AI Acceptable Use Policy Template (2026): Free Template & GDPR/EU AI Act Guide

Written and reviewed by Irfan Ullah, Founder of TrusteraAI and creator of the TrusteraAI AI Risk Assessment Framework™. Last updated: August 2026 · Regulatory review: August 2026.

Employees are already using AI at work. The question is whether that use is governed and visible to the organization — or happening invisibly outside its controls. A policy that exists only as a document nobody enforces is barely better than no policy at all — and a policy that ignores the GDPR and EU AI Act obligations already attached to how your team uses AI is a compliance gap waiting to surface during an audit or an incident.

Quick Answer: An AI Acceptable Use Policy (AUP) is a written policy defining which AI tools employees may use, what data may be shared with them, what uses are prohibited, and how violations are detected, reported, and enforced. For organizations and AI systems within the relevant scope of the EU AI Act, a complete AI AUP should account for Article 4 AI-literacy measures and, where applicable, Article 50 transparency obligations — both applicable from August 2026 in their respective contexts.

Gartner’s survey of 302 cybersecurity leaders found that 69% of organizations suspect or have direct evidence of employees using unsanctioned generative AI tools. Separately, IBM’s 2025 Cost of a Data Breach Report found that breaches involving a high level of shadow AI cost organizations $670,000 more on average than standard breaches. A written, enforced acceptable use policy is a practical control for reducing both risks.


🎯 Start Here


What Is an AI Acceptable Use Policy?

Quick Answer: An AI Acceptable Use Policy (AUP) is a written policy governing how employees, contractors, and increasingly AI agents use AI tools — covering which tools are sanctioned, what data may be shared, what uses are prohibited, what oversight applies, and how violations are handled.

A complete AI AUP answers six questions: which tools are sanctioned, what data may be shared with them, what uses are prohibited even with sanctioned tools, when human review is required before acting on AI output, what happens when someone violates the policy, and — the piece most first-draft policies skip — how the policy is actually enforced. A written policy nobody can technically verify functions as a policy in name only.

An AI acceptable use policy template gives organizations a practical starting point for defining sanctioned tools, permitted data, prohibited uses, and employee responsibilities.

Why Companies Are Adopting an AI AUP in 2026

The AI acceptable use policy template below is designed for organizations that need practical controls for AI usage, data protection, human oversight, and compliance.

Three shifts have made an AI AUP increasingly difficult to treat as a nice-to-have:

Shadow AI is already the default state. Employees have already decided which AI tools they use — the policy is your chance to bring that usage into the open before it causes a data incident, not to prevent it from starting.

AI governance controls are increasingly part of security and compliance assessments. AI governance, acceptable-use, and access-control controls are showing up more often in security, privacy, and compliance reviews as AI adoption grows. For organizations within the EU AI Act’s scope specifically, two obligations are already live and directly touch how employees use AI — covered in full below.

Documentation matters when something goes wrong. Post-incident, regulators, auditors, and investigators may examine whether documented controls existed and whether those controls were actually implemented — not just whether a policy document existed somewhere.

GDPR & EU AI Act: What’s Already Mandatory

This is the section most AI AUP guides skip entirely, and it’s where organizations within the EU AI Act’s scope have real, current obligations — not future ones. Note that applicability depends on your organization’s specific role (provider, deployer, or both) and the AI systems involved — not simply on having customers in the EU.

EU AI Act Article 4: AI Literacy

Article 4’s AI literacy obligation has applied since February 2, 2025, and supervision and enforcement by national market surveillance authorities began August 2, 2026 — a date unaffected by the Digital Omnibus’s delay to the Act’s high-risk provisions.

The Digital Omnibus (in force since July 27, 2026) changed the wording from requiring providers and deployers to ensure a sufficient level of AI literacy, to requiring them to take measures to support the development of AI literacy among staff and other persons dealing with AI systems on their behalf. The amended provision does not prescribe a universal certification requirement or a single measurable literacy threshold. According to the European Commission’s own guidance, no specific certificate is required, and organizations should retain appropriate records of their AI-literacy measures, such as training and other initiatives.

An AI Acceptable Use Policy, paired with documented training and other literacy measures, gives organizations a practical way to operationalize this obligation.

EU AI Act Article 50: Transparency

Article 50’s transparency obligations became applicable on August 2, 2026, and create different duties for providers and deployers, per the European Commission. Providers have obligations concerning disclosure of certain AI interactions and machine-readable marking of certain AI-generated or manipulated content. Deployers have specific duties concerning emotion-recognition and biometric-categorization systems, deepfakes, and certain AI-generated or manipulated text on matters of public interest published without human review or editorial control. Whether a particular duty applies depends on your organization’s role and the specific AI system involved.

Deployer-side disclosure duties apply immediately with no grace period; a limited transition (until December 2, 2026) applies only to the provider-side machine-readable marking obligation for generative AI systems already on the market before August 2, 2026.

GDPR Articles 6 & 9: Lawful Data Use

Submitting personal data to an AI tool needs a lawful basis under Article 6, the same as any other processing activity. Special-category data (health, biometric, and similar data under Article 9) is prohibited by default, subject to narrow exceptions — a company approval process alone doesn’t create a lawful basis; it needs to be paired with a documented Article 6 basis and applicable Article 9 condition.

GDPR Article 30: Records of Processing

When an employee uses personal data in an AI system, that use generally constitutes processing under GDPR. The organization should assess whether that processing needs to be documented in its Article 30 records — including whether the Article 30(5) exception for smaller organizations applies to your specific situation.

GDPR Article 35: DPIA Screening

Where AI processing is likely to result in high risk to individuals, an Article 35 DPIA may be required. The existence of AI does not automatically trigger a DPIA — the organization must assess whether the specific processing is likely to result in high risk under Article 35 and applicable supervisory-authority criteria. Your policy’s processing-awareness trigger (Section 7 of the template below) is what surfaces these use cases for that screening before they become routine, unreviewed practice.

Employee Monitoring & Privacy

Enforcing this policy — logging prompts, monitoring for shadow AI, inspecting AI tool usage — is itself a form of employee monitoring that GDPR and, in some jurisdictions, separate employment-privacy rules regulate. Do not assume that because monitoring improves policy enforcement it is automatically lawful: employee-monitoring controls should be assessed for necessity, proportionality, transparency, data minimization, retention limits, and applicable employment/privacy law before deployment — not adopted by default because the technology is available. Notify employees clearly that AI tool usage may be logged, and identify and document the applicable lawful basis and other required safeguards before deploying monitoring controls.

2026 AI acceptable use policy GDPR and EU AI Act regulatory control map

The TrusteraAI AI Acceptable Use Policy Framework™

Quick Answer: A complete AI AUP has nine control domains — the six covering AI tool governance, plus three specific to GDPR- and EU AI Act-facing organizations that many generic templates treat too lightly. These are control areas, not one-to-one policy sections — several are intentionally combined within the 15-section template below.

Control DomainWhat It Covers
1. Scope & DefinitionsWho and what the policy covers — employees, contractors, AI agents, BYOD
2. Sanctioned Tools ListExplicit approved tools; anything else is unsanctioned by default
3. Data Classification & Permitted UseWhich data classes may reach which tools — explicitly flagging personal and special-category data
4. Prohibited UsesSpecific uses barred regardless of tool or data class
5. Human OversightWhen a human must review AI output before it’s acted on, as a matter of company policy
6. AI Literacy & TrainingHow the organization supports its AI literacy measures under Article 4, if applicable
7. GDPR Processing AwarenessWhen AI use crosses into personal-data processing requiring Article 30/35 screening
8. Transparency (Article 50)Escalation and labeling procedures for AI interaction and AI-generated content
9. Monitoring, Enforcement & Employee NoticeTechnical controls used, and the privacy notice and lawfulness assessment covering that monitoring

This structure is deliberately consistent with the domains in our AI Risk Assessment Checklist and AI Inventory Template — the tools this policy sanctions should be the same tools tracked in your inventory, not a separate list maintained in isolation.

The AI Acceptable Use Policy Template

Copy this into your policy system and replace the bracketed fields. This is a 15-section template — Article 50 transparency controls are integrated into Section 7 rather than given a separate numbered section.

[Company Name] — AI Acceptable Use Policy

Version: 1.0
Owner: [AI Governance Lead / CISO]
Approved By: [Name / Role]
Effective Date: [Date]
Next Review Date: [Date]
Classification: Internal
Review Cadence: Annual or upon material change

1. PURPOSE
This policy defines how employees, contractors, and authorized users of
[Company Name] may use AI tools. It protects company and customer data
and supports the organization's GDPR and EU AI Act compliance efforts.

2. SCOPE
Applies to all employees, contractors, and third parties acting on behalf
of [Company Name]; all AI tools including generative AI, AI agents, and
AI features embedded in existing SaaS; all devices used for company work,
including BYOD; and all data classes handled by the organization.

3. DEFINITIONS
AI Tool — any system using machine learning or generative AI capabilities.
AI Agent — an AI system capable of taking actions (API calls, record
changes, communications) rather than only generating content.
Shadow AI — any AI tool in use that is not on the Sanctioned Tools list.
Personal Data — [as defined under GDPR Article 4(1)].
Special-Category Data — [as defined under GDPR Article 9].

4. SANCTIONED AI TOOLS
Only the following tools are approved for work use:
[List approved tools]
Any tool not listed is unsanctioned. Personal accounts of otherwise-
approved tools (e.g., personal ChatGPT) are not covered by this policy
and may not be used for company work. AI agents capable of taking
actions in company systems additionally require: explicit written
authorization, least-privilege access scoped to the task, approved
credentials/API scopes, defined action boundaries, logging of every
action taken, and human approval for any designated high-impact action
(e.g., sending external communications, modifying financial records,
or altering permissions).

5. DATA CLASSIFICATION & PERMITTED AI USE
Public data:            Any sanctioned tool
Internal data:          Sanctioned tools only
Confidential data:      Sanctioned tools under enterprise agreement
Personal data:          Sanctioned tools only, after the applicable
                        processing has been assessed and authorized
                        under Section 7
Special-category data:  Prohibited by company policy unless reviewed
                        and approved by [Privacy Officer/DPO] with a
                        documented Article 6 lawful basis and applicable
                        Article 9 condition, together with any required
                        safeguards

6. PROHIBITED USES
- Submitting special-category or Restricted data without written approval
  as described in Section 5
- Acting on AI output for a consequential decision without documented
  human review (see Section 8)
- Using personal AI accounts for company work
- Uploading data covered by a customer NDA to non-approved tools
- Presenting AI-generated content as human-authored where disclosure
  is required under Section 7

7. GDPR PROCESSING AWARENESS & AI TRANSPARENCY
Employees must not use personal data with an AI tool for a new or
materially changed use case until the required assessment and
authorization have been completed. Employees must flag any such AI use
case to [Privacy Officer / DPO], who will assess it against the
organization's Article 30 Record of Processing Activities (including
whether any small-organization exception applies) and screen it for
Article 35 DPIA triggers.

Where applicable under EU AI Act Article 50, employees must follow the
organization's approved disclosure and labeling procedures for AI
interactions and AI-generated or manipulated content. Employees must
escalate potentially covered use cases to [AI Governance Lead] rather
than independently determining whether an Article 50 disclosure or
labeling obligation applies, and must use the disclosure method
designated by [AI Governance Lead] where a specific obligation is
confirmed to apply.

8. HUMAN OVERSIGHT
As a matter of company policy, human review is required before acting on
AI output for: external communications, legal or regulatory documents,
security or access decisions, employment decisions, and financial
decisions above [$ threshold]. Note: for AI systems separately classified
as high-risk under the EU AI Act, additional human-oversight and staff
training obligations may apply directly under the Act, independent of
this internal policy requirement.

9. AI LITERACY & TRAINING
All employees complete AI literacy training at onboarding and annually,
supporting the organization's AI literacy measures under EU AI Act
Article 4 where applicable. Training covers this policy, safe data
handling, and known AI limitations (hallucination, bias, inconsistent
outputs). Records of training and other AI-literacy measures are
retained; no certification is required.

10. MONITORING, ENFORCEMENT & EMPLOYEE NOTICE
[Company Name] uses [monitoring tools/methods] to enforce this policy,
including shadow AI discovery and audit logging. These controls have
been assessed for necessity, proportionality, and applicable employment/
privacy law. Employees are notified that AI tool usage may be logged in
accordance with this policy and [Company Name]'s employee privacy notice.

11. INCIDENT REPORTING
Employees must report within [24 hours] to [security contact]:
inadvertent submission of Restricted or personal data to any AI tool,
suspected prompt injection, or AI output that caused or could cause harm.

12. CONSEQUENCES FOR VIOLATION
Violations may result in additional training, revoked AI tool access,
disciplinary action up to termination, and legal action for serious or
repeated violations.

13. ROLES & RESPONSIBILITIES
AI Governance Lead — approves sanctioned tools, exceptions, and
                      Article 50 disclosure/labeling decisions
Privacy Officer / DPO — GDPR screening for AI use cases
Security Team — enforcement, shadow AI discovery, incident response
People Team — training delivery
Employees — compliance, reporting, training completion

14. POLICY REVIEW
Reviewed annually and upon: new AI tool adoption, new regulation,
material AI-related incident, or material change to a sanctioned
vendor's terms.

15. ACKNOWLEDGMENT
All employees acknowledge this policy at onboarding and annually.

This AI acceptable use policy template is designed as a starting point, so customize the sanctioned tools, data classifications, approval roles, reporting timelines, and employee requirements to match your organization’s risk profile, technology environment, and applicable legal obligations.

Want a fillable version pre-formatted for your policy system? Explore our AI Governance Resource Library.

Policy Isn’t Enough: Closing the Enforcement Gap

A written policy and an enforced control are different things. A policy that says “don’t paste customer data into ChatGPT” with no way to detect when it happens is a rule nobody can verify — and an unenforced policy is a weak answer when a regulator, auditor, or investigator asks what control actually operated.

Signs your AI AUP is policy-only:

  • No way to answer “which AI tools did employees actually use last week?”
  • No log of what data reached which AI tool
  • Incident response depends entirely on employees self-reporting
  • The policy is acknowledged once a year and never referenced again

Closing this gap doesn’t require a dedicated monitoring product on day one. Start with what your existing AI Inventory discovery methods already give you — SSO/OAuth logs, an amnesty survey, and periodic reviews of your existing SaaS admin consoles — and formalize the sanctioned tools list from what that discovery actually surfaces, not from an aspirational list nobody’s checked against reality.

Rollout Plan: 30/60/90 Days

Days 1–30 — Draft and Discover

  • Determine whether the organization is a provider, deployer, or both under the EU AI Act, and identify which AI systems fall within Article 50’s transparency scope
  • Run shadow AI discovery using the methods in your AI Inventory process to build the sanctioned tools list from real usage
  • Map identified AI use cases into your AI inventory as part of this process, rather than as a separate later exercise
  • Customize the template above; align with legal, privacy, security, and a business sponsor

Days 30–60 — Deploy the Basics

  • Publish the sanctioned tools list and the data classification table
  • Stand up the incident reporting channel
  • Assign the Privacy Officer/DPO role for GDPR processing-awareness screening (Section 7)

Days 60–90 — Train and Review

  • Roll out AI literacy training and policy acknowledgment
  • Run the first quarterly review: which tools are actually in use, any reported incidents, any GDPR/DPIA flags raised
  • Set the annual review date and the specific triggers (Section 14) that override it

Connecting This Policy to Your Governance Chain

This policy shouldn’t be the only document governing AI use — it’s the front door to a chain you’re likely already building:

AI Acceptable Use Policy (what’s allowed?)AI Inventory (what’s actually in use?)AI Vendor Risk Assessment (is a newly requested tool safe to sanction?)AI Risk Assessment (what’s the ongoing risk?)AI Incident Response Plan (what happens when the policy is violated or a tool is compromised?)

When an employee requests a new AI tool be sanctioned, run it through your AI Vendor Risk Assessment before adding it to Section 4. Every sanctioned tool should have an entry in your AI Inventory before — or at the point it becomes — approved for production use. A policy violation involving data exposure is handled by your AI Incident Response Plan — the two documents should reference each other, not operate as strangers.

AI Acceptable Use Policy Template
I recommend no caption unless you want the diagram to be referenced explicitly in the surrounding text.

Framework Mapping

FrameworkWhat This Policy Supports
EU AI Act Article 4Supports the organization’s AI literacy measures — the obligation shifted from ensuring a specific literacy level to taking measures that support its development, following the 2026 Digital Omnibus
EU AI Act Article 50Section 7 operationalizes escalation and labeling procedures for the transparency obligations applicable since August 2, 2026
GDPR Articles 6 & 9Section 5’s data classification requires a documented lawful basis and, where applicable, an Article 9 condition before special-category data reaches an AI tool
GDPR Article 30Section 7’s processing-awareness trigger flags AI use cases for ROPA assessment
GDPR Article 35The same trigger supports DPIA screening for higher-risk AI use cases
NIST AI Risk Management FrameworkSupports the Govern function — establishing policy, roles, and accountability
ISO/IEC 42001Supports relevant AI policy, governance, accountability, and operational-control requirements within an AI management system

For Spain-specific regulatory context around the GDPR sections above, see our Spain GDPR Checklist for SaaS and AEPD Inspection Guide.

Common Mistakes to Avoid

  • Treating an AI acceptable use policy template as a complete compliance solution without adapting its controls, responsibilities, and enforcement procedures to the organization’s actual AI use cases
  • Building the sanctioned tools list from what should be allowed rather than what discovery shows is actually in use
  • Assuming the Article 4 AI literacy obligation requires certification or a guaranteed literacy level — it doesn’t, following the 2026 amendment
  • Letting employees independently decide whether an Article 50 disclosure obligation applies, rather than escalating to a designated owner
  • Assuming a sanctioned tool automatically means personal-data processing through it is authorized, without the Section 7 assessment
  • Never flagging AI use cases involving personal data for GDPR Article 30/35 screening
  • Deploying AI usage monitoring without first assessing necessity, proportionality, and documenting the applicable lawful basis and safeguards
  • Treating this policy as disconnected from your AI inventory, vendor assessment, and incident response processes

Best Practices

  • Build the sanctioned tools list from real shadow AI discovery, not from a wish list
  • Keep the list short — a handful of well-governed tools beats a long, unenforceable one
  • Route every AI use case touching personal data through GDPR processing-awareness screening before it becomes routine
  • Pair the policy with an AI literacy program that goes beyond a single annual read-through, even though no specific level is legally mandated
  • Distinguish company policy requirements (Section 8) from AI Act legal requirements that may apply directly to high-risk systems
  • Review the policy on the triggers listed, not just the annual calendar date

Key Takeaways

✅ An AI Acceptable Use Policy is only as strong as its enforcement — a policy nobody can verify functions as a policy in name only.

✅ The 2026 Digital Omnibus shifted Article 4 from an obligation to ensure a specific AI-literacy level to an obligation to take measures supporting its development — the underlying obligation and its August 2026 enforcement date remain.

✅ EU AI Act Article 50’s transparency obligations became applicable August 2, 2026 and create different duties for providers and deployers — employees should escalate, not self-determine, whether a specific disclosure applies.

✅ Employee AI use involving personal data generally constitutes processing under GDPR — route it through Article 30/35 screening rather than around it, and remember AI use alone doesn’t automatically trigger a DPIA.

✅ This policy connects directly to your AI Inventory, AI Vendor Risk Assessment, and AI Incident Response Plan — it isn’t a standalone document.

Frequently Asked Questions

What is an AI Acceptable Use Policy?

A written policy defining which AI tools employees may use, what data may be shared with them, what uses are prohibited, what human oversight applies, and how the policy is enforced.

Is an AI Acceptable Use Policy legally required?

Not directly, in most jurisdictions, under that specific name. But for organizations and AI systems within the relevant scope of the EU AI Act, Article 4’s AI literacy obligation and, where applicable, Article 50’s transparency obligations are already enforceable, and GDPR obligations attach to AI use involving personal data. An AI AUP is the practical document most organizations use to operationalize these.

Where can I find an AI acceptable use policy template?

This AI acceptable use policy template provides a practical starting point covering sanctioned AI tools, data classification, prohibited uses, human oversight, GDPR processing awareness, AI literacy, transparency procedures, incident reporting, monitoring, and enforcement. Organizations should customize the template to their specific AI systems, data, regulatory obligations, and internal governance structure.

What does Article 50 require, and does it apply to us?

Article 50 creates different transparency duties for providers and deployers. Providers have obligations concerning disclosure of certain AI interactions and machine-readable marking of certain AI-generated or manipulated content. Deployers have specific duties concerning emotion recognition, biometric categorization, deepfakes, and certain AI-generated or manipulated text on matters of public interest. Whether a particular duty applies depends on your organization’s role and the specific AI system involved; confirm applicability with qualified counsel.

Does using AI automatically require a GDPR DPIA?

No. A DPIA is required where the specific processing is likely to result in high risk to individuals under Article 35 and applicable supervisory-authority criteria — the mere presence of AI doesn’t trigger it automatically.

How is this different from a general Acceptable Use Policy?

A general AUP covers network, device, and software use broadly. An AI AUP adds AI-specific concerns — sanctioned tools, data classification for AI inputs, human oversight of AI output, shadow AI discovery, and AI-specific incident reporting — that a general policy doesn’t address.

Do I need a separate policy for every AI tool?

No. One policy with a sanctioned tools list and clear data classification rules covers all approved tools — your AI Inventory tracks the specific systems and their risk tiers.

How often should this policy be updated?

At minimum annually, and immediately after: a new AI tool is sanctioned, a new regulation applies, a material AI-related incident occurs, or a sanctioned vendor’s data-use terms change materially.

Who should own this policy?

Typically the AI governance lead or CISO, with the Privacy Officer/DPO owning GDPR processing-awareness screening and People/HR owning training delivery and acknowledgment tracking.

What happens if an employee violates the policy?

Consequences should scale with severity — from additional training for a first minor violation up to termination and legal action for intentional or repeated exposure of Restricted or personal data. Define this explicitly in Section 12 before an incident forces the decision under pressure.

Leave a Comment