# Acceptable AI Use Policy: [Company name]

Version: [1.0] · Effective date: [date] · Owner: [name, role] · Next review: [date, quarterly]

Free template by Easy Cyber Protection (easycyberprotection.com). Replace every [bracketed] placeholder, delete what does not apply, and keep the policy itself to one page.

---

## 1. The policy (one page)

### 1.1 Approved AI tools

Only the tools below may be used for work. Use business accounts, never private ones. Any tool not on this list needs approval from [contact person] first.

| Tool | Approved for | Account type |
|------|--------------|--------------|
| [Tool 1] | [e.g. drafting text, no customer data] | Business |
| [Tool 2] | [e.g. meeting transcription, internal only] | Business |

### 1.2 Data that never goes into an external AI tool

- Customer names, addresses and any other personal data
- Payroll and financial records
- Passwords, access keys and security codes
- Contract terms and anything under a confidentiality agreement
- [Add categories specific to your business]

If you would not email it to a stranger, do not paste it into an AI tool.

### 1.3 Labelling AI-generated content

From 2 August 2026, Article 50 of the EU AI Act requires labels on certain AI-generated content. Before anything AI-generated is published (text on matters of public interest, images, video, chatbots), [name] checks whether it must be labelled and how.

### 1.4 When in doubt, ask

For the question "may I use this tool, with this data?": ask [name], [channel, e.g. direct message or email]. Asking is always free of consequences.

### 1.5 If data ended up in the wrong tool

Tell [name] immediately. Reporting is never punished. Fast reporting is the only way to limit damage.

---

## 2. AI tool and agent register

One row per approved tool and per AI agent. The register owner is [name].

| Name | Type (tool / agent) | Purpose | Data allowed | Owner | Review date |
|------|--------------------|---------|--------------|-------|-------------|
| [ ] | [ ] | [ ] | [ ] | [ ] | [ ] |

## 3. Rules for AI agents

Every autonomous AI agent is treated like a new hire:

1. **Owner:** one named person is accountable for what the agent does.
2. **Scope:** written down which systems it may touch and which data it may read.
3. **Offboarding:** when the owner leaves or changes roles, the agent is reassigned or switched off and its credentials are revoked.

An agent nobody owns is switched off.

## 4. Quarterly review checklist

Fifteen minutes, every quarter, same calendar slot as the patch or access review:

- [ ] Any new AI tools in use since last quarter? (survey answers, expenses, IT signals)
- [ ] Any approved tools no longer used? Remove from the register, close the accounts.
- [ ] Any vendor terms changed? (training on your data, storage location)
- [ ] Any agents without a current owner? Reassign or switch off.
- [ ] Policy date and register review dates updated.

---

This template is provided as-is, free to use and adapt. It is not legal advice.
