1. Purpose
The purpose of this AI Acceptable Use Policy is to establish requirements for the responsible, secure, and appropriate use of artificial intelligence (AI) and generative AI tools within the organization.
The policy is intended to:
- Protect organizational, customer, employee, and confidential information.
- Reduce security, privacy, legal, and operational risks associated with AI use.
- Define which AI use cases are acceptable and which require approval.
- Establish requirements for using third-party AI services.
- Prevent unauthorized disclosure of sensitive information through AI tools.
- Ensure appropriate human review of AI-generated outputs.
- Support responsible adoption of AI while maintaining information security and compliance.
Core principle:
AI may be used to support business activities, but users remain responsible for protecting information, validating AI outputs, and complying with organizational requirements.
2. Scope
This policy applies to:
- Employees
- Contractors
- Consultants
- Interns
- Temporary personnel
- Third parties authorized to use organizational AI resources
It applies to AI systems used for:
- Text generation
- Code generation
- Data analysis
- Document summarization
- Translation
- Research
- Customer support
- Content creation
- Image generation
- Audio/video generation
- Automation
- Decision support
- Machine learning
- AI-powered SaaS applications
- AI APIs and models
- Internally developed AI systems
This policy applies whether AI is accessed through:
- Web applications
- Mobile applications
- Enterprise platforms
- APIs
- Cloud services
- Developer tools
- Integrated SaaS applications
- Internally hosted models
3. What Is AI?
For this policy, AI includes systems that can generate, analyze, classify, predict, recommend, summarize, or otherwise process information using machine-learning or artificial-intelligence techniques.
Examples include:
- Generative AI assistants
- Large language models
- AI coding assistants
- AI-powered productivity tools
- AI chatbots
- Machine-learning platforms
- AI analytics tools
- AI image/video generators
- AI-enabled SaaS applications
The organization may maintain an Approved AI Tools Register to identify AI services authorized for business use.
4. AI Use Principles
Users must follow these principles:
4.1 Authorized Use
Use only AI tools approved or permitted by the organization for the intended business purpose.
4.2 Data Protection
Do not provide information to an AI service unless the user is authorized to disclose that information to the service.
4.3 Minimum Necessary Information
Provide only the minimum information necessary to achieve the intended purpose.
4.4 Human Responsibility
AI output does not replace human accountability.
The employee using the AI system remains responsible for reviewing and appropriately using its output.
4.5 Accuracy
AI-generated information should be verified before being used for important business, security, legal, financial, customer, or technical decisions.
4.6 Security
AI tools must not be used to bypass organizational security controls.
4.7 Transparency
Where required, users should disclose the use of AI in accordance with organizational, customer, contractual, legal, or regulatory requirements.
5. Approved AI Tools
The organization should maintain a list of AI tools approved for business use.
Example:
| AI Tool | Purpose | Approved Data | Restrictions | Owner | Status |
|---|---|---|---|---|---|
| Enterprise AI Assistant | Productivity | Internal information | No restricted data | IT | Approved |
| AI Coding Assistant | Development | Approved source code | No secrets/credentials | Engineering | Approved |
| Public AI Service | General research | Public information only | No confidential data | Security | Restricted |
| AI Customer Support Tool | Customer support | Approved customer data | Contract/security review required | Support | Approved |
Approval should consider:
- Security
- Privacy
- Data handling
- Provider terms
- Data retention
- Model training/data-use practices
- Access control
- Encryption
- Contractual requirements
- Regulatory considerations
- Business purpose
6. Prohibited AI Use
Unless specifically authorized, users must not use AI tools to:
- Enter passwords or credentials.
- Enter API keys or access tokens.
- Enter encryption keys.
- Upload confidential customer information.
- Upload restricted organizational information.
- Upload sensitive employee information.
- Upload security incident information.
- Upload confidential contracts.
- Upload proprietary source code.
- Upload production databases.
- Upload security configurations that could expose organizational defenses.
- Circumvent security controls.
- Generate malware for unauthorized purposes.
- Conduct unauthorized attacks or penetration testing.
- Impersonate individuals.
- Create fraudulent content.
- Generate content for illegal activities.
- Make unauthorized decisions on behalf of the organization.
7. Data Classification and AI Use
AI usage must follow the organization’s information classification requirements.
A practical model is:
| Data Classification | AI Usage |
|---|---|
| Public | Generally permitted for approved business use |
| Internal | Permitted only with approved AI tools |
| Confidential | Requires an approved tool and appropriate safeguards |
| Restricted | Prohibited unless specifically authorized |
The organization should define its own classification and AI handling rules based on its risk assessment.
8. Customer Information
Customer information must not be entered into an AI service unless:
- The service is approved.
- The intended use is authorized.
- The data handling arrangements are understood.
- Applicable contractual requirements are satisfied.
- Applicable privacy/security requirements are addressed.
Example
An employee receives a confidential customer security report.
They should not copy the report into a public AI chatbot to obtain a summary.
If AI-assisted summarization is required:
Confirm authorization → Confirm approved AI service → Minimize data → Process → Review output → Secure/delete working data where required
9. Personal Data
Users must handle personal data in accordance with applicable privacy requirements and organizational policies.
Unless specifically authorized, users should not enter:
- Customer personal data
- Employee personal data
- Applicant information
- Health information
- Financial information
- Government identifiers
- Authentication information
into public or unapproved AI tools.
Where AI processing of personal data is approved, appropriate security, privacy, contractual, and retention requirements should be considered.
10. Source Code and AI Coding Tools
AI coding assistants may be used only in accordance with approved development practices.
Developers must:
- Use approved coding tools.
- Follow repository access controls.
- Avoid entering secrets into AI prompts.
- Avoid exposing customer data.
- Review AI-generated code.
- Conduct appropriate security testing.
- Check dependencies and licenses.
- Follow secure coding standards.
- Ensure generated code does not introduce security vulnerabilities.
AI-generated code must not automatically be treated as secure or production-ready.
Required Flow
Generate → Review → Security Check → Test → Approve → Deploy
11. Secrets and Credentials
The following must never be entered into an unapproved AI service:
- Passwords
- API keys
- Access tokens
- Private keys
- Encryption keys
- Database credentials
- AWS credentials
- Azure credentials
- GCP credentials
- Production secrets
- Session tokens
Example
Instead of submitting:
“Here is our AWS access key and secret. Fix this authentication error.”
the employee should remove the credentials and provide only the minimum non-sensitive technical information required for troubleshooting.
12. AI-Generated Content
AI-generated content may contain:
- Incorrect information
- Outdated information
- Fabricated references
- Biased conclusions
- Incomplete analysis
- Security weaknesses
- Copyright or licensing concerns
Users must review AI-generated content before relying on it.
For important business content, the reviewer should verify:
- Accuracy
- Relevance
- Completeness
- Confidentiality
- Security
- Legal/compliance implications
- Source credibility
13. Human Review
AI must not replace appropriate human judgment for high-impact activities.
Human review should be performed before AI output is used for significant:
- Customer decisions
- Security decisions
- Legal conclusions
- Financial decisions
- Employment decisions
- Compliance conclusions
- Risk assessments
- Production changes
- Contractual commitments
The level of review should be proportionate to the risk.
14. AI and Customer Communications
AI-generated customer communications should be reviewed before being sent where the content could materially affect:
- Customer commitments
- Security statements
- Contractual obligations
- Pricing
- Legal positions
- Incident communications
- Regulatory communications
- Service availability
- Technical instructions
Employees remain responsible for the accuracy of communications they send.
15. AI and Security Operations
AI may be used to support security activities such as:
- Log analysis
- Alert summarization
- Threat intelligence analysis
- Security documentation
- Detection-rule development
- Security research
- Code review
- Incident analysis
However:
- Sensitive information must be handled appropriately.
- AI output must be validated.
- Security decisions should not rely blindly on AI output.
- High-impact actions require appropriate human authorization.
16. AI for Incident Response
During a security incident, employees must not upload sensitive incident information to public AI tools unless specifically authorized.
Potentially sensitive information may include:
- Customer information
- Attack details
- Credentials
- Logs containing personal data
- Vulnerability details
- Security architecture
- Internal IP addresses
- Incident response records
AI may be used through an approved enterprise service where the organization’s security and privacy requirements are satisfied.
17. AI and Confidential Business Information
Confidential business information should only be processed by AI services that are approved for the relevant classification.
Examples include:
- Business plans
- Financial forecasts
- Pricing strategy
- Contracts
- M&A information
- Customer proposals
- Internal audit information
- Security assessments
- Risk registers
- Intellectual property
When in doubt:
Do not upload the information → Consult Security/IT → Confirm whether the AI tool is approved.
18. AI Output and Intellectual Property
Users should consider intellectual property and licensing implications when using AI-generated content or code.
Users should:
- Review applicable tool/provider terms.
- Avoid assuming that AI-generated material is automatically free from third-party rights.
- Review generated code and dependencies.
- Follow organizational intellectual-property requirements.
- Obtain appropriate review before externally distributing AI-generated material where necessary.
19. AI-Generated Code and Software Dependencies
Where AI generates software code, developers should verify:
- Code quality
- Security
- Licensing
- Dependency provenance
- Vulnerabilities
- Secrets
- Malicious or unsafe functionality
- Compatibility
- Test coverage
AI-generated code should pass the organization’s normal development and security controls.
AI should not become a mechanism for bypassing:
- Code review
- SAST
- SCA
- DAST
- Security testing
- VAPT
- Change management
- Production approval
20. AI and Decision Making
AI should generally be treated as a decision-support mechanism rather than an autonomous authority for significant organizational decisions.
Users should understand:
- What information the AI used.
- Whether the information is reliable.
- Whether the output can be independently verified.
- What limitations apply.
- What human approval is required.
The organization should identify higher-risk AI use cases that require additional governance.
21. AI-Generated Images, Audio, and Video
Users must ensure that AI-generated or AI-modified media is used appropriately.
Users must not use AI to:
- Impersonate individuals without authorization.
- Create fraudulent representations.
- Misrepresent events or statements.
- Violate privacy.
- Infringe applicable intellectual-property rights.
- Produce prohibited or illegal material.
Where disclosure of AI-generated or AI-modified content is appropriate or required, users should provide suitable disclosure.
22. AI Accounts and Access
AI services used for business purposes should use approved organizational accounts where available.
Users should:
- Use organizational authentication.
- Enable MFA where supported.
- Avoid sharing AI accounts.
- Protect API keys.
- Follow role-based access requirements.
- Remove access when no longer required.
Business AI accounts should not be created using personal email addresses where organizational accounts are available and required.
23. AI API Keys and Integrations
AI API keys must be treated as confidential credentials.
They should:
- Be stored in approved secrets-management systems.
- Never be committed to source code.
- Not be shared through chat or email.
- Be rotated when compromised.
- Have appropriate permissions and usage limits.
- Be monitored where appropriate.
24. Third-Party AI Services
Before an AI service is approved for business use, the organization should consider:
- Provider security
- Data processing
- Data retention
- Model training/use of submitted data
- Data location
- Subprocessors
- Encryption
- Access control
- Incident notification
- Availability
- Contractual terms
- Privacy requirements
- Exit and deletion arrangements
The level of review should be proportionate to the information and business process involved.
25. AI Vendor and Supplier Risk
Where an AI service processes confidential, customer, personal, or otherwise sensitive information, the supplier may need to undergo appropriate security/privacy assessment.
Possible evidence includes:
- Security certifications/assurance
- Security questionnaire
- Privacy documentation
- Data processing agreement
- Contract
- Data retention information
- Subprocessor information
- Incident response commitments
- Business continuity information
The AI service should be recorded in the organization’s SaaS Application Register where applicable.
26. Prompt Security
Users should treat prompts as business information where they contain sensitive content.
Users should:
- Provide only necessary information.
- Remove unnecessary identifiers.
- Avoid secrets.
- Avoid confidential information unless approved.
- Avoid copying entire documents when only a small section is required.
- Review the output before reuse.
Example
Instead of uploading an entire customer contract, provide only the specific non-sensitive clause requiring analysis where authorized and appropriate.
27. Prompt Injection and Untrusted AI Content
Users and developers should recognize that AI systems may process untrusted instructions embedded in:
- Documents
- Websites
- Emails
- Code
- Customer content
- External data
- Uploaded files
AI output should not automatically be trusted merely because it was generated by an AI system.
Where AI is integrated into applications, developers should consider risks such as:
- Prompt injection
- Data leakage
- Excessive agency
- Unauthorized tool use
- Insecure output handling
- Model manipulation
- Sensitive information disclosure
28. AI-Integrated Applications
Applications that use AI should follow applicable software security requirements.
Before deployment, consider:
- AI model/provider
- Data flows
- Input data
- Output data
- Access controls
- Prompt security
- API security
- Logging
- Monitoring
- Data retention
- Third-party dependencies
- Security testing
- Failure handling
- Human oversight
AI functionality should be included in relevant security architecture and risk assessments.
29. AI Risk Assessment
Significant AI use cases should be assessed for relevant risks.
Consider:
- Confidentiality
- Integrity
- Availability
- Privacy
- Accuracy
- Bias
- Intellectual property
- Security
- Regulatory requirements
- Customer impact
- Supplier dependency
- Operational dependency
Example:
AI customer-support assistant
Potential risks:
- Customer data exposure
- Incorrect response
- Unauthorized actions
- Prompt injection
- Excessive system permissions
- Provider outage
Treatment may include:
- Data minimization
- Access restrictions
- Human review
- Approved provider
- Logging
- Testing
- Output validation
- Restricted tool permissions
30. AI Use Cases
The organization may categorize AI use cases.
Low-Risk Examples
- Public-content summarization
- Brainstorming
- Translation of public information
- Formatting
- Drafting generic content
Moderate-Risk Examples
- Internal document summarization
- Code assistance
- Security analysis
- Internal research
- Business analysis
Higher-Risk Examples
- Customer decisions
- Employee decisions
- Processing sensitive personal information
- Automated security actions
- AI agents with production access
- AI making financial/legal/compliance decisions
- AI directly controlling business-critical systems
Higher-risk use cases should receive additional review and approval.
31. AI Agents and Autonomous Actions
AI agents that can perform actions in organizational systems require additional controls.
Examples include agents that can:
- Send emails
- Modify tickets
- Execute code
- Access databases
- Modify cloud resources
- Create users
- Change configurations
- Purchase services
Such systems should use:
- Least privilege
- Restricted permissions
- Approved tools
- Authentication
- Logging
- Monitoring
- Human approval for high-impact actions
- Rate limits
- Defined boundaries
- Emergency disablement mechanisms
An AI agent should not receive unrestricted administrative access merely because it is technically capable of using it.
32. Monitoring AI Usage
Where appropriate and legally permissible, the organization may monitor business AI usage to:
- Detect unauthorized AI services.
- Identify sensitive-data exposure.
- Monitor approved AI use.
- Investigate incidents.
- Assess compliance.
- Improve AI governance.
Monitoring should be proportionate and consider applicable privacy requirements.
33. Reporting AI Security Incidents
Users must report suspected AI-related incidents.
Examples include:
- Confidential information sent to an unauthorized AI service.
- AI account compromise.
- API key exposure.
- Unexpected AI data disclosure.
- AI-generated malicious content.
- Prompt injection.
- Unauthorized AI agent action.
- Incorrect AI output causing significant business impact.
- Unauthorized AI tool usage.
Response
Detect → Stop/Contain → Report → Assess → Investigate → Remediate → Verify → Learn
34. Exceptions
Exceptions to this policy must be:
- Business justified.
- Risk assessed.
- Approved by an authorized person.
- Documented.
- Time-bound where appropriate.
- Reviewed periodically.
An exception should record:
- AI service/use case
- Data involved
- Business reason
- Risk
- Compensating controls
- Approver
- Expiry/review date
35. Employee Responsibilities
Employees must:
- Use only approved AI tools for business information.
- Protect confidential information.
- Avoid entering secrets into AI systems.
- Review AI output.
- Follow data-classification requirements.
- Follow security and privacy requirements.
- Report AI-related incidents.
- Complete required AI/security awareness training.
Employees remain accountable for how AI-generated output is used.
36. Management Responsibilities
Management should:
- Approve appropriate AI use.
- Provide resources for secure AI adoption.
- Define risk tolerance for AI use.
- Ensure significant AI risks are addressed.
- Support employee awareness.
- Review significant AI-related incidents and risks.
37. IT and Information Security Responsibilities
IT/Security should:
- Maintain approved AI tools.
- Assess AI security risks.
- Support secure configuration.
- Monitor relevant AI usage.
- Review AI suppliers where appropriate.
- Establish security requirements.
- Support incident response.
- Periodically review AI risks.
38. Legal/Privacy Responsibilities
Where applicable, Legal/Privacy should support:
- Privacy assessments
- Data processing requirements
- Contract review
- Intellectual-property considerations
- Regulatory requirements
- Customer contractual requirements
- Cross-border data-transfer considerations
The level of legal/privacy review should be proportionate to the AI use case.
39. Approved AI Tool Register
The organization should maintain an AI Tool Register where appropriate.
| ID | AI Tool | Provider | Purpose | Data Allowed | Owner | Security Review | Privacy Review | Status |
|---|---|---|---|---|---|---|---|---|
| AI-001 | Enterprise AI Assistant | Provider | Productivity | Internal | IT | Completed | Completed | Approved |
| AI-002 | Coding Assistant | Provider | Development | Approved source code | Engineering | Completed | As applicable | Approved |
| AI-003 | Public AI Tool | Provider | General research | Public only | Security | Restricted | N/A | Restricted |
The actual tools and approval status should be based on the organization’s own assessment.
40. AI Use Case Register
For significant AI applications, maintain an AI Use Case Register.
| Field | Example |
|---|---|
| AI Use Case ID | AIUC-001 |
| Use Case | Customer Support Assistant |
| Business Owner | Customer Support |
| AI Provider | Approved Provider |
| Purpose | Support response assistance |
| Data Processed | Customer support information |
| Classification | Confidential |
| Personal Data | Yes, where applicable |
| Human Review | Required |
| Risk Level | High |
| Security Review | Completed |
| Privacy Review | Completed |
| Supplier Review | Completed |
| Related Risk | AI-R-001 |
| Status | Approved |
41. AWS SaaS Startup Example
Consider a SaaS company using AI to help its customer-support team draft responses.
Data Flow
Customer Ticket
↓
Support Platform
↓
Approved AI Service
↓
Draft Response
↓
Human Support Agent
↓
Customer
Required Controls
- Approved AI provider
- Defined data scope
- Data minimization
- Access control
- Contractual review
- Privacy assessment where applicable
- Prompt restrictions
- Human review
- Logging
- Incident reporting
- Periodic risk review
The AI should assist the support employee rather than automatically sending unrestricted responses to customers unless the use case has been specifically assessed and approved.
42. Audit Evidence
Possible evidence includes:
- AI Acceptable Use Policy
- Approved AI Tool Register
- AI Use Case Register
- AI risk assessments
- Security assessments
- Privacy assessments
- Supplier assessments
- Contracts
- Data-processing agreements
- Access-control records
- AI awareness training
- Security monitoring
- Incident records
- Exception approvals
- AI application architecture
- Security testing
- Human-review records where required
An auditor may sample an AI use case and trace:
Use Case → Data → AI Provider → Risk → Controls → Approval → Operation → Monitoring → Review
43. Common Mistakes
Mistake 1 — Simply banning AI
A complete prohibition may push employees toward unauthorized “shadow AI” usage.
A controlled approach is generally more practical:
Identify → Assess → Approve → Control → Monitor → Review
Mistake 2 — Allowing public AI for confidential information
Employees may unintentionally expose customer or company information.
Mistake 3 — Assuming AI output is correct
AI output can be inaccurate or incomplete.
Mistake 4 — Ignoring AI coding tools
Source code, secrets, dependencies, and intellectual-property considerations require specific controls.
Mistake 5 — Ignoring AI agents
AI systems with the ability to perform actions require stronger access and monitoring controls.
Mistake 6 — No approved-tool list
Employees may not know which AI services are permitted.
Mistake 7 — No human accountability
AI-generated output should not automatically become an organizational decision.
Mistake 8 — No supplier assessment
AI services may process organizational information outside the organization’s direct environment.
44. Startup-Friendly AI Governance Model
A startup does not necessarily need a complex AI governance platform.
A practical initial model can use:
1. Approved AI Tool Register
What AI tools can employees use?
2. AI Use Case Register
How is the organization using AI?
3. AI Risk Assessment
What could go wrong?
4. Data Rules
What information can and cannot be entered?
5. Human Review
Which AI outputs require verification or approval?
6. Supplier Review
Who processes the information?
7. Incident Process
What happens if AI causes or contributes to a security incident?
This provides a practical foundation without requiring a large AI governance platform.
45. Relationship with Other ISMS Documents
The AI Acceptable Use Policy should connect with:
Information Security Policy
→ Overall security requirements
Acceptable Use Policy
→ General technology usage
Employee IT Usage Policy
→ Employee IT responsibilities
Information & Asset Inventory
→ AI-related systems and information
Data Inventory
→ Information processed by AI
Asset Classification Procedure
→ Classification and handling requirements
Access Control Policy
→ AI accounts and permissions
SaaS Application Register
→ Third-party AI services
Supplier Security Assessment
→ AI provider risk
Risk Assessment
→ AI-specific risks
Incident Management
→ AI-related incidents
Security Awareness Policy
→ Employee AI awareness
Secure Development Policy
→ AI-generated code and AI-enabled applications
Privacy/RoPA Processes
→ Personal-data processing through AI
The relationship is:
AI Use Case → Data → Provider/System → Risk → Approval → Controls → Human Review → Monitoring → Incident Response → Review
46. Quick Audit Checklist
| Check | Yes/No | Evidence |
|---|---|---|
| Is an AI Acceptable Use Policy approved? | ||
| Are approved AI tools identified? | ||
| Are prohibited AI uses defined? | ||
| Are confidential and restricted data rules defined? | ||
| Are customer data requirements addressed? | ||
| Are personal-data requirements addressed? | ||
| Are passwords, keys, and credentials prohibited from unauthorized AI use? | ||
| Are source-code requirements defined? | ||
| Is AI-generated output subject to appropriate review? | ||
| Are AI suppliers assessed where required? | ||
| Are AI use cases risk assessed where appropriate? | ||
| Are AI agents addressed? | ||
| Are AI API keys protected? | ||
| Are AI-related incidents reportable? | ||
| Are exceptions controlled? | ||
| Are employees trained? | ||
| Is AI usage monitored where appropriate? | ||
| Are AI tools periodically reviewed? | ||
| Is the policy periodically reviewed? |
47. Policy Review
This policy should be reviewed periodically and whenever significant changes occur, including:
- Introduction of new AI technologies.
- Adoption of new AI providers.
- Significant changes in AI capabilities.
- New AI-enabled business processes.
- Security incidents involving AI.
- Changes in applicable legal or regulatory requirements.
- Changes to customer contractual requirements.
- Significant changes in the organization’s risk profile.
The policy should be updated when existing controls no longer adequately address the organization’s AI risks.
48. Final Principle
The objective of AI governance is not simply to prevent employees from using AI.
It is to enable useful AI adoption while protecting the organization’s information, customers, employees, systems, and reputation.
The practical model is:
Identify → Assess → Approve → Minimize Data → Use Securely → Validate → Monitor → Report → Improve
Or, more simply:
Use AI where it creates value. Protect the data. Verify the output. Keep humans accountable.
