How-To
How to Write an AI Acceptable Use Policy: 5 Essentials
Your staff are already using AI. A clear acceptable use policy covers approved tools, data that stays out, human review, disclosure and training — with a one-minute video walkthrough.

How-To · Episode H04
Presented by an AI presenter. Written and reviewed by Cendien.
5 steps in this how-to
- List the approved tools — Name which AI tools staff may use for work, and which they may not.
- Define what data stays out — Make clear that confidential, personal and regulated information never goes into unapproved tools.
- Keep a human in the loop — People must check AI output before it is shared or acted on.
- Set disclosure rules — Decide when staff must say that content was created with AI help.
- Train and revisit — Walk your team through the policy, and review it regularly as tools and rules change.
Read the transcript
Here's a quick how-to from Cendien: writing an AI acceptable use policy. Step one: list the approved tools. Name which AI tools staff may use for work, and which they may not. Step two: define what data stays out. Make clear that confidential, personal and regulated information never goes into unapproved tools. Step three: keep a human in the loop. People must check AI output before it is shared or acted on. Step four: set disclosure rules. Decide when staff must say that content was created with AI help. Step five: train and revisit. Walk your team through the policy, and review it regularly as tools and rules change. If you'd like help putting an AI policy in place, talk to us at cendien.com.
Whether or not you have approved it, some of your staff are probably already using AI tools to draft emails, summarize documents or answer questions. An acceptable use policy does not have to slow that down. It makes expectations clear, protects sensitive information, and gives people the confidence to use AI well.
Watch the one-minute video above, then use the five essentials below as the outline for your policy.
Step 1: List the approved tools
- Name the AI tools staff may use for work — for example, an enterprise assistant licensed through your organization — and the tools they may not.
- Explain why. Approved tools typically come with contractual and technical protections for your data; consumer tools often do not.
- Provide a request process so staff can ask for a new tool to be reviewed instead of using it quietly.
Step 2: Define what data stays out
- Spell out the categories that must never go into unapproved tools: confidential business information, personal information about staff or the public, and regulated data such as health, financial or criminal justice records.
- Give concrete examples relevant to your organization, such as personnel files, case records, unpublished budgets or procurement documents.
- Point to your existing data classification where you have one, so the AI policy reinforces rules people already know.
Step 3: Keep a human in the loop
- Make the user responsible for any AI output they share, send or act on.
- Require checking for accuracy, completeness and appropriateness before output is used, especially for anything external, legal, financial or affecting individuals.
- Prohibit fully automated decisions about people — eligibility, hiring, discipline — unless a specific, reviewed process allows it.
Step 4: Set disclosure rules
- Decide when staff must disclose AI assistance — for example, in public communications, reports to elected officials or boards, or formal correspondence.
- Keep it simple and consistent, with a standard line people can use.
- Address records requirements, including how AI-assisted drafts and prompts are retained where public-records or retention rules apply.
Step 5: Train and revisit
- Walk your team through the policy with practical examples of what is and is not allowed.
- Name an owner for questions and exceptions.
- Review the policy regularly — at least annually, and whenever you adopt a new tool or rules change.
Frequently asked questions
Should we just ban AI tools until we have a policy?
Bans tend to push usage out of sight. A short interim policy — approved tools, data that stays out, and human review — is usually safer than a ban while you build the full version.
How long should the policy be?
Short enough that people actually read it. Two to three pages of clear rules and examples, supported by a one-page quick reference, works well for most teams.
Does the policy need legal review?
Yes. Have your legal counsel and records or privacy officer review it, especially for public agencies with records-retention and transparency obligations.
Need help putting an AI policy in place?
Cendien helps organizations adopt AI responsibly — from acceptable use policies and data guardrails to approved tools, training and practical pilots. Talk to our AI team or explore our AI solutions.
Related services
- ERP Services — Implementation, upgrades and managed ERP support.
- Managed IT Services — Help desk, monitoring and co-managed IT.
- AI & Automation — AI strategy, automation and analytics.
Related insights
- The Future of Healthcare IT: Trends to Watch in 2026 — Explore emerging technologies transforming healthcare delivery, from AI-powered diagnostics to interoperable EHR systems.
- HIPAA Compliance in 2026: What Healthcare Organizations Must Know — A comprehensive breakdown of updated HIPAA requirements, enforcement trends, and practical compliance strategies for healthcare IT