Generate a foundational AI usage policy tailored to your company size, industry, and risk tolerance. Covers acceptable use, data handling, liability, and employee guidelines.
You are a business operations and compliance advisor. Draft a comprehensive internal AI usage policy for {{company_name}}, a {{company_size}} company in {{industry}}.
The policy should be clear, enforceable, and appropriate for our risk tolerance ({{risk_tolerance}}).
Include these sections:
1. **Purpose & Scope** – Who this applies to and why it exists.
2. **Approved AI Tools** – List {{approved_tools}} as permitted for business use.
3. **Prohibited Uses** – Specific restrictions (e.g., no customer PII in prompts, no confidential strategy).
4. **Data Security & Privacy** – Requirements for data handling, retention, and third-party tool vetting.
5. **Employee Responsibilities** – Training, reporting, and accountability.
6. **Liability & Indemnification** – Company's position on AI-generated output accuracy and IP ownership.
7. **Review & Updates** – Policy review schedule (suggest quarterly or biannual).
8. **Enforcement** – Consequences for violations.
Tone: Professional, clear, non-legal-jargon where possible. Assume employees have basic AI familiarity but may not understand governance.
Format: Use headings, bullet points, and short paragraphs for scannability. Include a one-page summary at the top.1. Fill in your company details (name, size, industry, risk tolerance). 2. List any AI tools you've already approved or plan to approve; the prompt will adapt recommendations. 3. Run the prompt and review the draft policy. 4. Customize sections to match your actual tech stack, data sensitivity, and compliance requirements (HIPAA, GDPR, SOC 2, etc.). 5. Share with your legal advisor or compliance officer for final review. 6. Publish internally and schedule a policy review meeting with leadership and key teams. 7. Set a calendar reminder to revisit the policy quarterly or when new AI tools are adopted.
Company Name: CloudVault Company Size: 20–50 people Industry: SaaS (data storage) Risk Tolerance: Conservative Approved Tools: ChatGPT (business), Claude, internal documentation AI
**CloudVault Internal AI Usage Policy** **Executive Summary** This policy governs the use of artificial intelligence tools by CloudVault employees. It balances innovation with data security and compliance. All employees must comply by [date]. **1. Purpose & Scope** CloudVault processes sensitive customer data. This policy ensures AI use does not expose customer information, violate contracts, or create legal liability. It applies to all employees, contractors, and board members. **2. Approved AI Tools** - ChatGPT (business tier, SSO-managed) - Claude (via web or API, no data retention) - Internal documentation AI (self-hosted, no external data transfer) **3. Prohibited Uses** - Do not input customer data, API keys, or credentials into public AI tools. - Do not use AI to generate customer-facing content without human review. - Do not rely on AI output for security or compliance decisions without verification. - Do not share company strategy, pricing, or roadmap with external AI services. **4. Data Security & Privacy** - Vet all new AI tools with the ops team before use. - Ensure tools have data processing agreements (DPA) aligned with GDPR and SOC 2. - Disable data retention and training on all external tools. - Log AI tool usage for audit purposes. **5. Employee Responsibilities** - Complete AI governance training (annual). - Report misuse or data breaches immediately to ops@cloudvault.com. - Use approved tools only; request new tools via the AI tool request form. **6. Liability & Indemnification** CloudVault does not warrant the accuracy of AI-generated output. Employees are responsible for human review before publishing or acting on AI recommendations. IP ownership of AI-generated work belongs to CloudVault. **7. Review & Updates** This policy will be reviewed quarterly and updated as new tools and risks emerge. **8. Enforcement** Violations may result in tool access revocation, retraining, or disciplinary action per company policy.