ModelCharter
ModelCharter Team

How to Write a Code of Conduct for AI Use at Work

Compass representing values and ethics in a code of conduct for AI use

Photo: Brett Jordan / Pexels

Key takeaways

  • A code of conduct explains the 'why' behind your AI rules; a usage policy handles the 'what' and 'how'.
  • Five principles cover most of it: human oversight, transparency, fairness, privacy, accountability.
  • It works best shared publicly and tied directly to your operational policy, not left to stand alone.
  • Keep it to one page, written in 'we' language, signed off by one named leader.
  • Pair it with a proper usage policy so your stated values and your actual rules match.

An AI usage policy tells your team what they can and cannot do with AI tools. A code of conduct for AI goes a layer deeper: it sets out the values behind those rules, not just the rules themselves. It answers why your organisation uses AI the way it does, not only what is allowed. Boards, investors and enterprise customers increasingly want to see this stated somewhere they can read in five minutes, not buried in clause 14 of a policy document. Written well, a code of conduct becomes the reference point every other AI decision gets measured against. Written badly, it is a page nobody remembers past the first read.

How it differs from an AI usage policy

An AI usage policy is operational. It names the approved tools, sets data-handling rules, and says who to tell if something goes wrong. A code of conduct for AI is principled. It states your stance on fairness, transparency, human oversight and accountability, the ideas that justify the rules rather than the rules themselves. Think of the policy as the how and the code of conduct as the why. In practice, most organisations need both. The policy tells a new starter exactly what to do on day one. The code of conduct tells a customer, an investor, or a new hire's future manager what your organisation believes about AI, in language they can quote back to you. Skip the code of conduct and your policy reads as a list of restrictions with no stated purpose. Skip the policy and your code of conduct is good intentions nobody can act on. See how to write an AI usage policy for the operational half of this pair.

What a good code of conduct actually contains

Five principles cover most of what an AI code of conduct needs to say. Human oversight: AI output gets a human review before it shapes an important decision or goes out to a customer. Transparency: the organisation says when AI was materially involved in something, rather than letting people assume it was human-made throughout. Fairness: AI use is checked for discriminatory patterns, particularly anywhere it touches hiring, pricing or customer decisions. Privacy: AI tools only process data where the right contractual and technical safeguards exist, no exceptions for convenience. Accountability: one named person owns AI use across the organisation, so 'nobody's job' never becomes the answer to a question. These five map reasonably well onto the broader characteristics the NIST AI RMF uses to describe trustworthy AI, so borrowing its language is a shortcut, not a sign you need the full framework. Each principle should get a sentence or two, not a paragraph. The temptation is to write a mission statement; resist it. A code of conduct a new employee can read in ninety seconds and repeat back accurately has done its job. One that needs a training session to explain has already failed the format.

Does a code of conduct replace the need for a policy?

No, and treating it as a substitute is the most common mistake. A code of conduct states values; it does not tell someone which tools are approved or what to do with a client's email address. Without an operational policy behind it, a code of conduct is unenforceable, nobody can be held to a value statement the way they can be held to a specific rule. The reverse failure is just as common: a detailed usage policy with no stated principles behind it, which reads as arbitrary even when the rules are sound. Use our free AI usage policy generator to produce the operational document first, then write the code of conduct as a short cover statement that explains the thinking behind it.

Tone and audience: who actually reads this

A usage policy is read by staff. A code of conduct is often read by people who will never open the policy: customers doing due diligence, investors during a raise, a candidate deciding whether to accept an offer. Write it in the first person plural, 'we believe', 'we commit to', not the second-person, 'you must' language of a policy. Keep it to one page. Avoid legal hedging; a code of conduct full of 'reasonable efforts' and 'where practicable' reads as a document written to avoid a lawsuit rather than one written to state a position. If your legal team wants to soften a line, ask what specifically worries them, then fix that sentence rather than hedging the whole document.

Where it earns its keep

A 25-person design studio picked up an enterprise client that needed a security and ethics questionnaire completed before signing. Two of the questions asked, in different words, what the studio's principles were for using AI in client work; a data-handling clause alone did not answer either one. The studio's operations lead pulled together a one-page code of conduct that afternoon, covering the same five principles above, and pointed the client's procurement team to it alongside the existing usage policy. The questionnaire cleared in a day. What mattered was not the document's length, it was one page, but that it existed, was dated, and matched what the studio's usage policy already said in practice. Without it, the studio would have been improvising an answer to a question it should already have covered.

What happens if you publish a code of conduct nobody follows?

It becomes a liability rather than an asset. A public statement about fairness and transparency that does not match actual practice is worse than no statement at all, because it gives a customer, journalist or regulator a specific claim to hold you to. If your code of conduct says AI output gets human review before it reaches a client, and an unreviewed AI draft goes out under your name, that gap is now the story. The fix is not softer language, it is tighter alignment: only commit to what your usage policy and your actual tooling already support, and update both documents together whenever either one changes.

Making it real rather than decorative

Put the code of conduct in onboarding, not just on the website. Reference it when a genuinely difficult AI decision comes up, a client asking you to disclose AI use, a hiring manager wondering whether an AI-screened shortlist is fair, and let it settle the question rather than sitting there as decoration. Cross-link it directly to your usage policy and your AI literacy training so a new starter sees the values and the rules in the same session, not as two disconnected documents six months apart. Review it annually alongside your policy. A code of conduct that never changes as your AI use grows either was not specific enough to begin with, or nobody is checking whether you still mean it.

Start with the values, then generate the rules

The order that works best in practice: settle on your five principles, write them down on a page, then build the operational policy that puts them into effect. If you already have a policy but no code of conduct, that is a missing page, not a missing programme. It is an afternoon's work, not a quarter's. For the day-to-day rules employees actually need, see our guide to AI policy for employees, and for the broader thinking this connects to, see our guide to responsible AI.

AttributeAI Usage PolicyCode of Conduct
PurposeSets operational rules: approved tools, data handling, reportingStates the values behind the rules: fairness, oversight, transparency
Primary audienceStaff who use AI day to dayStaff, customers, partners, investors
ToneInstructional, specificAspirational, first person plural
Typical lengthOne to three pagesUnder one page
EnforceabilityBacked by a disciplinary process and attestation recordsBacked by leadership example and cross-linking to the policy
AI usage policy vs code of conduct
A code of conduct without an operational policy behind it is a poster. A policy without a stated set of values behind it is just a list of prohibitions.
ModelCharter's compliance team

Frequently asked questions

Do we need both a code of conduct and an AI usage policy?
Yes, ideally. The policy tells staff exactly what they can do with which tools and data. The code of conduct explains the values behind those rules for anyone who will not read the full policy: customers, investors, new hires. Together they cover the operational and the reputational side of AI use.
Is a code of conduct for AI a legal requirement?
No single law requires a document by that name. But the [EU AI Act's Article 4 duty](https://artificialintelligenceact.eu/article/4/) to ensure staff have sufficient AI literacy, in force since February 2025, is easier to evidence when you can point to a clear statement of principles as well as a policy staff have acknowledged.
How long should a code of conduct for AI be?
One page, ideally shorter. Five principles with a sentence or two each is enough. If it needs a training session to explain, it is too long or too vague to be useful.
Who should own and sign off a code of conduct for AI?
One named senior leader, not a committee. Committees tend to produce hedged language; a single owner can write a clear position and update it when circumstances change.

Put this into practice

Generate a free AI usage policy for your team, then see which of your tools are safe to use.

Open the generator