Back to blog
Govern·Jun 22, 2026·4 min read

How to write an AI acceptable use policy your team will actually follow

A ban tells people what they cannot do and watches them do it anyway. An acceptable use policy tells them how to use AI well, which is the only instruction that survives contact with a deadline.

An AI acceptable use policy is the document that turns good intentions about AI into rules people can actually follow. Most organisations either have nothing, leaving employees to guess, or have a blanket ban that simply pushes usage underground. A clear, short policy is the middle path, and it is the foundation the rest of your AI governance sits on.

This guide covers what an AI acceptable use policy should contain, the structure to follow, and the mistake that makes most of them fail.

Why a ban is not a policy

The instinct to ban AI tools is understandable and almost always counterproductive. Employees who find a tool genuinely useful do not stop using it; they stop telling you, which converts a manageable risk into an invisible one. The full argument is in why banning AI tools backfires, but the short version is that a policy people can follow beats a rule they route around.

A policy only works if you can see whether it is followed, which is why Grasp pairs it with the visibility to enforce an acceptable use policy rather than just publish it.

What an AI acceptable use policy should cover

Scope. Which tools and which people the policy applies to, including AI features embedded in software you already use.

Approved tools. A clear list of sanctioned AI tools and how to request a new one, so the compliant path is the easy path.

Prohibited data. The specific categories that must never go into an AI tool, such as customer personal data, source code, financial records and anything covered by confidentiality. Concrete beats abstract here.

Acceptable uses. Examples of what good looks like, so the policy guides rather than only forbids.

Human oversight. Where a person must review AI output before it is used, particularly for decisions that affect customers or staff.

Responsibilities. Who owns the policy, who approves tools, and what happens when something goes wrong.

A simple structure to follow

Keep it to two pages. Open with a short statement of intent that frames AI as encouraged within guardrails, not feared. List the approved tools and the request route. State the prohibited data categories plainly. Give a handful of acceptable-use examples. Set out the oversight expectations for higher-stakes work. Name the owner and the review date. A forty-page document nobody reads protects no one; a two-page document everybody understands protects you a great deal.

Why the policy needs the inventory behind it

A policy is only as good as your ability to see whether it is followed. If you cannot tell which AI tools are actually in use, the approved-tools list is aspirational and the prohibited-data rule is unenforceable. That is why the policy works hand in hand with discovery: the policy sets the rules, and visibility tells you whether reality matches them. The link between unsanctioned tools and the rules they break is covered in employees using AI without IT approval.

Frequently asked questions

What is an AI acceptable use policy?

A short internal document that sets out which AI tools employees may use, what data must never be entered into them, and how AI output should be overseen. It replaces guesswork and blanket bans with rules people can actually follow.

What should an AI acceptable use policy include?

Scope, a list of approved tools and how to request new ones, prohibited data categories, examples of acceptable use, human-oversight expectations, and named responsibilities. Clarity and brevity matter more than length.

How long should an AI acceptable use policy be?

Around two pages. A policy people read and remember protects you far more than a comprehensive document that sits unread. Keep the rules concrete, especially the prohibited-data list, and point to detail elsewhere if needed.

Should we just ban AI tools instead?

No. Bans tend to push usage out of sight rather than stop it, turning a visible risk into a hidden one. A policy that channels usage toward approved tools and away from prohibited data manages the risk without losing the benefit.

How do we enforce an AI acceptable use policy?

By pairing it with visibility. You need to see which AI tools are actually in use to know whether the policy is followed, which is why discovery and the policy work together rather than one substituting for the other.

Grasp shows you every AI tool in use across the organisation, so your acceptable use policy becomes something you can enforce rather than just publish. See the AI governance solution →