# AI Acceptable Use Policy — template

> Replace bracketed text. Written to be short enough that people actually read it.
> Pair it with the AI System Inventory and the intake process in section 5.

**Owner:** [role] · **Approved by:** [body] · **Effective:** [date] · **Review:** annually

---

## 1. Purpose and scope

This policy governs how [Organisation] develops, procures and uses artificial intelligence
systems. It applies to all employees, contractors and third parties acting on our behalf, and
covers AI that is built in-house, bought, embedded in a wider product, or accessed as a public
service.

If you are unsure whether a tool counts as AI under this policy, assume it does and ask [contact].

## 2. Principles

1. **Human accountability.** A named person is accountable for every AI system. Accountability is never delegated to the system.
2. **Proportionality.** We use AI where it is a justified means to a legitimate end, not by default.
3. **Transparency.** People are told when they are interacting with AI, and when AI materially affects a decision about them.
4. **Fairness.** We test for discriminatory outcomes before deployment and monitor after.
5. **Privacy and security by design.** Data protection obligations are addressed at design time.
6. **Contestability.** Anyone materially affected by an AI-supported decision can seek human review.

## 3. Approved and prohibited uses

**Permitted with standard approval**
- Drafting, summarising and translating non-confidential internal material
- Code assistance within approved repositories
- Analysis of internal, non-personal data

**Requires impact assessment before use**
- Any system processing personal data
- Any system informing decisions about individuals (hiring, pay, credit, access to services, discipline)
- Any system whose output is customer-facing without human review
- Any use of special-category data

**Prohibited**
- Entering personal data, confidential information, credentials or client data into public AI tools not on the approved list
- Using AI to make a final decision about a person without human review
- Emotion recognition in the workplace or in education settings
- Social scoring of individuals
- Scraping facial images to build or expand recognition databases
- Presenting AI-generated content as human-authored where that would mislead
- Circumventing the intake process in section 5

> The prohibited list above is aligned to EU AI Act Article 5 practices plus common
> organisational red lines. Adjust to your jurisdiction and risk appetite.

## 4. Roles

| Role | Responsibility |
|---|---|
| System owner | Accountable for the system across its life cycle; keeps the inventory entry current |
| Data protection officer / privacy lead | Advises on DPIAs, lawful basis, rights |
| Security | Threat modelling, access control, incident response |
| Legal / compliance | Regulatory classification, contracts |
| AI governance forum | Reviews high-risk proposals; can require conditions or refuse |
| All staff | Follow this policy; escalate concerns |

## 5. Intake and approval

1. Register the proposed system in the AI inventory.
2. Complete the triage questions: personal data? decisions about people? customer-facing? special category?
3. Any "yes" routes to an AI Impact Assessment.
4. High-risk proposals go to the AI governance forum.
5. No production deployment without a recorded decision.

## 6. Ongoing obligations

- Human oversight arrangements must remain effective — reviewers need time, information and authority to disagree.
- Monitor performance and drift at the frequency recorded in the inventory.
- Re-assess on material change: new purpose, new data, new model version, new affected population.
- Report suspected AI incidents to [contact] within [24 hours] (see the incident runbook).

## 7. Third-party AI

Vendors must complete due diligence before procurement. Contracts must address data use for
vendor model training, security, sub-processors, audit rights, and notification of material model
changes. Assume a vendor that trains on your data is acting as a controller for that purpose.

## 8. Breach of this policy

Handled under [disciplinary policy]. Deliberate circumvention that exposes personal data or
creates regulatory risk is treated as a serious matter.
