ModelCharter
ModelCharter Team

AI Acceptable Use Policy: What to Include

Person signing a business agreement representing an AI acceptable use policy

Photo: Pixabay / Pexels

Key takeaways

  • An AI acceptable use policy (AUP) is the short, staff-facing document; a full AI usage policy can be longer and more technical.
  • Four clauses cover most of it: a data rule, an approved-tools list, a transparency rule, and a reporting route.
  • Since 2 February 2025, the EU AI Act's Article 4 expects staff to have a sufficient level of AI literacy - an AUP is the easiest way to evidence that.
  • Legal, health and finance teams usually need a stricter data rule than a marketing or product team.
  • A one-to-two page AUP that staff actually read beats a ten-page one that sits in a drive nobody opens.

An AI acceptable use policy is the one-page document employees actually read, not the longer internal standard that sits behind it. Where a full AI usage policy might cover vendor evaluation and data classification in detail, an AUP boils that down to what staff need to know before they open ChatGPT: what data is off-limits, which tools are approved, and when they need to say AI was involved. Get those four things right and most of the risk is covered; get them wrong and no amount of extra pages fixes it.

AUP vs. a full AI usage policy - what's the difference?

Think of the AUP as the summary a new hire reads in their first week, and the full policy as the reference document behind it that ops or legal maintain. Some small teams merge the two into a single short document, and that's fine below a certain size - under about 25 people, a single page usually covers both jobs without anyone feeling short-changed. Once you're running multiple tool tiers, sector-specific rules, or a formal register, it's worth splitting them so the version staff sign stays short.

The four things every AUP needs

A clear data rule: never enter confidential, personal or client data into a tool that isn't approved. An approved-tools list, or a link to a live one, since a printed list goes stale within a month. A transparency rule: disclose AI-generated content where it's material, particularly anything client-facing or regulatory. And a reporting route: where to ask about a new tool, and where to flag a concern, ideally the same address so people don't have to guess. Put these four in that order, too - data first, because it's the one clause that stops the worst outcomes, and reporting last, because it's the safety net for everything the first three don't catch.

Writing a data rule people actually follow

Vague rules get ignored. 'Use good judgement with sensitive data' means different things to different people. 'Never paste a client's name, contact details or financial figures into a consumer AI account - use the approved Team workspace instead' is a rule someone can actually check themselves against before hitting send. Give one or two concrete examples of what counts as confidential in your business specifically, not a generic list copied from a template. If personal data is involved, the ICO's guidance on AI and data protection is a useful sense-check on what 'reasonable' looks like in practice.

The approved-tools list, and why it needs a home

Naming tools in the policy text is a trap, because your approved list will change faster than your policy gets reviewed. Better to reference a living register - a page, a spreadsheet, or the register inside a policy tool - and keep the policy's job to stating the rule ('only use tools on the approved list') rather than the list itself. Review the list on a fixed schedule, not whenever someone remembers to, and note the date of the last review somewhere staff can see it, so nobody assumes a two-year-old list is still accurate.

Does a five-person company really need one of these?

Yes, and it can be short. A 40-person marketing agency we've seen go through this had staff on six different AI tools before anyone wrote anything down: some on personal ChatGPT accounts, one team on a free image generator with no idea what its terms said about ownership. Their AUP ended up one page: three approved tools, a one-line data rule, and a note to ask before adding a fourth. It took an afternoon to write and about a week to get everyone to actually read it - the writing was always the easy part.

Transparency and the AI-literacy duty

Since 2 February 2025, the EU AI Act's Article 4 has required providers and deployers to ensure staff using AI systems have a sufficient level of AI literacy, so far as is reasonably possible. A written AUP that staff read and acknowledge is the simplest way to build an evidence trail for that duty - you have a document, a date, and a record of who signed it, rather than a training programme you'd need to design from scratch. If you have EU customers or EU-based staff, this clause isn't optional decoration; it's the part a regulator would actually ask to see.

What about AI features nobody chose?

The trickiest gap in most AUPs is AI functionality built into software you already use and didn't evaluate as 'an AI tool' - a summarise button in your inbox, a drafting assistant in your CRM, meeting notes that auto-generate in your video-call app. These slip past approval processes because nobody requested them; they just appeared in an update. Add a line covering this explicitly: 'AI features inside existing approved software are covered by this policy the same as standalone AI tools' closes the gap without you having to chase every vendor's release notes.

Sector differences worth knowing

Legal, medical and financial services teams typically need a stricter data rule that rules out even anonymised or aggregate client data, since re-identification risk is harder to rule out than it looks. Education settings need a line about AI-generated content that reaches students or parents. If you're in healthcare or legal, it's worth checking your sector's compliance requirements before finalising the wording rather than after - a rewrite after the fact is more disruptive than getting it right the first time.

Mistakes that make an AUP fail quietly, and how to keep it alive

The most common one is writing the policy once and never revisiting it, so it still bans a tool the company now pays for. The second is making it too long: a three-page AUP with sub-clauses and cross-references gets the same treatment as a terms-and-conditions box, ticked without reading. The third is putting it somewhere staff never look, a wiki page three folders deep instead of somewhere it gets surfaced during onboarding. A signed AUP that nobody remembers a month later isn't much better than no policy at all, so re-send it, or at least the summary, whenever a genuinely new tool is approved, and make signing it part of onboarding for every new hire rather than a one-off exercise for the people employed when it was first written. None of these fixes are dramatic, but together they explain why so many AUPs exist on paper without changing anyone's behaviour.

Turn the policy into a document people actually sign

A policy nobody has read is a policy that doesn't exist when an auditor or a client asks. Generate an AUP with our free AI usage policy generator - it asks about your sector and data sensitivity and produces a document that's already structured for attestation, so the next step is sending it, not writing it.

ClauseWhat it coversExample line
Data ruleWhat can and can't go into an AI toolNever enter client, personal or confidential data into a consumer AI tool.
Approved toolsWhich apps are sanctioned, and at what tierOnly ChatGPT Team accounts are approved for work use.
TransparencyWhen AI involvement must be disclosedDisclose AI-generated content in anything sent to a client or regulator.
ReportingWhere to ask about a new tool or flag a concernRequest new tools or report concerns to the ops team address.
The four clauses every AI acceptable use policy needs
Providers and deployers of AI systems shall take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff.
EU AI Act, Article 4

Frequently asked questions

What's the difference between an AI usage policy and an AI acceptable use policy?
In practice the terms overlap a lot, and plenty of teams use them interchangeably. Where companies do distinguish them, the AUP is the short, staff-facing summary; the usage policy is the fuller document covering vendor evaluation, data classification and ownership.
Do contractors and freelancers need to follow the AUP too?
Yes, if they can act on your behalf or touch your data. Say so explicitly in the scope section - 'applies to employees, contractors and anyone acting for the company' - since contractors are a common gap, and it's worth building acknowledgement into contractor onboarding paperwork rather than assuming it's covered by a general confidentiality clause.
How long should an AI acceptable use policy be?
One to two pages for most small and mid-sized teams. If it's longer than that, staff skim it rather than read it, which defeats the point of having one.
Does an AUP satisfy the EU AI Act's AI-literacy duty on its own?
It's a strong start and the cheapest way to evidence the duty, but 'sufficient' literacy under Article 4 is judged on context - a regulated sector or high-risk use case may need a short briefing alongside the document, not just a signature.
What happens if an employee breaks the AUP?
Say this in the policy itself, not just in a general HR handbook. A short line - 'breaches are handled under the standard disciplinary process; report suspected data exposure to the address above immediately' - is usually enough, and it removes the ambiguity of staff wondering whether raising a mistake will make things worse for them.

Put this into practice

Generate a free AI usage policy for your team, then see which of your tools are safe to use.

Open the generator