Policies, Procedures & FormsFree

AI Usage Policy Template

A generative AI acceptable-use policy template for employees: permitted use, confidential data input restrictions, output review, and accountability — aligned with the direction of ISO/IEC 42001.

In short

An AI usage policy governs which artificial intelligence tools personnel may use, what data must never be entered into them, and how outputs are verified before use. Without a policy, usage still happens — only without agreed boundaries and without a reviewable trail.

Format
DOCX
Size
15 KB
Price
Free

Your data is handled in accordance with Indonesia's Personal Data Protection Law. We only send the document you requested and the occasional relevant GRC insight — no spam.

What This Document Is For

A blanket ban on AI tools almost always fails: usage moves to personal devices, beyond monitoring and without records. What remains is not eliminated risk but invisible risk.

This policy takes a different position: name approved tools, draw a firm line around data that must never be entered, and require output verification before it informs a decision or leaves the organisation. The most important part is the prohibited data list — that is what keeps customer data out of third-party services with no lawful basis.

Most Useful For

  • Organisations whose staff already use AI tools with no written rules
  • Security teams needing to answer client questions about AI use in their services
  • Companies pursuing ISO 27001 and asked to show control over new tooling

What's Inside

01

Scope & definitions

Tools covered, from conversational assistants to AI features bolted onto software already in use.

02

Approved tools

The approval mechanism for new tools and the security and privacy considerations assessed.

03

Prohibited data

Categories that must never be entered into AI tools, including personal data, trade secrets, and credentials.

04

Output verification

The duty to check outputs before they inform decisions, enter production code, or reach external parties.

05

User accountability

Confirmation that accountability stays with the person using the tool, not the tool.

06

Monitoring & sanctions

How compliance is monitored and the consequences of breach.

Standards & Regulations It Helps Satisfy

Standard / RegulationClause / ArticleWhat this document covers
ISO/IEC 27001:2022Control A.5.1Information security policy and its topic-specific subordinate policies.
ISO/IEC 27001:2022Control A.5.10Acceptable use of information and associated assets.
Law 27/2022 (PDP Law)Lawful basisPreventing third-party processing of personal data without a valid basis.

This document helps satisfy the requirements above, but does not by itself make an organisation compliant. Compliance is judged on practice in operation, not on documents held.

Questions About This Document

Does this policy ban AI use?

No. The frame permits use under conditions: approved tools, restricted data, verified outputs. A blanket ban simply relocates usage somewhere invisible, which is the worse security outcome.

What about AI features inside software we already use?

That is the part most often missed. Automatic summarisation in a meeting or email tool can process data just as sensitive as a conversational assistant, yet never passes through an approval process because it is seen as part of an old tool. This policy covers it explicitly.

Is there a dedicated AI governance standard?

Yes: ISO/IEC 42001 covers artificial intelligence management systems. For most organisations starting out, a usage policy like this closes the largest risks; ISO 42001 becomes relevant when AI is a core part of the product or service you offer.

Related Reading

Background that helps you fill this document in correctly, rather than merely filling it in.

Need guidance, not just a template?

A template speeds up producing the document. What decides whether an audit passes is whether its contents genuinely reflect how your organisation works — and that is what we support.