Blog

How to write an AI acceptable use policy

WitnessAI | August 16, 2026

An AI acceptable use policy identifies the AI tools employees, contractors, and AI agents may use, defines acceptable use, governs the data shared with AI systems, and establishes accountability for AI interactions. It also assigns responsibility for incidents. Your employees aren’t waiting for that document. Many employees already use AI without approval. This limits your security team’s visibility. If you’re pushing AI from pilot to production, that gap is where your risk lives.

Recent rulings and regulations show which controls organizations need. A tribunal has held an organization liable for its chatbot’s statements, and EU regulators can now enforce AI transparency and literacy obligations directly.

A written policy is one control within a broader AI governance and risk management program that covers vendor diligence and incident response, with monitoring across both areas. This guide explains what a practical document can contain and which functions are assigned to each part. It also shows how to enforce and document the rules during an AI interaction.

Key takeaways

  • An AI acceptable use policy sets binding boundaries for approved tools, permissible data, use cases, and accountability across employees, contractors, and AI agents.
  • Strong enterprise AI governance requires addressing shadow AI, inaccurate outputs, autonomous AI agents, discriminatory automation, and regulatory obligations through transparency, runtime controls, and appropriate human oversight.
  • A practical policy should cover scope and ownership, approved tools and data handling, permitted and prohibited uses, agent and MCP rules, enforcement, training, exceptions, and review.
  • Granular audit trails make AI governance provable by linking interactions and enforcement decisions to the relevant user, agent, tool, and rule.

What is an AI acceptable use policy?

An AI acceptable use policy is an internal governance document that sets binding rules for how employees and contractors interact with AI systems. It increasingly covers AI agents as well. It names the approved tools, classifies which data may reach them, lists permitted and prohibited uses, and assigns accountability for exceptions and violations.

It differs from a broader AI governance program in scope. The policy governs day-to-day usage decisions: whether a marketer can paste customer data into a chatbot, or whether a developer can install an agentic plugin in an IDE. Companion documents typically include model development standards and vendor risk assessments. They also cover board reporting.

WitnessAI Observe
OBSERVE

Your Employees Use 5x More AI Tools Than You Think

WitnessAI scans your entire network to catalog every AI app, agent, and conversation. No endpoint clients or browser extensions are required.

See How Observe Works

How AI use policies support enterprise AI governance

An AI acceptable use policy gives you enforceable control over shadow AI, chatbot output, automated hiring, and rising regulatory obligations. Each of the recent cases below points to a specific policy provision you can adopt. Shadow AI moves activity outside sanctioned tools and controls. This creates a visibility and control gap.

Recent cases show which controls an AI policy should cover. Air Canada was liable for negligent misrepresentation after its chatbot invented a bereavement fare policy. The tribunal found the airline responsible for the information on its website. Its policy gap was output accuracy and human oversight.

iTutorGroup paid $365,000 to settle the EEOC’s first AI-hiring discrimination lawsuit after its recruiting software automatically rejected older applicants. That gap was the absence of a prohibition on unreviewed employment decisions.

Regulation now assumes a policy exists, and the EU AI Act requires proof that it works. The EU AI Act’s remaining provisions became generally applicable on August 2, 2026, except Article 6(1). They cover transparency duties for chatbots and AI-generated content. Non-compliance with Article 50 can result in penalties of up to 3% of worldwide annual turnover. Rules for organizations deploying high-risk AI systems listed in Annex III will take effect on December 2, 2027.

WitnessAI Protect
PROTECT

Is Your Customer-Facing AI Secure?

WitnessAI filters harmful and off-brand outputs before they reach users, tokenizes sensitive data before it reaches models, and hardens your defenses with automated red teaming.

See How Protect Works

What to include in an AI acceptable use policy

A practical AI acceptable use policy should contain five core sections. Each answers a question a regulator or your own board is likely to ask. Under ISO/IEC 42001, your organization needs a documented AI policy that aligns with its other policies and is subject to periodic review. This structure also supports certification work under the AI management system standard.

The five sections below map to the questions most CISOs and CAIOs face when they take the policy to the steering committee.

1. Scope, definitions, and named owners

State who the policy binds, including employees and contractors across the geographies where the company operates. Address third-party vendors separately. Then define AI tools, since embedded copilots and browser extensions often fall outside approval workflows.

Then name the owners. The NIST AI Risk Management Framework expects executive leadership to be responsible for AI risk decisions, with documented roles and clear lines of communication. In practice, use a cross-functional steering committee that spans security, legal, compliance, HR, and risk.

Give legal responsibility for hiring rules and disclosure requirements. That includes the hiring rules exposed by the iTutorGroup settlement. Business units that publish customer-facing content should own output rules such as those implicated in the Air Canada case. HR owns training and sanctions; compliance and risk own the audit evidence.

2. Approved tools and data handling rules

List sanctioned tools by name and tier so the policy distinguishes approved enterprise deployments from consumer versions. Tools not on the approved list are prohibited by default, with a documented path to request a review.

Then map data classes to permitted destinations. Public data can be accessed by most tools, while internal data can be accessed only by sanctioned tools. Require written approval before employees send PHI, payment data, credentials, or other restricted data to an AI tool.

3. Permitted uses, prohibited uses, and human review

Spell out that employees may use AI to draft internal documents and summarize meetings. AI-generated code should receive human review before it ships. Then enumerate the uses that create legal exposure: final employment decisions without human review, regulated disclosures, and legal or medical advice for external parties.

The iTutorGroup settlement illustrates the need for a prohibition on unreviewed employment decisions. The policy can require human review before AI output reaches a customer or appears in a court filing. Apply the same review to a hiring decision. Name the role that performs it.

4. Rules for AI agents and MCP connections

AI agents take actions, so the policy needs provisions for autonomous operation. Enterprise apps increasingly include task-specific AI agents. Agents use credentials to call APIs at machine speed, so a policy written for chat sessions misses much of their risk.

The policy can give each agent a verified identity and permissions scoped to its task. Assign a named human owner who remains accountable for its actions. It can also require audit records connecting the agent’s actions back to that owner.

Only 28% of organizations can trace agent actions back to a human sponsor. Explicitly cover MCP server connections and agentic IDE plugins, because developers often install them outside procurement.

5. Enforcement, exceptions, training, and review cadence

Graduated enforcement helps keep the policy credible. A first violation can trigger a warning and a referral to the policy, with escalation reserved for repeated or high-risk behavior. Shadow AI grows without a safe AI adoption path, so a fast exception route can bring legitimate use cases into the approval process.

The EU AI Act’s Article 4 literacy obligation requires measures to ensure staff have a sufficient level of AI literacy, and documented role-based training is the natural evidence. Conduct periodic policy reviews of those sections and the full document. Incidents or new regulation can trigger an out-of-cycle review. Changes to a sanctioned vendor’s data-handling terms can have the same effect.

WitnessAI for Compliance
FOR COMPLIANCE

What Does AI Compliance Look Like?

WitnessAI automatically logs every AI interaction, masks sensitive data in real time, and enforces regulatory policies across every region and business line. Audit-ready from day one.

See WitnessAI For Compliance

How to enforce an AI acceptable use policy at runtime

A signed policy has limits and rarely changes behavior on its own. ISACA warns that relying exclusively on an AI acceptable use policy is an “overly simplistic and insufficient approach” to AI risk management. Organizations that deployed AI governance platforms were 3.4 times more likely to achieve high AI governance effectiveness in Gartner’s survey.

Keyword- and regex-based controls were built for structured patterns, and AI conversations rarely contain the words a blocklist expects. A prompt describing an unannounced acquisition holds no credit card number and no “confidential” label, yet it’s among the most sensitive text in the company.

WitnessAI is an AI security and governance platform that gives security and risk teams visibility and runtime control over how employees and agents use AI. It connects what the policy says with what happens during an AI interaction on a single, unified platform.

Runtime AI governance starts with an accurate picture of what employees and agents are actually using, then applies the rules during the interaction itself. Without runtime enforcement, a large share of AI agent deployments stall or fail once they move beyond the pilot phase. This makes runtime controls a practical part of deployment.

1. Start from the AI already in use

Rules written against a procurement list miss the tools nobody requested. Network-level discovery in the Observe module matches network activity routed through the platform against an AI application catalog, with no endpoint clients or browser extensions.

Coverage includes Windows Copilot and Microsoft 365, as well as developer IDEs. The network layer can also detect connections to agents and MCP servers.

2. Enforce the policy through intent classification

Intent classification uses advanced AI models to understand what a user is trying to accomplish. The Control module enforces the written rules for AI interactions routed through the platform. Its intent-based intelligent policies read conversational context rather than matching keywords.

Enforcement uses four actions:

  • Allow: Legitimate work is permitted. The interaction proceeds without modification.
  • Warn: An employee who takes a risky action receives a warning that includes the relevant policy language. The employee can reconsider the action before proceeding.
  • Block: Clear violations are blocked. The interaction doesn’t proceed to the destination.
  • Route: Sensitive prompts can be routed to an approved internal model, keeping productive work within an approved environment.

Together, these actions support productive AI use while applying the written policy during the interaction.

Real-time data tokenization replaces SSNs, credentials, and PII in traffic routed through the platform before a prompt reaches a third-party model. It then restores the original values in the response.

3. Prove enforcement to auditors and the board

Enforcement becomes provable when each action captured through the platform leaves an audit trail. The trail identifies the user, agent, tool, and rule. Auditable AI evidence can show that sensitive AI output was “generated from an authenticated request, using authorized data and under enforced controls.” Without it, the organization has only a “policy position that still needs proof”.

The Protect module checks prompts captured through the platform before they reach a model. It also checks responses before they reach a user or trigger an agent action. For interactions captured through the platform, WitnessAI guardrails deliver a 99.3% true positive rate, validated in production customer environments.

If you’re the CISO who has to answer the board’s next question about AI use, those audit trails let your security team respond without reconstructing events manually. InComm Payments’ CISO reports AI security visibility while maximizing productivity.

WitnessAI Control
CONTROL

Can You Prove How Your Organization Governs AI?

WitnessAI generates granular audit trails, enforces policies across every role and region, and redacts sensitive data before it ever leaves your network. Compliance-ready from day one.

See How Control Works

From written policy to provable AI risk management

The written policy defines expectations: scope, approved tools, data rules, human oversight, and agent provisions. AI risk management begins when those expectations become observable and enforceable.

WitnessAI provides security, risk, and AI teams with intention-based governance, intelligent AI routing, and network-level visibility across AI interactions routed through the platform. The same console provides runtime guardrails for the human and digital workforce.

Schedule a demo to see how your AI acceptable use policy becomes enforced and auditable control.

Frequently asked questions