AI Usage Policy Template
AI Use Policy: A Practical Template Your Team Will Actually Follow
An AI use policy is a short written agreement that tells your team which AI tools they may use, what company information may never go into those tools, and when they must say AI helped with the work. If your employees use ChatGPT, Claude, or anything like them, your business needs one.
1-on-1 with Pete Enestrom, on your actual work

Written by Pete Enestrom
Yale & Columbia, ex-Microsoft & Intel — 1-on-1 AI coaching for executives

Your coach’s background
An AI use policy—sometimes called an AI usage policy—is usually one or two pages long. It answers four questions in plain language: which AI tools employees may use, what information may never be pasted into an AI tool, when employees must disclose that AI contributed to a piece of work, and who keeps the policy current as the tools change. This page gives you a complete starter policy you can copy clause by clause, explains what each clause is doing, and shows you how to introduce it to your team in a single 30-minute meeting. It is written for owners of small and mid-sized companies who need a policy their employees will actually read.
The owners I coach who write a first AI policy see the same pattern: the companies that get hurt have no policy at all, not an imperfect one. A short policy people read beats a long one nobody opens. Everything below is deliberately plain—no legalese, no filler—because a policy only works if a new hire can understand it in five minutes.
Are your employees already using AI?
In nearly every company I coach, the honest answer is yes—whether or not leadership has said a word about AI. Someone on the team is pasting meeting notes into ChatGPT to get clean summaries. Someone else is drafting customer emails with it. A manager is using it to pressure-test a plan before it reaches your desk. People sometimes call this “shadow AI”: employees using consumer AI tools on personal accounts, outside any company rule, usually with perfectly good intentions. The tools are genuinely useful, which is exactly why employees reach for them without asking. None of this should alarm you. Shadow use is evidence that your team sees real value in these tools. The risk is not that your employees are using AI. The risk is that nobody has told them where the lines are.
A ban can look simpler than a policy, and some owners try one first. What I have watched happen: the work does not stop, it moves to personal phones and personal accounts, where the company has no visibility and no say. Employees who would have mentioned their AI use stop mentioning it—same usage, none of the control. A clear policy with two or three firm rules, plus a team that understands why the rules exist, beats a prohibition nobody can enforce.
What should an AI use policy cover?
Every workable AI use policy covers the same five things, and a small company can cover them in a page. First, an approved-tools list: name the specific AI tools employees may use, under company accounts, so “use good judgment” is never the whole rule. Second, a short list of information that may never go into any AI tool, written concretely enough that a new hire can apply it without asking. Third, a rule for client and confidential work, because client trust is where mistakes become expensive. Fourth, a disclosure rule: when and to whom employees say that AI contributed to the work. Fifth, an owner and a review date, because the tools change faster than any document. The template in the next section covers all five.
- Approved tools—the specific AI products employees may use for company work, and the expectation that new tools get asked about before they get adopted.
- Information that never goes in—credentials, personal data about employees or customers, account numbers, and anything covered by an NDA or client contract.
- Client and confidential work—what must be anonymized before it goes near an AI tool, and which tier of account, if any, is approved for sensitive work.
- Human review and disclosure—AI output is a draft that a person checks, and employees say when AI contributed to client-facing or public work.
- Ownership and review—one named person keeps the policy, and the team revisits it on a fixed schedule.
An AI usage policy template you can copy today
Copy this clause by clause, replace the brackets, and you have a working first version of an AI usage policy for your company: ten clauses, plain English, one page when printed. One honest note before you use it—I am a coach, not a lawyer, and this template is not legal advice. If you operate in a regulated industry, handle health or financial data, or have client contracts that restrict data handling, have an attorney review your final version.
- Purpose. We use AI tools to do better work in less time. This policy sets the ground rules so our company gets the benefit of these tools without risking our clients' trust or our own information.
- Approved tools. Company work may be done with the AI tools on our approved list—currently [list your approved tools]—using company accounts. If you want to use a tool that is not on the list, ask [policy owner] first.
- Information that never goes in. Never paste the following into any AI tool: passwords or login credentials, bank or payment account numbers, government ID numbers, medical information, or personal details about employees or customers beyond what a specific task genuinely requires.
- Client and confidential work. Do not paste client names, deal terms, unpublished financials, or anything covered by an NDA or client contract into a consumer AI tool. Anonymize the material first (“a client in the logistics industry”) or get approval to use a business-tier account for that work.
- Human review. AI output is a first draft, never a finished product. A person checks facts, figures, names, and tone before anything produced with AI leaves the company or goes to a client.
- Disclosure. When AI meaningfully contributed to a client deliverable or a public piece of content, tell your manager. We disclose AI use to clients wherever a contract or the relationship calls for it.
- No automated decisions about people. We do not use AI tools to make final decisions about hiring, firing, promotion, pay, or performance. Those decisions are made by people.
- Accuracy. AI tools sometimes state wrong things confidently. Verify every name, number, date, and quote against a primary source before you rely on it.
- Ownership and review. [Name or role] owns this policy, answers questions about it, and keeps the approved-tools list current. We review this policy every six months, and sooner if a tool we use changes how it handles our data.
- Questions and mistakes. If you are unsure whether something is allowed, ask before you paste it. If you realize you pasted something you should not have, tell [policy owner] right away. Reporting a mistake early is always the right call and is never punished.
How do you adapt the template to your business?
The ten clauses are a skeleton; the value is in making each one concrete for your business. Take clause four, the client-confidentiality rule. A marketing agency I worked with rewrote that clause to name its actual failure mode: account managers were pasting client campaign data into personal ChatGPT accounts to write reports faster. The agency's final version named the approved business-tier account, banned personal accounts for any client material, and gave a two-sentence example of an anonymized prompt that was fine. That specificity is what makes an AI policy usable. “Be careful with client data” protects nobody. “Client names and campaign numbers only go into the company's approved account, never a personal one” protects everyone.
Clause three, the never-paste list, deserves the same treatment. A distribution company might add photographs from the warehouse floor, because those photos show customer labels and shipment volumes. A professional services firm might add draft engagement letters, because the pricing in those letters is confidential. A business anywhere near healthcare might decide the simpler answer is right: no AI tools for anything touching patients, full stop. Sit with your leadership team for twenty minutes and ask one question: what would hurt most if it appeared in someone else's AI chat? The answers become your clause three.
Clause six, disclosure, is where owners most often overreach. Requiring employees to log every AI interaction creates a tracking burden nobody sustains, and it quietly punishes honesty. Reserve formal disclosure for work that leaves the building: client deliverables, published content, anything with your company's name on it. Inside the building, the norm you want is simpler—AI use is unremarkable, discussed openly, and never hidden. That norm is worth more than any tracking spreadsheet.
How do you roll out an AI policy in one 30-minute meeting?
The rollout matters more than the document. A policy that arrives as an attachment labeled “please read” gets ignored; a policy introduced in person, with the reasoning explained, gets followed. Here is the meeting I have owners run.
Send the policy two days early
Email the one-page policy with a two-line note: “We're putting simple guardrails around AI tools. Please read this before Thursday—it's a five-minute read, and we'll discuss it together.” No drama, no buildup. You want people arriving curious, not worried.
First ten minutes: explain why
Open by saying the quiet part out loud: you know people are already using AI, you are glad they are, and this meeting is not about blame. Explain the two or three real risks the policy guards against—client confidentiality, wrong facts going out the door, personal data—in your company's own terms.
Middle ten minutes: walk the red lines
Read clause three and clause four aloud, then give two concrete examples from your actual business: one thing that is fine, one that is not. Concrete beats comprehensive. If employees remember one thing from the meeting, it should be the short list of what never goes into an AI tool.
Final ten minutes: questions and the owner
Take questions. Most will be some version of “is this allowed?”—answer them on the spot and treat them as free intelligence about where the policy is unclear. Close by naming the policy owner and where questions go after the meeting: a person, not an inbox.
After the meeting
Post the policy where people actually look—your shared drive, your chat's pinned items, the onboarding folder—and ask each employee for a one-line acknowledgment by reply. Put the six-month review on the policy owner's calendar that same day, or it will not happen.
What comes after the policy?
A written policy is the foundation, and for some companies it is enough for a while. The ceiling I see owners hit arrives once the policy starts working: employees are using approved tools openly, the red lines are holding, and the next question is capability. Who teaches the team to brief an AI tool well, to check its work quickly, to build the repeatable workflows—a weekly report, a client-update draft, a meeting-notes habit—that make the tools worth the guardrails? A policy without training gives you safe, shallow use. Most of the value sits on the other side of skill.
That combination—guardrails plus training—is exactly what I do with owners and their teams. In coaching, we write the policy together so the rules fit how your company actually works; then I train your team to work confidently inside those rules, on real tasks from their real week. The policy keeps your information where it belongs; the training turns the tools into hours back. For a starting picture of what day-to-day use looks like once the guardrails are in place, my guide to using Claude walks through the workflows I teach first.
1-on-1 coaching
Get the guardrails—and the training—right.
A policy nobody understands protects no one. We'll set the rules and teach your people to work well inside them.

Your coach
Coached by Pete Enestrom
Yale and Columbia grad, former Microsoft and Intel, and a venture-backed exited founder. Pete has spent the last four and a half years going deep on every major AI tool, and he teaches the way operators learn: on your real work, at your pace, with nothing assumed.

Common questions
Straight answers, the way I'd give them across a table.
Keep reading
Beyond coaching
When the workflow needs to be encoded, not just learned — that's what our team at Zaigo builds.