcontracting and confidentiality.
Nonprofits
Donor and beneficiary data often includes special categories. The strict data rule is usually the safer starting point, with named exceptions once business accounts are in place.
Law firms and tax advisers
Professional confidentiality rules sit on top of data protection. Check your professional body's guidance before any client matter goes into a tool, and write the answer into section 3.
Schools
Pupils are the people affected, so the policy needs a second audience. Keep the staff policy here and write the rules for pupils separately in plain language.
Terms
Usage policy, generative AI policy or governance policy?
They overlap. A usage or acceptable use policy, which is what this generator writes, tells people how to use AI tools at work. A generative AI policy is the same document focused on text and image tools. A governance policy goes further, into how the organisation selects, builds and monitors AI systems and assesses their risk.
A small organisation that uses AI tools and builds none needs the first. A governance policy becomes worth writing once you deploy AI in your own products or in decisions about people.
How it works
Each answer switches a block of text in or out. The data rule decides between a strict version, where no personal or confidential data goes into any AI tool, and a business-account version, where it may go only into approved tools covered by a data processing agreement.
Two sections are always included because they are the ones people skip: what is not permitted at all, and a record of who was trained on the tools and when.
Frequently asked
Does a small business need an AI policy?
Once more than one person uses AI tools for work, a short written policy is the simplest way to agree on which tools are allowed and what data stays out. It is also where the training record lives, which is what you show when someone asks how your staff learned to use the tools.
What does the EU AI Act say about training staff?
Article 4 of the EU AI Act is about the AI literacy of people who use AI systems at work. The European Commission's Q&A on AI literacy says there is no need for a certificate and that organisations can keep an internal record of their trainings. Section 7 of the policy sets that record up.
What is a data processing agreement?
A contract in which the tool provider commits to processing your data only on your instructions, as the GDPR requires when a provider handles personal data for you. Business and team plans of the large AI tools usually offer one; free and personal accounts usually do not.
Can I change the text?
Yes. Copy it or download it as a text file and edit it like any document. The generator gives you the structure; the details of your organisation belong in it.
Is there a free AI policy template?
This page is one. The generator writes a nine-section AI acceptable use policy from your answers, and the complete sample further down is exactly what it produces. Copy it or download it as text.
What should an AI acceptable use policy include?
Scope, approved tools, a data rule, which outputs a person reviews, transparency towards customers, uses that are not permitted, a training record, what to do after an incident, and a review date.
Do staff need a certificate for AI training?
No. The European Commission's Q&A on AI literacy says there is no need for a certificate and that organisations can keep an internal record of their trainings.
How often should an AI policy be reviewed?
Every six to twelve months, and whenever a new tool is approved. Tools change faster than documents, so a fixed date in the calendar is what keeps the policy true.
More free tools
All free toolsA policy is the start, not the rollout
The part that decides whether a team actually uses AI well is the training behind section 7. We are building a course for exactly that. Join the waiting list and we write once, when it opens.
See the courseFor information only. The results are estimates and templates that may not fit your situation, and ENLIX accepts no liability for decisions based on them. Check anything important with a lawyer or your data protection officer.