What should an AI acceptable use policy include?

Skip to main content

A good AI policy is short and practical. It should cover:

Want this sorted for you?Talk to our Burgess Hill team about microsoft defender and purview. Free, friendly and no obligation.
  • Approved tools: which AI tools are allowed.
  • Data rules: what must never be entered, such as personal data, client confidential information and passwords.
  • Checking outputs: AI results must be checked before they’re used or sent.
  • Disclosure: when to tell clients that AI was used.
  • Accountability: who owns AI decisions.
  • Reporting: how to report a mistake or data leak.
  • Review: how often the policy is reviewed.

It should match your data protection and information security policies. ABCOM writes AI policies as part of the AI Readiness Sprint (Week 3).

Want this looked after for you?

ABCOM has supported Sussex businesses and charities since 1996 and is an NCSC Assured Service Provider – Cyber Advisor (Cyber Essentials). Talk to a real person about your IT.

Also read

How ABCOM can help

Talk to a real person at our Burgess Hill office. We are an NCSC Assured Service Provider and have supported Sussex businesses since 1996.

Scroll to Top
Free 3-minute quiz · No sign-up for your score

Is your team using AI you don’t know about?

Score your Shadow AI risk across policy, data, tools, people and detection, then get the three controls to fix first.

Take the Shadow AI Check10 questions · about 3 minutes