A practical AI acceptable use policy and governance framework — short enough to be read, specific enough to be followed, and matched to controls that make it real.
It is already happening
The question is not whether to allow AI in your business. Your staff are using it — on personal accounts, on personal devices, with company information — because it saves them time on real work.
Every AI policy conversation should start from that position rather than from a hypothetical decision. What you are choosing is whether that usage is governed and visible, or ungoverned and invisible.
Why prohibition fails
A ban with no alternative does not stop usage. It moves it somewhere you cannot see.
The same client information goes into the same models, from a personal account with consumer terms rather than a business account with commercial data protection, on a device you do not manage, by someone who now cannot ask for help because they are not supposed to be doing it.
That is a materially worse position than sanctioned use, and it is the predictable outcome of a policy that only prohibits.
What a workable policy contains
What must never go in. Specific categories rather than a vague instruction to use judgement: client and customer personal information, anything under a confidentiality obligation, credentials, unreleased financial data, health information. The test we suggest to staff is whether they would be comfortable with it in a competitor’s hands.
Which tools are approved. Named, with the reason. This is the part that makes the restriction workable, because it gives people a route rather than only a wall.
What must be verified. Anything going to a client, into a record, into a financial figure, or into a decision. With the person accountable for checking it named rather than implied.
Where accountability sits. Explicitly: with the person who used the tool and the business that relied on the output. Not with the vendor, not with the model. This is the point most often misunderstood and it is worth stating in plain words.
Two pages, not twenty
For a business of 10 to 200 staff, a short readable policy that people follow beats a comprehensive framework that satisfies an auditor and changes nothing.
The measure of a policy is whether the person drafting a client email at 4pm knows what they are allowed to do. That requires them to have read it, which requires it to be short.
Back it with controls where it matters
A rule nobody can enforce is a suggestion.
Where the risk justifies it, the policy is supported by configuration — providing a licensed tool with commercial data protection terms, and where appropriate restricting access to consumer AI services on managed devices. That is a judgement call rather than a default; heavy-handed blocking has its own costs.
The related work is awareness training, because the behaviours a policy describes are learned rather than announced.
Review it, because the ground moves
AI tooling changes on a timescale of months. A policy naming specific products and specific terms will be partly out of date within a year.
Building in a review cycle is more useful than trying to write something durable. So is writing the policy around principles — what kind of information, what kind of verification — with the tool names in an appendix that is cheap to update.