The AI usage policy
your team will actually follow.
Most AI policies are written to protect the author, so nobody reads them and everybody
quietly uses ChatGPT on their phone. This one is written to be short enough to follow
and specific enough to show a regulator. Copy it, replace the
[placeholders], and put your name on it. If you'd like the
editable version or want it adapted to your setup on a call, both are free:
email us.
AI usage policy · [Company] · version 1.0 · [date] · owner: [name, role]
01Why this policy exists
[Company] wants staff using AI tools wherever they make work
better, and never in ways that put customer data, company IP or our regulatory
standing at risk. This policy says which tools are approved, what may go into them,
and who answers for the output. It applies to everyone, including directors.
02Approved tools
- Approved tools and tiers are listed at [link to internal list]. Only business or enterprise tiers whose terms exclude our data from model training are approved.
- Personal accounts and free tiers are not approved for company work, on any device.
- Anyone can propose a new tool to [owner]; the answer arrives within a week. Until then it stays off the list.
03What may go into a prompt
- Fine: our code (per section 04), public information, drafts and internal documents that carry no personal data.
- Never: customer or member personal data, credentials, API keys, financial account details, or anything covered by an NDA with a third party, unless the tool sits on an approved tier and the data is necessary for the task.
- When in doubt, anonymise first or ask [owner]. The two minutes that takes is always cheaper than an incident.
04Code and intellectual property
- Company code may be used with approved coding tools. Output belongs to [Company], like any other work product.
- AI-assisted code goes through the same review as human code. Nothing merges unreviewed because "the AI wrote it".
- Repositories are scrubbed of secrets before any AI tool reads them; secrets live in [secret manager], never in code or prompts.
05Accountability
- The person who ships the work owns the work. "The AI said so" is not a defence, in code review or anywhere else.
- AI-generated content sent outside the company (to customers, members, regulators, the public) is reviewed by a human first, every time.
06Records and audit
- [Owner] keeps the list of approved tools, their tiers, and the vendor terms covering data retention and training, reviewed quarterly.
- Where a tool offers usage or audit logs, they stay enabled. If a regulator or auditor asks how we use AI, this policy and those records are the answer.
07When something goes wrong
- Pasted something you shouldn't have? Tell [owner] the same day. Reporting an accident is never a disciplinary matter; hiding one is.
- If credentials leaked into a prompt, they get rotated immediately, same as any other exposure.
08Keeping this current
Models, tools and terms change quickly. [Owner] reviews this
policy every quarter, and any member of staff can propose a change at any time. The
version number above tells you if the copy you're reading is current.
Written by Future Proof Consulting, the advisory arm of an Isle of Man engineering
practice that builds and operates software for a licensed financial operator. This
template is part of the governance pack every engagement ships with; the rest of it,
and the adoption programme behind it, start with a
free 30-minute call.