AI Acceptable Use Policy Template for Enterprise Teams
Most organizations have a ChatGPT problem before they have a ChatGPT policy. This template gives you a starting point that you can adapt to your organization in under an hour.
This is a working policy document — not a framework or a checklist. Copy the template below, replace the bracketed placeholders, and run it through your legal and security review before publishing internally.
AI Acceptable Use Policy Template
Policy name: Generative AI Acceptable Use Policy Version: 1.0 Owner: [CISO / Head of Information Security] Effective date: [DATE] Review cycle: Annual, or upon material change to approved tools or regulatory requirements
1. Purpose
This policy establishes the rules for employee use of generative artificial intelligence (AI) tools, including large language model (LLM) chat interfaces, AI coding assistants, and AI-powered productivity applications. It defines which tools are approved for use, what data may and may not be submitted to these tools, and the controls that enforce these rules.
The purpose of this policy is to enable employees to benefit from AI-powered productivity tools while protecting [ORGANIZATION NAME], its customers, and its partners from data leakage, regulatory violation, and intellectual property exposure.
2. Scope
This policy applies to all employees, contractors, and third parties who access [ORGANIZATION NAME] systems, data, or networks. It applies to use of AI tools on all devices — corporate-managed and personal — when used for work purposes.
3. Approved AI Tools
Employees may use the following AI tools for work purposes:
| Tool | Approved use | Restrictions |
|---|---|---|
| ChatGPT (chat.openai.com) | Drafting, research, coding assistance | Subject to data restrictions in Section 4 |
| Claude (claude.ai) | Drafting, analysis, summarization | Subject to data restrictions in Section 4 |
| Gemini (gemini.google.com) | Drafting, research | Subject to data restrictions in Section 4 |
| [ADDITIONAL TOOLS] | [USE CASE] | [RESTRICTIONS] |
Use of AI tools not listed above requires prior approval from [CISO / IT Security]. Employees must not route organizational data through unapproved AI tools or services.
4. Prohibited Data
The following data categories must never be submitted to any AI tool, including approved tools:
Category A — Always prohibited (block): - Personal data as defined under applicable privacy law, including names, email addresses, phone numbers, national identification numbers, dates of birth, and financial account details of customers, employees, or any identifiable individual - Payment card numbers, bank account numbers, and financial credentials - Passwords, API keys, authentication tokens, private cryptographic keys, and database connection strings - Protected health information (PHI) as defined under HIPAA, including patient names, medical record numbers, diagnoses, and treatment information - Attorney-client privileged communications and attorney work product - Material non-public information (MNPI) about [ORGANIZATION NAME] or any publicly traded entity - Information subject to a signed non-disclosure agreement where disclosure to a third party is prohibited
Category B — Use caution, justification required (warn): - Internal project names, codenames, and unreleased product information - Vendor pricing, contract terms, and negotiation details - Organizational headcount, compensation, and performance information - Information about pending business transactions or partnerships
5. Employee Responsibilities
Employees who use AI tools for work purposes are responsible for:
- Reading and understanding this policy before submitting any work-related content to an AI tool.
- Reviewing every prompt before submission to ensure it does not contain data from Category A.
- Exercising judgment on Category B data and obtaining supervisor approval where required.
- Reporting any accidental submission of prohibited data to [security@yourcompany.com] within [24 hours] of discovery.
- Not attempting to circumvent the technical controls enforcing this policy.
6. Technical Enforcement
[ORGANIZATION NAME] enforces this policy through browser-based DLP controls deployed via the Pretzel browser extension. The extension intercepts AI prompts before submission and enforces the prohibitions in Section 4 automatically.
Employees will see a notification if a prompt is blocked or flagged. Blocked prompts are not submitted to the AI tool. All enforcement events are logged for compliance and audit purposes.
Attempting to circumvent these controls constitutes a violation of this policy.
7. Audit and Monitoring
[ORGANIZATION NAME] logs all AI tool enforcement events, including blocked prompts and warned submissions. Logs include: timestamp, user identifier, tool accessed, rule triggered, and action taken. Logs do not include the full content of blocked prompts.
Logs are retained for [12 months / as required by applicable law or your audit retention schedule] and may be reviewed by the Information Security team, Internal Audit, and Legal as required.
8. Violations
Violations of this policy — including intentional submission of prohibited data or circumvention of technical controls — may result in disciplinary action up to and including termination of employment or contract, and may be referred to relevant regulatory authorities where required by law.
9. Exceptions
Employees who require an exception to this policy for a specific, time-limited business purpose must submit a written request to [CISO / IT Security] with: the specific data category, the proposed AI tool, the business justification, and the duration required. Exceptions require written approval and are logged.
10. Review and Updates
This policy is reviewed annually or upon material change to: approved AI tools, technical enforcement capabilities, or applicable regulatory requirements. The current version is maintained at [INTERNAL POLICY URL].
How to Customize This Template
Replace all bracketed placeholders — dates, names, email addresses, and internal URLs — before publishing.
Section 3 (Approved Tools): Add any internal AI tools your organization has built or licensed. Remove tools you have not evaluated and approved.
Section 4 (Prohibited Data): Tailor Category A to your regulatory environment. Healthcare organizations should explicitly enumerate the 18 HIPAA PHI identifiers. Financial services organizations should add PCI-DSS card data and MNPI. Legal teams should add matter numbers and client names. Category B is where your organization's specific sensitivities go — internal codenames, deal names, and competitive information.
Section 6 (Technical Enforcement): If you are not yet using a technical enforcement tool, update this section to reflect your current approach (for example: "enforced by employee attestation and periodic audit" — be honest about your maturity level). The gap between policy and enforcement is where incidents happen.
Section 8 (Violations): Review this section with your employment counsel before publishing. The consequences must be consistent with your existing HR policies and employment contracts.
Deploying the Policy
Once finalized:
- Publish to your internal policy repository and update the URL in Section 10.
- Communicate to all employees with a read-receipt or attestation requirement.
- Configure your technical enforcement tool to match the data categories in Section 4.
- Brief managers on the policy before launch — they will get the first questions.
- Schedule a 90-day review to assess whether enforcement data reveals gaps in the policy.
Pretzel Console lets you import the data categories from this policy as detection rules directly. Start free and configure your policy in the console before rolling out to your team.
Get the Policy Kit (Policy + Implementation Checklist)
The template above covers the policy document. The full AI Policy Kit includes:
- This AUP template (pre-filled for healthcare, legal, fintech, and engineering)
- A 10-point implementation checklist for rolling the policy out company-wide
- A one-page employee summary you can use for the announcement email
- A 90-day post-launch review scorecard
The kit is included in your Pretzel account. Create a free account — no credit card, no sales call — and access it from the Resources tab in your console.
Already have a Pretzel account? Log in to your console and go to Resources → Policy Templates.
Try Pretzel free — protect your team today
Start Free — No Credit Card