Starter Kit · Vol. 01
[ Free resource ]
The AI Acceptable Use Policy Starter Kit.
A ready-to-customize policy template, a three-layer security checklist, and a rollout plan that won't kill adoption.
01 Executive summary
02 The AUP template
03 Security checklist
04 Why this cannot wait
05 Five questions for IT
06 Rollout plan
AI Acceptable Use Policy · Starter Kit
[ Section 01 ] Executive summary
Your team is already using AI.
This kit puts a fence around it.
98% of organizations have employees using AI tools nobody approved. An Acceptable Use Policy is the single fastest control you can put in place — one afternoon of work, no new software, no IT department required.
1.1What this kit gets you
- A working AUP by end of day. Fill in the blanks in Section 02, circulate it, done. Revise quarterly.
- A security floor. The three-layer checklist (Section 03) covers identity, data, and monitoring at SMB scale.
- A rollout that sticks. The plan in Section 06 introduces the policy without making your team hide their tools.
1.2How to use it
-
Print this kit, or duplicate the template.
The blanks are designed to be written in by hand. The policy doesn't need to be pretty — it needs to exist.
-
Fill in Section 02 with one other person.
Owner + one operator. Two people, ninety minutes. Don't form a committee.
-
Run the checklist and the five questions.
Sections 03 and 05 tell you what to verify yourself and what to demand from your IT provider.
-
Roll it out using Section 06 — in this order.
Amnesty first, policy second. Companies that reverse the order push AI use underground.
This template is a starting point, not legal advice. Have counsel review the final policy — especially if you handle regulated data (health, finance, legal).
AI Acceptable Use Policy · Starter Kit
[ Section 02 ] The AUP template
The policy. Fill in the blanks.
Everything in dotted blanks is yours to complete. Keep the final document under three pages — a policy nobody reads is a policy nobody follows.
2.1Purpose & scope
Policy title
Organization
Effective date
Policy owner (name + role)
This policy governs the use of artificial intelligence tools by all employees, contractors, and temporary staff of , across all locations and devices — including personal devices used for work.
2.2Approved AI tools
Only tools listed here may touch company data. Anything not on the list is not approved — adding a tool requires sign-off from the policy owner.
| Tool | Approved use | Data permitted | Account owner |
| | | |
| | | |
| | | |
| | | |
Start with what people already use. Survey the team first (Section 06, step 1) — the approved list should legalize the good tools, not pretend they don't exist.
AI Acceptable Use Policy · Starter Kit
2.3Prohibited uses
These apply to every tool, including approved ones.
- Client data in any AI tool not on the approved list — names, contracts, financials, correspondence.
- Credentials & access — never paste passwords, API keys, or system configurations into a prompt.
- Personal accounts for company work. Company AI use happens on company-controlled accounts only.
- Legal, hiring, or disciplinary decisions made by AI without documented human review.
- Proprietary code or trade secrets in tools that train on user data — check the vendor's data policy.
- Impersonation — AI-generated content presented as a specific person's words without their sign-off.
2.4Data handling rules
Classify before you paste. When unsure, treat data as one level more sensitive than you think it is.
| Data class | What it includes | AI handling |
| Public | Published marketing, website copy, public filings. | Any approved tool. |
| Internal | Process docs, internal memos, non-sensitive ops data. | Approved tools on company accounts only. |
| Confidential | Client records, contracts, financials, employee data. | Only tools with a zero-retention agreement, listed in 2.2. |
| Restricted | Health, payment, legal-hold, or regulated data. | No AI tools. No exceptions without counsel. |
2.5Oversight & accountability
AI governance owner
Backup / second reviewer
The governance owner maintains the approved list, reviews new tool requests within business days, and reports AI-related incidents to leadership.
AI Acceptable Use Policy · Starter Kit
2.6Incident response
What counts as an incident: sensitive data pasted into an unapproved tool · an AI agent acting outside its scope · AI-generated content sent externally with material errors · a vendor breach affecting a tool on the approved list.
-
Report it the same day — no blame attached.
To the governance owner, via . The policy explicitly protects good-faith reporting.
-
Contain.
Revoke the tool's access, rotate any exposed credentials, export the chat/agent history before it ages out.
-
Assess and notify.
Governance owner determines if client or regulated data was exposed; if so, follow your breach-notification obligations.
-
Fix the rule, not just the mistake.
Every incident ends with one sentence added or changed in this policy.
2.7Review cadence
This policy is reviewed every months by the governance owner, and immediately after: any incident (2.6) · adoption of a new AI tool · a major vendor policy change · new regulation affecting your industry.
Next scheduled review
Employee acknowledgment collected via
Signature block: each employee signs once at rollout and re-acknowledges at each review. Keep it to one line — "I have read and will follow the AI Acceptable Use Policy, version ."
AI Acceptable Use Policy · Starter Kit
[ Section 03 ] The three-layer security checklist
Three layers. Check every box.
This is the security floor for AI at SMB scale. If a box stays unchecked for more than a quarter, that's the agenda for your next IT conversation.
Layer 01Identity & access
- Every AI tool is accessed through company-managed accounts — no personal logins for work.
- MFA is enforced on every account that can reach an AI tool with company data.
- AI agents have their own service accounts with least-privilege scopes — never a person's credentials.
- Departing employees lose AI tool access the same day as email access.
Why this matters → Most AI data leaks aren't hacks. They're personal accounts that never got offboarded.
Layer 02Data protection
- Every approved tool has a written data-retention answer: does it train on our inputs, and for how long are they stored?
- Confidential data only flows to tools with zero-retention or enterprise agreements (per table 2.4).
- Browser extensions with AI features are inventoried and approved like any other tool.
- File-sharing permissions are reviewed so AI integrations can't reach folders they don't need.
Why this matters → An AI integration inherits every permission of the account that installed it. Scope the account, scope the AI.
Layer 03Monitoring & response
- Someone (internal or your IT provider) can see which AI tools are in use across company devices.
- Agent actions — emails sent, records changed — are logged and reviewable.
- The incident path in 2.6 has been tested once, on purpose, as a drill.
- Shadow-AI discovery runs at least quarterly — new tools found go to the approved list or the blocked list.
Why this matters → You can't write rules for tools you can't see. Discovery is the control that makes every other control real.
AI Acceptable Use Policy · Starter Kit
[ Section 04 ] Why this cannot wait
The numbers from the room you're already in.
The evidence base behind this kit. None of it requires a prediction — it's already happening inside companies your size.
98%
of organizations have employees already using unsanctioned AI tools.
Second Talent · Shadow AI Report
21%
have a mature governance model for autonomous AI agents.
Gartner / McKinsey / IDC
40%
of agentic AI projects will be cancelled by end of 2027 — mostly for missing foundations, not failed tech.
Gartner · 2026 forecast
$301B
projected global AI spend in 2026 — most of it racing past governance.
IDC · 2026 outlook
Read together: adoption is universal, oversight is rare, and the gap is where incidents live. The AUP in Section 02 is the cheapest way to close it.
AI Acceptable Use Policy · Starter Kit
[ Section 05 ] Five questions for your IT provider
Which AI tools can you see running in our environment right now?
If the answer is "we'd have to check," discovery isn't happening.
Which of our current tools have AI features switched on by the vendor?
Most "shadow AI" arrives inside software you already pay for.
What data-retention terms do our AI vendors actually commit to?
You need the written answer per tool — it drives table 2.4.
If an agent sends something it shouldn't, what gets logged — and for how long?
Incident response (2.6) is only as good as the logs behind it.
What would you block first, today, if we asked?
A provider with a ready answer has thought about your environment. Silence is its own answer.
[ Section 06 ] Rollout without killing adoption
Amnesty week.
Ask everyone what AI tools they use, with a written promise of zero consequences. You're mapping, not policing.
Legalize the good tools.
Put the popular, safe ones on the approved list (2.2) on company accounts. Adoption goes up, not down.
Publish the policy — two pages, plain language.
Walk it through in one all-hands. The tone is "here's how we use AI well," never "AI is dangerous."
Run the checklist with IT.
Section 03, one meeting, boxes checked or scheduled.
Review quarterly. Celebrate good catches.
The first person who reports an incident in good faith should be thanked publicly. That's the whole culture.
Want a second set of eyes on your AI setup?
Book a
free 30-minute discovery call — we'll review your policy draft, walk the security checklist together, and flag the one gap most likely to bite you. No pitch, no obligation. Prefer to self-assess first?
Take the free AI Readiness Assessment →
Book a free call