Etoolio

Company AI Policy Generator

Free company AI policy generator. Answer a short wizard about your approved tools, data rules and stance, and get a tailored AI acceptable-use policy to copy or download. Runs in your browser, private.

Overall stance
Approved tools
AI-generated code

Your policy

AI Acceptable Use Policy

the Company

Review: Every 6 months

1. Purpose

We support the use of approved AI tools where they add value, within clear limits that protect our data, our customers and our obligations. This policy explains how AI tools may and may not be used at the Company, to protect our people, our customers, our information and our legal obligations while getting the benefits of AI.

2. Who this applies to

This policy applies to all employees, contractors and workers. "AI tools" means generative and other artificial-intelligence systems, chatbots, assistants, code helpers, image and audio generators, whether standalone or built into other software.

3. Approved tools

  • ChatGPT (OpenAI), approved for the uses permitted below.
  • Claude (Anthropic), approved for the uses permitted below.
  • Microsoft Copilot, approved for the uses permitted below.
  • Any other AI tool must be approved in writing by the policy owner before use, including free browser tools and AI features built into other software.
  • Only enterprise or business tiers configured so that our inputs are not used to train the provider's models may be used. Consumer tiers that train on your data are not permitted for company work.

4. Acceptable use

Approved tools may be used for:

  • Drafting, summarising, translating and improving text you are allowed to share with the tool.
  • Brainstorming, research starting points and explaining concepts.
  • Analysing data that contains no personal, confidential or regulated information.
  • Assisting with code, subject to the code rules below.
  • Automating routine, low-risk tasks where a human checks the result.

5. Prohibited use

You must not use any AI tool for:

  • Any illegal activity, or use that breaches a contract, licence or another policy.
  • Entering data in breach of the data-handling rules below.
  • Producing content that is discriminatory, harassing, defamatory or infringes others' intellectual property.
  • Creating malware, phishing, or tools designed to deceive or harm.
  • Generating deepfakes or synthetic media of real people without explicit authorisation.
  • Presenting AI output as fact without checking it, or as your own professional judgement where a human sign-off is required.
  • Using AI to make final decisions about people (hiring, firing, credit, discipline) without meaningful human review.

6. Handling data

  • Do not enter personal data, names, emails, customer records, health or financial data, into any AI tool.
  • Do not paste confidential, proprietary or commercially sensitive information (source code, contracts, unreleased plans, credentials) into any AI tool.
  • Never enter passwords, API keys, access tokens or other secrets into an AI tool.
  • Assume anything typed into a consumer AI tool could be stored or reviewed. If you would not email it to an outsider, do not paste it into AI.

7. Code and technical work

AI-generated code is allowed only with human review. A qualified person must read, test and take ownership of any AI-suggested code before it is merged or shipped.

8. Accuracy, disclosure and human oversight

  • AI output can be confidently wrong. You are accountable for anything you produce with AI, exactly as if you had written it yourself.
  • Check facts, figures, quotes and citations before relying on or sharing them.
  • Anything AI helped produce that goes to a customer, the public or a regulator must be reviewed and approved by a human before it is sent or published.
  • Disclose material AI involvement where a reader would reasonably expect to know, and follow any legal AI-transparency requirements that apply to us.

9. Compliance

  • Follow all other company policies (data protection, security, confidentiality, code of conduct) when using AI.
  • Where AI processes personal data, our data-protection obligations (such as GDPR) still apply in full.
  • Emerging AI regulation (for example the EU AI Act) may impose extra duties for certain uses, check with the policy owner before deploying AI in a high-stakes context.

10. Reporting and breaches

If you are unsure whether something is allowed, ask the policy owner before doing it. Report any accidental disclosure of data to an AI tool, or any suspected misuse, promptly. Breaching this policy may lead to disciplinary action, up to and including termination, and could have legal consequences.

11. Questions and changes

Questions about this policy should go to the policy owner. We may update this policy as tools and the law change; it is reviewed every 6 months.


This document was generated as a starting template and is not legal advice. Have it reviewed by a qualified professional and adapt it to your organisation before adopting it.

Give your team clear rules for using AI

Your employees are already using ChatGPT, Copilot and other AI tools, whether or not you have a policy. The risk is not the tools; it is the absence of rules. People paste customer records into consumer chatbots, ship AI-written code without review, or present unchecked AI output as fact. A short, clear AI acceptable-use policy fixes that, and this free generator builds one tailored to your organisation in a couple of minutes, entirely in your browser.

What the wizard asks

  • Your company and policy owner, so the document names who to ask.
  • Your stance: permissive, balanced or restrictive.
  • Approved tools, and whether anything else needs written approval.
  • Data rules: whether personal or confidential data may go into approved tools, and whether only tools that do not train on your data are allowed.
  • AI-generated code: allowed, allowed with review, or not allowed.
  • Disclosure and human review expectations for anything published or sent externally.

What the policy covers

The generated document is a complete, editable policy with the sections a good AI policy needs:

  • Purpose and scope, why the policy exists and who it applies to.
  • Approved tools, the specific tools your people may use.
  • Acceptable and prohibited use, what AI may and may not be used for, including bans on deepfakes, malware and unreviewed decisions about people.
  • Handling data, clear rules on personal data, confidential information and secrets.
  • Accuracy and human oversight, making clear that the human, not the AI, is accountable.
  • Compliance, how the policy sits alongside data protection and emerging rules like the EU AI Act.
  • Reporting, breaches and review, what to do when something goes wrong, and how often to revisit the policy.

Private by design

Everything runs in your browser. Your company name, approved-tools list and settings are never sent to a server or stored. When you are happy with the draft, copy it or download it as a Markdown or text file.

Important

This generator produces a solid starting template, not legal advice, and using it does not create a lawyer-client relationship. Organisations differ by industry, jurisdiction and existing policy, so have the draft reviewed by a qualified professional and adapt it before you adopt it.

Good to know

Company AI Policy Generator, frequently asked questions

What does the AI policy generator do?

It builds a tailored AI acceptable-use policy for your organisation. You answer a short wizard, your company name, which AI tools are approved, whether personal or confidential data may be used, your rules on AI-generated code, disclosure and human review, and it assembles a clear, ready-to-edit policy document covering purpose, scope, approved tools, acceptable and prohibited use, data handling, oversight and compliance.

Why does my company need an AI acceptable-use policy?

Employees are already using AI tools, often pasting company or customer data into consumer chatbots that may train on it. A clear policy protects your confidential information, your data-protection obligations and your reputation, while letting people use AI productively. It also gives you a documented standard to point to if something goes wrong.

Is the generated policy legally binding or legal advice?

No. It's a well-structured starting template, not legal advice, and it doesn't create a lawyer-client relationship. Every organisation is different, review the draft with a qualified professional and adapt it to your industry, jurisdiction and existing policies before adopting it.

What should an AI policy cover?

At minimum: which tools are approved, what data may and may not be entered (personal data, confidential information, secrets), acceptable and prohibited uses, rules for AI-generated code and content, the need for human review and fact-checking, disclosure expectations, and how it fits with data-protection and emerging AI regulation like the EU AI Act. This generator includes all of those sections.

Can I choose how strict the policy is?

Yes. Pick a permissive, balanced or restrictive stance, choose exactly which tools are approved, and toggle whether personal data, confidential data and AI-generated code are allowed. The policy text changes to match your choices.

Is my information kept private?

Yes. The whole generator runs in your browser. Nothing you type, no company name, tool list or settings, is sent to a server or stored. You just copy or download the finished document.

Is it free?

Yes, free with no signup. You can copy the policy or download it as a Markdown or text file.