An IT leader at a mid-market manufacturer told us he was racing to get his company’s first AI policy to a working version within the week. He had a borrowed template from his managed service provider open in one window and a blank page in the other. Then his infrastructure partner asked a simple question: do you have any data privacy requirements around AI, like no training on your data, no retention, no PII? His answer was honest. Not yet.
That moment plays out in mid-market companies everywhere. Your people adopted AI first, and the rules are trying to catch up. An AI acceptable use policy is how you close that gap, but only if you write one that people can actually follow.
Why most AI policies fail before they launch
Two failure modes kill most first attempts. The first is silence. At a town hall we heard about, an employee asked leadership directly what the company policy on AI was, and the answer was that one did not exist yet. In one of our operations workshops, a leader admitted the same thing plainly: no governance policy, nothing. Employees in that vacuum make up their own rules, and the most common question they carry is whether it is even okay to use AI at all.
The second failure mode is overcorrection. One leader we work with borrowed a policy from a friend at a cybersecurity firm, and it was so restrictive it effectively banned AI outright. A policy that reads like a ban does not stop AI use. It just stops honest AI use, and pushes everything underground where you cannot see it.
A policy that reads like a ban does not stop AI use. It just stops honest AI use.
The numbers say most companies are still stuck between those two failures. Only about 15 percent of organizations have updated their acceptable use policies to cover AI specifically, according to research compiled by JumpCloud, even as unsanctioned AI use shows up in nearly every workforce.
Decide what your policy is for
At a recent executive roundtable we hosted, the sharpest question of the session was deceptively simple: is this policy a structure for the organization to operate with AI, or a defensive legal and HR document? The answer shapes everything. A defensive policy protects the company from its people. An operating policy protects the company through its people, by giving them a safe, clear way to work.
Write the operating version. It should answer, in plain language, the questions your employees are already asking: which tools are approved, what data can go where, and what to do when they want something new.
The six sections your AI acceptable use policy needs
Keep it to one page if you can. Here is the structure we help clients build:
- Approved tools: Name the sanctioned tools and accounts. If AI use must run through IT approval on enterprise licenses rather than personal accounts, say exactly that.
- Data rules: Spell out what can never enter an AI tool, such as customer records, financials, and regulated data, and where protected work can happen safely.
- Verification duty: If you get output from AI, you verify it before it ships. Define what verification means for high-stakes work like quotes, contracts, and customer communication.
- Accountability: Every AI workflow and agent rolls up to a named human owner. When an agent produces a bad quote, the accountability trail should already exist.
- The request path: Give people a fast, judgment-free way to propose new tools. This turns shadow AI into a pipeline instead of a threat.
- Ownership and review: Name who signs the policy, who manages it, and when it gets revisited. A policy nobody owns goes stale in a quarter.
Roll it out like you mean it
Publishing a PDF is not a rollout. Two moves make the difference. First, put adoption metrics on managers, not just individuals. In one client rollout, training participation jumped significantly the moment completion became a management team metric rather than an individual one. Second, pair the policy with real training so people understand the why behind each rule; the gap between publishing rules and building skills is covered well in our piece on the hidden cost of not training your team on AI.
Your policy also does not live alone. It is the front door of a broader governance posture, and our guide on what every executive needs to know about AI governance covers the structures behind it. And once rules exist, adoption becomes the next battle, so keep getting your team to actually use approved AI on your radar.
From policy to activation
The gap between AI aspiration and AI that works is rarely about the technology. It is about whether your people know the safe path and trust it enough to take it. Across our client work we have seen what happens when they do: leaders standardizing on governed platforms so company information stops flowing through personal accounts, teams coordinating so three people are not quietly building the same agent, and manager-led rollouts that measurably lifted training completion.
That is Company Intelligence working alongside Security Intelligence: rules that amplify your people instead of restraining them. Diagnose where AI is already carrying weight in your business, write the one-page policy that makes it safe, and stand behind it in production.
Put AI to work for your people, with rules they can actually follow.
Frequently Asked Questions
What is an AI acceptable use policy?
A short document that tells employees which AI tools are approved, what data can and cannot enter them, how AI output must be verified, and how to request new tools.
How long should an AI acceptable use policy be?
One page is the goal. A forty-page policy nobody reads is worse than a one-page standard everyone follows.
Who should own the AI acceptable use policy?
Assign a named owner, typically IT or security leadership with HR input, plus a review cadence. Every AI workflow in the policy should also roll up to a named human owner.
Should the policy ban public AI tools?
Usually not. Over-restrictive policies push AI use underground. Provide approved alternatives that are genuinely better, then restrict only the highest-risk behavior.
Let's work together.
Partner with Augusto to streamline your digital operations, improve scalability, and enhance user experience. Whether you're facing infrastructure challenges or looking to elevate your digital strategy, our team is ready to help.
Schedule a Consult


