AI Usage Policy Template
A generative AI acceptable-use policy template for employees: permitted use, confidential data input restrictions, output review, and accountability — aligned with the direction of ISO/IEC 42001.
In short
An AI usage policy governs which artificial intelligence tools personnel may use, what data must never be entered into them, and how outputs are verified before use. Without a policy, usage still happens — only without agreed boundaries and without a reviewable trail.
- Format
- DOCX
- Size
- 15 KB
- Price
- Free
Your data is handled in accordance with Indonesia's Personal Data Protection Law. We only send the document you requested and the occasional relevant GRC insight — no spam.
What This Document Is For
A blanket ban on AI tools almost always fails: usage moves to personal devices, beyond monitoring and without records. What remains is not eliminated risk but invisible risk.
This policy takes a different position: name approved tools, draw a firm line around data that must never be entered, and require output verification before it informs a decision or leaves the organisation. The most important part is the prohibited data list — that is what keeps customer data out of third-party services with no lawful basis.
Most Useful For
- Organisations whose staff already use AI tools with no written rules
- Security teams needing to answer client questions about AI use in their services
- Companies pursuing ISO 27001 and asked to show control over new tooling
What's Inside
Scope & definitions
Tools covered, from conversational assistants to AI features bolted onto software already in use.
Approved tools
The approval mechanism for new tools and the security and privacy considerations assessed.
Prohibited data
Categories that must never be entered into AI tools, including personal data, trade secrets, and credentials.
Output verification
The duty to check outputs before they inform decisions, enter production code, or reach external parties.
User accountability
Confirmation that accountability stays with the person using the tool, not the tool.
Monitoring & sanctions
How compliance is monitored and the consequences of breach.
Standards & Regulations It Helps Satisfy
| Standard / Regulation | Clause / Article | What this document covers |
|---|---|---|
| ISO/IEC 27001:2022 | Control A.5.1 | Information security policy and its topic-specific subordinate policies. |
| ISO/IEC 27001:2022 | Control A.5.10 | Acceptable use of information and associated assets. |
| Law 27/2022 (PDP Law) | Lawful basis | Preventing third-party processing of personal data without a valid basis. |
This document helps satisfy the requirements above, but does not by itself make an organisation compliant. Compliance is judged on practice in operation, not on documents held.
Questions About This Document
Does this policy ban AI use?
No. The frame permits use under conditions: approved tools, restricted data, verified outputs. A blanket ban simply relocates usage somewhere invisible, which is the worse security outcome.
What about AI features inside software we already use?
That is the part most often missed. Automatic summarisation in a meeting or email tool can process data just as sensitive as a conversational assistant, yet never passes through an approval process because it is seen as part of an old tool. This policy covers it explicitly.
Is there a dedicated AI governance standard?
Yes: ISO/IEC 42001 covers artificial intelligence management systems. For most organisations starting out, a usage policy like this closes the largest risks; ISO 42001 becomes relevant when AI is a core part of the product or service you offer.
Related Reading
Background that helps you fill this document in correctly, rather than merely filling it in.
Documents Often Taken Together With This One
Policy, Procedure & Form Template Pack
A ready-to-use collection of information security policy, procedure, and form templates.
Free DownloadAcceptable Use Policy (AUP) Template
Ground rules for company devices, networks, email, and internet use — including prohibited activities, user responsibilities, and consequences, aligned with ISO 27001 control A.5.10.
Free DownloadRemote Working Policy Template
Security standards for remote and hybrid work: devices, home networks, VPN, document storage, and physical security — aligned with ISO 27001 control A.6.7.
Free DownloadNeed guidance, not just a template?
A template speeds up producing the document. What decides whether an audit passes is whether its contents genuinely reflect how your organisation works — and that is what we support.