An AI acceptable use policy is a written document that tells employees which AI tools they can use at work, what business data can go into those tools, who owns the outputs, and what is off limits. If you do not have one, you are in the majority. IBM's 2025 Cost of a Data Breach Report found that 63% of breached organizations had no AI governance policy in place. That same report found shadow AI added an average of $670,000 to breach costs.

This post walks through what goes in a policy, what cyber insurers are starting to require, and how to get something on paper before your next renewal.

Why This Is Urgent Right Now

The pattern across businesses in the 25 to 200 employee range is consistent. Either there is no AI policy at all, or there is a paragraph buried in the employee handbook that mentions AI once. Neither holds up when something goes wrong.

IBM studied 600 organizations globally for its 2025 breach report. One in five had experienced a breach tied to shadow AI. The additional cost: $670,000 on top of the base breach. In those incidents, customer PII exposure jumped from 53% to 65% compared to non-shadow-AI breaches. And 97% of organizations that had their AI models or applications compromised reported no AI access controls in place.

The insurance environment caught up quickly. Cyber insurance applications now include explicit questions about AI tool governance. Carriers want to know which tools are sanctioned, what data classifications apply, and whether employees have signed a policy. A blank field or vague answer affects both qualification and premium pricing. Some businesses are seeing 30 to 50 percent premium increases at renewal when those questions go unanswered.

What Goes Into an AI Acceptable Use Policy

A workable policy covers seven areas. None of these require a lawyer. Most businesses in the 25 to 150 employee range can get a usable first version done in an afternoon.

1. Approved tools list

Name the specific AI tools employees may use. Business accounts on Microsoft 365 Copilot, Claude, or ChatGPT are workable for most purposes. Consumer free tiers are not. Personal Gmail accounts feeding ChatGPT, unapproved browser extensions with AI features, and any tool not reviewed by IT are off limits until reviewed. The policy should name what is approved, not just what is prohibited.

2. Data classification rules

Define what business data can go into which tools. A three-tier model works well: public information is fine for any approved tool, internal business information goes into approved business-tier tools only, and sensitive data such as client PII, financial records, or health information does not go into any third-party AI tool. When employees are unsure which tier something belongs to, the policy should tell them who to ask.

3. Prohibited uses

A short list of hard stops. Common ones: no client data in consumer AI tools, no AI-generated client-facing legal or financial documents without human review, no using AI to create content that misrepresents the business or its services.

4. Output review rules

AI-generated outputs are drafts. Anything going to a client, used in a business decision, or published externally needs human review before it goes out. The policy should name who owns that review step for higher-stakes work.

5. Disclosure and labeling

Establish when employees need to flag that something was AI-assisted. The answer varies by industry and context. Set a clear default so people are not guessing.

6. Incident reporting

If an employee realizes they pasted client data into an unapproved tool, what do they do? The policy needs a name or a process for reporting it without consequences for honest disclosure. Early reporting is the difference between a minor incident and a $670,000 one.

7. Review cadence

The AI landscape changes fast. Build in a review date at least once a year and assign someone to own it. A policy written in Q1 2026 may need an update by Q3.

What Cyber Insurers Are Now Looking For

Starting in 2026, carriers have introduced what the market is calling AI security riders. These are policy addendums that condition full coverage on documented AI governance controls.

The five things most carriers now want to see: a written AI acceptable use policy, an inventory of AI tools and the data they can access, employee training records on acceptable AI use, a process for detecting or reporting shadow AI, and enforcement evidence. Not just a policy document, but proof that employees have acknowledged it.

The last point matters. A policy sitting in a shared drive that nobody has read is not an AI governance program. Carriers are moving toward verifying enforcement, not just existence.

Related posts: Shadow AI Risks: What Your Business Needs to Know and AI Agent Sprawl: What Growing Businesses Need to Know.

The Gap Between Writing and Enforcing

Writing the policy is step one. Enforcing it is where most businesses stall.

The practical markers of an enforced policy: employees can name the approved tools from memory, there is a process for requesting approval of a new AI tool before downloading it, someone reviews the AI tool inventory on a quarterly basis, and new hires go through the policy during onboarding.

The technology side matters too. Shadow AI is difficult to police if your IT infrastructure has no visibility into which applications are being accessed from company devices. Network monitoring and endpoint management are the enforcement layer that sits behind the policy. Without them, the policy is a document. With them, it is a control.

How to Get Started

If you have no policy today, this is the minimum viable version:

  1. List every AI tool employees are currently using. Ask department heads directly, because IT may not know about tools adopted through individual credit cards or browser extensions.
  2. Decide which tools on that list are approved and which are not.
  3. Write the three data classification tiers and map them to the approved tools.
  4. Add the short sections above: prohibited uses, output review rules, disclosure standards, incident reporting process, and a review date.
  5. Have every employee sign or acknowledge it in writing.

A 30-person business can complete this in an afternoon. A 100-person firm needs a day or two, plus IT involvement to build the tool inventory accurately.

The AI governance question is not going to get easier to answer at your next insurance renewal or compliance audit. Getting something on paper now puts you ahead of 63% of businesses that have been through a breach.

Putting together an AI use policy for your business and not sure where to start? Get in touch and we can help you build the tool inventory, draft the policy, and put the enforcement pieces in place.

Frequently Asked Questions

What is an AI acceptable use policy?

An AI acceptable use policy is a written document that governs how employees may use AI tools at work. It defines which tools are approved, what business data can go into them, what outputs require human review, and what the consequences are for unsanctioned use. It is distinct from a general acceptable use policy in that it addresses the specific data risks that come with feeding business information into third-party AI systems.

Does my business legally need an AI acceptable use policy?

There is no single U.S. law that requires one right now, but cyber insurance carriers increasingly require it or price coverage differently without it. If your business handles regulated data such as healthcare records or financial information, the absence of an AI governance policy creates risk under existing frameworks like HIPAA and the FTC Safeguards Rule. The EU AI Act introduced disclosure requirements in 2025 for businesses operating in that market.

How long should an AI acceptable use policy be?

One to two pages is enough for most businesses in the 25 to 150 employee range. The policy needs to be specific enough to tell employees what is and is not allowed, but simple enough that people will actually read it. A 20-page document with no employee training is less effective than a one-page policy with a signature line.

What is shadow AI and why does it matter?

Shadow AI refers to AI tools employees use without business or IT approval, often through personal accounts or free tiers that have no enterprise data protections. IBM's 2025 breach data found that 20% of studied organizations had experienced breaches linked to shadow AI, adding an average of $670,000 to breach costs. A policy that names approved tools and requires employees to request approval for new ones is the first line of defense.

Who should write the AI acceptable use policy?

IT and a business leader work on it together. IT evaluates the security and data implications of different tools; the business leader represents how departments actually use them. Many businesses in the 50 to 200 employee range work with their managed IT provider to build the initial tool inventory and draft the policy, then bring department heads in for input before final sign-off.