According to a Gartner survey of 2,986 employees, 62% say generative AI has already saved them time at work. Meanwhile, only 36% of organizations have a formal AI policy in place. That gap between what employees are already doing and what organizations have governed is where data leaks, IP disputes and compliance failures quietly accumulate.
This template and accompanying guidance gives compliance teams, HR leaders and GRC professionals a complete, cross-framework employee AI use policy they can adapt for ChatGPT, Microsoft 365 Copilot and any other workplace AI tool. Every section is mapped to its corresponding ISO/IEC 42001:2023 clause, EU AI Act article, and NIST AI RMF function so the policy doubles as compliance evidence, not just an HR document.
Why Most Organizations Need an AI Use Policy Right Now
The short answer: because your employees are already using AI whether you have a policy or not.
In 2023, Samsung engineers pasted proprietary source code into ChatGPT during a debugging session. The data was processed by OpenAI’s servers, potentially used in model training, and could not be retrieved. That incident has since become the standard case study in enterprise AI risk briefings not because it was unusual, but because it was the first time the risk became undeniably concrete.
Since then, the usage patterns have only accelerated. Research by EisnerAmper in 2025 found that 60% of employees rely on free AI tools rather than company-approved platforms. These consumer-grade tools typically have no enterprise data protection controls, no Data Processing Agreements and no audit trail when something goes wrong.
There are also regulatory dimensions that compress the timeline. The EU AI Act’s Article 4, which mandates that organizations ensure AI literacy among staff who use AI systems, entered into application on 2 February 2025. Enforcement by national market surveillance authorities begins 2 August 2026. For US-headquartered companies operating in Europe or with European customers, that obligation already applies and a documented AI use policy is the foundational evidence that Article 4 measures are in place.
The risk calculus is not complicated. An employee who pastes client financials into an unapproved AI tool has created a data exposure incident with no audit trail, no incident response path and in regulated industries a potential HIPAA, PCI, or GDPR violation. A policy does not prevent all of this. It establishes the controls, the training and the accountability that allow organizations to demonstrate reasonable governance if something does go wrong.
Scope: Who and What Your Policy Must Cover
The most common gap in AI use policies is scope that is too narrow.
A policy that governs “employee use of ChatGPT” misses every contractor who uses Copilot, every temp who runs prompts through Google Gemini, and every embedded AI feature that staff interact with daily without recognizing as “AI.” Getting scope right is not bureaucratic precision it determines whether your policy provides any actual protection.
Who the policy covers: All employees, contractors, temporary workers, consultants, and third-party service providers who access AI tools in connection with the organization’s work. EU AI Act Article 4 is explicit on this point: the AI literacy obligation extends to “other persons dealing with the operation and use of AI systems on their behalf,” which includes contractors and service providers operating AI on the organization’s behalf.
What tools the policy covers: Three categories require explicit inclusion:
- Standalone large language models (LLMs) accessed via web or API: ChatGPT, Claude, Google Gemini, Perplexity, and equivalent tools
- AI features embedded in existing productivity software: Microsoft 365 Copilot, Google Workspace Duet/Gemini, Salesforce Einstein, GitHub Copilot, Adobe Firefly
- AI-assisted automation tools used in workflows: Zapier AI, Notion AI, HubSpot AI content tools, and similar
The embedded AI category deserves particular attention. When Microsoft 365 Copilot became standard across enterprise Microsoft environments, many employees began using AI without thinking of it as “using an AI tool.” They summarize emails, draft documents, and analyze spreadsheets with Copilot prompts. The policy must name these features explicitly, because employees who would never consider pasting client data into ChatGPT may do the same thing via a Copilot prompt without a second thought.
Personal accounts on company devices: Employees who access ChatGPT through a personal (free) account on a corporate laptop are operating outside enterprise data protections even on a managed device. The policy must address this specifically prohibiting use of personal AI accounts for work-related tasks is a common and necessary provision.
AI Tools in Scope – Policy Coverage Categories
| Category | Examples | Primary Risk |
|---|---|---|
| Standalone LLMs (consumer) | ChatGPT Free, Claude.ai free tier, Gemini free | No enterprise data controls; potential training data exposure |
| Standalone LLMs (enterprise) | ChatGPT Enterprise, Claude Teams, Copilot standalone | Data protection depends on contract terms; verify DPA |
| Embedded AI in productivity tools | Microsoft 365 Copilot, Google Workspace Gemini, GitHub Copilot | Staff may not recognize as ‘AI’; permissions scope risk |
| AI automation/workflow tools | Zapier AI, Notion AI, HubSpot AI, Adobe Firefly | Often connected to sensitive systems; audit trail gaps |
| Custom/internal AI systems | Company-built LLM wrappers, internal chatbots | Governed by AI model registry, not just this policy |
Tool Governance: Approved, Conditional, Prohibited, and Pending Review
Most AI use policies divide tools into two buckets: approved and prohibited. That binary does not reflect how enterprises actually operate. A more functional taxonomy uses four tiers and the distinction matters both operationally and for audit purposes.
Tier 1 Approved without restriction: Tools that have been fully vetted by IT, security, and legal; have executed Data Processing Agreements where required; meet the organization’s security and data handling standards; and are licensed for enterprise use. Examples: Microsoft 365 Copilot with enterprise data protection enabled under the organization’s Microsoft 365 E3/E5 license; ChatGPT Enterprise under an executed BAA where HIPAA obligations apply.
Tier 2 Approved with conditions: Tools permitted for specific use cases with defined safeguards. Example: ChatGPT (consumer or Plus) approved for drafting non-confidential content only, with the explicit condition that no internal, confidential, or regulated data is entered. The condition is not a loophole — it must be accompanied by training on what qualifies as each data type.
Tier 3 Prohibited: Tools that fail security or data protection requirements, have unclear data retention practices, or have not completed the organization’s vendor review process. Consumer-grade AI tools with no enterprise data agreements default to this tier until assessed.
Tier 4 Pending review: Tools under evaluation, with a defined process for employees to request reviews of new tools they encounter. This tier prevents the policy from becoming a bottleneck that drives employees toward shadow AI. A clear, fast review pathway (target: 10 business days for initial assessment) reduces the incentive to use unapproved tools.
Update the approved tools list quarterly. The AI landscape moves faster than annual policy review cycles. A tool that lacked enterprise data protections six months ago may have added them; a previously approved tool may have changed its data processing terms. The Q1/Q2/Q3/Q4 update cadence also creates a natural audit record of the tool governance process.
Four-Tier AI Tool Classification Framework
| Tier | Classification | Example Tools | Data Rules |
|---|---|---|---|
| 1 | Approved – unrestricted | Microsoft 365 Copilot (enterprise), ChatGPT Enterprise (with BAA) | All internal data classes permitted within tool’s data handling scope |
| 2 | Approved – conditional | ChatGPT Plus (non-confidential use only), Perplexity Pro | Public and internal data only; confidential/regulated data prohibited |
| 3 | Prohibited | ChatGPT Free (personal account), unapproved consumer LLMs | No organizational data of any classification |
| 4 | Pending review | Any new tool requested by employees | No organizational data until assessment complete |
Every new AI tool should go through a documented AI approval process before employees are allowed to use it.
Data Classification – What Can and Cannot Enter an AI Tool
This is the section that actually prevents incidents. Every other policy provision can be in place, but without clear data classification rules that employees can apply in the moment, the policy offers limited protection against the kind of leak that Samsung experienced.
The data classification matrix below defines five categories and maps each to permitted AI tool use:
Data Classification Matrix for AI Tool Use
| Data Class | Description | Examples | Permitted AI Use |
|---|---|---|---|
| Public | Information approved for public release | Press releases, published marketing content, public pricing | Any approved tool, any tier |
| Internal | General business information not for external distribution | Internal memos, project plans, non-sensitive operational data | Tier 1 and Tier 2 tools only |
| Confidential | Sensitive business information with potential competitive or legal impact | Client contracts, M&A information, proprietary processes, source code | Tier 1 tools only, with documented business justification |
| Restricted | Highly sensitive data requiring strict access controls | Board-level strategy, trade secrets, unreleased financial results | Prohibited from all AI tools unless specifically approved by CISO |
| Regulated | Data subject to legal compliance obligations | Personal data (GDPR/CCPA), PHI (HIPAA), PCI card data, export-controlled data | Prohibited from all AI tools without executed DPA and legal approval |
A few practical points that most policies leave unaddressed:
Source code is confidential by default. This catches organizations that have clear policies for client data but haven’t thought through the developer use case. Engineers use AI coding assistants constantly. The policy must specify whether source code can be entered into GitHub Copilot (which processes code through Microsoft’s contracted infrastructure) vs. ChatGPT (which it typically cannot).
The “is this confidential?” test should be in the policy. Give employees a practical rule of thumb: if the information would not appear in a press release or a public filing, treat it as at least Internal. If sharing it with a competitor would harm the business, treat it as Confidential. This reduces the cognitive load of classification decisions under time pressure.
Data Processing Agreements are a prerequisite for personal data. Before any personally identifiable information (PII) can be entered into an AI tool including employee names in HR-related prompts the organization must have an executed DPA with the tool provider that complies with applicable privacy law. This requirement applies regardless of tool tier.
Human Review and AI Output Accuracy Standards
The requirement for human review appears in almost every AI use policy. What most policies do not specify is what “review” actually means.
Signing off on AI-generated content after reading it once is not adequate review for high-stakes outputs. A review standard that works operationally defines three things: what must be reviewed, by whom, and to what standard.
What must be reviewed before use:– All AI-generated content intended for external distribution (client deliverables, marketing copy, press releases, regulatory submissions)- Any AI-assisted analysis that informs a consequential decision (hiring recommendations, performance evaluations, contract terms, financial projections)- Legal, medical, financial, or compliance content where hallucinated outputs could cause material harm
Prohibited uses of AI without human review:– AI tool outputs must not be directly submitted as regulatory filings, legal documents, or client deliverables without human verification- Consequential decisions in employment (hiring, termination, performance ratings), credit, or healthcare must not be made based solely on AI output- AI-generated code must be reviewed for security vulnerabilities before deployment
The hallucination problem: Large language models generate plausible-sounding text that may be factually incorrect. This is not a bug that will be patched in the next update it is an inherent characteristic of how current LLMs function. The policy must communicate this clearly to employees who may not have technical backgrounds. A practical framing: treat AI-generated factual claims the way you would treat a first draft from a junior researcher valuable as a starting point, always requiring verification before you stake your reputation on it.
Regulated industries may need to document their review process. For organizations in healthcare, financial services, or legal services, AI output that informs a client-facing deliverable may need an audit trail demonstrating that a qualified human reviewed and approved the final content. Build that documentation requirement into the policy, and make sure your workflows support it.
Intellectual Property and Copyright in AI-Generated Work
This is the section most AI policies handle poorly typically with a single sentence that gestures at “complex IP questions” without resolving any of them. Three specific questions require explicit policy positions.
1. Who owns AI-generated work created during employment?
Under US work-for-hire doctrine, creative works produced by employees within the scope of their employment belong to the employer. The complication with AI-generated content is that the US Copyright Office has taken the position confirmed in its February 2023 guidance and subsequent decisions that purely AI-generated content without sufficient human creative contribution is not copyrightable. This creates a category of output that is not protected by copyright, which is both an IP risk (competitors can freely copy it) and a potential issue for client deliverables where originality is expected.
The policy position that works in practice: AI-generated outputs are company property when produced using company tools during employment. However, employees must be informed that AI-assisted content may have limited or no copyright protection unless it incorporates sufficient original human creative contribution.
2. Does AI-generated content infringe third-party copyright?
LLMs are trained on large corpora of existing text and code. There is ongoing litigation over whether AI outputs that closely mirror training data constitute copyright infringement. The policy should require employees to treat AI-generated content as potentially carrying copyright risk in commercial use particularly for creative content, code, and any output that closely resembles a known work. Where copyright-free status matters (marketing assets, published articles, commercial products), human creative contribution and editing reduces though does not eliminate this risk.
3. May employees use AI to generate content for personal use on company time or tools?
The answer should be no, and it should be explicit. Personal creative projects using company AI tool licenses create both IP ambiguity and terms-of-service exposure.
The NIST AI RMF’s Govern function (GV-1.1) specifically calls for policies that address AI-related intellectual property issues. Including that citation in the policy document itself signals to auditors that the IP section is not incidental but framework-aligned.
Disclosure and Transparency Standards
When must employees disclose that AI was used in creating work product? The policy needs a clear answer to this question, because the default answer “never, unless caught” is not the culture most organizations want to build.
The disclosure standard should be tiered by context and stakes:
Always disclose:– AI-generated content submitted to academic institutions, professional licensing bodies, or regulatory agencies where human authorship is an explicit requirement- Client deliverables where the client’s contract or expectation specifies human-authored content- Content presented as personal original analysis (opinion pieces, expert commentary, signed articles)
Disclose internally:– Reports and analyses presented at internal decision-making forums should note whether AI tools were used in research or drafting, so decision-makers can apply appropriate scrutiny- Code committed to production repositories should note AI-assisted generation in commit messages where materially AI-generated
Disclosure recommended but not required:– Routine communications, internal drafts, and working documents where AI assistance is used for efficiency rather than substance
The framing matters. Disclosure requirements work when employees understand them as protective, not punitive. An employee who discloses AI use in a deliverable is demonstrating good judgment, not admitting a shortcut. Policies that treat disclosure as a risk signal (something to hide) produce the opposite of the transparency the organization needs.
One practical note: some clients are beginning to include AI disclosure clauses in their service contracts. Organizations that have not established internal disclosure standards will find it difficult to comply with client contractual obligations when those clauses appear.
Mapping the Policy to ISO 42001, EU AI Act and NIST AI RMF
An employee AI use policy is not just an HR document. Written correctly, it constitutes compliance evidence for multiple framework requirements simultaneously. This is the section that most enterprise AI policies miss and the section that matters most when an auditor asks how you govern employee AI use.
The table below maps each policy section to its corresponding requirements across ISO/IEC 42001:2023, the EU AI Act (Regulation 2024/1689), and the NIST AI RMF 1.0:
Policy-to-Framework Cross-Reference Mapping
| Policy Section | ISO 42001:2023 Clause | EU AI Act Article | NIST AI RMF Function |
|---|---|---|---|
| Scope & applicability | Clause 4.3 (scope of AIMS) | Article 3 (definitions, deployer obligations) | GOVERN GV-1.1 |
| Tool governance (approved/prohibited) | Clause 6.1.2 (AI risk assessment) | Article 9 (risk management system) | MAP MP-2.3, MP-3.5 |
| Data classification | Clause 8.4 (documentation requirements) | Article 10 (data governance) | MEASURE MS-2.5 |
| Human review & oversight | Clause 8.4, Clause 9.1 | Article 14 (human oversight) | MANAGE MG-2.2 |
| Intellectual property | Clause 6.1.2 (risk identification) | Article 4 (AI literacy – IP awareness) | GOVERN GV-1.6 |
| Disclosure standards | Clause 8.2 (AI system transparency) | Article 50 (transparency obligations) | GOVERN GV-6.1 |
| Training & AI literacy | Clause 7.2 (competence) | Article 4 (AI literacy obligation) | GOVERN GV-4.1, GV-4.2 |
| Incident reporting | Clause 10.1 (nonconformity) | Article 73 (serious incident reporting) | MANAGE MG-4.1 |
A few notes on using this mapping in practice:
EU AI Act Article 4 applicability for US companies: Article 4’s AI literacy obligation applies to providers and deployers of AI systems. A US company deploying ChatGPT, Copilot, or any AI tool to EU-based employees, or using AI tools whose outputs are used in the EU, falls within Article 4’s scope. The obligation is not limited to companies headquartered in EU member states.
ISO 42001 policy documentation: For organizations pursuing ISO 42001 certification, the employee AI use policy maps primarily to Clause 6.1 (planning for risks and opportunities), Clause 7.2 (competence), and Clause 8.4 (documentation). The policy alone does not constitute an AI Management System it is one element of it but it is typically one of the first documentation artifacts auditors request.
Using Govern365.ai to operationalize this mapping: An AI use policy is a governance document. The operational challenge is maintaining evidence that the policy is actually being followed tracking which tools are in use, which employees have completed required training, and which incidents have been logged and resolved. Govern365.ai‘s compliance dashboard maps these policy commitments to their ISO 42001 and EU AI Act controls in real time, giving GRC teams the audit-ready evidence trail that a document alone cannot provide.
Governance, Training and Keeping the Policy Current
A policy that nobody has read, nobody enforces, and nobody updates within 12 months of publication is worse than no policy at all. It creates the appearance of governance without the substance which can actually increase liability in the event of an incident.
Assign a policy owner. The policy needs a named owner responsible for updates, training, and enforcement. In most mid-market and enterprise organizations, this sits with the GRC team, the CISO’s office, or an AI governance committee that includes representatives from Legal, IT, HR, and a business unit lead. Whoever owns it must have the authority to update the tool approval list without running a full policy revision cycle.
Mandatory training at key points:– New employee onboarding before access to any company AI tools is provisioned- Policy updates when material changes are made (new tool approvals, new data classification rules, regulatory changes)- Annual refresh even if the policy is unchanged, a short annual acknowledgment serves as documented evidence of ongoing AI literacy measures under EU AI Act Article 4
Training records matter. The EU AI Act Article 4 Q&A published by the European Commission in 2025 makes clear that organizations should be able to document the training measures they have taken. A signed acknowledgment of the policy at onboarding, combined with completion records for AI literacy training modules, constitutes the minimum evidence base. A more robust evidence trail timestamped training completions, assessed understanding, refresher records is appropriate for organizations with significant AI use or EU market exposure.
Policy review cadence:–
Quarterly: Update the approved/conditional/prohibited tool list-
Annually: Full policy review – update data classification rules, refresh framework mappings for any regulatory changes, revise enforcement provisions if needed-
Triggered: Immediate review following any AI-related data incident, new tool deployment, or material change to a framework requirement (such as the EU AI Act’s August 2026 high-risk obligations coming into force)
A static AI use policy is a liability. The tool landscape, the regulatory environment, and the organization’s own AI use patterns will all shift within 12 months of publication. The review cadence is not administrative overhead it is what keeps the policy from becoming a legal artifact that looks like governance while the actual risk management happens ad hoc.
Learn how to define governance roles in your AI governance committee charter before rolling out an organization-wide AI use policy.
Frequently Asked Questions
The following questions address query clusters that appear in People Also Ask and related search patterns for this topic. Apply FAQPage schema markup to this section in the published HTML.
Q1: Does an employee AI use policy need to cover Microsoft Copilot separately from ChatGPT?
Yes. Microsoft 365 Copilot operates under Microsoft’s enterprise data protection terms and typically does not train on customer data when deployed under commercial licensing. ChatGPT’s data handling varies significantly by account tier Enterprise accounts have stronger protections than consumer accounts. Your policy should specify both tools by name, their applicable tier, and the data classification rules that apply to each. Treating them identically understates the risk difference.
Q2: What happens if an employee leaks confidential data through an AI tool?
The answer depends on whether a policy existed, whether the employee was trained on it, and whether the incident was documented. Without a policy and documented training, the organization has limited grounds for disciplinary action and limited defense in regulatory inquiries. With a documented policy and training record, the incident can be treated as a violation of a known standard which affects both the internal response and any regulatory or legal exposure. This is precisely why the policy’s enforcement provisions and training records matter beyond paperwork.
Q3: Do US companies need to comply with EU AI Act Article 4?
If the organization deploys AI tools used by EU-based employees, or if AI outputs are used in the EU, the EU AI Act’s deployer obligations including Article 4’s AI literacy requirement may apply regardless of where the company is headquartered. Article 4 has been in application since 2 February 2025; enforcement by national market surveillance authorities begins 2 August 2026.
Q4: Who owns the copyright on AI-generated work created by employees?
Under US work-for-hire principles, work product created by employees within the scope of their employment belongs to the employer including AI-assisted work. However, the US Copyright Office has held that purely AI-generated content without sufficient human creative contribution may not be copyrightable. Your policy should assert employer ownership of AI-assisted outputs while requiring employees to maintain records of human creative contribution for content where copyright protection matters commercially.
Q5: How often should we update our AI use policy?
Quarterly for the approved tools list; annually for the full policy; immediately following any AI-related data incident or material regulatory change. The EU AI Act’s high-risk system obligations come into force in August 2026, which is a triggered review event for organizations using AI in employment, education, or critical infrastructure contexts. A static policy becomes inaccurate faster in AI governance than in almost any other domain.
Q6: What is the difference between an AI use policy and an AI governance framework?
An AI use policy governs how employees interact with AI tools the acceptable use rules, data classification standards, and disclosure requirements. An AI governance framework (such as one structured around ISO/IEC 42001:2023 or NIST AI RMF) is the broader organizational system for managing AI risk, including model inventory, risk assessment, lifecycle governance, and audit evidence management. The policy is one component of the framework, typically one of the first to be formalized.
Q7: Can employees use personal ChatGPT accounts on company devices?
Most organizations prohibit this, and for good reason: a personal ChatGPT account on a corporate device creates a data pathway that bypasses enterprise data protections. Work-related prompts entered through a personal account may be used in model training, have no organizational audit trail, and are not covered by any Data Processing Agreement the organization may have with OpenAI. The policy should explicitly prohibit use of personal AI accounts for work-related tasks on any device, managed or unmanaged.
Q8: What data is always prohibited from entering any AI tool?
Regulated data including personally identifiable information under GDPR or CCPA, protected health information under HIPAA, payment card data subject to PCI DSS, and export-controlled technical data — should be treated as prohibited from all AI tools unless the organization has an executed Data Processing Agreement with the tool provider and explicit legal approval. Source code is typically confidential by default. Even with strong enterprise data protections in place, regulated data inputs require documented approval before entry.
The Policy Is the Starting Point, Not the Finish Line
The organizations that navigate AI adoption cleanly are not necessarily the ones that move slowest. They are the ones that built clear rules before the incidents gave them no choice. An employee AI use policy that covers tool governance, data classification, human review requirements, IP ownership, and disclosure standards gives your workforce the clarity to use these tools productively and gives your legal and compliance teams the documented foundation they need if something goes wrong.
Start with the cross-framework mapping table in this guide. Match each section to the ISO 42001 clauses, EU AI Act articles, and NIST AI RMF functions it satisfies. That turns an HR document into compliance evidence, which is what your next audit will actually ask for.
Ready to move from policy document to operational governance? Start your 14-day free trial of Govern365.ai, by the Global AI Certification Council and map your AI use policy directly to your ISO 42001 controls from day one.
