ModelCharter
ModelCharter Team

How to Write an AI Usage Policy (with a Free Template)

Notebook and pen on a desk for writing an AI usage policy

Photo: David Bares / Pexels

Key takeaways

  • A good AI usage policy is short, specific and readable in five minutes - not a 20-page legal document nobody opens.
  • It needs five things: scope, a clear stance, data rules, regulatory clauses, and a named owner.
  • The data rules section is the one that actually prevents incidents; everything else supports it.
  • Contractors and anyone acting on the company's behalf should be covered, not just employees.
  • A generator tailored to your answers gets you further, faster, than editing a generic template.

An AI usage policy tells your team how they may and may not use AI tools at work. A good one is short, specific and easy to follow, not a twenty-page legal document nobody reads past the first paragraph. Whether you're writing an ai usage policy template from scratch or adapting one, the same five building blocks apply every time: scope, stance, data rules, regulatory clauses, and an owner. Get those right and the rest is formatting. This guide walks through each one, plus a free generator that builds the whole thing from your answers in a few minutes.

What the policy actually needs to cover

Before writing a word, decide what 'done' looks like. A usage policy earns its keep if a new hire can read it in five minutes, understand exactly what they can and can't do, and know who to ask when a new AI tool shows up that isn't covered yet. If your draft doesn't pass that test, it's too long, too vague, or both. It also helps to write it for the person having their worst day at work - rushed, distracted, half-reading - rather than for the careful reader you'd like everyone to be.

Step 1: define the scope

Say who it applies to: employees, contractors, and anyone else acting on the company's behalf. Then define what counts as an 'AI tool,' because the answer is broader than people expect. It includes standalone assistants like ChatGPT or Claude, AI features baked into everyday software such as Notion AI or Grammarly, and anything that quietly sends your data to a third-party model behind the scenes, even a plugin or a browser extension nobody thinks of as 'AI' until you actually look at what it does.

Step 2: set your stance

Decide how permissive to be, and say so plainly rather than leaving it implied. Most teams land on 'balanced': AI is allowed, with guardrails around data and approved tools. Regulated or data-sensitive teams - healthcare, legal, finance - often go stricter, allowing only explicitly approved tools for explicitly approved uses, with everything else needing sign-off first. Whichever you choose, write the reasoning down in one sentence; it makes exceptions easier to judge consistently later, instead of case by case from memory.

Step 3: nail the data rules

This is the heart of the policy, and the part that actually prevents incidents. Be explicit about customer data, personal data, trade secrets and confidential plans. The simplest safe default that works for almost every team: never put confidential or personal data into a consumer-tier AI tool, and only use tools confirmed not to train on your data for anything sensitive. Naming a handful of pre-approved tools here, rather than leaving people to guess, removes most of the ambiguity that leads to shadow AI in the first place. If GDPR applies to you, this section should also nod to lawful basis and data-subject rights, since the full GDPR text treats AI processing the same as any other processing of personal data. A useful test for staff: if you wouldn't paste it into a public forum, don't paste it into a free AI tool either, since the retention and training terms can end up surprisingly similar.

Is a generator better than a template?

A static template gives you a starting shape but leaves you to work out which clauses actually apply to your business. A generator asks a handful of questions - do you handle health data, do you have EU customers, what size is your team - and builds a policy tailored to the answers, with the regulatory clauses that matter to you already in place and the ones that don't left out. For most small teams that's faster and more accurate than editing a generic document line by line, and it's harder to accidentally leave a clause half-finished.

Step 4: add the regulatory clauses that apply to you

If you have EU users or EU-based staff, the EU AI Act, and specifically its Article 4 AI-literacy duty, expects you to disclose AI interactions and ensure basic AI literacy among staff who use it. If you handle health data, HIPAA requires a signed Business Associate Agreement with any AI vendor that touches patient information. If you sell into enterprise or B2B accounts, SOC 2 auditors increasingly expect an AI usage policy to exist as evidence of vendor-risk controls, referencing something close to the AICPA's Trust Services Criteria, not just as a nice-to-have.

Do contractors and freelancers need to follow it too?

Yes, and it's an easy thing to miss. Contractors, agency staff and freelancers acting on your behalf can create exactly the same exposure as an employee, sometimes more, since they're often working across several clients' confidential data at once. Naming them explicitly in the scope, and referencing the policy in contractor agreements, closes a gap that a lot of otherwise-solid policies leave open.

Step 5: name an owner and get it signed

Say who owns the policy and handles questions, exceptions and breaches, whether that's an IT lead, an HR manager or a founder wearing several hats. Then circulate it and collect acknowledgement from everyone it applies to; an unsigned policy sitting in a shared drive proves nothing to an auditor. A fifteen-person design studio we've seen do this well ran the whole rollout in one afternoon: a short all-hands walkthrough, a link to the policy, and a one-click acknowledgement logged against each name. Six months later, when a prospective client's procurement team asked for evidence of an AI policy during due diligence, the studio had a dated document and a signed list ready to send within the hour, instead of scrambling to write one under deadline pressure.

Start from the generator, not a blank page

You don't need to draft any of this from scratch. Our free AI usage policy generator builds all of the above - scope, stance, data rules, the regulatory clauses relevant to your answers, and an owner field - tailored to your team in a couple of minutes, ready to circulate and collect sign-off on the same day. It's a faster route to something specific than starting from a generic ai usage policy template and stripping out the clauses that don't apply to you, and it's harder to accidentally miss a section that matters.

Policy sectionPurposeExample clause
ScopeWho and what it coversApplies to employees, contractors and anyone using AI on the company's behalf
Data rulesWhat can and can't go into an AI toolNever enter customer PII or source code into a consumer-tier AI tool
Approved tools listRemoves guesswork for staffOnly tools on the approved register may be used for company work
TransparencyEU AI Act and customer trustDisclose when content or a decision was AI-assisted
Owner and reviewAccountability over timePolicy owner reviews it annually, or after any vendor data-policy change
What to include in each section of an AI usage policy
The policies that actually get followed are the ones a new hire can read in five minutes and still remember on a Friday afternoon.
ModelCharter's compliance team

Frequently asked questions

Is an AI usage policy legally required?
Not as a single named document in most jurisdictions, but the underlying obligations often are. The EU AI Act's AI-literacy duty, GDPR's data-handling rules and HIPAA's BAA requirement are all easiest to evidence with a written policy, even where no law names 'AI usage policy' specifically.
How long should an AI usage policy be?
Long enough to cover scope, stance, data rules, relevant regulatory clauses and an owner - usually one to three pages. If it's much longer than that, most staff won't read it, which defeats the purpose.
Can I use a generic template instead of writing my own?
You can as a starting point, but a generic template won't reflect your actual data sensitivity, sector or which tools your team uses, so it usually needs real editing. A generator that asks about your business gets you closer to a finished, accurate policy faster.
What happens if an employee breaks the AI usage policy?
That should be defined in the policy itself, typically a tiered response: a conversation and retraining for a first, low-harm slip, escalating for repeated or high-harm breaches such as entering regulated customer data into an unapproved tool.
Does the policy need updating every time we adopt a new AI tool?
The approved-tools register does, yes, ideally as a living list rather than a static one, updated as soon as a tool is approved or removed. The policy text itself usually only needs a full review annually, unless a new tool or a new regulatory requirement changes your data-handling stance meaningfully in between.

Put this into practice

Generate a free AI usage policy for your team, then see which of your tools are safe to use.

Open the generator