AI Acceptable Use Policy: A Free 2026 Template (and How to Enforce It)
.jpg)
An AI acceptable use policy (AUP) is a short document that tells employees which AI tools they can use, what data they can put into them, and what is off-limits. It is the foundation of AI governance: the rulebook everything else enforces. This guide gives you a free, copy-paste template and, just as important, shows how to make sure the policy is actually followed instead of ignored.
The short answer: a good AI acceptable use policy is one page, names the approved tools, bans sensitive data in unapproved tools, and explains the consequences. But a policy only works if you can enforce it. dope.security is the tool that turns your AUP from a PDF into controls that run on every device.
What is an AI acceptable use policy?
An AI acceptable use policy defines the acceptable and unacceptable use of AI tools at work. It typically covers approved tools, prohibited data, account rules (corporate vs personal), human review expectations, and consequences for violations. It is usually one part of a wider AI governance framework, but it is the part employees actually read.
Free AI acceptable use policy template
Copy this, adjust the bracketed parts, and circulate it. Keep it short: the best policies fit on a page.
1. Purpose. This policy explains how employees of [Company] may use artificial intelligence tools to protect company and customer data while enabling productivity.
2. Scope. This policy applies to all employees, contractors, and anyone using [Company] devices or accounts, and covers all generative AI tools including ChatGPT, Claude, Gemini, Copilot, and any other AI application.
3. Approved tools. Employees may use the following AI tools on approved corporate accounts only: [list, e.g. ChatGPT Enterprise, Microsoft 365 Copilot, Claude for Work]. Personal AI accounts must not be used for company work on managed devices.
4. Prohibited data. Do not enter the following into any AI tool unless it is an approved enterprise tool covered by a data protection agreement: customer PII, payment (PCI) data, health (PHI) data, credentials or secrets, source code, and confidential or unreleased business information.
5. Human oversight. AI output must be reviewed by a person before it is used in customer-facing, legal, financial, or safety-related work. Employees are accountable for the accuracy of anything they produce with AI.
6. Monitoring. [Company] monitors AI tool usage on managed devices to protect data. Monitoring is limited to security purposes and applied transparently.
7. Consequences. Violations may result in loss of AI access and disciplinary action consistent with [Company]'s existing conduct policies.
8. Questions. Contact [security team / email] with any questions or to request a new AI tool be reviewed for approval.
The clause everyone forgets: enforcement
Most AI acceptable use policies fail on clauses 3 and 4. They say "approved accounts only" and "no sensitive data," but nothing on the device actually checks. Employees keep using personal ChatGPT because there is no consequence at the moment it happens. A policy without enforcement trains people to ignore policies. That is worse than having no policy at all.
dope.security: enforce the policy you just wrote
dope.security makes each clause of your AUP real, from a lightweight on-device agent that inspects locally with no backhaul (up to 4x faster than legacy proxies):
- Clause 3 (approved accounts): Cloud Application Control restricts AI tools to your approved tenants, so enterprise ChatGPT and Claude work while personal logins are blocked. See how to block personal ChatGPT.
- Clause 4 (prohibited data): Dopamine DLP inspects prompts and uploads in real time and blocks PII, PCI, PHI, secrets, and source code, classifying through zero-retention APIs so content is checked but never stored (US Patent no. 12,464,023). This is AI DLP in practice.
- Clause 6 (monitoring): Shadow IT discovery shows which AI tools are in use and on which accounts, giving you the transparent audit trail the policy promises. See monitoring ChatGPT usage.
Write the policy in the morning, enforce it that afternoon. dope.security pushes policy in seconds and deploys in days.
Policy clause to control mapping
| Policy clause | What it says | How dope.security enforces it |
|---|---|---|
| Approved accounts only | Corporate AI tenants, not personal | Cloud Application Control |
| No prohibited data | No PII, PCI, PHI, secrets, code | Dopamine DLP (Block/Monitor) |
| Monitoring | Transparent usage visibility | Shadow IT discovery |
| Approved tool list | Allow some AI, block the rest | dope.SWG allow/warn/block |
Tips for a policy people actually follow
- Keep it to one page. Nobody enforces a ten-page policy on themselves.
- Say yes to something. Name approved tools so people have a sanctioned path, not just prohibitions.
- Explain the why. "Protecting customer data" lands better than "because IT said so."
- Pair it with enforcement. A rule that is checked is a rule that is followed.
Frequently asked questions
What should an AI acceptable use policy include?
Purpose, scope, approved tools, prohibited data, human oversight, monitoring, and consequences. Keep it to about one page so people read it.
Is an AI acceptable use policy enough on its own?
No. A policy states intent; it does not enforce itself. Pair it with a tool that controls accounts and inspects data, like dope.security, or it becomes shelfware.
Can I allow ChatGPT in my AI policy but block personal accounts?
Yes, and you should. Approve the enterprise tenant and use Cloud Application Control to block personal logins, so employees stay productive without leaking data.
How do I monitor compliance with the policy?
Use Shadow IT discovery to see which AI tools and accounts are in use, and AI DLP to log or block sensitive data entering AI tools. Keep monitoring transparent.
See it in action
Write your AI acceptable use policy, then enforce every clause of it. Try dope.security free or book a 20-minute demo.



.jpg)
.jpg)

