The One-Page AI Acceptable Use Policy Template

Published on September 23, 2026

The One-Page AI Acceptable Use Policy Template

Most AI policies are written for companies with a compliance officer. This one is for the founder who needs a page the team will remember mid-task.

What to know first

  • A small firm’s AI acceptable use policy needs 6 clauses on one page: where AI may be used, which tools and accounts, what may never go in, who owns the output, when to tell a client, and how to report a problem.
  • Before writing the policy, decide which accounts the team may use and write down 4 real examples of what counts as client data in your firm.
  • An AI policy should start permissive, because a policy that opens with a list of bans gets read as an obstacle and routed around.
  • Definitions sections, vendor lists, regulatory recitals and disciplinary ladders add length to an AI policy without adding control in a firm of 20 or 30 people.
  • An AI policy holds when it is walked through in person in 15 minutes, names one person to ask, and treats the first breach as a tooling problem to fix.

What an AI acceptable use policy template has to do

A policy people cannot recall while working is a document, not a control. That single test decides everything about how this is written.

A 30-person firm needs 6 clauses on one page. A searcher looking for an AI acceptable use policy template usually finds either a law firm’s 14-page instrument built for a company with a compliance officer, or a 200-word blog snippet that says use good judgment. The first never gets read. The second decides nothing.

Below is the full text of a one-page version, clause by clause, with the reasoning for each so you can change it without breaking it. Copy it, put your own examples in, and it is done in an afternoon. Where it sits in the wider picture is covered in AI governance for small businesses.


Before you write it, settle 2 things

Both decisions have to be made by a person, not inherited from a template, or the clauses below will contradict how your firm actually works.

Which accounts your team is allowed to use. Consumer and business tiers of the same product treat your data differently by default. Buying business tier for the 2 or 3 tools people actually use changes the treatment of every prompt your team writes, and it does more for your exposure than any wording will. The reasoning is set out in AI data security for small business.

What counts as client data in your firm. A recruiter, a bookkeeper and a design studio draw that line in 3 different places. Write down 4 real examples from your own work before you write a single clause, because the examples are the part people remember.


The 6 clauses your policy template needs

Here is the whole thing. Replace the bracketed parts.

1. Where AI may be used. AI tools may be used for any work in this firm unless a clause below prohibits it. Drafting, summarising, research, code, analysis and first versions of client-facing material are all permitted and encouraged.

Starting permissive matters. A policy whose first move is a list of bans gets read as an obstacle and routed around, and shadow use is the outcome you are trying to prevent.

2. Which tools and accounts. Work may only be done in the approved tools listed at [location], using your company account. Personal accounts may not be used for company work. To get a new tool approved, ask [name].

The approved list lives somewhere editable, not inside the policy. Otherwise adding a tool means reissuing the document, and after the second time nobody reissues it.

3. What may never go in. Do not put client-identifying material, personal data about any individual, credentials, or anything covered by a confidentiality agreement into a general AI tool. In this firm that means [4 real examples]. When unsure, ask [name] before pasting.

The examples carry this clause. “Sensitive data” means nothing at 4pm on a Thursday. “A candidate CV, a signed client contract, management accounts with the client name on them, anything from the [X] engagement” means something.

4. You own the output. Anything you produce with AI is your work and you are answerable for it. Check facts, figures, names and quotes before it leaves the firm. Do not send AI-written material to a client without reading it in full.

This is the clause that prevents the failure mode that actually damages small firms, which is confident wrong output reaching a client with nobody having read it.

5. Tell a client when it matters. [Choose one: we do not disclose routine AI assistance, in the same way we do not disclose spellcheck. / We tell clients when AI has been used substantially in work delivered to them.] Where a client contract sets its own rule, that rule wins.

Pick a side. Firms that leave this blank find out their position during a client conversation, which is a bad time to form one.

6. Say something when it goes wrong. If client data goes somewhere it should not, or AI output causes a problem, tell [name] the same day. Nobody is disciplined for reporting quickly.

Without the last sentence this clause does nothing, because the incidents you need to hear about are the ones someone is embarrassed by.

ClauseWhat it setsWhy it holds
1. Where AI may be usedAny work, unless a later clause prohibits itA permissive start stops people routing around the policy
2. Which tools and accountsApproved tools only, company accounts onlyThe approved list lives outside the policy, so it stays current
3. What may never go inClient-identifying material, personal data, credentials, confidential materialYour 4 real examples are the part people remember
4. You own the outputFacts, figures, names and quotes checked before anything leavesStops confident wrong output reaching a client
5. Tell a client when it mattersYour chosen disclosure positionDeciding in advance beats deciding mid-conversation
6. Say something when it goes wrongSame-day reporting, nobody disciplined for reporting quicklyThe no-blame line keeps incidents visible

Using This as a Company AI Policy Example

The 6 clauses double as a corporate AI policy example for a small firm. Paste them into a Word or Google Doc, fill the brackets, and you have a company AI policy you can circulate the same day. If you search for a generative AI policy template, most of what you find covers the same ground at far greater length. Clauses 1 to 4 are the generative AI acceptable use rules. Clauses 5 and 6 cover the client and incident side that longer documents tend to bury.

A few adjustments by organization type.

For a nonprofit, clause 3 needs your own examples: donor records, beneficiary details and grant applications that name individuals. Clause 5 usually points at funder agreements, since funders sometimes set their own AI rules.

If a client has its own AI clause, add that client’s rule as a separate page, as covered in the section on when one page stops being enough.

If someone asks about NIST, a NIST-aligned policy is a larger exercise built around the NIST AI Risk Management Framework. A 30-person firm does not need that to get control of day-to-day use, and a client or funder that asks for it should say so in writing.

Treat the template as the company AI use policy for your firm, then change it whenever a real incident or contract says the line is in the wrong place.


What to leave out, and why

Most of the length in a long AI policy comes from 4 things that do not belong in a firm of your size.

Definitions sections. Three paragraphs defining generative AI, large language model and machine learning. Nobody reads them and nothing downstream depends on them.

Vendor lists inside the policy. Tools change every quarter. Keep the list separate and the policy stable.

Regulatory recitals. Naming 4 frameworks that do not apply to you reads as seriousness and creates obligations you have not scoped. Name only what a client contract or your sector actually imposes.

Enforcement and sanctions language. In a 20-person firm the escalation path is a conversation. Writing a disciplinary ladder makes the document adversarial and makes clause 6 fail, because people stop reporting.


Rolling it out so it holds

The document is 20% of the work. Getting it used is the rest.

Walk the team through it once, in person, in 15 minutes. Read the 4 examples in clause 3 aloud and ask whether they are right. You will get corrections, and the corrections are the most valuable part of the exercise. A policy emailed as an attachment has roughly the compliance rate you would expect.

Ask what people already use, with no blame attached. You will discover tools you did not know about. That is the point. Reacting badly the first time guarantees you never find out again, and the unapproved tool problem is covered in shadow AI.

Name one person in the blanks. Every [name] above should be the same person, and it should not be a committee. Ambiguity about who to ask is the most common reason clause 2 gets skipped.

Put it where the work is. A policy in a shared drive nobody opens is not deployed. Pin it in the channel people work in.

A written rule changes behaviour only when someone can recall it mid-task, which is the argument made at length in AI policy versus AI training. One page exists to serve recall, not brevity for its own sake.


What to do the first time someone breaks it

This happens in the first quarter in nearly every firm, and how you handle it decides whether the policy survives.

The usual case is not defiance. Somebody pasted a client document into a personal account to hit a deadline, then read clause 3 afterwards and realised. What you do in the next 10 minutes sets whether anyone ever tells you again.

Deal with the exposure first, separately from the person. Find out which tool, which account, and what was in the document. Delete the conversation if the product allows it, check the retention setting on that account, and note whether the client has a contract clause the incident touches. That is the whole technical response in most cases.

Then ask why the rule lost. Almost always the approved route was slower, unavailable, or unclear at the moment of the task. Somebody had 4 minutes and the compliant path took 15. That is a design problem in your tooling, and fixing it prevents the next 5 incidents in a way that a warning does not.

Change the policy if the policy was wrong. If 3 people have hit the same wall, clause 3 is drawn in the wrong place or clause 2’s approved list is missing something people really need. Move the line and say you moved it.

Tell the client only when the facts require it. If the material was covered by a confidentiality obligation or names an individual, check what you committed to and act on that. Deciding this case by case under pressure is worse than having read your own contracts once in advance.

The firms that end up with real control are the ones where the first incident produced a tooling change and no drama. The firms that end up blind are the ones where it produced a stern email.


When one page stops being enough

Three signals, and none of them is headcount alone.

A client writes an AI clause into a contract that is stricter than yours. Their rule now governs that engagement and you need it written down separately.

You start putting client data through a specific approved setup instead of keeping it out. That is a deliberate exception and it needs its own page describing the tool, the terms checked, and who approved it.

You deploy something that acts on its own instead of producing drafts. An agent that sends, files or updates records raises questions this policy does not answer, and they should be settled before it runs. That is the argument in when to use an AI agent.

Short of those, adding pages adds nothing you can enforce.


The bottom line for founders

Your exposure comes from a handful of people, using a handful of tools, on a handful of document types. Six clauses cover it. The examples in clause 3 do most of the work, the named person in clause 2 does the rest, and the no-blame line in clause 6 is what keeps you informed.

Write it this week, walk the team through it once, and revisit it when a client contract or an agent forces the question. That is a real control. A 14-page instrument nobody has finished reading is paperwork you can point at after something has already gone wrong.

If you want a read on whether your version covers the way your firm actually handles client work, you can book a call and we will look at the real documents rather than the policy on paper.


Frequently asked questions

What should an AI acceptable use policy include for a small business?

Six clauses: where AI may be used, which tools and accounts, what may never go in, who owns the output, when to tell a client, and how to report a problem. Put 4 real examples of your own client data in clause 3, because that is the part people remember.

How long should an AI usage policy be?

One page. A policy people cannot recall while they work is a document, not a control. If the team can’t remember it at 4pm on a Thursday, it’s just a file in a drawer.

Can employees use personal AI accounts for work?

Not under this template. Clause 2 limits company work to approved tools on company accounts, because consumer and business tiers treat your data differently by default. If people keep reaching for personal accounts, the approved route is probably too slow, and that is the thing to fix.

Do we have to tell clients when we use AI?

The template makes you pick a side: no disclosure for routine help, the same as spellcheck, or disclosure whenever AI was used substantially in delivered work. Where a client contract sets its own rule, that rule wins. Decide now, because working it out on a client call goes badly.

What should I do the first time someone breaks the AI policy?

Deal with the exposure first: which tool, which account, and what was in the document. Then ask why the approved route lost, because it was usually slower or unclear at the moment of the task. People take the shortcut when the main road is blocked, so clear the road.

Is there a Word version of this AI policy template?

Copy the clause text into a Word or Google Doc. It is about 300 words, so formatting takes minutes. Keep the approved tool list in a separate editable file so the policy itself stays stable.

Can a nonprofit use this AI policy template?

Yes. Swap the clause 3 examples for donor records, beneficiary details and anything a funder agreement covers. Keep the other 5 clauses as written, and name one staff member in every blank.

Does this template follow the NIST AI framework?

No, and it does not claim to. It is a working rule set for a small firm. NIST publishes an AI Risk Management Framework for organizations that need a formal structure, which is a bigger project than a one-page policy. Start with the page, and move to the framework only if a client or funder requires it.

Photo of David Forer
David Forer AI Operations Consultant

I help founder-led businesses turn chaotic workflows into AI-powered operations that drive growth without adding headcount.

Connect on LinkedIn