What is an AI acceptable use policy?
Updated · By Robert Breen
An AI acceptable use policy is a written set of rules for how a business's staff may use AI tools: which tools are approved, what information can and cannot be entered, what AI may be used for, and who must review AI-generated work before it reaches customers.
Why it matters for a small business
Without a policy, every employee decides alone whether to paste a client file into a free AI app, whether to send an AI draft unread, or whether AI can answer a legal or medical question. Some of those choices will be fine and some will not, and you may not find out until a client complains. A short policy turns guesswork into a shared routine.
It also makes AI easier to adopt. Staff who know the approved tools and the "never paste" list use AI with more confidence. A good small-business policy fits on a page or two: approved tools and plans, data that stays out, tasks AI may help with, tasks that need a professional, and the review step before anything goes out.
In a real lesson: Reply Faster to a Client Asking for a Case Update: ChatGPT for Small Law Firms
The law firm case update lesson shows a firm's rules shaping AI use. You are Owen Park, a paralegal at Harbor Street Law, a made-up firm, replying to Carla, a florist suing an event venue over $8,400. Two of the numbered facts you paste with Paste facts are firm policy: no predictions and no legal advice by email, and no case details or evidence by text message or social media.
The instructions repeat "No legal advice". When ChatGPT's first draft calls a missed deadline an automatic win and guesses about getting paid, Paste check flags them, and the fixed reply says plainly that the firm cannot predict the outcome. The lesson's finish adds the review step a policy would require: you read it last, and if your firm has an attorney approve client updates, they read it too.
An acceptable use policy is where rules like these live permanently, so every draft starts from them instead of depending on who remembers.

Try this lesson free or read the step-by-step guide.
Common confusions
AI policy vs a provider's terms of use
OpenAI's or Google's terms govern your use of their service. Your acceptable use policy governs your staff: which of those services they may use, with what data, for which tasks. You need both.
AI policy vs banning AI
Banning AI tends to push use onto personal accounts nobody can see. A clear policy that names approved tools and safe uses usually reduces risk more than a ban.
Tips
- List approved tools and plans, and say whether personal accounts are allowed for work.
- Spell out data that never goes in (ID numbers, account numbers, health details) and tasks that need a professional.
- Require a person to review AI drafts before they reach customers; have a qualified professional review the policy itself, as this is not legal advice.
Related terms
Where you use it: free lessons
- Reply Faster to a Client Asking for a Case Update: ChatGPT for Small Law Firms (ChatGPT, 10 min)
- Turn an Interview Debrief into a Scorecard and a Candidate Follow-Up (Recruiting & HR) (ChatGPT, 9 min)
- Summarize a Meeting Transcript with ChatGPT (ChatGPT, 9 min)
Prompt templates that use it
Frequently asked questions
- Does a small business really need an AI policy?
- If staff use AI with customer or client information, yes. Even a one-page policy prevents the most common mistakes, like pasting ID numbers or sending unreviewed drafts.
- What should an AI acceptable use policy include?
- Approved tools and plans, information that must never be entered, allowed and forbidden uses, the review step for AI output, and who to ask when unsure.