How to protect business data, set AI boundaries, and keep humans accountable for the robot’s homework.
Artificial intelligence has entered the workplace in roughly the same way smartphones did: quickly, enthusiastically, and well ahead of the policy manual.
One employee is asking AI to clean up an email. Another is generating spreadsheet formulas. Someone in marketing is brainstorming headlines. Meanwhile, Bob from accounting may be five minutes away from pasting a confidential financial report into whatever chatbot appeared first in his search results.
Bob means well.
That is precisely why businesses need an AI acceptable use policy.
An AI acceptable use policy, or AI AUP, gives employees practical rules for using artificial intelligence at work. Done correctly, it does not exist to ban AI. It establishes where AI can help, where humans need to remain firmly in charge, which information must stay out of AI systems, and what employees should do when something goes wrong.
The timing matters because AI risk management is becoming a normal part of business governance. The National Institute of Standards and Technology AI Risk Management Framework is designed to help organizations manage AI-related risks, and its four core functions are Govern, Map, Measure, and Manage. NIST also published a Generative AI Profile specifically addressing risks associated with generative systems. [nist.gov], [nist.gov]
For a small or midsize business, however, the first useful step does not need to be a 90-page governance manifesto.
It can start with one good policy.
First, Recognize That “Don’t Use AI” Is Not Much of a Policy
Imagine an employee has 200 rows of messy product descriptions and discovers that an AI assistant can clean them up in minutes.
The employee has three choices:
- Do it manually.
- Ask whether AI is approved.
- Quietly use an AI tool and hope nobody notices.
If your policy consists entirely of “AI is prohibited,” option three can become rather tempting.
A better policy acknowledges the business reality that AI can be useful while drawing meaningful boundaries around its use. The objective should be governed adoption, not merely prohibition.
That approach fits neatly with NIST’s governance guidance. The NIST AI RMF Playbook recommends putting organizational policies, processes, procedures, and practices in place around AI risk and calls for legal and regulatory requirements to be understood, managed, and documented. [airc.nist.gov]
In plain English: know what people are doing with AI, decide what is acceptable, document it, and make sure somebody owns the decisions.
Step 1: Define What You Mean by “AI”
This sounds ridiculously obvious until someone says, “Oh, I didn’t realize that counted.”
Your policy should establish what technologies fall under it. That will usually include generative AI chatbots, AI assistants built into business applications, image and video generators, coding assistants, meeting assistants, autonomous or agentic tools, and other systems capable of analyzing or generating company information.
You do not need a definition worthy of a computer science textbook. You need one an employee can understand.
For example: For purposes of this policy, AI tools include software and online services that use artificial intelligence to generate, transform, summarize, analyze, recommend, automate, or make decisions using text, images, audio, video, code, or business data.
The definition should also make clear that the policy applies whether an AI feature is a standalone chatbot or quietly built into software the business already uses.
That last part is important. AI increasingly looks less like a destination and more like a feature.
Step 2: Create an Approved-AI List
This may be the most practical part of the entire policy.
Tell employees which AI tools they may use for company work.
An approved list avoids forcing every employee to conduct their own miniature cybersecurity assessment at 4:47 on a Friday afternoon.
Your approval process can consider questions such as:
- What data does the provider collect?
- How is company information handled?
- What administrative and security controls are available?
- Can your organization manage accounts centrally?
- Are authentication and access controls appropriate?
- What contractual, privacy, retention, or compliance obligations apply?
Keep the employee-facing rule simple: Use only company-approved AI services for company business. If you want to use an AI service that has not been approved, request approval before entering company information into it.
That turns a vague warning into an actionable instruction.
Step 3: Draw a Bright Red Line Around Sensitive Data
Here is where policy language needs to be painfully clear.
An employee who would never deliberately email your customer database to a stranger might see nothing alarming about asking an AI tool: “Can you find some interesting trends in this customer spreadsheet?”
The intent is productivity. The potential problem is everything contained in the spreadsheet.
Your policy should identify information employees may not submit to unapproved AI tools. Depending on the organization, that could encompass passwords and credentials, customer records, employee information, confidential financial information, intellectual property, regulated records, contracts, security configurations, source code, or other nonpublic business information.
The exact classification should follow your existing security and data-handling policies rather than creating a completely separate universe for AI.
This emphasis on data is well founded. Joint guidance published by CISA, the NSA, FBI, and international cybersecurity partners emphasizes that data security is critical throughout the AI lifecycle and identifies practices including encryption, provenance tracking, secure storage, access controls, and protecting data integrity. [cisa.gov], [media.defense.gov]
So give employees a memorable rule: If you would not post the information publicly, do not put it into an unapproved AI system.
It is intentionally conservative. Exceptions can then be defined for properly approved systems that are authorized to process particular kinds of business data.
Step 4: Remind Everyone That AI Can Be Spectacularly Confident and Still Wrong
AI has an interesting personality trait: uncertainty does not always prevent it from sounding certain.
NIST’s Generative AI Profile specifically recognizes “confabulation,” the production of confidently stated but erroneous or false content, as one of the risks associated with generative AI systems. [nvlpubs.nist.gov]
That makes human verification essential.
Your policy should state that employees remain responsible for work they create with AI assistance. AI-generated facts, calculations, citations, recommendations, code, and other important outputs should be appropriately verified before they influence business decisions or reach customers.
A useful rule might be: Treat AI-generated content as a draft, not as an authority. Employees are responsible for reviewing and validating AI-assisted work before using, publishing, or relying upon it.
Think of the chatbot as an extraordinarily fast intern who has read half the internet but occasionally invents the name of a book.
You would check the intern’s work.
Check the robot’s work too.
Step 5: Identify the Decisions AI Should Not Make on Its Own
Not every mistake carries the same consequences.
If AI suggests a terrible headline for the company picnic invitation, civilization will probably survive. If an AI system independently determines who gets hired, fired, promoted, approved, rejected, investigated, or disciplined, the stakes are considerably higher.
Your AI AUP should distinguish low-risk assistance from high-impact decisions.
For ordinary employees, the instruction does not need to become an AI ethics dissertation. It could simply state that AI must not be used to make consequential decisions about employees, applicants, customers, finances, safety, legal matters, or similarly sensitive subjects unless the use has been specifically reviewed and authorized.
This principle is consistent with broader responsible-AI frameworks. Microsoft, for example, describes its responsible AI approach around fairness, reliability and safety, privacy and security, inclusiveness, transparency, and accountability. [microsoft.com], [support.mi…rosoft.com]
The important word for your policy is accountability.
AI should not become the corporate equivalent of “the dog ate my homework.”
“The AI told me to do it” is not an accountability model.
Step 6: Establish Rules for AI-Generated Content
AI can now contribute to emails, reports, code, presentations, images, research, customer communications, and much more.
That creates a deceptively simple question: When does AI-generated work require disclosure or additional review?
There is no sensible universal answer for every business and every use. Your company should establish rules appropriate to risk and context.
A brainstorming session may not require special treatment. A client deliverable, public statement, legal communication, important research report, or automated customer interaction may warrant a higher standard of review or disclosure.
The policy should also tell employees to respect intellectual property, licensing requirements, contractual obligations, and company rules when using generated material. An AI output should not automatically be treated as clean, verified, company-owned material simply because it appeared instantly on a screen.
Again, the principle is straightforward: AI can assist the employee. It does not eliminate the employee’s responsibilities.
Step 7: Give People a Safe Way to Experiment
This is the part organizations sometimes forget.
If your AI policy is purely a catalog of things employees must never do, you have written a warning label, not an adoption strategy.
Give people examples of acceptable uses.
Perhaps employees may use an approved AI platform to brainstorm nonconfidential ideas, rewrite internal text, summarize authorized documents, produce first drafts, explain unfamiliar technical concepts, or develop formulas and scripts that are subsequently tested.
Contrast those with clearly unacceptable uses, such as bypassing security controls, entering protected information into unauthorized systems, impersonating someone deceptively, creating fraudulent content, or relying on unverified AI output for sensitive decisions.
Employees should be able to read the policy and think, “Great, now I know how I can use this.”
That is much better than wondering whether the AI police are hiding behind the printer.
Step 8: Create an AI Incident Plan
Eventually, someone will make a mistake.
Maybe confidential information is submitted to the wrong platform. Perhaps an AI-generated document is distributed before anyone notices that several “facts” are fictional. Or an employee connects an AI application to company information without authorization.
The policy should tell employees what to do next.
Keep this refreshingly simple: If confidential or sensitive information is accidentally submitted to an unauthorized AI system, or you believe AI has caused a security, privacy, legal, or operational issue, report the incident immediately through the company’s established security or IT reporting process.
Do not make employees solve the incident themselves before reporting it.
Fast reporting gives IT, security, privacy, or legal personnel the opportunity to determine what actually happened and what response is appropriate.
Step 9: Assign an Owner and Review the Policy Regularly
AI policy cannot live forever inside a PDF named AI-Policy-FINAL-Final-v3-ReallyFinal.pdf.
Someone needs to own it.
For a smaller company, that might be an IT leader working with management, HR, legal counsel, and other relevant stakeholders. Larger or regulated organizations may require a more formal AI governance group.
Ownership matters because the landscape changes. As of September 2026, the NIST AI RMF page states that version 1.0 is being revised, while its Generative AI Profile remains a companion resource for managing generative-AI-specific risks. [nist.gov], [nist.gov]
Your approved applications will change too. So will their capabilities.
A tool approved when it merely summarized text might later gain connections to email, files, databases, or external systems. Same brand name, very different risk.
Review the policy on a defined schedule and whenever there is a substantial change in technology, regulation, organizational risk, or the company’s AI environment.
What Should an AI Acceptable Use Policy Actually Contain?
A practical policy does not have to resemble a telephone directory.
For many businesses, the core structure is surprisingly manageable:
Purpose and scope: Explain why the policy exists, who it applies to, and what qualifies as AI.
Approved tools: Define which services may be used and how employees request additional ones.
Data rules: Explain what information may and may not be entered into AI systems.
Permitted uses: Give employees examples of productive, authorized AI use.
Prohibited uses: Establish clear boundaries around unsafe, unlawful, deceptive, or unauthorized activity.
Human oversight: Require appropriate validation of AI output and human responsibility for consequential work.
Security and privacy: Connect AI use with existing cybersecurity, confidentiality, privacy, and data-classification rules.
High-impact decisions: Define additional approval requirements for consequential AI uses.
Incident reporting: Tell employees exactly where problems should be reported.
Training and enforcement: Establish required awareness or training and explain that AI use remains subject to company policies.
Ownership and review: Name the role responsible for maintaining the policy and establish a review cycle.
You can make those rules stricter where risk demands it and lighter where it does not. In fact, a risk-based approach is one of the most important ideas to borrow from established AI governance frameworks. NIST describes AI RMF profiles as a way for organizations to manage risk according to goals, legal or regulatory requirements, priorities, and context. [airc.nist.gov]
The Policy Should Be Part of the Security Program, Not an Island
Here is perhaps the biggest takeaway.
You probably do not need to reinvent every company policy because AI arrived.
Your existing rules about passwords still matter. Your data classifications still matter. Access control still matters. Privacy requirements still matter. Vendor management still matters. Incident response still matters.
AI introduces new ways for old problems to occur.
That is why an AI AUP works best when it connects to existing security, privacy, HR, acceptable-use, and information-governance practices rather than competing with them. Current Microsoft Cloud Adoption Framework guidance makes a similar recommendation, advising organizations to map responsible-AI requirements to existing corporate policies for security, data governance, and risk management instead of creating parallel governance processes. [learn.microsoft.com]
How an MSP Like Ethixa Solutions Can Help
For many small and midsize organizations, writing the words “employees must use approved AI tools” is easier than answering the obvious next question: Which tools should we approve?
This is where an MSP such as Ethixa Solutions can play a practical role.
An MSP can help a business inventory the technology environment, examine how employees are accessing AI, connect AI policies with existing identity and security controls, review relevant vendor settings, document approved technology, and incorporate AI-related events into established support and security processes.
The goal is not to turn IT into the Department of No.
It is to turn “Can I use AI for this?” into a question that has a useful, repeatable answer.
Give AI Guardrails, Not a Blindfold
AI acceptable use policies are ultimately about something more interesting than restriction.
They are about permission.
Employees should know where they can experiment. Management should know where the company’s boundaries are. IT should know which technologies it is expected to support and secure. Everyone should understand that entering sensitive data into a random AI service is a fundamentally different activity from brainstorming an office-party slogan.
A strong policy communicates one uncomplicated message: Use AI. Use it thoughtfully. Protect company information. Check its work. Keep humans accountable. Ask when you’re unsure.
The goal is not to make your organization afraid of AI.
The goal is to make sure Bob can use it without uploading the customer database.
That seems like a reasonable place to start.


Leave a Reply