Generative AI Acceptable Use Policy: A Practical Guide for Employers

Quick answer: A generative AI acceptable use policy tells employees which GenAI tools they can use, what data they can put into them, which tasks are allowed without sign-off, and when AI involvement must be disclosed. The most effective format is a traffic-light model — green (go ahead), yellow (allowed with review), red (never) — backed by clear data rules and a named approval path. It complements your general AI usage policy by answering the day-to-day questions: "Can I paste this into ChatGPT?"

Your general AI policy sets principles. Your acceptable use policy answers the question your designer is asking right now with a client brief open in one tab and Claude in the other. This guide covers how to write one that people read, remember, and follow.

Why a Separate Acceptable Use Policy?

Three documents tend to work better than one mega-policy at SMB scale:

  1. AI usage policy — principles, scope, accountability, enforcement (what to include)
  2. Generative AI acceptable use policy — the day-to-day "can I do this?" answers (this article)
  3. AI data handling rules — what data classes can go where

The acceptable use policy is the one employees consult weekly. Optimize it ruthlessly for skimmability: one page of rules, one page of examples.

The Traffic-Light Model

Green — allowed without approval

  • Brainstorming, outlining, first drafts of internal documents
  • Summarizing public or internal non-confidential material
  • Code assistance on non-sensitive repositories (with review before merge)
  • Rewriting your own text for tone, clarity, or length
  • Research with verification of any factual claims

Yellow — allowed with review or conditions

  • Client-facing deliverables → human review by the owner, AI assistance disclosed if the client contract requires it
  • Code touching production or handling personal data → senior review
  • Published marketing content → editorial review; AI-generated images/video labeled per Article 50 of the EU AI Act from 2 August 2026
  • Translations of contractual or legal text → bilingual human check

Red — never

  • Entering customer personal data, health data, credentials, or unreleased financials into any tool not explicitly approved for that data class
  • Using GenAI to make or substantially drive employment decisions (hiring, evaluation, termination) — this crosses into high-risk territory under the EU AI Act
  • Generating content that impersonates real people without consent
  • Personal free-tier accounts for any work content

Data Rules: The Section That Prevents Disasters

Data class Examples Allowed in GenAI?
Public Published content, marketing site copy Any approved tool
Internal Process docs, internal drafts Approved business-tier tools only
Confidential Client deliverables, financials, source code Only tools with DPA + training opt-out, listed by name
Personal data Customer/employee PII Prohibited unless tool is explicitly approved for it

Don't draft this from zero: the AI Usage Policy Pack ($29) includes a ready-made generative AI acceptable use policy with the traffic-light structure built in, alongside a general AI policy, data handling rules, and a rollout guide.

Disclosure: When to Say "AI Helped With This"

  • Internally: disclosure not required for green-tier work; encouraged for substantial drafting so reviewers calibrate their scrutiny.
  • Client work: follow the contract. AI-assistance clauses are increasingly common — check before assuming.
  • Published content: from 2 August 2026, EU AI Act Article 50 requires marking AI-generated audio, images, video, and certain text.

Rolling It Out So People Actually Comply

  1. Announce with leadership backing and a one-line rationale (enable, not ban)
  2. Train — 30 minutes, real examples from your own workflows, including one "here's how this goes wrong" story
  3. Attest — signed acknowledgment from every employee and contractor
  4. Channel — a place to ask "is this okay?" and get an answer within a day

That training-plus-attestation step doubles as your evidence for the EU AI Act's Article 4 AI literacy obligation, in force since February 2025. For full sequencing, see the 30-day AI policy rollout plan. If ChatGPT is your dominant tool, the companion ChatGPT policy guide covers tool-specific settings.

FAQ

What's the difference between an AI usage policy and an acceptable use policy?

The usage policy sets principles, scope, and accountability across all AI. The acceptable use policy is the operational layer for generative AI specifically — which tasks are green, yellow, or red, and what data can go into which tool.

Should we ban free AI accounts?

For work content, yes. Free tiers often lack admin controls, audit logs, and contractual data protections. Provide business-tier accounts for approved tools so the sanctioned path is also the convenient one.

How do we enforce an acceptable use policy?

Tie violations to your existing disciplinary process, but lead with enablement: approved tools that are genuinely good, fast answers to "is this okay?", and a no-blame incident reporting window.


Ship your acceptable use policy this week. The AI Usage Policy Pack ($29) contains all three policies SMBs need plus the rollout guide — or get policies, governance tools, and EU AI Act checklists together in the Complete AI Compliance Stack ($199).

This article is for general information only and is not legal advice. Consult qualified counsel for your specific situation.