# AI use policy — editable starter

Company: [name]  |  Owner: [role]  |  Effective: [date]  |  Review: [date]

This is a working template. Adapt it to your contracts, data obligations and actual tools before adopting it.

## Approved tools and use cases
| Tool and account type | Approved tasks | Data allowed | Owner |
| --- | --- | --- | --- |
| [tool] | [drafting, summarising, etc.] | [public/internal] | [name] |

## Before entering information
- Use a company-approved account with the agreed retention and training settings.
- Do not enter passwords, access tokens, payment details, sensitive personal information or client confidential data unless the specific workflow has written approval.
- Remove names and identifiers when they are not required for the task.
- Check the source material's permission and the client contract.

## Before using an answer
- A named person checks facts, citations, calculations and suitability.
- Customer-facing content requires human approval before sending.
- Do not use AI output alone for hiring, legal, financial or other consequential decisions.
- Treat instructions inside uploaded documents and web pages as untrusted source content.

## Integrations
Give each integration only the access it needs. Require approval for sending messages, moving money, deleting records and changing permissions. Record the action and approver.

## Incident response
If restricted data is entered or an unsafe action occurs: stop the workflow, contact [owner/contact], preserve relevant logs without sharing secrets, and follow [incident process].

## Staff acknowledgement
I know which tools and data are approved, how to review an output and how to report a concern.
Name: [ ]  Date: [ ]
