GovernanceCore

Generative AI Usage Policy Template for Employees (2026)

A real, copy-paste generative AI Acceptable Use Policy for employees, plus the guidance to adapt it. Covers why every organization needs one now (shadow AI, data leakage, the EU AI Act AI-literacy duty), the nine areas a good policy must address, a complete thirteen-section template with bracketed placeholders, how to roll it out, and the four mistakes that make policies fail.

AI Governance TeamPublished July 13, 202610 min read
Key takeaways
  • A real, copy-paste generative-AI acceptable-use policy for employees.
  • Addresses shadow AI, data leakage and EU AI Act transparency duties.
  • Every organization needs one now, adapted to its risk appetite.
  • Pair the policy with discovery and training to make it stick.
~2 in 3Employees use unapproved AI tools at work (Gartner)
88%Organizations use AI in at least one function (McKinsey 2025)
51%Report a negative AI incident (McKinsey State of AI 2025)
2 Feb 2025EU AI Act AI-literacy duty in force (Art. 4)

Your staff are already using generative AI. The only real question is whether they are doing it under a policy you wrote or in a vacuum you did not. Gartner estimates that roughly two-thirds of employees use AI tools their employer never approved, a pattern usually called shadow AI. Every one of those sessions can carry customer records, source code, or unreleased strategy into a third-party model with no contract, no data-handling terms, and no audit trail.

A written generative AI usage policy is the cheapest control you can put in place, and one of the few now expected by law. Since 2 February 2025, Article 4 of the EU AI Act requires providers and deployers to ensure staff who work with AI have a sufficient level of AI literacy. A clear policy, paired with training, is how most organizations meet that duty. This guide gives you a real, copy-paste template plus the guidance to adapt it to your organization.

This template is a practical starting point, not legal advice. Have your legal, HR, and data protection teams review and tailor it before you publish. Requirements vary by jurisdiction, sector, and the AI tools you actually run.

Why Every Organization Needs One Now

The tools spread faster than any procurement process, and the exposure is legal, commercial, and reputational at once.

Generative AI reached the workforce before governance did. A single employee can paste a confidential contract into a public chatbot for a summary and, in doing so, hand that text to a vendor whose default terms may allow it to be retained or used to train a model. The intent is harmless. The exposure is not. That is the core of the shadow AI problem: adoption happens at the level of the individual, quietly, without a review anyone can see.

The stakes are concrete. In its State of AI 2025 report, McKinsey found that 88% of organizations now use AI in at least one business function, and 51% had experienced a negative consequence from it, from inaccuracy to security and compliance incidents. When the tools are unmanaged, three failure modes recur: sensitive data leaves the building, staff act on confident but wrong output, and no one can reconstruct what happened afterward.

Regulation has caught up to the point where silence is its own risk. Article 4 of the EU AI Act, in force since 2 February 2025, obliges providers and deployers of AI to ensure a sufficient level of AI literacy among staff who use it on their behalf. Transparency duties under Article 50 apply from 2 August 2026. A usage policy turns those duties into everyday behavior, and it is the document an auditor or regulator asks to see first.

A policy nobody can enforce is a wish. The value of a generative AI policy is not the document. It is the combination of clear rules, real training, an approved-tools list, and the ability to see whether the rules are being followed. AI Governance Core, editorial view

What a Good Policy Must Cover

Nine building blocks separate a usable policy from a vague statement of principles.

Most weak policies fail the same way: they state that employees should use AI "responsibly" and stop there. Responsibly is not a rule. A policy that changes behavior names the tools, draws bright lines around the data, and says what happens when someone crosses them. The nine areas below are the ones your template needs to address in plain terms.

1. Approved tools

Name the specific tools staff may use and for what. An allowlist beats a vague blessing, because it gives people a safe default and makes shadow AI easier to spot.

2. Prohibited uses

State the hard limits: no confidential data in unapproved tools, no fully automated decisions about people, no illegal or deceptive output.

3. Data and confidentiality

Define what may never be entered into a public model: personal data, client information, trade secrets, credentials, and source code.

4. Human review of outputs

Require a competent person to check AI output before it is used, published, or acted on. The employee, not the tool, owns the result.

5. Disclosure and labeling

Say when AI involvement must be disclosed, internally and to customers, in line with EU AI Act Article 50 transparency duties.

6. IP and copyright

Address ownership of prompts and output, and the risk that generated content reproduces third-party or copyrighted material.

7. Bias and accuracy

Make clear that outputs can be wrong or biased, and that the user is responsible for checking facts, figures, and fairness.

8. Security

Cover account and access rules, prompt injection awareness, and a duty to report suspected AI-related security incidents.

9. Consequences

Tie violations to the existing disciplinary process so the policy has teeth, and reassure staff that honest questions are welcome.

Write for the reader, not the auditor. The people who need this policy are marketers, engineers, and analysts under deadline pressure. If a rule cannot be understood in one read and applied without a lawyer, it will be ignored. Short clauses and a clear approved-tools list do more for compliance than ten pages of caveats.

The Template: A Copy-Paste Acceptable Use Policy

Copy the thirteen sections below, replace every [bracketed placeholder], and run it past legal and HR before you publish.

What follows is a complete Generative AI Acceptable Use Policy written in plain language. Each numbered section carries a sample clause you can adopt with light editing. Keep the numbering; it makes the policy easy to reference in training and in disciplinary discussions. Placeholders in square brackets mark the parts that must reflect your organization.

Generative AI Acceptable Use Policy · [Company Name] · Version [1.0] · Effective [date] · Owner: [role, e.g. Head of AI Governance]

1. Purpose

This policy sets out how employees, contractors, and temporary staff of [Company Name] may use generative AI tools in their work. Its aim is to let people benefit from these tools while protecting our data, our customers, our legal position, and the quality of what we produce. It supports our obligations under applicable law, including the AI-literacy duty in Article 4 of the EU AI Act.

2. Scope

This policy applies to all [Company Name] personnel and to all generative AI tools, whether paid, free, standalone, or built into other software, when used for company purposes or with company data. It applies on any device, including personal devices used for work. It sits alongside our [Acceptable Use Policy], [Data Protection Policy], and [Information Security Policy], which continue to apply in full.

3. Definitions

Generative AI means a system that produces text, code, images, audio, video, or other content from a prompt, including large language models and the assistants and agents built on them. Prompt means any input you provide to such a tool. Output means anything the tool returns. Confidential information has the meaning given in [Company Name]'s [Data Classification Policy].

4. Approved Tools

You may use only the generative AI tools on the current approved list, published at [link or location], and only within any usage tier stated there. The approved list names the tool, the permitted data classification, and the business owner. To request a new tool, submit [intake process]. Do not use unapproved tools for company work or with company data, even for a quick test.

5. Acceptable Uses

Within the approved tools, you may use generative AI to support tasks such as drafting and editing content, summarizing non-confidential material, brainstorming, writing and reviewing code within [approved repositories or environments], and research, provided you verify the output. You remain responsible for anything you produce with AI assistance, exactly as if you had produced it unaided.

6. Prohibited Uses

You must not: enter confidential, personal, or client data into an unapproved tool; use AI to make a final decision that significantly affects a person (such as hiring, firing, credit, or discipline) without human review and any legally required assessment; generate content that is illegal, harassing, discriminatory, or deliberately misleading; impersonate a real person; or present AI output as human work where disclosure is required. Do not attempt to bypass a tool's safety controls.

7. Data and Confidentiality

Never enter into a generative AI tool anything you would not be comfortable sending to an outside party, unless the tool is approved for that data classification and covered by an appropriate contract. This includes personal data, customer and client information, trade secrets, financial results before release, credentials, and proprietary source code. When in doubt, treat the information as confidential and ask [team or channel] before you proceed.

8. Human Oversight and Accountability

A competent person must review AI output before it is published, sent to a customer, committed to a codebase, or used to make a decision. Check facts, figures, quotations, and code for accuracy, and check that the output is fair and free of harmful bias. The reviewer, not the tool, is accountable for the result. Higher-stakes uses require proportionately more scrutiny.

9. Disclosure and Labeling

Disclose the use of generative AI where a reasonable person would expect to know, and where the law requires it. Label AI-generated or AI-assisted content that is published externally in line with [Company Name]'s disclosure standard and with Article 50 of the EU AI Act, which requires that people be told when they are interacting with an AI system or viewing AI-generated content. Follow any client or contractual disclosure terms.

10. Intellectual Property and Copyright

Do not paste third-party copyrighted material into a tool without the right to do so, and do not assume that AI output is free of others' rights. Generated content can resemble or reproduce protected work. Treat AI output as a draft to be checked, not a cleared asset. Ownership of prompts and outputs is governed by [Company Name]'s [IP policy] and the terms of the approved tool.

11. Security

Use only your own authorized account, protected by [company SSO or multi-factor authentication]. Do not share accounts or API keys. Be alert to prompt injection and manipulated content: treat unexpected instructions embedded in documents, emails, or web pages with the same suspicion as a phishing attempt. Report any suspected AI-related security incident to [security contact] without delay.

12. Compliance and Monitoring

[Company Name] may monitor the use of approved AI tools and detect the use of unapproved ones, to the extent permitted by law and our [Employee Privacy Notice], in order to protect data and confirm this policy is followed. Use of company AI tools is subject to logging and review. We will handle any monitoring proportionately and transparently.

13. Violations and Review

Breaches of this policy may lead to action under [Company Name]'s [disciplinary procedure], up to and including termination, and may be reported to authorities where required by law. Raising a concern or reporting a mistake in good faith will not itself be treated as a breach. This policy will be reviewed at least [annually] and whenever the law or our approved tools change. Questions go to [owner or channel].

Do not ship it as-is. Every bracket in the template is a decision your organization has to make: which tools, which data rules, which disciplinary process, which jurisdictions. A policy copied without those choices reads as generic and will not hold up if it is ever tested.

How to Roll It Out

A policy only works once people know it exists, understand it, and can see the approved path. Treat rollout as a project, not an email.

  1. Tailor it to your organization
    Fill every placeholder with a real answer. Decide your approved tools, your data classifications, and how this policy connects to your existing security and data protection documents.
    • Map the AI tools already in use, including the ones bought without IT.
    • Align the language to your sector's rules and your highest-risk use cases.
  2. Get legal and HR sign-off
    Route the draft through legal, HR, data protection, and security. The monitoring, disclosure, and disciplinary clauses in particular must match local employment and privacy law before publication.
    • Confirm the monitoring clause is lawful in every country you operate in.
    • Tie violations to an existing, tested disciplinary process.
  3. Train staff and record it
    Publishing is not the same as training. Run short, role-relevant sessions that show good and bad examples, and keep a record of who was trained. This is how most organizations satisfy the AI-literacy duty in Article 4 of the EU AI Act.
    • Use concrete before-and-after examples from real workflows.
    • Log completion so you can evidence literacy if asked.
  4. Publish the approved-tools list and keep it live
    Give people a single, current page that names what they may use and for what. A living list is the difference between a policy people follow and one they route around.
    • Show the permitted data class and owner for each tool.
    • Make the request process for new tools fast and visible.
  5. Monitor actual usage and review
    A policy you cannot observe is a policy you cannot defend. Watch for shadow AI, track adoption of approved tools, and revisit the document as tools and law change.
    • Detect unapproved tool use and treat spikes as a signal, not only a violation.
    • Review at a set cadence and after any material change.

From policy to practice. Spreadsheets and ticket queues rarely keep up with how fast AI spreads across an enterprise, or with the job of proving a policy is actually followed rather than merely published. Dedicated AI governance platforms give governance teams one place to discover, assess, monitor, and evidence every model and agent against frameworks like the EU AI Act, NIST AI RMF, and ISO 42001.

Common Mistakes to Avoid

Most policies fail in predictable ways. Avoid these four and you are ahead of the majority.

Banning everything. A blanket prohibition does not stop AI use. It pushes it onto personal accounts and personal devices where you have no visibility and no contract, which is worse than the problem you started with.

No approved alternative. If you tell people not to use public chatbots but offer nothing sanctioned in their place, they will keep using the public ones. A prohibition without a safe default is an unfunded mandate.

No monitoring. A policy you cannot measure is a statement of hope. If you have no way to see whether staff follow the rules or which tools are in use, you cannot enforce the policy or evidence compliance to a regulator.

Set and forget. The tools, the vendors' terms, and the law all move quickly. A policy written once and left untouched is out of date within months. Assign an owner and a review cadence, and treat both as mandatory.

Key Takeaways

  • Your staff already use generative AI. Gartner estimates roughly two-thirds use unapproved tools, so the choice is a written policy or an unmanaged one.
  • A usage policy is now partly a legal expectation: Article 4 of the EU AI Act requires AI literacy among staff since 2 February 2025, and Article 50 disclosure duties apply from 2 August 2026.
  • A usable policy names approved tools, draws bright lines around data, requires human review, and ties violations to an existing disciplinary process.
  • Use the thirteen-section template above as a starting point, then replace every placeholder and have legal and HR sign off before you publish.
  • Rollout is the hard part: tailor, get sign-off, train and record it, publish a living approved-tools list, and monitor actual usage.
  • Avoid the four classic failures: banning everything, offering no approved alternative, no monitoring, and set-and-forget.

Frequently Asked Questions

Do we legally need a generative AI usage policy?

No single law says "publish a policy," but several make one the practical way to comply. Since 2 February 2025, Article 4 of the EU AI Act requires organizations that provide or deploy AI to ensure staff have sufficient AI literacy, and a policy paired with training is the standard evidence of that. Data protection and confidentiality obligations also make a written rule the sensible baseline.

Can we just copy this template and publish it?

Use it as a strong starting point, not a finished document. Every bracketed placeholder is a decision only your organization can make: which tools are approved, how your data is classified, which disciplinary process applies, and which jurisdictions you operate in. Have legal, HR, data protection, and security review it before it goes live.

Should we ban public AI tools like ChatGPT outright?

Usually not. A blanket ban tends to push usage onto personal accounts and devices where you have no visibility, no contract, and no data-handling terms. A more effective approach is to approve specific tools, ideally on enterprise plans with proper data terms, and to give people a clear safe default so they do not route around the policy.

What is shadow AI and why does it matter?

Shadow AI is the use of AI tools that the organization never approved or reviewed. Gartner estimates that around two-thirds of employees use such tools at work. It matters because each unmanaged session can move confidential or personal data to a third party outside your contracts and controls, with no audit trail to reconstruct afterward.

How often should the policy be reviewed?

At least annually, and whenever something material changes: a new law or enforcement date, a change to a vendor's terms, a new approved tool, or a serious incident. Assign a named owner responsible for the review so it does not quietly lapse. AI tools and their terms move faster than most policy cycles.

Who should own the policy internally?

Ownership works best when a single accountable role, such as a Head of AI Governance or a designated lead in risk or legal, owns the document, supported by a cross-functional group spanning HR, IT security, legal, and data protection. That group tailors the template, approves the tools list, oversees training, and reviews monitoring results.

ai-usage-policygenerative-aiacceptable-use-policyai-governanceaccountability-oversightshadow-aiEU-AI-Actai-literacyai-complianceresponsible-aipolicy-template
AI Governance Team
Editorial Team

Expert analysis and in-depth reporting from the AI Governance Core editorial team, covering enterprise AI compliance, ethics, and responsible AI practices.

Related analysis

Building an AI Governance Framework: A Practical Guide for Organizations Serious About AI

Building an AI Governance Framework: A Practical Guide for Organizations Serious About AI

AI Governance Team··14 min read
Shadow AI: The Hidden Risk in Every Enterprise (2026)

Shadow AI: The Hidden Risk in Every Enterprise (2026)

AI Governance Team··11 min read