An AI use policy tells your team which AI tools they may use, what information may go into them, and who checks the results before they reach a customer. For a small team, one page is enough. This guide gives you an AI use policy template you can copy, explains each rule in plain words, and shows how to roll it out in a week.
You may feel too small to need one. But if anyone on your team uses AI for work, you already have a policy. It is just unwritten, and each person has made up their own version.
- A one-page policy beats none. It turns private habits into shared rules that people can remember.
- Cover six things: approved tools, data rules, human review, disclosure, ownership and security.
- Sort information into green, amber and red, so nobody has to guess what may go into an AI tool.
- Give the policy one owner and a review date, because tools and their settings keep changing.
- Roll it out with a 30-minute walkthrough built on real examples, not a signature form.
Why a one-page policy beats none
Most AI mistakes at work are not exotic. Someone pastes the wrong thing, trusts an answer without checking it, or assumes the tool is responsible for what it said. Three well-documented cases show the pattern.
| What happened | What went wrong | The rule that prevents it |
|---|---|---|
| Samsung, 2023: staff shared sensitive internal data with ChatGPT, and the company temporarily restricted generative AI tools on its devices | Confidential data left the company | Data rules and approved accounts |
| Air Canada, 2024: its website chatbot gave a customer wrong information about bereavement refunds, and a tribunal ordered the airline to pay | The airline argued the chatbot was responsible for its own actions | You own what your AI tells customers |
| Deloitte Australia, 2025: a government report worth A$440,000 contained nonexistent references. Deloitte disclosed its AI use in a corrected version and agreed to repay the final instalment | Errors reached the client | Human review and disclosure |
The Air Canada tribunal rejected that defense in plain terms: a chatbot is part of the company’s website, and the company is responsible for all of it. Your customers will see it the same way.
What an AI use policy should cover
Six topics cover almost everything. Keep each one to a few lines.
Approved tools. Name the tools and, just as important, the accounts. A company business plan and a personal free account can treat your data very differently. Our guide to AI privacy compares the settings.
Data rules. What may go into which tool. The traffic-light system below does most of the work.
Human review. Who checks what before it is sent, published or merged. Scale the check to the risk.
Disclosure. When you tell customers and clients that AI was involved.
Ownership. Who owns work made with AI, and when to be careful about copyright.
Security. Accounts, sign-in, keys, agents, and a firm rule about money.
Add an owner, a review date and a way to report mistakes, and you are done.
Sort your information into three colors
The data rule is the one people break by accident, so make it visual. Everyone can remember three colors.
| Green | Amber | Red | |
|---|---|---|---|
| What it is | Public or already published | Internal, but not personal or secret | Personal, secret or under contract |
| Examples | Website copy, published docs, public data | Draft plans, internal notes, code without secrets | Passwords, API keys, customer records, health or financial data, anything under NDA |
| Where it may go | Any approved tool | Approved company accounts only | Nowhere, unless the owner approves one tool for that data in writing |
Tailor the red list to your business. A clinic will name patient details. An agency will name client briefs under NDA. A software team will name production credentials, which our guide to keeping API keys safe covers in depth.
The AI use policy template
Copy this, replace the brackets, and delete anything that does not apply. It is written to fit on one printed page.
# How we use AI at [Company]
Owner: [name]. Last reviewed: [date]. Next review: [date + 6 months].
## 1. Approved tools
- [Chat assistant] on our company [business or team] plan: writing,
research and analysis.
- [Coding assistant or agent] in company repositories: code.
- [Meeting notes tool]: internal meetings, with everyone told it is on.
- Anything else, including browser extensions and plugins: ask [owner].
- Personal AI accounts: green information only, with training turned off.
## 2. Information rules
- Green (public or published): any approved tool.
- Amber (internal, not personal, not secret): company accounts only.
- Red (passwords, keys, customer personal data, health or financial
records, anything under NDA): never, unless [owner] approves a
specific tool for it in writing.
## 3. Check before it ships
- You are responsible for anything you send, publish or merge,
whoever or whatever wrote the first draft.
- Check every fact, number, quote and reference against its source.
- AI-written code passes the same tests and review as any other code.
- Anything legal, medical, financial or about a real person gets a
second reviewer.
## 4. Tell people when it matters
- Customers are told when they are talking to an AI, not a person.
- We follow each client's contract terms on AI use. If a contract
is silent and the AI contribution is substantial, we ask.
- We label realistic AI images, audio and video, and never create
them of a real person without consent.
## 5. Ownership
- Work made with AI for [Company] belongs to [Company], like any
other work.
- Purely AI-generated material may not be protected by copyright.
For logos, brand assets and anything we must own outright, talk
to [owner] first.
## 6. Security
- Company accounts only, with passkeys or an authenticator app.
- Never paste passwords or keys into a prompt. AI agents get test
keys and a project folder, never production credentials.
- New connectors that can read email, files or calendars need
[owner]'s approval.
- Money rule: never pay, change bank details or share a code
because of a call, voice note, video or message alone. Confirm
on a number we already know.
## 7. When something goes wrong
Pasted something red? AI output caused a problem? Tell [owner]
the same day. We fix first and we do not blame.
## 8. Learning
New starters read this page in their first week. Share useful
prompts and near misses in [channel].The money rule is there because cloned voices and deepfake video calls now target staff who can move money. Calling back on a known number is the defense the FBI recommends.
How to fill in the blanks
A few choices make the difference between a policy people follow and one they ignore.
Name one owner. Not a committee. One person who answers questions within a day.
Name real tools and accounts. “Approved AI tools” means nothing. “[Assistant] on the company workspace, signed in with your work email” is a rule.
Write rules as actions. “Never paste API keys into a prompt” works. “Ensure appropriate handling of credentials” does not.
Use your own examples. Replace the red list with the five things your team is most likely to paste by mistake.
Treat agents separately. An agent that can run commands, read files or send email can do more damage than a chat window. Many agent tools, including our own Cyborb, let you choose how much the agent may do without asking. Your policy should name the default.
How to roll it out in one week
Monday: draft it
The owner fills in the template in under an hour. Use the tools and accounts you have today, not the ones you plan to buy.
Tuesday: ask two people to break it
Give the draft to two colleagues and ask for real edge cases. “Can I paste this client email?” and “Can I use my own account on my phone?” are the questions that fix a policy.
Wednesday: walk the team through it
Spend 30 minutes on real examples from your own work: one green, one amber and one red. Answer every question, then fold the answers into the page.
Thursday: put it where work happens
Pin it in your team chat, link it from onboarding, and set up the approved business accounts. The right choice should also be the easy one.
Friday: set the review date
Put a reminder in the calendar for six months from now. Review sooner if you add a tool, a client asks, or a law changes.
Keep your AI policy current
Review it every six months, because providers change defaults, add features and rename plans. Ask the team what they actually use. The gap between that and the approved list is the most useful thing you will learn.
Laws can add duties too. The EU AI Act can apply if your team is in the EU or your AI output is used there. Its transparency rules, such as labeling deepfakes, apply from August 2, 2026.
The Act also requires companies that use AI at work to take measures for their staff’s AI literacy. That duty has applied since February 2025. A July 2026 amendment softened it: you must support AI literacy, not guarantee a set level. Our guide to the EU AI Act for small builders explains what applies to you.
FAQ
Do small teams really need an AI use policy?
Yes, if anyone uses AI for work. Without one, each person sets their own rules, and you only find out what they were after something goes wrong. A one-page policy takes about an hour to write.
Should we just ban AI tools?
Usually not. Samsung restricted them for a while in 2023, but bans are hard to enforce on personal phones and accounts, so AI use moves out of sight. Approving a few tools on company accounts, with clear data rules, gives you more control.
Do we have to tell clients we use AI?
Check your contracts first, because some clients set rules. Beyond that, tell customers when they are talking to an AI, label realistic AI media, and be open about substantial AI use in work you deliver. Clients forgive tools more easily than surprises.
Who owns work made with AI tools?
Your policy should say the company owns work staff make for it, with or without AI. Copyright is a separate question: purely AI-generated material may not be protected, so be careful with logos and anything you need to own outright.
How often should we update the policy?
Every six months, and whenever you add a tool, change plans or take on a client with AI rules. AI products change their settings often, so a policy that is a year old is probably wrong somewhere.
Next, see how AI scams target the people who can move money, or read who owns what AI makes.
- Samsung bans use of generative AI tools like ChatGPT after April internal data leak, TechCrunch, May 2023
- Air Canada ordered to pay customer who was misled by airline’s chatbot, The Guardian, February 2024
- Deloitte to pay money back to Albanese government after using AI in $440,000 report, The Guardian, October 2025
- Criminals use generative artificial intelligence to facilitate financial fraud, FBI Internet Crime Complaint Center, December 2024
- AI Act: regulatory framework for AI, European Commission
- Regulation (EU) 2026/1744 (Digital Omnibus on AI), EUR-Lex, July 2026
- Copyright Office releases Part 2 of Artificial Intelligence report, U.S. Copyright Office, January 2025




