How to Write an AI Usage Policy (with a Free Template)

Photo: David Bares / Pexels
Key takeaways
- A good AI usage policy is short, specific and readable in five minutes - not a 20-page legal document nobody opens.
- It needs five things: scope, a clear stance, data rules, regulatory clauses, and a named owner.
- The data rules section is the one that actually prevents incidents; everything else supports it.
- Contractors and anyone acting on the company's behalf should be covered, not just employees.
- A generator tailored to your answers gets you further, faster, than editing a generic template.
An AI usage policy tells your team how they may and may not use AI tools at work. A good one is short, specific and easy to follow, not a twenty-page legal document nobody reads past the first paragraph. Whether you're writing an ai usage policy template from scratch or adapting one, the same five building blocks apply every time: scope, stance, data rules, regulatory clauses, and an owner. Get those right and the rest is formatting. This guide walks through each one, plus a free generator that builds the whole thing from your answers in a few minutes.
What the policy actually needs to cover
Before writing a word, decide what 'done' looks like. A usage policy earns its keep if a new hire can read it in five minutes, understand exactly what they can and can't do, and know who to ask when a new AI tool shows up that isn't covered yet. If your draft doesn't pass that test, it's too long, too vague, or both. It also helps to write it for the person having their worst day at work - rushed, distracted, half-reading - rather than for the careful reader you'd like everyone to be.
Step 1: define the scope
Say who it applies to: employees, contractors, and anyone else acting on the company's behalf. Then define what counts as an 'AI tool,' because the answer is broader than people expect. It includes standalone assistants like ChatGPT or Claude, AI features baked into everyday software such as Notion AI or Grammarly, and anything that quietly sends your data to a third-party model behind the scenes, even a plugin or a browser extension nobody thinks of as 'AI' until you actually look at what it does.
Step 2: set your stance
Decide how permissive to be, and say so plainly rather than leaving it implied. Most teams land on 'balanced': AI is allowed, with guardrails around data and approved tools. Regulated or data-sensitive teams - healthcare, legal, finance - often go stricter, allowing only explicitly approved tools for explicitly approved uses, with everything else needing sign-off first. Whichever you choose, write the reasoning down in one sentence; it makes exceptions easier to judge consistently later, instead of case by case from memory.
Step 3: nail the data rules
This is the heart of the policy, and the part that actually prevents incidents. Be explicit about customer data, personal data, trade secrets and confidential plans. The simplest safe default that works for almost every team: never put confidential or personal data into a consumer-tier AI tool, and only use tools confirmed not to train on your data for anything sensitive. Naming a handful of pre-approved tools here, rather than leaving people to guess, removes most of the ambiguity that leads to shadow AI in the first place. If GDPR applies to you, this section should also nod to lawful basis and data-subject rights, since the full GDPR text treats AI processing the same as any other processing of personal data. A useful test for staff: if you wouldn't paste it into a public forum, don't paste it into a free AI tool either, since the retention and training terms can end up surprisingly similar.
Is a generator better than a template?
A static template gives you a starting shape but leaves you to work out which clauses actually apply to your business. A generator asks a handful of questions - do you handle health data, do you have EU customers, what size is your team - and builds a policy tailored to the answers, with the regulatory clauses that matter to you already in place and the ones that don't left out. For most small teams that's faster and more accurate than editing a generic document line by line, and it's harder to accidentally leave a clause half-finished.
Step 4: add the regulatory clauses that apply to you
If you have EU users or EU-based staff, the EU AI Act, and specifically its Article 4 AI-literacy duty, expects you to disclose AI interactions and ensure basic AI literacy among staff who use it. If you handle health data, HIPAA requires a signed Business Associate Agreement with any AI vendor that touches patient information. If you sell into enterprise or B2B accounts, SOC 2 auditors increasingly expect an AI usage policy to exist as evidence of vendor-risk controls, referencing something close to the AICPA's Trust Services Criteria, not just as a nice-to-have.
Do contractors and freelancers need to follow it too?
Yes, and it's an easy thing to miss. Contractors, agency staff and freelancers acting on your behalf can create exactly the same exposure as an employee, sometimes more, since they're often working across several clients' confidential data at once. Naming them explicitly in the scope, and referencing the policy in contractor agreements, closes a gap that a lot of otherwise-solid policies leave open.
Step 5: name an owner and get it signed
Say who owns the policy and handles questions, exceptions and breaches, whether that's an IT lead, an HR manager or a founder wearing several hats. Then circulate it and collect acknowledgement from everyone it applies to; an unsigned policy sitting in a shared drive proves nothing to an auditor. A fifteen-person design studio we've seen do this well ran the whole rollout in one afternoon: a short all-hands walkthrough, a link to the policy, and a one-click acknowledgement logged against each name. Six months later, when a prospective client's procurement team asked for evidence of an AI policy during due diligence, the studio had a dated document and a signed list ready to send within the hour, instead of scrambling to write one under deadline pressure.
Start from the generator, not a blank page
You don't need to draft any of this from scratch. Our free AI usage policy generator builds all of the above - scope, stance, data rules, the regulatory clauses relevant to your answers, and an owner field - tailored to your team in a couple of minutes, ready to circulate and collect sign-off on the same day. It's a faster route to something specific than starting from a generic ai usage policy template and stripping out the clauses that don't apply to you, and it's harder to accidentally miss a section that matters.
| Policy section | Purpose | Example clause |
|---|---|---|
| Scope | Who and what it covers | Applies to employees, contractors and anyone using AI on the company's behalf |
| Data rules | What can and can't go into an AI tool | Never enter customer PII or source code into a consumer-tier AI tool |
| Approved tools list | Removes guesswork for staff | Only tools on the approved register may be used for company work |
| Transparency | EU AI Act and customer trust | Disclose when content or a decision was AI-assisted |
| Owner and review | Accountability over time | Policy owner reviews it annually, or after any vendor data-policy change |
“The policies that actually get followed are the ones a new hire can read in five minutes and still remember on a Friday afternoon.”