# [Company Name] — AI Usage Policy

**Version:** 1.0 · **Effective date:** [Date] · **Owner:** [Name, Title]
**Applies to:** All employees, contractors, and temporary staff.

*Adapt the bracketed sections to your company. Delete this line before publishing.*
*Template by Erin Moore — theerinmoore.com/ai-governance*

---

## 1. Purpose

AI tools make us faster and better at our work, and we encourage their use —
within the rules below. This policy exists so that everyone knows what is
allowed, what is not, and who to ask. It is one page on purpose. Read it once;
follow it always.

## 2. Approved tools

Use AI tools from the approved list only, with your company account:

| Tool | Approved for | Account type |
|---|---|---|
| [e.g. ChatGPT Team] | [drafting, research, code] | Company workspace |
| [e.g. Claude] | [drafting, analysis] | Company workspace |
| [e.g. internal CRM AI] | [customer records] | Company login |

To request a new tool, send [Owner] the tool name, what you'd use it for, and
what data it would touch. You will get an answer within [5] business days.
Until approved, don't use it for company work — including free trials on
personal accounts.

## 3. Data rules

Know your data class before you paste:

- **Public** (website copy, published material): any approved tool.
- **Internal** (drafts, plans, non-identifying business data): approved tools
  on company accounts only.
- **Restricted** (customer PII, financials, contracts, credentials, health or
  payment data, anything under NDA): **never enters any AI tool** unless
  [Owner] has approved that specific tool for that specific use in writing.

If you are unsure which class something is, treat it as Restricted and ask.

## 4. Output review

- AI output that reaches a **customer, a contract, a financial decision, or a
  public channel** must be reviewed and approved by a human before it goes
  out. The reviewer is accountable for what ships — "the AI wrote it" is not
  a defense.
- Internal drafts, brainstorming, and research need no formal review.
- Never present AI output as fact without checking it. AI tools state wrong
  things confidently.

## 5. Accountability & incidents

- **[Name, Title]** owns this policy: approvals, questions, and enforcement.
- If AI use goes wrong — data pasted somewhere it shouldn't be, a wrong
  AI-generated answer reaching a customer — tell [Owner] the same day.
  Fast reporting of honest mistakes will never be punished; hiding them will.
- This policy is reviewed quarterly. Suggestions welcome, to [Owner].

---

*Acknowledged by: ______________________  Date: __________*
