How to Write an AI Use Policy: A Step-by-Step Guide With Template

Write an AI use policy in 8 steps, with a plain template built on NIST, ISO/IEC 42001, the EU AI Act and data regulators' advice on chatbots at work.

An illustrated cover card headed “How to Write an AI Use Policy”, with the line “A step-by-step guide with template”. Line drawing of an open laptop on a desk showing a chat window with two speech bubbles and a teal sparkle badge; beside it stands a single page with three rows, marked by a teal tick, an amber dot and a coral cross.

The Dutch data protection authority issued a warning to employers in August 2024, after several data breach notifications with a single cause: employees pasting personal data into AI chatbots. At a family doctor’s practice, an employee entered patients’ medical data against the practice’s agreements; at a telecom company, an employee entered a file of customer addresses. The regulator’s advice to employers was direct: decide whether staff may use AI chatbots and, if they may, tell them which data they can and cannot enter.1

An AI use policy is the document that gives that answer. It tells staff which AI tools they may use, for which tasks, with which data, who checks the results and whom to ask when unsure. You can write one in eight steps:

  1. Name an owner and a small drafting group
  2. List the AI tools people already use
  3. Decide which data may go into which tool
  4. Sort uses into allowed, ask first and not allowed
  5. Keep a person responsible for every output
  6. Train people on the policy, not just the tool
  7. Give people one place to ask and report
  8. Set a date to review it

A copyable template follows the steps. This is one of our guides to AI at work, written for managers and whoever drafts the rules.

One page beside the chat window: what is allowed, what needs asking first, and what stays out.

Do written AI rules keep company data safe?

Written rules on their own may not be enough. A 2025 survey by the University of Melbourne, co-funded by KPMG, found that employees whose employer had an AI policy or a ban were more likely, not less, to report having put company information into public AI tools.2

The study

Limited evidence

Where employers had AI rules, more staff reported uploading company data

Nicole Gillespie and colleagues asked employees how they used AI at work. Only about two in five said their organization had a policy or guidance on generative AI. About half of those using AI admitted uploading company information, such as financial, sales or customer data, into public AI tools. That behavior was most common where the employer had banned generative AI (67 percent) or had a policy guiding it (56 percent), against about a third where there was no policy.2

The study is a survey taken oncecross-sectional: Describes a study that measures everyone in its sample at a single point in time. Because the possible cause and the outcome are recorded together, it can show that two things occur together but not which of them came first.Full entry in the glossary, so it cannot say which came first: organizations that had already seen problems may have been the ones to write rules. The authors’ own reading is that outright bans may not work and that a policy alone does not guarantee people follow it, so clear guidance and education need to come with it.2

One likely reason, our inference rather than the survey’s finding: a rule that takes a tool away leaves the work where it was, and a free chatbot is one browser tab away. Picture a support agent with a long complaint queue under a policy that says only “do not use public AI tools”. Pasting a complaint into a chatbot on a personal phone is the quickest route, and exactly the case the Dutch authority described.

Eight steps to a first AI use policy

A first AI use policy comes together in eight steps, from naming an owner to fixing a review date. The order matters: data rules need a tool list, and training needs rules.

1. Name an owner and a small drafting group

One person owns the policy and keeps it current, and a senior leader signs it off. A small group covers the rest: someone from IT, whoever handles legal matters and data protection, HR, and one or two people who use AI every day, so the rules fit real work.

Start soon rather than waiting for the perfect draft. The Hamburg data protection commissioner in Germany opens its 2023 checklist for chatbots at work with written internal rules on whether, and under what conditions, which tools may be used, and warns that without them an employer should assume staff will use the tools without permission.3

2. List the AI tools people already use

Among the first questions the European Commission suggests an employer ask is what AI the organization actually uses.4 Include free chatbots, browser extensions and AI features inside existing software, not only what IT bought. Ask without blame, because the goal is a true list, not a list of culprits.

3. Decide which data may go into which tool

Data rules are the core of the policy. The Hamburg checklist says no personal data should go into a chatbot whose terms let the provider use it for its own purposes, and warns that deleting names is not enough when the context still points to someone. Its example: a request to draft a job reference for a salesperson at a named car dealership can identify the employee once it is clear where and when it was written.3

Write data rules per tool, not per type of data alone: the same customer email may be allowed in a tool whose provider has agreed not to store it and forbidden in a free chatbot. Approval is not the same as legality, though: the Dutch authority warns that chatbot use an organization itself allows is not a data breach but is often not permitted by law.1 For a first policy, a short list of data that must never be entered does most of the work.

4. Sort uses into allowed, ask first and not allowed

Concrete examples do more than principles. A 2019 review of 84 AI ethics guidelines by Anna Jobin and colleagues at ETH Zurich found them converging on five principles, including transparency and privacy, while differing widely on what those mean and how to apply them.5 A line such as “use AI responsibly” leaves each employee to decide alone.

The Hamburg checklist asks for specific examples of authorized and prohibited uses, and for work accounts owned by the organization rather than personal sign-ups. Its own pair of examples: asking a chatbot to write advertising copy for a product is unproblematic, while asking which people are likely to be interested in the product is not, because the answer is about people.3

Add a middle column for uses that need the owner’s approval first, such as anything involving personal data.

5. Keep a person responsible for every output

The Hamburg checklist makes users responsible for checking each result for accuracy, since chatbots can invent plausible statements, and for discrimination. Decisions with legal effect on people should generally be made by humans, or else meet the conditions of Article 22 of the GDPR, the EU’s data protection law.3 A chatbot-drafted reply to a customer still goes out under the employee’s name; the policy should say so.

6. Train people on the policy, not just the tool

The European Commission cautions that simply handing staff a tool’s instructions for use and telling them to read them may, in many cases, not work, and says training can vary with the AI systems people use and what they already know.4 A short session per team, working through real tasks under the new rules, does more than an emailed document. The five things every employee should grasp about AI make a sensible outline for that session.

7. Give people one place to ask and report

The Dutch authority notes that when an employee enters personal data into a chatbot against the employer’s agreements, notifying the authority and the people affected is mandatory in many cases.1 That depends on people speaking up quickly, so name one contact for questions and mistakes. Say in writing that reporting an honest mistake the same day is expected, not punished.

8. Set a date to review it

Tools, terms of service and laws change faster than most policies, and the Hamburg checklist advises checking regularly whether internal rules need to change as tools and regulation move.3 Write the next review date into the policy itself, and name the events that bring it forward: a new tool, a new law or an incident. If your teams are adding AI to shared tasks one at a time, each new routine is a natural moment to check the rules still fit.

Your first AI use policy

A plain AI use policy template you can adapt

The template below turns the eight steps into eight short sections. Keep each to a few lines of plain language that people will read, and have any wording that sets legal duties checked for your country. Swap the example wording for your own tools, data and names.

Section What to write, with example wording Evidence
Scope and who it covers Who must follow it: “This policy covers AI tools and AI features in software we use, for employees, contractors and agency staff.” Expert: European Commission guidance, EU, 20264
Approved tools and accounts How to sign in: “Use only the tools on the approved list, signed in with your work account, never a personal one.” Expert: data protection regulator, Hamburg, Germany, 20233
Data rules “Never enter personal data about customers, colleagues or applicants into a tool that is not approved for it.” Expert: data protection regulator, Hamburg, Germany, 20233
Uses Three lists with examples, including: “Ask the policy owner before using AI on anything involving a person’s data or a decision about them.” Expert: data protection regulator, Hamburg, Germany, 20233
Checking and responsibility “You are responsible for anything you send or publish, however it was drafted.” Expert: data protection regulator, Hamburg, Germany, 20233
Training “Complete the AI session before using approved tools; HR keeps the record.” Law and guidance: EU AI Act Article 4 (amended 2026), binding in the EU4
Questions and mistakes “If data went somewhere it should not, tell the policy owner the same day.” Expert: data protection regulator, the Netherlands, 20241
Owner and review “Owner: the operations lead. Next review: [date], or sooner after a new tool, law or incident.” Expert: NIST AI RMF, voluntary, US, 20236

Every row rests on official guidance, not on tests of policies against each other. No study we found compares organizations with and without a written AI policy on data incidents or errors, so watch how your own policy works in practice, starting at the first review.

Which official guidance is law, and which is advice?

None of the main official frameworks hands employers a finished AI use policy, but they point to the same parts: a named owner, a list of the AI in use, clear rules, training and regular review. They differ in force: NIST’s framework is voluntary US guidance, ISO/IEC 42001 is an international standard, and the EU AI Act is law.

NIST, the US standards agency, published its AI Risk Management Framework in January 2023 and puts policies under its govern function: documented roles, an inventory of AI systems, training for staff and partners, and review at a frequency the organization sets. NIST says the framework is being revised.6 Its 2024 profile for generative AI adds a recommendation to set transparent acceptable use policies.7 In plain terms: decide who is responsible, know what AI you run, train people and review on a schedule.

ISO/IEC 42001, published in December 2023, specifies requirements for establishing, maintaining and continually improving an AI management system, for organizations of any size that develop, provide or use AI.8 ISO sells the full text; this guide relies on its public description.

  1. NIST AI Risk Management Framework (US, voluntary guidance): documented roles, an inventory of AI systems, training and periodic review
  2. ISO/IEC 42001 (international standard): an AI management system that is maintained and continually improved
  3. EU AI Act, Article 4 (EU law): measures to support the AI literacy of staff and others using AI for you
  4. Data protection regulators (for example the Netherlands and Hamburg, Germany): whether chatbots are allowed and which data must never go in
Four sources behind one policy page, each labelled with where it applies and how binding it is.

In the EU, Article 4 of the AI Act, reworded by a July 2026 amendment, says providers and deployers of AI systems must take steps that support AI literacy among their staff and others using AI for them, with no duty to guarantee a set level for any one person.9 The European Commission’s guidance adds that the duty has applied since 2 February 2025 and reaches even a company whose staff use ChatGPT to write advertising copy. No certificate is required; an internal record of the training is an accepted way to document it.4

Two agencies, one policy

Take a small design agency in Lyon and a similar one in Ohio, both using a chatbot for client copy. Both would want the same basic rules on tools, data and checking. The Lyon agency also falls under the EU AI Act, so its policy should say how staff are trained and where that is recorded.

The practical reading: use NIST and ISO as checklists of what a policy should cover, and let the law where you operate decide what is compulsory.

Questions to take to a lawyer or data protection officer

Most of an AI use policy is plain operational sense, but some questions depend on your country, sector and contracts, and official guidance cannot settle them for you. A recruiter who wants a chatbot to sort job applications, for example, raises questions no template answers.

  • Now: if someone has entered personal data into an AI tool against your rules, involve your data protection officer or a lawyer the same day. The Dutch data protection authority treats this as a data breach that in many cases must be reported; elsewhere, your own regulator’s rules decide.1
  • Soon: before AI is used in decisions about people, such as hiring or performance, involve your data protection officer and, where one exists, the works council, and ask whether you need a data protection impact assessment, as the Hamburg checklist advises.3
  • Routine: at each review, check which countries’ rules apply to your staff and customers, and whether contracts with AI providers match what the policy promises.

The bottom line

A first AI use policy can be short, but it should name approved tools and say which data never goes in. Name an owner, find out what people already use, give real examples of allowed and forbidden uses, and put a review date in the document. In the 2025 survey, rules on paper did not go with fewer risky uploads, so back them with training and a safe way to do the work.

This article is general information, not legal advice. Rules differ by country and change over time; for your own situation, speak to a qualified lawyer or an official advice service where you live.

Frequently asked questions

Is an AI use policy a legal requirement?

Not under that name in the sources reviewed here, though rules differ by country and sector. In the EU, the AI Act as amended in 2026 obliges organizations using AI systems to take measures supporting their staff's AI literacy, and the European Commission says no specific governance structure is mandated. EU data protection law still covers personal data entered into AI tools, and Germany's Hamburg data protection commissioner advised written internal rules in 2023.

Should an AI use policy cover contractors and freelancers?

Usually, yes. The European Commission's guidance, last updated in 2026, says the AI literacy obligation in the EU also reaches people acting on an organization's behalf, such as contractors, service providers and even clients. NIST's 2024 generative AI profile, voluntary US guidance, likewise suggests updating acceptable use policies to cover contractors, consultants and other third-party personnel. Whether the rule also belongs in contracts is a question for your lawyer.

Can employees use their personal chatbot accounts for work?

The Hamburg data protection commissioner in Germany advises against it. Its 2023 checklist says organizations should provide work accounts, that staff should not sign up with private details for work use, and that business accounts should not be used privately. The same checklist advises opting out of having inputs used to train the provider's models where the service allows it, which on some services needs a specific contract.

What happens if someone breaks the AI use policy by entering personal data?

In the EU, it may be a personal data breach. According to the Dutch data protection authority's 2024 warning, an employee entering personal data into a chatbot against the employer's agreements is a data breach, and notifying the authority and the people affected is mandatory in many cases. Beyond that, consequences depend on employment law and your own disciplinary rules, which differ by country.

Sources

  1. Caution: use of AI chatbot may lead to data breaches. Autoriteit Persoonsgegevens, the Dutch Data Protection Authority (6 August 2024)
  2. Trust, attitudes and use of artificial intelligence: A global study 2025. Gillespie, N., Lockey, S., Ward, T., Macdade, A. & Hassed, G. (2025). The University of Melbourne and KPMG; funded by KPMG and the University of Melbourne; not peer reviewed
  3. Checklist for the use of LLM-based chatbots. The Hamburg Commissioner for Data Protection and Freedom of Information, Germany (13 November 2023)
  4. AI Literacy - Questions & Answers. European Commission, AI Office (last updated 27 July 2026)
  5. The global landscape of AI ethics guidelines. Jobin, A., Ienca, M. & Vayena, E. (2019). Nature Machine Intelligence, 1(9), 389-399
  6. Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1. US National Institute of Standards and Technology (January 2023; NIST says it is being revised, checked 24 September 2026)
  7. Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile, NIST AI 600-1. US National Institute of Standards and Technology (July 2024)
  8. ISO/IEC 42001:2023 Information technology: Artificial intelligence: Management system. International Organization for Standardization and International Electrotechnical Commission (Edition 1, December 2023; status published, checked 24 September 2026)
  9. Regulation (EU) 2026/1744 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI). European Parliament and Council of the European Union (8 July 2026). Official Journal of the European Union, L series, 24 July 2026

How we researched this

We read the NIST AI Risk Management Framework and its 2024 generative AI profile, ISO's public description of ISO/IEC 42001, the EU AI Act's Article 4 as amended in 2026 with the European Commission's guidance, and guidance from Dutch and Hamburg data protection authorities, each confirmed as the current version on 24 September 2026. For behavior at work we used a 2025 survey by the University of Melbourne and KPMG. Main limitation: whether a written AI policy reduces incidents is untested in any study we could locate.

Last updated . Read our editorial policy.

Cite this article: WiserHours. (2026). How to Write an AI Use Policy: A Step-by-Step Guide With Template. WiserHours. https://wiserhours.com/ai-at-work/ai-use-policy/. Tables and charts may be reused with a link back to this page.