AI Policy Template: A Free, Editable Structure for 2026

Photo: Alex Green / Pexels
Key takeaways
- A good AI policy template has five sections: scope, approved tools, data rules, review/transparency, and owner/attestation.
- Concrete data rules beat vague ones: name exactly what must never be typed into an AI tool.
- Regulated sectors keep the same structure but tighten the data-rules section, not the whole document.
- Attestation, proof staff read and accepted the policy, is what turns a document into audit evidence.
- Contractors and freelancers acting for the business should sign it too, not just direct employees.
An AI policy template is only useful if it stops being a template the moment you open it. Too many are generic skeletons, a document you paste your logo onto, file away, and nobody reads again. This one is built from five sections that map to what an auditor, a regulator, or a new employee actually needs to know: scope, approved tools, data rules, review and transparency, and sign-off. Use the structure below as a starting skeleton, then fill each section in with how your team really works. The two sections that matter most, by far, are the data rules and the approved-tools list; get those right and the rest is formatting. Neither a template nor a generator is wrong here, they solve different problems: a template is what you edit yourself in an afternoon, a generator is what you use when you'd rather answer five questions than write five sections from scratch.
Section 1: scope and purpose
Say who the policy covers, employees, contractors, anyone acting on the company's behalf, and define what counts as an 'AI tool'. That's broader than people assume: standalone assistants like ChatGPT or Claude, AI features baked into other software, and anything that quietly sends your data to a third-party model. Include the AI features hiding inside tools you already use, like autocomplete suggestions in a CRM or a drafting assistant in a helpdesk platform. These rarely feel like 'an AI tool' to the person using them, which is exactly why the policy needs to say so explicitly. Add one sentence on why the policy exists. People follow rules they understand the reason for; a policy that reads as pure compliance box-ticking gets skimmed and ignored.
Section 2: approved tools and tiers
This is the section staff will actually come back to. List which tools are approved and, critically, at what tier: 'ChatGPT Team, not personal free or Plus accounts' is a rule people can follow; 'use AI responsibly' is not. Name what's explicitly not approved for work, and add a short process for requesting a new tool, so the fastest route to trying something new is asking, not smuggling it in on a personal account. Review the list on a set cadence, not just when someone complains it's out of date; a tool that was safe on last year's terms can change its data-handling policy without much fanfare, so a review date on the list itself is worth adding. See our guide on writing an AI usage policy from scratch if you're starting before any tools have been vetted at all. Most shadow AI exists because the approved list was never written down, not because anyone meant to break a rule.
Section 3: data rules
The heart of the policy, and the section worth spending the most time on. Write it concretely: 'do not paste customer names, email addresses, financial figures, source code or unreleased plans into any AI tool that isn't on the approved list' beats 'do not process personal data' every time, because a busy employee can actually apply the first one without stopping to work out what 'personal data' means in this context. A useful test for any rule: could a new starter follow it correctly on their first day without asking a follow-up question? If the answer is no, the rule needs a concrete example added, not a longer explanation. If you handle health, legal or financial information, add a stricter clause here; for healthcare teams that typically means no PHI in any tool without a signed BAA on file.
Section 4: review and transparency
Require a human to check AI output before it reaches a customer or informs a real decision; this single line catches most of the embarrassing mistakes companies make with AI. Human review doesn't need to be heavyweight: for most small teams it means one person reads AI-drafted client communication before it's sent, which catches the factual errors and odd phrasing that AI tools still produce fairly often. Add a transparency rule too: say when staff must disclose that content was AI-assisted, particularly anything customer-facing. If you have EU users or staff, this section is also where you evidence the EU AI Act's Article 4 AI-literacy duty, which has applied since 2 February 2025 and expects staff using AI to have a basic understanding of how it works and where it can go wrong.
Section 5: owner and attestation
Name one person who owns the policy, approves new tools and answers questions; 'the AI policy' with no named owner tends to quietly stop being anyone's job. Then close the loop: record that each member of staff has read and accepted the policy, with a timestamp, and set a re-attestation date, typically annual, so the record doesn't quietly go stale as staff join and leave. That attestation record is what turns a document into evidence, and it's what a SOC 2 auditor or the ISO 42001 management-system standard actually wants to see, not the policy's prose.
Do you need a different template for a regulated industry?
Mostly, no; the five sections above are the same skeleton for a marketing agency and a healthcare startup. What changes is the strictness of Section 3. A healthcare team adds a flat no-PHI-without-a-BAA rule tied to our HIPAA compliance hub and probably restricts AI tools to a shorter approved list; a law firm anchors a stricter human-review requirement to its client confidentiality obligations. The structure holds; only the guardrails tighten.
What if an employee ignores the policy?
Treat it like any other workplace policy breach: a conversation first, in most cases, because the majority of AI policy breaches come from people trying to do their job faster, not from malice. Ask what they were trying to achieve and whether the approved tools genuinely couldn't do it; sometimes the policy is missing a tool people actually need, and the fix is adding it, not enforcing harder. Reserve formal disciplinary steps for repeated or deliberate breaches involving sensitive data, and make sure the policy itself says what happens next, so it isn't invented on the spot the first time it's needed.
One page beats twenty
A 15-person design studio inherited a 22-page AI policy template from a client's legal team, and it sat unread in a shared drive for eight months. When a new hire asked which AI tools were actually approved, nobody could answer without opening the document and searching. The studio rewrote it down to a single page using the five sections above: three lines of scope, a five-tool approved list with tiers named, four data rules, and one owner. Staff started reading it because it took ninety seconds, and for the first time, new starters actually knew the rules on day one.
Don't fill it in by hand
A template gets you a structure; it doesn't do the thinking of tailoring it to your company's size, sector and data sensitivity. Rather than editing a generic document section by section, ModelCharter's free AI usage policy generator asks about your company type, the data you handle and your regulatory context, then produces a policy with all five sections already tailored, including the attestation trail. If you're also weighing up which tools to name in Section 2, the AI Tool Risk Directory has the training, retention and DPA status for 60-plus popular tools, so you're not guessing at what's safe to approve. Either way, the goal is the same: a document staff can actually recite the gist of, not one they signed once and forgot.
| Section | What it must answer |
|---|---|
| Scope and purpose | Who does this apply to, and what counts as an AI tool? |
| Approved tools and tiers | Which tools, at which tier, are staff allowed to use? |
| Data rules | What must never be typed into an AI tool? |
| Review and transparency | Who checks AI output, and when must AI involvement be disclosed? |
| Owner and attestation | Who owns the policy, and how do you prove staff read it? |
“A one-page policy everyone has read beats a twenty-page policy nobody has opened.”