1. Home
  2. Free tools
  3. AI Policy Generator
Free tool

AI Policy Generator

Answer a few questions and get a one-page policy your team can actually follow. Edit it, copy it, or download it as Markdown.

About your organization

Approved tools

Data rules

Rules of use

Your policy draft

# [Organization] AI Use Policy

**Effective:** 2026-09-11  ·  **Owner:** [Policy owner]  ·  **Questions and incidents:** [contact]  ·  **Review:** every 6 months

## 1. Purpose

[Organization] encourages the use of AI tools to do better work faster. This policy explains which tools are approved, what information may be used with them, and how we stay accountable for the results. It applies to all employees, contractors, and anyone using [Organization] systems or data.

## 2. Approved tools

Use only the tools and accounts below for work. Personal accounts on consumer AI products are not approved for [Organization] information.

- ChatGPT (Team or Enterprise plan)

To request a new tool, contact [contact] with the use case and the vendor's data-handling terms. Tools are reviewed for data retention, training opt-outs, access controls, and export.

## 3. Data rules: Red, Yellow, Green

Apply this check before every paste, upload, or connection.

**Red: never enter into any AI tool, approved or not.**
- Customer or employee personal data (names with contact details, SSNs, dates of birth, health or financial information)
- Passwords, API keys, access tokens, and credentials
- Unreleased financial results, M&A, or material non-public information
- Source code or documents marked confidential or restricted
- Anything covered by a customer NDA or regulatory restriction

**Yellow: approved tools only, and remove or anonymize identifying details where you can.**
- Internal documents, plans, and reports that are not marked confidential
- Customer communications with identifying details removed
- Draft contracts and proposals with names and pricing removed
- Aggregated or anonymized data

**Green: fine in any approved tool.**
- Public information (our website, press releases, published research)
- General questions, explanations, and learning
- Your own drafts that contain no confidential or personal data
- Brainstorming and planning that references no protected information

If you are unsure which category applies, treat the information as Red and ask.

## 4. You own the output

AI tools draft; people decide. Whoever sends, submits, publishes, or acts on AI-assisted work is responsible for it exactly as if they had produced it alone. Before use:

- Verify every fact, number, name, date, quotation, and citation against a reliable source.
- Check that the tone and content are appropriate for the audience.
- Confirm the work does not reproduce third-party copyrighted material or confidential information.
- Do not rely on AI for final decisions about people (hiring, performance, discipline), legal positions, medical matters, or safety-critical matters without qualified human review.

## 5. Disclosure

Disclose AI use when an AI tool materially shaped content that goes to customers, the public, regulators, or courts. Internal drafting help does not require disclosure. When in doubt, disclose.

## 6. Intellectual property and confidentiality

- Do not upload [Organization] source code, designs, or documents marked confidential to any tool that is not approved for that data.
- Treat AI outputs as drafts owned by [Organization] once reviewed and adopted; check vendor terms for output ownership before relying on generated images, audio, or code in products.
- Respect third-party rights: do not prompt tools to imitate a named person's voice, likeness, or copyrighted work.

## 7. Security

- Enable multi-factor authentication on all AI tool accounts.
- Do not paste credentials, keys, or tokens into any AI tool.
- Be alert to prompt injection: AI tools that read emails, documents, or web pages can be manipulated by hidden instructions. Do not let an AI agent take irreversible actions (send, pay, delete, share) without a human check.
- Treat unexpected voice or video requests for money, credentials, or data as potential deepfakes; verify through a known channel.

## 8. Training

Complete the [Organization] AI basics session before using AI tools for work, and a refresher when this policy changes. Managers are responsible for making sure their teams have completed it.

## 9. Reporting mistakes and incidents

If you paste something you should not have, notice an inaccurate AI-assisted deliverable that has gone out, or see a tool behave unexpectedly, report it to [contact] the same day. Early reports are welcomed and will not be penalized; the goal is to fix problems fast and improve the rules.

## 10. Review

This policy is reviewed every 6 months, when a tool is added or removed, or after any incident. Suggestions go to [policy owner].

---
Generated with the GetMoreFromAI AI Policy Generator (getmorefromai.com/tools/ai-policy-generator). This is a starting draft, not legal advice.

A starting draft, not legal advice. Have legal, HR, and IT review before adoption.

What a good AI policy does

  • Names the approved tools and accounts, so nobody has to guess.
  • Gives a data rule people can apply before every paste.
  • Makes the human accountable for whatever they send, regardless of who or what drafted it.
  • Says when to disclose AI use, and when it is not necessary.
  • Tells people how to report a mistake without fear, so you learn about incidents early.

For the reasoning behind each section, read how to write a team AI policy and AI privacy at work.

Frequently asked questions

Is the generated policy legal advice?
No. It is a practical starting draft built from common-sense controls. Have legal, HR, IT or security, and leadership review it before adoption, especially in regulated industries.
Why does the policy use red, yellow, and green data categories?
Because people need a rule they can apply in two seconds before they paste. Red never goes into an AI tool; yellow needs an approved tool or anonymizing; green is fine. It is easier to follow than a long list of data types.
Should we ban AI tools instead?
Bans push usage underground onto personal accounts, which is the worst outcome for data. A short policy with approved tools and clear rules gets you the benefits with the risks managed.
How often should we update it?
Every six months, or whenever you add a tool, change plans, or have an incident. The generated policy includes a review cadence line for that reason.