How to Write an AI Usage Policy for Your Team (Template)
How to write an AI usage policy for your team: a step-by-step guide with a copy-ready outline, data classification, approved tools list and training plan.

An AI usage policy is a short document that tells your team which AI tools they may use, what data they may put into them, and who checks the output. Write it in five steps: set the goal, classify your data, approve tools, define review rules, and train people. Keep it to a few pages, and ship it before the next rollout, not after.
Key takeaways
- Your team is already using AI. The policy's job is to make safe use easy, not to ban things.
- Data classification does most of the work. Three or four tiers is plenty.
- An approved tools list beats a vague "use good judgment" rule. Keep it on its own page.
- Humans stay accountable for anything that goes to a customer, a regulator or production.
- Training can be 60 minutes plus a quarterly refresh. Keep a simple record.
Why do you need an AI usage policy?
Because the risk is not exotic. It is a salesperson pasting a customer list into a free chatbot, or a developer pasting a secret key. A policy gives people a clear answer before they ask. It also helps in sales cycles: larger customers now ask how you use AI on their data. If you are building a wider plan, start with our guide on how to build an AI strategy for a small business, then come back and lock in the rules.
How do you write an AI usage policy, step by step?
- Name an owner. One person, with legal and security as reviewers.
- Inventory what is in use. Ask the team. Check browser extensions, meeting bots and the AI features inside tools you already pay for. Expect surprises.
- Classify your data (next section).
- Pick approved tools and the account type for each.
- Write the rules using the outline below.
- Train, publish, review. Put the policy where people work, not in a drive nobody opens.
A tracked checklist helps here. A workflow tool such as Process Street can run the onboarding and quarterly review as a recurring checklist, though a shared doc and a calendar reminder work too.
What data can go into AI tools?
Use four tiers. Name each one, give examples from your own business, and say what is allowed.
| Tier | Examples | Approved AI tools | Free or personal AI accounts |
|---|---|---|---|
| Public | Published website copy, press releases, job ads | Allowed | Allowed |
| Internal | Meeting notes without client names, internal SOPs, draft plans | Allowed | Not allowed |
| Confidential | Customer names and contracts, pricing, financials, source code | Allowed only in tools approved for this tier | Not allowed |
| Restricted | Passwords, API keys, health data, payment card data, government IDs, employee HR files | Never, unless the security owner signs off in writing | Never |
Two notes. First, personal data of EU residents falls under GDPR, which is a separate regime from the AI Act. Treat it as at least Confidential and ask counsel about your lawful basis. Second, the tier depends on the tool's contract, not just the data. The same chatbot can be fine on a business plan with no training on your data and a bad idea on a free personal account. Check this in the vendor's terms. Our AI vendor checklist shows how.
What should the approved tools list look like?
Keep it as a table. Four columns are enough.
| Tool | Approved account type | Highest data tier | Owner |
|---|---|---|---|
| ChatGPT | Company workspace, SSO login | Confidential (if terms confirmed) | IT |
| Claude | Company workspace, SSO login | Confidential (if terms confirmed) | IT |
| Gemini | Company workspace account | Internal | IT |
| Meeting note-taker (pick one) | Company account | Internal | Ops |
This table is an example of the format, not a recommendation or a statement about what any vendor allows. Fill in the tier only after you have read each vendor's current data terms. Add a request process: anyone can ask for a new tool, and the owner answers within five working days. If you do not offer a fast yes or no, people go around you. Teams building their own automations should also read custom AI agents: build vs buy and n8n vs Zapier vs Make, because workflow tools that call AI models are tools too and belong on the list.
What goes into the policy? A copy-ready outline
Paste this into a doc and edit it. Adjust the example rules to your business.
1. Purpose and scope. "This policy covers all employees, contractors and interns using AI tools for company work, on any device."
2. Definitions. Say what you mean by AI tool: chatbots, writing assistants, coding assistants, meeting bots, AI features inside other software, and agents that take actions.
3. Approved tools. "Use only tools on the Approved Tools List, with the account type listed. Do not use personal accounts for work."
4. Data rules. "Never enter Restricted data. Enter Confidential data only in tools approved for it. When unsure, treat the data as one tier higher."
5. Human review. "You are responsible for anything you send, publish or ship, whether or not AI wrote it. Check facts, numbers, names and quotes. A person must review AI output before it reaches a customer, a regulator or production."
6. Customer-facing use. "Do not let AI send messages to customers without a documented review step. Tell customers when they are talking to an AI where law or contract requires it." If you run support automation, see our comparison of AI support agents.
7. Decisions about people. "Do not use AI as the only basis for hiring, firing, pay or performance decisions." Hiring tools can fall in the EU AI Act's high-risk category, so get advice before using them.
8. Intellectual property and confidentiality. "Do not paste third-party confidential material or licensed content into AI tools unless the contract allows it."
9. Code and technical work. "No secrets, keys or customer data in prompts. Review AI-written code like any other pull request."
10. Recording and transcription. "Get consent before recording calls with AI note-takers, as the law in the relevant country requires."
11. Incidents. "If you pasted something you should not have, tell the owner within 24 hours. No blame for fast reports."
12. Training and review. "Everyone completes AI training at onboarding and then yearly. This policy is reviewed every six months."
13. Consequences. "Breaches are handled under existing disciplinary policy."
How do you review AI output and handle incidents?
Make review proportional. Low-risk internal drafts need a quick read. Anything external needs a named human approver. Anything involving money, legal commitments or personal data needs two sets of eyes. Log incidents in a simple sheet: date, tool, data tier, what happened, fix. After three incidents of the same kind, change the rule or the tool, not the reminder email.
What does the EU AI Act say about training staff?
This is not legal advice. Talk to counsel about your own situation.
Here is what the official sources say. Article 4 of the AI Act, as adopted, says providers and deployers of AI systems shall take measures to support the development of AI literacy of their staff and other people operating AI systems on their behalf. According to artificialintelligenceact.eu, it applied from 2 February 2025. The full regulation is Regulation (EU) 2024/1689, published on EUR-Lex.
The European Commission's AI literacy Q&A says there is no need for a certificate, and that organizations can keep an internal record of training or other guiding initiatives. It also says there is no one-size-fits-all approach: tailor it to role, system risk and technical background.
Rules have moved. The Commission's pages describe an "AI Omnibus" that entered into force on 27 July 2026. Per the Commission Q&A, it shifted primary responsibility for promoting AI literacy to the Commission and Member States, while the duty for deployers of high-risk systems to train staff for human oversight remains. The same Commission page lists later dates for some high-risk systems, 2 December 2027 for certain areas and 2 August 2028 for product-integrated systems. Dates and wording are still being applied in practice, so confirm the current position before you rely on it.
My take: train anyway. Even if the legal duty is lighter than first drafted, trained staff make fewer data mistakes. Keep a one-page record of who was trained, when and on what.
For a wider risk method, the voluntary NIST AI Risk Management Framework is a useful reference. Larger customers may ask about ISO/IEC 42001, the AI management system standard published in 2023. Most SMBs do not need certification to start. A clear policy is the first step.
What should training cover?
Keep the first session to about 60 minutes:
- What the tools can and cannot do, including made-up facts.
- The four data tiers, with five real examples from your business.
- The approved tools list and how to request a new tool.
- Prompt basics and review habits.
- What to do when something goes wrong.
Then add a 15 minute refresh each quarter with new examples. Role-specific modules help: sales on customer data, engineering on code and secrets, HR on people decisions.
Bottom line
Start small. Name an owner, publish four data tiers, list the approved tools, and require a human on anything external. Train everyone once and keep a record. Review in six months. A two-page policy people follow beats a twenty-page policy they skim.
Frequently asked questions
How long should an AI usage policy be?+
Two to four pages is enough for most SMBs. If people will not read it in ten minutes, they will not follow it. Put the data rules and the approved tools list up front and move detail into appendices.
Do we need an AI usage policy if we only use ChatGPT or Claude?+
Yes. Staff are already pasting work into AI tools, whether you have a policy or not. A short policy tells them which data is off limits, which accounts to use, and who to ask.
Does the EU AI Act require AI training for staff?+
Article 4 of the EU AI Act, as adopted, asks providers and deployers to take measures to support AI literacy of their staff, and it applied from 2 February 2025. The Commission says a later AI Omnibus shifted primary responsibility for promoting literacy to the Commission and Member States, while deployers of high-risk systems must still train staff for human oversight. Check current text with a lawyer. This is not legal advice.
Who should own the AI policy?+
One named person, usually the head of operations, IT or the COO at a smaller company. Legal and security review it, but one owner keeps it alive and answers questions.
How often should we update the policy?+
Review it every six months and any time you add a new tool or a vendor changes its data terms. Keep the approved tools list as a separate page so you can update it without re-approving the whole policy.
Sources, checked 2 Oct 2026
- EU AI Act, Article 4: AI literacy (artificialintelligenceact.eu)
- EU AI Act implementation timeline (artificialintelligenceact.eu)
- European Commission: AI literacy questions and answers
- European Commission: Regulatory framework for AI
- Regulation (EU) 2024/1689 on EUR-Lex
- NIST AI Risk Management Framework
- ISO/IEC 42001:2023 AI management systems (iso.org)

