AI Acceptable Use Policy
the Company
Review: Every 6 months
1. Purpose
We support the use of approved AI tools where they add value, within clear limits that protect our data, our customers and our obligations. This policy explains how AI tools may and may not be used at the Company, to protect our people, our customers, our information and our legal obligations while getting the benefits of AI.
2. Who this applies to
This policy applies to all employees, contractors and workers. "AI tools" means generative and other artificial-intelligence systems, chatbots, assistants, code helpers, image and audio generators, whether standalone or built into other software.
3. Approved tools
- ChatGPT (OpenAI), approved for the uses permitted below.
- Claude (Anthropic), approved for the uses permitted below.
- Microsoft Copilot, approved for the uses permitted below.
- Any other AI tool must be approved in writing by the policy owner before use, including free browser tools and AI features built into other software.
- Only enterprise or business tiers configured so that our inputs are not used to train the provider's models may be used. Consumer tiers that train on your data are not permitted for company work.
4. Acceptable use
Approved tools may be used for:
- Drafting, summarising, translating and improving text you are allowed to share with the tool.
- Brainstorming, research starting points and explaining concepts.
- Analysing data that contains no personal, confidential or regulated information.
- Assisting with code, subject to the code rules below.
- Automating routine, low-risk tasks where a human checks the result.
5. Prohibited use
You must not use any AI tool for:
- Any illegal activity, or use that breaches a contract, licence or another policy.
- Entering data in breach of the data-handling rules below.
- Producing content that is discriminatory, harassing, defamatory or infringes others' intellectual property.
- Creating malware, phishing, or tools designed to deceive or harm.
- Generating deepfakes or synthetic media of real people without explicit authorisation.
- Presenting AI output as fact without checking it, or as your own professional judgement where a human sign-off is required.
- Using AI to make final decisions about people (hiring, firing, credit, discipline) without meaningful human review.
6. Handling data
- Do not enter personal data, names, emails, customer records, health or financial data, into any AI tool.
- Do not paste confidential, proprietary or commercially sensitive information (source code, contracts, unreleased plans, credentials) into any AI tool.
- Never enter passwords, API keys, access tokens or other secrets into an AI tool.
- Assume anything typed into a consumer AI tool could be stored or reviewed. If you would not email it to an outsider, do not paste it into AI.
7. Code and technical work
AI-generated code is allowed only with human review. A qualified person must read, test and take ownership of any AI-suggested code before it is merged or shipped.
8. Accuracy, disclosure and human oversight
- AI output can be confidently wrong. You are accountable for anything you produce with AI, exactly as if you had written it yourself.
- Check facts, figures, quotes and citations before relying on or sharing them.
- Anything AI helped produce that goes to a customer, the public or a regulator must be reviewed and approved by a human before it is sent or published.
- Disclose material AI involvement where a reader would reasonably expect to know, and follow any legal AI-transparency requirements that apply to us.
9. Compliance
- Follow all other company policies (data protection, security, confidentiality, code of conduct) when using AI.
- Where AI processes personal data, our data-protection obligations (such as GDPR) still apply in full.
- Emerging AI regulation (for example the EU AI Act) may impose extra duties for certain uses, check with the policy owner before deploying AI in a high-stakes context.
10. Reporting and breaches
If you are unsure whether something is allowed, ask the policy owner before doing it. Report any accidental disclosure of data to an AI tool, or any suspected misuse, promptly. Breaching this policy may lead to disciplinary action, up to and including termination, and could have legal consequences.
11. Questions and changes
Questions about this policy should go to the policy owner. We may update this policy as tools and the law change; it is reviewed every 6 months.
This document was generated as a starting template and is not legal advice. Have it reviewed by a qualified professional and adapt it to your organisation before adopting it.