Generate Your Company's AI Acceptable Use Policy
Answer seven questions and get an acceptable use policy written for your organization: which tools are approved and for what, the data rules, when a human has to review, how someone asks for an exception, and a one-page card your team can actually keep. Takes about three minutes.
About 3 minutes. No signup, just your work email at the end.
Where should we send it?
Your AI Acceptable Use Policy is ready to generate. We show it on screen and email you a PDF copy to share with your team.
By submitting this form you will be subscribed to the AI Operator Weekly newsletter — practical AI plays for operators, every other week. You can unsubscribe from any email, any time.
Building your AI Acceptable Use Policy
From your answers to your policy in three steps
Answer seven questions
Your size, your industry, which AI tools people may use, how sensitive your data is, and how strict you want to be.
We write the policy
Ten sections, written to your employees in plain words, with your approved tools named and your data rules spelled out.
Hand it to your team
On screen and as a PDF, with a one-page quick reference card people can keep beside them.
Frequently asked questions
What should an AI policy include?
At minimum: who it applies to, which tools are approved and for what, what may never be pasted into an AI tool, when a person has to check the output before it goes anywhere, how someone asks for an exception, and when the whole thing gets reviewed. A policy that stops at principles gives nobody an answer on a Tuesday afternoon.
Is a generative AI policy different from an AI policy?
In practice most companies mean the same document. A generative AI policy governs the tools people type into: chat assistants, writing tools, image and code generators. A broader AI policy also covers systems that score, rank or decide, which usually need heavier review. This generator writes the first and flags the second where your answers suggest you have it.
Do small companies need an AI policy?
Yes, and a shorter one. Under fifty people the risk is not a rogue department, it is one person pasting a client contract into a free tool because nobody ever said not to. Two pages that name the approved tools and the data rules solve most of that. The size of the company changes the length of the policy, not whether it exists.
How often should we update our AI policy?
The list of approved tools moves fastest, so it is worth checking monthly. The policy itself holds up for a quarter. Anything that changes what you are exposed to, a new client contract clause, a new regulation, an incident, resets the clock and should trigger a review straight away.
Does this replace legal advice?
No. It gives you a working draft and names the regimes you told us apply to you, so the conversation with your counsel starts from a document rather than a blank page. It never states what a specific law requires.