Summary: Your staff are already using AI tools, with or without a policy. Pretending otherwise is the only genuinely risky option. A workable acceptable-use policy is short, names specific tools, is explicit about data, and gets reviewed on a schedule — because this landscape changes faster than your employee handbook does.
This is operational guidance, not legal advice. Have counsel review anything you adopt, particularly if you are in a regulated sector.
Start from what is already happening
Before drafting, find out what is in use. Ask without blame — people who fear punishment simply stop telling you, and shadow usage is far more dangerous than sanctioned usage. You will usually find a handful of tools in play and at least one person pasting genuinely sensitive material into a consumer chatbot.
What the policy needs to cover
- Approved tools, by name. "Use AI responsibly" is not a policy. "Microsoft Copilot and [named tool] are approved; anything else needs a conversation first" is one.
- Data that never goes in — specifically. Client confidential information, personal and health data, credentials, source code, unreleased financials. List your categories, not generic principles.
- The consumer-versus-business distinction. Most staff do not know that a free personal account and a licensed business tenant have completely different data-handling terms. Explain it once, clearly.
- Human review requirements. Where AI output can go directly to a client, and where a person must check it first. Anything that carries legal, financial or clinical weight belongs in the second category.
- Disclosure expectations. Whether AI-assisted work needs flagging to clients — for law firms and regulated sectors this may not be optional.
- Who to ask. A named person, not "IT". Ambiguity here is what produces shadow usage.
What to leave out
Resist writing a policy that bans everything, because it will be ignored within a fortnight and you will have taught your staff that the policy is theatre. Also resist enumerating every model and version — you will be out of date before the ink dries. Write principles plus a short approved-tools list you can update without reissuing the document.
Make it enforceable
Policy alone changes little. Pair it with the technical controls that make the right path the easy one: licensed business-tier tools so people are not driven to consumer accounts, sensitivity labels and DLP so the worst material is blocked rather than merely discouraged, and a review cadence — quarterly is realistic — that keeps the approved list current.
A sensible cadence
Draft in an afternoon. Circulate for a fortnight and take feedback seriously, because objections tell you where the policy collides with real work. Adopt, train briefly, and diarise the first review for ninety days out.
ECS helps Houston organisations put the governance and technical controls in place together — policy without enforcement is just a document. See AI & Copilot consulting or book a readiness conversation.