What is an AI acceptable use policy?
By Identra · Updated
An AI acceptable use policy defines how employees, contractors and AI agents may use AI for work, including permitted tools, accounts, data and actions. It assigns responsibility for approvals, output review, exceptions and incident reporting so people can apply the rules to everyday tasks.
What should an AI acceptable use policy cover?
One question, really. Can this person or this agent use this tool, signed in with this account, on this data, for this task? If an employee can't answer that from the policy without emailing security, it's too abstract.
The policy sits under AI governance. Governance decides who owns AI risk and who approves what. The acceptable use policy turns those decisions into rules a recruiter or a support lead can follow while they work. It needs a named owner and a clear route for approvals.
- Who and what it covers: employees, contractors, managed and personal devices, and work done through personal AI accounts.
- Approved tools and accounts, by name. ChatGPT Enterprise and someone's personal ChatGPT login live at the same URL and have very different terms.
- Data rules for prompts, uploads, meeting recordings and connected sources like Google Drive or SharePoint. Name credentials and customer data explicitly.
- Agent rules covering the owner of each agent, what it can touch and which actions need sign-off.
- What has to be checked before AI-written text is published, AI-written code is merged or a decision rests on AI output.
- How to ask for an exception, and how to report a mistake.
How do tool, account and data rules fit together?
Approve a combination of tool, account, purpose and data class. A company workspace in Microsoft 365 Copilot or Gemini in Google Workspace runs under your tenant's admin settings and contract. A personal account on the same service doesn't. Check the actual plan and configuration before you approve sensitive work on it.
A policy can require account-aware AI access, so anyone using ChatGPT for work is signed into the company workspace. The right account still doesn't make every input acceptable. Say when data has to be trimmed or de-identified first, and which tasks stay out of AI entirely.
Tool approval
- Question it answers
- Which service may I use?
- Example rule
- Use the reviewed AI writing service for drafting
Account requirement
- Question it answers
- Where may I sign in?
- Example rule
- Use the company workspace for internal work
Data restriction
- Question it answers
- What may I share?
- Example rule
- Never paste credentials or raw customer exports
Action limit
- Question it answers
- What may the AI do?
- Example rule
- A person approves before any customer email is sent
How does the policy play out on a real task?
Say a support manager wants a summary of recurring complaints. The source is a Zendesk export with customer names, email addresses and full ticket threads. The policy allows summarizing in the company workspace. It bans raw customer exports and personal accounts.
So she pulls excerpts through the approved process and removes what's restricted. Deleting the name column isn't enough. A ticket that mentions an order number and a small town can still point to one person. If the analysis really needs the raw records, she asks for a review first.
Now suppose she had already uploaded the raw export to her personal account. The policy tells her to report it with the tool, the account and the data involved. Deleting the chat may not remove every copy the provider keeps, so the response team works out what's exposed and what can be contained.
What changes with agents and extensions?
Agents act. Claude Code runs shell commands. An agent built in Copilot Studio can send email through a connector. So the policy has to limit actions as well as inputs. Name an owner, scope permissions to the task and list the actions that need approval, such as deleting records or changing access.
Put those limits into AI agent guardrails that the surrounding systems enforce. A prompt that says ask before acting proves nothing about what the agent can do without asking.
Browser extensions and OAuth-connected apps can read data without anyone pasting it anywhere. Review what they reach and who is allowed to approve a connection. OAuth app risk belongs in the policy, along with a way to revoke grants once the purpose ends.
How do you enforce an AI acceptable use policy?
Every rule needs an owner, a control and proof the control works. Training tells people what's expected. Controls in the browser, on endpoints and in the identity provider make some rules stick. Test a setting before assuming it applies everywhere.
- Inventory AI use across browsers, endpoints and connected SaaS and cloud apps. Shadow AI findings show which tools people need that nobody has approved yet.
- Publish the approved list where people actually look, with account and data conditions next to each tool.
- Try real cases. A personal login, a sensitive upload, an agent action that needs sign-off. Confirm the control blocks what it should and the legitimate task still gets done.
- Give people a way to report mistakes that doesn't feel like a confession.
How do you keep the policy current?
Exceptions need a business reason, an approver, a scope and an end date. Without those, one team's exception for a single project quietly turns into approval for the whole tool.
Revisit approvals when a tool adds connectors, an agent gets new permissions or a team starts handling different data. Keep an AI audit trail of approvals and outcomes. You don't need to store everyone's prompts to show the policy exists.
How Identra thinks about it
Identra shows security teams AI use across the browser, the endpoint and connected identity, SaaS and cloud providers. For ChatGPT, Gemini, Claude, Perplexity and Grok it can allow, redirect to the company AI workspace or block based on the signed-in account. Prompt and upload policies apply to what people send, tool-call policy applies to AI agents on endpoints, and analysts can revoke risky OAuth grants with the result recorded.
Go deeper: AI security, built on identity
Frequently asked questions
Who should own an AI acceptable use policy?
One accountable owner, with security, IT, privacy, legal and HR contributing. Business teams should help define the tasks people actually need AI for.
Can an existing acceptable use policy cover AI?
Yes, if it explicitly covers AI tools, accounts, data sharing, output review and agent actions. A separate AI policy helps when those rules would get lost inside a long general document.
Should personal AI accounts be prohibited for work?
Decide per use and data class, and write the decision down. Where work needs company controls, require the company workspace and make sure people actually have access to it.
Does the policy cover AI meeting assistants?
It should. Cover recording, transcription, how participants are told, who can read transcripts and which meetings are off limits.
Does acknowledging the policy prove compliance?
No. A signed acknowledgment shows someone saw the policy. Control tests, activity reviews, incident reports and exception records show whether it's followed.
Related terms
Compare
All comparisons →- AI Governance vs AI Security: Turn Policy Into ProtectionAI governance decides which AI uses are acceptable and who is accountable.
- ChatGPT Enterprise vs personal ChatGPT accounts: The account decidesChatGPT Enterprise gives organizations a managed workspace for work use.
- AI DLP vs Traditional DLP: Protect the Data Before SendTraditional DLP protects sensitive data across email, network traffic and endpoint activity.
