A ready-to-adopt template for small and mid-sized businesses, from Open Arm Solutions
How to use this template
- Replace everything in [square brackets] with your company's details. Search the document for "[" to find them all.
- Fill in the Approved AI Tools list (Appendix A). Start small: one or two approved tools are better than an open door.
- Decide who owns the policy and who approves new tools (section 3). In a small company this can be the owner.
- Have your attorney review the policy, especially if you are in a regulated industry such as healthcare, finance, insurance, or legal services.
- Walk your team through the Quick Reference page, have everyone sign the acknowledgment (Appendix C), and post the Quick Reference where people work.
- Put a review date on the calendar. AI tools change monthly; review this policy at least every 6 months.
This template is general information, not legal advice. Laws differ by state and industry.
Quick Reference: AI at [Company Name]
The one rule: Use AI to help with your work, never to replace your judgment, and never with information you would not be allowed to post on our website, unless the tool is on our approved list for that kind of information.
Green: go ahead (approved tools)
- Brainstorming, outlining, and first drafts of emails, posts, and documents
- Rewriting, summarizing, or translating public information
- Explaining a concept, a spreadsheet formula, or a piece of code that contains no secrets
- Checking grammar and tone
Yellow: approved tools and company accounts only, and review the output
- Internal information such as procedures, meeting notes, and non-sensitive project details
- Anything that will be sent to a customer or published
- Code that will be used in our systems
- Any AI feature that connects to company email, files, calendar, or CRM
Red: never put this into any AI tool unless Appendix A specifically approves that tool for it
- Customer or employee personal information (names with contact details, addresses, dates of birth)
- Social Security numbers, driver's license or passport numbers
- Payment card numbers, bank account and routing numbers
- Passwords, API keys, access tokens, security codes
- Health or medical information about anyone
- Employee HR information: pay, performance, discipline, medical leave
- Client information covered by a contract or NDA
- Legal matters, disputes, and anything from our attorneys
- Unreleased financial results, pricing strategy, or deals in progress
- Details of our security setup or vulnerabilities
Always
- Use your company account, never a personal or free account, for work.
- Check every fact, number, name, quote, citation, and line of code before you use it. AI makes things up confidently.
- Have a person review anything before it goes to a customer or the public.
- Tell people when they are talking to an AI system or seeing realistic AI-generated images, video, or voices.
- Never let an AI tool approve or send a payment, refund, transfer, or change to bank details.
- Verify any unusual request for money or data by calling back on a number you already have, even if the voice or video looks and sounds exactly like someone you know.
- Report mistakes, leaks, and suspicious requests to [Name, email, phone] within [24 hours]. Reporting quickly will never get you in trouble.
Not sure? Ask [Name] before you paste.
Full Policy
| Item | Details |
|---|---|
| Policy owner | [Name, Title] |
| Approved by | [Name, Title] |
| Effective date | [Date] |
| Next review | [Date, no more than 6 months after the effective date] |
| Version | [1.0] |
1. Purpose
AI tools can save our team real time. They can also leak confidential information, produce confident mistakes, and create legal risk. This policy sets out how [Company Name] uses AI so we get the benefits while protecting our customers, our employees, and our business.
2. Scope
This policy applies to:
- People: all employees, contractors, interns, and temporary staff, whenever they do work for [Company Name].
- Devices: company devices and personal devices used for company work.
- Tools: every tool that uses AI to generate, analyze, or act on content, including:
- chat assistants (for example, ChatGPT, Claude, Gemini, Copilot);
- AI features built into software we already use (email, documents, spreadsheets, CRM, help desk, accounting, design tools);
- meeting recorders, transcription, and note-taking tools;
- browser extensions and plug-ins with AI features;
- image, video, and voice generators;
- coding assistants;
- AI "agents" that can take actions such as sending email, updating records, or browsing the web.
3. Roles
- Policy owner ([Name, Title]) keeps this policy and the Approved AI Tools list current, approves new tools and new uses of Restricted data, and handles incident reports.
- Managers make sure their teams know the policy and review AI-assisted work in their area.
- Everyone follows the policy, asks when unsure, and reports problems quickly.
4. Approved tools
4.1 Only tools listed in Appendix A may be used for company work, and only for the data classes listed for each tool.
4.2 Use company-provided accounts. Personal and free consumer accounts may not be used with any company information other than Public information, because their terms often allow the provider to keep your inputs or use them to improve its models.
4.3 Where a tool offers settings to turn off use of our data for model training, or to limit how long conversations are kept, the policy owner sets them for the company account. Do not change them.
4.4 Requesting a new tool or feature. Submit the request form in Appendix B. The policy owner reviews it against this checklist before approving:
- The provider's business terms do not allow it to train models on our inputs, or training can be turned off for our whole account.
- We can control how long data is retained, and delete it.
- It supports multi-factor authentication, and preferably single sign-on.
- An administrator can manage users and remove access when someone leaves.
- The provider publishes its security practices and, ideally, an independent attestation such as a SOC 2 Type II report.
- The provider will sign a data processing agreement, and a Business Associate Agreement if health information is involved.
- We know where the data is stored and which other companies (subprocessors) can access it.
- We understand what the tool can access once connected (for example, "read all email" versus "read one folder").
4.5 Browser extensions, meeting bots, and AI agents need approval even if they are free, because they can see far more than you paste into them.
5. Data classification
Every piece of information falls into one of four classes. When information mixes classes, treat it as the highest one.
| Class | What it is | Examples | AI rule |
|---|---|---|---|
| Public | Already published or meant for anyone | Website content, published prices, press releases, public product information | Any approved tool |
| Internal | Day-to-day information not meant for outsiders, but low harm if exposed | Internal procedures, meeting agendas, general project updates, non-sensitive drafts | Approved tools, company accounts only |
| Confidential | Would harm us, a customer, or a partner if exposed | Client information under contract or NDA, unreleased financials, pricing strategy, vendor contracts, non-public plans, source code | Only tools Appendix A approves for Confidential data, and only the minimum needed |
| Restricted | Regulated or highly sensitive; exposure could cause legal liability or real harm to people | Personal information about customers or employees, Social Security and ID numbers, payment card and bank data, passwords and keys, health information, HR records, legal matters | Never in any AI tool unless Appendix A names a specific system approved in writing by the policy owner for that data (for example, a private system we host ourselves, covered by the right contracts) |
How to remove sensitive details before using AI. Often you can get the same help without the sensitive part:
- Replace names with roles: "Customer A," "Employee 1."
- Remove or change account numbers, addresses, dates of birth, and amounts that could identify someone.
- Describe the situation instead of pasting the document: "A customer is disputing a late fee on a 60-day-old invoice; draft a polite reply" instead of pasting the customer's email thread.
- Use made-up sample data to test formulas, code, and workflows.
6. Human review and accountability
6.1 You own the output. If you use AI to help produce something, you are responsible for it as if you wrote it yourself.
6.2 Check before you use. Verify facts, figures, names, dates, quotations, legal or regulatory statements, and citations against a reliable source. Test code before it is used, and never run AI-generated code or commands you do not understand on company systems.
6.3 Documented review required. The following uses need review and approval by [a manager / the policy owner] before the output is used:
- Content sent to many customers at once, or published on our website or social media
- Contract terms, legal notices, or anything that states our legal obligations
- Financial figures in reports, invoices, quotes, or filings
- Code or configuration that goes into production systems
- Safety, health, or medical information
6.4 Decisions about people. AI may help organize information, but a person must make, and be able to explain, any decision about hiring, firing, promotion, discipline, pay, credit, pricing for an individual, eligibility, or benefits. Do not use AI tools to screen, rank, or evaluate job applicants or employees unless the policy owner has approved that specific tool and use in writing after legal review.
6.5 Money stays with people. AI tools and agents may draft or prepare payments, refunds, invoices, transfers, or changes to vendor bank details, but they may never approve or execute them. A person must approve each one through our normal financial controls.
6.6 Prohibited uses. Do not use AI to:
- Create fake reviews, testimonials, or endorsements, or reviews from people who never used our product or service. The FTC prohibits this and can seek large civil penalties.
- Impersonate a real person, or clone anyone's voice or likeness, without that person's written permission.
- Create deceptive, harassing, discriminatory, or sexually explicit content.
- Get around security controls, access information you are not authorized to see, or monitor coworkers.
- Copy content you do not have the rights to use, including uploading other companies' copyrighted materials to an AI tool in breach of their terms.
7. Disclosure and transparency
7.1 Talking to AI. Customers and the public must be told when they are interacting with an AI chatbot or AI voice agent rather than a person, and must be able to reach a person.
7.2 Realistic synthetic media. Label AI-generated images, video, or audio that show realistic people or events.
7.3 Calls and texts. Any automated, prerecorded, or AI-generated voice calls or automated texts to customers or prospects must be approved by the policy owner in advance. Federal rules treat AI-generated voices as "artificial" voices, which generally require the called person's prior express consent (prior express written consent for marketing), and Florida's telemarketing law adds its own requirements.
7.4 Brand assets. Logos, key marketing content, and other work we want to own and protect should involve meaningful human creative work. The U.S. Copyright Office has said that material generated entirely by AI from prompts is not protected by copyright.
7.5 Inside the company. Be open about AI use. If a manager or customer asks whether AI was used in a piece of work, answer honestly.
8. Meeting recorders and note-takers
- Use only the approved meeting tool listed in Appendix A.
- Announce it and get agreement. Florida, and a number of other states, require the consent of everyone in a conversation before it is recorded. Tell participants at the start that an AI note-taker or recording is running, and turn it off if anyone objects.
- Do not use recorders or note-takers in meetings about HR matters, legal matters, health information, or anything Restricted, unless the policy owner approves it.
- Do not let note-taking bots join meetings with customers or other outside parties unless they have agreed.
- Recordings and transcripts are company records. Keep them only as long as Appendix A says, then delete them.
9. AI agents and connected tools
AI tools that connect to company email, files, calendars, CRM, or other systems, or that can take actions on their own, carry extra risk.
- Get approval before connecting any AI tool to a company system, including through "Sign in with Google/Microsoft" or other permission screens. Never connect a personal AI account to company systems.
- Grant the least access needed: read-only first, one folder rather than the whole drive.
- Do not let agents send messages outside the company, delete data, or change records without a person reviewing the action, unless the policy owner has approved that automation in writing.
- Watch for prompt injection: emails, documents, and web pages can contain hidden instructions that try to trick an AI tool into leaking data or taking an action. Be suspicious if an AI tool suddenly wants to send data somewhere, change settings, or do something you did not ask for. Stop and report it.
10. Security
- Turn on multi-factor authentication for every AI tool account.
- Do not share AI tool accounts or logins.
- Never paste passwords, keys, or access tokens into an AI tool, even to "fix" a configuration.
- Install AI browser extensions, plug-ins, and apps only from Appendix A.
- Deepfake fraud is real. Criminals use cloned voices and fake video to impersonate executives, vendors, and customers. For any request involving money, gift cards, bank details, passwords, or sensitive data that arrives by email, text, call, or video, verify it by calling back on a number we already have on file. Urgency and secrecy are warning signs.
11. Reporting incidents
Report within [24 hours] to [Name, email, phone] if:
- You or someone else put Confidential or Restricted information into a tool not approved for it.
- AI-generated content with a significant error went to a customer, was published, or was used in a decision.
- An AI tool or agent did something unexpected, such as sending a message or changing data.
- You received a suspicious request that may involve a deepfake or impersonation.
- An AI tool account may have been compromised.
What to do:
- Stop using the tool for that task.
- Do not delete the conversation or files yet; the policy owner may need them.
- Report what happened, which tool, what information was involved, and when.
- Follow the policy owner's instructions, which may include deleting the conversation and asking the provider to delete the data.
The policy owner will assess whether customers, clients, or regulators must be notified. Some notice deadlines are short; for example, Florida's data breach law generally requires notice to affected individuals within 30 days.
No-blame reporting. People who report their own mistakes promptly will not be disciplined for the mistake itself. Hiding a problem is a much bigger issue than making one.
12. Training and acknowledgment
- New team members review this policy and sign Appendix C before they get access to AI tools.
- Everyone completes a short refresher at least once a year, and whenever the policy changes significantly.
13. Enforcement
Violations may result in loss of access to AI tools and disciplinary action, up to and including termination, in line with our other policies. Good-faith mistakes reported promptly are treated as learning opportunities.
14. Review
The policy owner reviews this policy and Appendix A at least every 6 months, and sooner if we adopt a major new tool, a law changes, or an incident shows a gap.
| Version | Date | Changes | Approved by |
|---|---|---|---|
| [1.0] | [Date] | Initial policy | [Name] |
Appendix A: Approved AI Tools
| Tool and plan | Account type | Approved for (highest data class) | Approved uses | Key settings | Retention | Owner |
|---|---|---|---|---|---|---|
| [Example: ChatGPT Business, Claude Team, Microsoft 365 Copilot, or Gemini in Google Workspace] | Company account with SSO/MFA | [Internal / Confidential] | [Drafting, summarizing, analysis] | [Model training off; chat history retention set to X days] | [X days] | [Name] |
| [Meeting note-taker] | Company account | [Internal] | [Internal meetings only, with announcement] | [Auto-join off; recording notice on] | [30 days] | [Name] |
| [Coding assistant] | Company account | [Confidential: our code, no secrets] | [Code suggestions, tests, documentation] | [Training on code off; secret scanning on] | [N/A] | [Name] |
| [Private AI system for Restricted data, if any] | Company-hosted | [Restricted, only as approved] | [Specific approved purpose] | [Access limited to named roles; audit logs on] | [Per records policy] | [Name] |
Not approved: personal or free accounts for company work; AI browser extensions not listed above; any tool not listed above.
Appendix B: New AI Tool or Use Request
| Question | Answer |
|---|---|
| Requested by / date | |
| Tool name, plan, and website | |
| What will you use it for? | |
| Highest data class it would touch (Public / Internal / Confidential / Restricted) | |
| Will it connect to company systems (email, files, CRM)? Which permissions does it ask for? | |
| Will it take actions on its own (send, delete, update)? | |
| Cost and who pays | |
| Does the provider train on our data? Can training be turned off for our account? | |
| Data retention and deletion options | |
| MFA / SSO / admin controls available? | |
| Security attestation (e.g., SOC 2 Type II) and data processing agreement available? | |
| Decision (approved / approved with conditions / declined), conditions, and date | |
| Approved by |
Appendix C: Employee Acknowledgment
I have read the [Company Name] AI Acceptable Use Policy, version [1.0]. I understand it and agree to follow it. I understand that:
- I may use only approved AI tools, with company accounts, for the data classes they are approved for.
- I will never put Restricted information into an AI tool unless that tool is specifically approved for it.
- I am responsible for checking AI output before I use it.
- I will report AI-related mistakes and suspicious requests within [24 hours].
Name: ______________________ Signature: ______________________ Date: ____________
AI Acceptable Use Policy template provided free by Open Arm Solutions (https://openarmsolutions.com). You may adapt it for your organization's internal use. It is general information, not legal advice; have your attorney review it before you adopt it. Want help choosing approved tools and rolling this out to your team? Ask about our "Using AI Safely: Protect Your Business Data" workshop: openarmsolutions@gmail.com.