Grading Every Clause in an AI Acceptable Use Policy

Last Updated : October 4, 2026
Share Article

Table of Contents

Open any AI acceptable use policy and the clauses look alike, set in the same type, numbered in the same sequence and written in the same register. Underneath, they have wildly different pedigrees. Some are demanded by a named instrument. Some are shaped by one without being required. Some rest on ordinary employment law and nothing to do with artificial intelligence. And some rest on custom alone, copied from a template whose author copied it from another.

Grading them matters because the grade decides what you argue when the clause is challenged. A clause with a named instrument behind it is defended by citation. A clause resting on custom is defended by reasonableness, and only if someone thought about reasonableness at drafting time.

What follows grades the clauses, names the instrument where one exists, and says plainly where none does. Govern365 covers the staff-facing translation of this document separately at /blogs/employee-ai-use-policy-template/, which addresses day to day use of tools such as ChatGPT and Copilot.

Clauses a named instrument requires you to have

Four instruments name an AI acceptable use policy directly. Each wants something different, and a document written for one satisfies none of the others by accident.

An AI acceptable use policy is a scope boundary in Colorado. Senate Bill 26-189, signed by Governor Polis on 14 May 2026, repeals and reenacts the state’s automated decision-making law with effect from 1 January 2027. The phrase “acceptable use policy” appears exactly once in the enrolled bill, and its placement is the most interesting drafting decision in any current AI statute. The phrase sits inside the definition section, as part of an exclusion. Technology that communicates with consumers in natural language to provide information, make referrals or recommendations, answer questions or generate other content falls outside the definition of automated decision-making technology where two conditions hold: the technology is not contracted, advertised, marketed, configured or intended to be used in a consequential decision, and, at section 6-1-1701(2)(b)(III)(B), “the technology is subject to an acceptable use policy that prohibits generated content to be used in a consequential decision.”

Read that as an operator. From January 2027 a general assistant deployed in Colorado without such a clause is a covered technology with the developer and deployer regime attaching. The same assistant with one clause is outside it. The acceptable use policy is not evidence filed afterwards; it decides which body of law applies. Note also how specific the required wording is, since consequential decision is a defined term in the same statute.

AI acceptable use policies are documented under the EU AI Act by providers of general-purpose AI models. Annex XI, Section 1, point 1(b) and Annex XII, point 1(b) both require the general description of the model to include “the acceptable use policies applicable”. One annex serves the AI Office and national authorities on request, the other serves downstream providers who integrate the model. Neither was amended by the Digital Omnibus. The duty falls on model providers, so an ordinary deployer does not inherit it.

An AI acceptable use policy is declared rather than supplied under the Code of Practice Its Model Documentation Form carries a row reading: “Acceptable Use Policy: Provide a link to the acceptable use policy applicable (or attach a copy to this document) or indicate that none exists.” The closing clause is doing the work. A signatory with no policy complies by saying so. The row is marked for disclosure to the AI Office, to national competent authorities and to downstream providers alike, which places it among roughly one row in three in that form disclosed to every audience.

AI acceptable use policies were ordered across the United States federal estate. Office of Management and Budget Memorandum M-25-21 of 3 April 2025, at section 3(b)(iv), states that “within 270 days of the issuance of this memorandum, agencies should develop a policy that sets the terms for acceptable use of generative AI for their missions and establishes adequate safeguards and oversight mechanisms”. The verb is should rather than shall, so this is direction rather than command, and the 270 days ran out at the end of December 2025. M-25-21 remains in force; the December 2025 memorandum M-26-04 builds on it rather than replacing it. Contractors inheriting agency policy terms are inheriting this one.

Clauses a named instrument shapes without requiring

Most of the useful content of an AI acceptable use policy sits in this grade. No law says write this clause. Several laws tell you precisely what the clause should say if you write it, and borrowing their numbers is free.

An AI acceptable use policy can borrow two published retention floors. Article 19 of the EU AI Act requires providers of high-risk AI systems to keep automatically generated logs “for a period appropriate to the intended purpose of the high-risk AI system, of at least six months”. Article 26(6) imposes the identical floor on deployers for logs under their control. Neither reaches a general assistant. Both are better than the silence most policies contain, and six months is a defensible starting point precisely because a legislature chose it after consultation.

Employment records have a longer one. California’s Civil Rights Council regulations, effective 1 October 2025, amended 2 CCR section 11013(c) to extend record preservation from two years to four, and the amended list expressly names “selection criteria, automated-decision system data” among the records covered. An employer using AI anywhere in hiring in California is already holding those records for four years, whatever the AI policy says.

An AI acceptable use policy assigns oversight against a resourcing standard. Article 26(2) requires deployers of high-risk systems to assign oversight “to natural persons who have the necessary competence, training and authority, as well as the necessary support”. Competence, authority and support are things an employer supplies. A policy that assigns a named reviewer without budgeting time for review has written half the clause. Note which article this is, because the design duty at Article 14 falls on the provider, and published guidance on acceptable use policies routinely cites the wrong one.

Over-reliance has a name in the statute. Article 14(4)(b) requires that oversight enable the person “to remain aware of the possible tendency of automatically relying or over-relying on the output produced by a high-risk AI system (automation bias)”. Any verification clause that says check the output before relying on it is restating this badly. The version that survives states verification as a task producing a record, because an unrecorded verification requirement cannot be shown to have been met.

Publishing AI-generated text has an escape route worth building towards. The second subparagraph of Article 50(4) requires deployers publishing AI-generated text on matters of public interest to disclose that fact, then disapplies the duty “where the AI-generated content has undergone a process of human review or editorial control and where a natural or legal person holds editorial responsibility for the publication of the content”. Naming an accountable editor removes a labelling obligation. Naming that editor is an acceptable use policy clause, not a technical control.

Prohibited-use lists in most AI acceptable use policies are two entries short. Regulation (EU) 2026/1744 inserted Article 5(1)(ba) and (bb), both applying from 2 December 2026. Point (ba) prohibits systems generating or manipulating realistic imagery of an identifiable person’s intimate parts, or of an identifiable person in sexually explicit activity, without that person’s “freely-given, specific, informed, unambiguous and explicit consent”. Point (bb) reaches material within the meaning of Article 2, points (c) and (e), of Directive 2011/93/EU. The scoping paragraph matters more than the prohibitions. Under the new Article 5(1a)(b), use of such a system “is only prohibited where the deployer uses the system for the purpose of generating or manipulating such material or performance”. Purpose, not capability. A clause banning tools that can generate images misclassifies most of the organisation while missing the offence, and the offence sits in the Article 99(3) tier at 35 million euro or seven per cent of worldwide turnover, against the 15 million euro and three per cent tier covering everything else a policy touches.

The AI acceptable use policy training clause rests on a duty that changed seven weeks ago. Regulation (EU) 2026/1744 replaced Article 4 in full with effect from 27 July 2026. The original required providers and deployers to “take measures to ensure, to their best extent, a sufficient level of AI literacy” of their staff. The replacement requires them to “take measures to support the development of AI literacy”, and adds a sentence that was not there: “This obligation does not require providers or deployers to guarantee any specific level of AI literacy of any individual.” The words “a sufficient level of” were deleted. The duty moved from outcome to effort, and pages quoting the old sentence are quoting repealed text.

Clauses that rest on employment law rather than AI law

Enforcement provisions are where an AI acceptable use policy is actually tested, and almost nothing in AI regulation governs them. What governs them is the ordinary law of the workplace, which is unglamorous and unforgiving.

Three requirements decide whether a disciplinary decision survives. The rule has to have been in force and communicated before the conduct. The employer has to have applied it consistently to comparable conduct by others. And the conduct itself has to be evidenced.

The first is a documentation problem. A newsroom AI policy reached the front page of Hacker News on 23 April 2026 and drew 131 comments, and one participant who had corresponded with the publication during the underlying incident raised the question that decides such cases: whether the policy existed in writing at the time. An acceptable use policy answers that with a version history, an effective date and a per-employee acknowledgement record, or it does not answer it.

The second is the one nobody drafts against. A June 2026 thread on unapproved software procurement, thirty-six replies long, contains the clearest statement of the problem I have seen anywhere. One participant suggested adding a prohibition to the code of conduct. Another replied that it is already there, that people do it anyway, “and for a lot of companies that will never get enforced unless they already want to fire you”.

Selective enforcement is evidence of pretext, and the twenty employees who were overlooked usually appear in the same logs finally pulled for the one who was not. Written severity tiers, explicit manager parity and a review cadence that removes unenforced clauses are the drafting answer.

The third has a documented failure. On 12 August 2026 a systems administrator posted that human resources had asked for a report on one named employee’s AI usage, potentially including inputs, uploads and prompts, flagged as urgent, with no time range and no named tool, over suspected handling of company drawings.

The thread reached forty-five replies and one conclusion: browser history yields topic labels, personal accounts yield nothing, and without screen-recording software the organisation could establish that the employee had used a chatbot and no more. One respondent objected to information technology “being used as corporate police” and noted that absent organisation-wide controls, the honest answer is that only the fact of AI use on company equipment can be confirmed.

Nothing in that failure was a missing rule. Using AI on company drawings was already prohibited. The missing clause stated, in advance, what would be logged, for how long, who could request it and on what authority. A policy permitting work on tools without enterprise logging has, by that permission, disclaimed the ability to investigate anything done on them.

Two duties cross back into AI law here and are easy to miss. Article 26(7) requires a deployer who is an employer, before putting a high-risk AI system into service at the workplace, to inform workers’ representatives and the affected workers that they will be subject to its use.

Illinois arrived at a comparable place differently: Public Act 103-0804, effective 1 January 2026, makes it a civil rights violation under 775 ILCS 5/2-102(L)(2) “for an employer to fail to provide notice to an employee that the employer is using artificial intelligence” for the purposes listed in (L)(1).

The Department of Human Rights proposed implementing rules on 15 May 2026, postponed them in June and formally withdrew them on 26 June 2026, with no reproposal announced. So the statutory duty applies today with no regulatory detail whatever on timing, content, format or retention, which is a harder position for an employer than either having rules or not having the duty.

Clauses that rest on nothing but custom

Three AI acceptable use policy clauses appear in almost every published template with no instrument behind them at all. Each is defensible, and each has to be defended on its own terms rather than by citation.

The approved-tools list in an AI acceptable use policy. Naming one assistant and prohibiting the rest is the oldest clause in the genre and the least enforceable. A sysadmin thread of 20 February 2026 opens with an administrator asking how to disable one vendor’s assistant after standardising on another, and the replies are uniform: it is preinstalled, it appears in Office add-ins, it surfaces in browser search results, and while group policy and device management reach it, “these only limit it in corporately managed systems / browser profiles”. A June thread makes the same point from the other direction, that even a single named assistant has “multiple models baked into the back end, so it’s hard to single out a one-and-only provider”. One participant in that thread described the construction they had settled on instead: their organisation’s standard does not name a single permitted assistant, “since AI is baked into every other application nowadays at various levels”, and says instead “this is what you can and cannot do with this tool”. Five threads are a small sample rather than an industry consensus, and that construction is the only one in the sample that survives contact with embedded AI. Tool names belong in a register the AI acceptable use policy references.

The personal-account clause every AI use policy carries. Prohibiting work on personal accounts is universal and unverifiable. Enterprise accounts with administrative logging produce prompts and uploads; personal accounts produce nothing, which is exactly why the August investigation stalled. The honest version of this AI use policy clause makes an enterprise agreement a condition of permitted use, so that the prohibition is enforced by provisioning rather than by hope.

The agent clause, which mostly does not exist. Published policies are written for a person typing into a box, and the few that raise autonomous software concede the difficulty rather than solving it. Four AI acceptable use policy clauses close most of the gap. Each agent needs its own credential and a named accountable person, because an agent running under a shared service account cannot be attributed to anyone and defeats every enforcement provision elsewhere in the document. Authority is granted per task rather than as standing access. Blast radius is capped before deployment through spending limits, record-count limits, rate limits and an explicit list of irreversible actions requiring human confirmation. And the threat model is stated separately, because as one practitioner put it in July 2026, a tool that ingests external content such as emails, web pages or files carries prompt injection and indirect manipulation risks that typing sensitive data into a chatbot does not.

Sandbox provision belongs in the same AI acceptable use policy grade. In the same July thread, a practitioner observed that relying on “a boring Acceptable Use Policy PDF that nobody reads isn’t going to cut it anymore”. Their prescription for getting controls without becoming the department that says no starts in one line: “first, you have to give people a safe sandbox, or they’ll just make their own”.

The February thread supplies a working version of the same instinct: use banned by default, released to an individual once they complete AI awareness training, with the enterprise assistant enabled and consumer versions blocked, and a named officer deciding what joins the approved set.

Where the standards bite, and where the text is behind a paywall

An AI acceptable use policy carries most of its audit weight through two frameworks, and both need a caveat that vendor pages omit.

ISO/IEC 42001:2023 is the management-system standard, and Clause 5.2 is the clause an AI acceptable use policy answers. Clause 5.2 requires top management to establish an AI policy appropriate to the organisation’s purpose, framing AI objectives, and committing to meet applicable requirements and to continual improvement.

Four handling requirements follow: the policy is documented, refers as relevant to other organisational policies, is communicated internally, and is available to interested parties as appropriate. Read those four as an evidence checklist rather than as administration. A policy without a version history, a communication record and an availability route fails all four at once while its content is impeccable.

One honesty note belongs here, since precision is the whole point of this page. The published edition of ISO/IEC 42001 is paywalled, and the freely available preview stops before Clause 5. The wording above is a paraphrase drawn from ISO’s own final draft preview, which may differ editorially from the published text.

Clause 5.3 covers roles, responsibilities and authorities. The standard’s body text cross-refers to Annex A group A.2 for policy controls and A.3.2 for roles, and those two identifiers are corroborated by the standard itself.

Group titles commonly given for A.9 responsible use and A.10 third-party relationships come from secondary sources rather than from the standard, and published totals for the number of Annex A controls disagree with one another. Verify identifiers and counts against Table A.1 in a purchased copy before putting them in a compliance mapping.

A ranking competitor page cites ISO/IEC 27001 control A.9.2 on this subject, which has not existed since the 2022 restructure into four themes at A.5 to A.8, while A.9 in ISO/IEC 42001 is the responsible-use group. Sharing a number is not sharing a control.

The NIST AI Risk Management Framework supplies an AI acceptable use policy with its evidence vocabulary outside Europe. GOVERN 1.6 requires mechanisms to inventory AI systems, which is the precondition for any enforceable use rule, since a policy cannot govern software nobody has counted. GOVERN 2.2 requires personnel and partners to receive AI risk management training. GOVERN 3.2 requires policies defining roles for human-AI configurations and oversight.

GOVERN 4.1 addresses organisational culture and GOVERN 6.1 third-party risk. The caveat here is on the record: NIST’s own framework page states that “the AI RMF 1.0 is being revised as part of the White House AI Action Plan”, and that plan directs removal of references to misinformation, diversity, equity and inclusion, and climate change. Date-stamp any subcategory a policy relies on.

What grading changes when the policy is tested

Grading is not an academic exercise. The grade changes the argument available to you at three specific moments.

An AI acceptable use policy clause in the employment-law grade is defended, at a disciplinary hearing, by showing communication, consistency and evidence. Citing an AI regulation in an AI acceptable use policy dispute helps nobody, because no AI regulation makes pasting a drawing into a chatbot a dismissible offence. What the regulation supplies is the retention floor that let you prove it happened.

The named-instrument grade is the only one that closes an audit finding by itself. An auditor asking how the organisation discharges Article 4 wants the training clause, the completion records and the release-on-completion gate, and will accept them because the article says what it says. An auditor asking about the approved-tools list is asking a reasonableness question, and the answer is the register, the review cadence and the discovery method, not a citation.

A regulator’s request tells you which clauses of the AI acceptable use policy are load-bearing. Colorado’s exclusion, the Annex XI and XII documentation duty and the Code of Practice declaration all turn on the existence and content of the policy itself. Everything else turns on whether the records the policy required actually exist.

Two tests reveal where an organisation sits against its own AI acceptable use policy. Ask what could be produced today if human resources requested one named employee’s AI activity for a given week. Then ask what could be produced if a regulator asked which version of the policy was in force on that date and who had acknowledged it. Most organisations fail the second test faster than the first, whatever the AI policy says.

Keeping the grade attached to the clause

AI acceptable use policy grades drift. A clause written when nothing named it acquires an instrument, as the agent clauses in most policies will once autonomous software attracts specific rules. A clause written against a named duty loses its footing when the duty is rewritten, which is what happened to every AI literacy clause on 27 July 2026.

A policy that does not record which instrument each clause answers cannot be updated when the instrument moves; it can only be rewritten from scratch, which is why so many of them are three years old.

Governance software earns its place at exactly that point, and the acceptable use policy is the problem Govern365.ai was built around. Mapping each clause to the instrument it answers and to the record that proves it, giving that record an owner and a retention period, and keeping a dated version history turns the policy from a document into a file that answers questions.

Govern365.ai holds that obligation-to-evidence mapping across the EU AI Act, ISO/IEC 42001 and the NIST AI Risk Management Framework, so an Article 4 training record, a Clause 5.2 handling requirement and a GOVERN 2.2 training record point at one artefact rather than three copies that drift apart.

Every clause and its pedigree

ClauseGradeInstrument
Prohibition on generated content in consequential decisionsNamed instrumentColorado C.R.S. 6-1-1701(2)(b)(III)(B), from 1 January 2027
Documented acceptable use policy for a general-purpose AI modelNamed instrumentEU AI Act Annex XI Section 1 point 1(b), Annex XII point 1(b)
Declaration of whether a policy existsNamed instrumentGPAI Code of Practice, Model Documentation Form
Terms of acceptable use for generative AI, federal agenciesNamed instrument, hortatoryOMB M-25-21, section 3(b)(iv)
Notice to workers and their representativesNamed instrumentEU AI Act Article 26(7); Illinois 775 ILCS 5/2-102(L)(2)
Training and AI literacyNamed instrumentEU AI Act Article 4, as replaced 27 July 2026
Prohibited uses covering the new offencesNamed instrumentEU AI Act Article 5(1)(ba), (bb), (1a)(b), from 2 December 2026
Log retention periodShaped, not requiredEU AI Act Articles 19 and 26(6), at least six months
Employment record retentionShaped, not required2 CCR 11013(c), four years
Oversight competence, authority and supportShaped, not requiredEU AI Act Article 26(2)
Verification against over-relianceShaped, not requiredEU AI Act Article 14(4)(b)
Named editorial responsibility for published AI textShaped, not requiredEU AI Act Article 50(4), second subparagraph
Version history, effective date, acknowledgement recordEmployment lawBurden on the employer to show the rule was communicated
Severity tiers and manager parityEmployment lawSelective enforcement exposure
Approved-tools listCustom onlyNo instrument; defend on reasonableness
Personal-account prohibitionCustom onlyNo instrument; enforce by provisioning
Agent identity, scoped authority, blast-radius capsCustom onlyNo instrument; drafting decision
Sandbox provisionCustom onlyNo instrument; reduces shadow adoption

Frequently Asked Questions

What is an AI acceptable use policy?

The governing document stating what data may be given to AI systems, what decisions may rest on their output, which uses are prohibited, who approves exceptions, and what records are kept. The EU AI Act uses the phrase as a term of art in Annexes XI and XII, where providers of general-purpose AI models must document “the acceptable use policies applicable”.

Does the EU AI Act require an AI acceptable use policy?

Not by that name, and not for deployers. What it requires is measures supporting AI literacy under Article 4, oversight assigned to competent and resourced people under Article 26(2), log retention of at least six months under Article 26(6), and worker notification under Article 26(7) for high-risk systems at the workplace. An acceptable use policy is the usual instrument for discharging those duties. Providers of general-purpose AI models do have to document theirs.

Did the AI literacy obligation change in 2026?

Yes. Regulation (EU) 2026/1744 replaced Article 4 with effect from 27 July 2026. The duty moved from measures “to ensure, to their best extent, a sufficient level of AI literacy” to measures “to support the development of AI literacy”, with an express statement that it does not require guaranteeing any specific level for any individual. The words “a sufficient level of” were removed.

Does Colorado require an AI acceptable use policy?

Not as a filing. Senate Bill 26-189, signed on 14 May 2026 and effective 1 January 2027, uses the phrase once, in an exclusion from the definition of automated decision-making technology. A general assistant stays outside the regime only where it is not intended for consequential decisions and is subject to an acceptable use policy prohibiting generated content from being used in a consequential decision.

Should an AI acceptable use policy name approved AI tools?

Name them in a register the policy references rather than in the policy body. AI features are embedded in productivity suites, browsers and search, so a fixed list goes stale within weeks and cannot be enforced on unmanaged devices. Governing data, decisions and records survives tool churn.

What logging should an AI acceptable use policy require?

State in advance what is logged, for how long, who may request it and on what grounds. Articles 19 and 26(6) of the EU AI Act supply a floor of at least six months for high-risk systems. California’s employment regulations at 2 CCR section 11013(c) require four years for records including automated-decision system data. Permitting work on tools without enterprise logging forfeits the ability to investigate anything done on them.

Can an employee be disciplined under an AI acceptable use policy?

On the same footing as any other workplace rule, which means showing the policy was in force and communicated before the conduct, applied consistently to comparable conduct, and supported by evidence. Severity tiers matter, because treating an accidental paste and a deliberate upload identically invites a challenge to both.

How should an AI acceptable use policy handle AI agents?

Give each agent its own identity and a named accountable person, grant authority per task rather than as standing access, cap blast radius with spending, volume and rate limits, and list irreversible actions requiring human confirmation. Agents ingesting external content carry prompt injection risks a person typing into a chatbot does not. No instrument names these clauses yet.

Which ISO/IEC 42001 clauses does an acceptable use policy satisfy?

Clause 5.2 sets what the AI policy must contain and how it must be handled, and Clause 5.3 covers roles, responsibilities and authorities. The standard cross-refers to Annex A group A.2 for policy controls and A.3.2 for roles. Individual Annex A control identifiers and the total number of controls should be checked against Table A.1 in a purchased copy, because the published edition is paywalled and secondary sources disagree.

What new prohibitions does an AI acceptable use policy need in 2026?

Regulation (EU) 2026/1744 inserted Article 5(1)(ba) and (bb), applying from 2 December 2026, covering AI systems generating non-consensual intimate imagery of an identifiable person and material within the meaning of Article 2, points (c) and (e), of Directive 2011/93/EU. Article 5(1a)(b) limits the deployer prohibition to use of such a system for the purpose of generating that material, so the clause must describe conduct rather than tool capability.

What are the penalties for getting deployer obligations wrong?

Article 99(4)(e) sets fines for breach of Article 26 at up to 15 million euro or three per cent of total worldwide annual turnover for the preceding financial year, whichever is higher. The 35 million euro and seven per cent tier is Article 99(3) and applies to prohibited practices under Article 5.

Do Illinois employers have rules telling them how to give AI notice?

None are in force. Public Act 103-0804 created the duty with effect from 1 January 2026. The Department of Human Rights proposed implementing rules on 15 May 2026, postponed them in June and formally withdrew them the same month. The statutory duty applies with no regulatory detail on timing, content, format or retention

Stay ahead of the curve

Join 5,000+ industry leaders who receive our weekly briefing on AI governance and secure enterprise collaboration.

About the Author

Dr Faiz Rasool

Director at the Global AI Certification Council (GAICC) and PM Training School

Globally certified instructor in ISO/IEC, PMI®, TOGAF®, and Scrum.org disciplines with hands-on experience in ISO/IEC 42001 AI governance across the US, EU, and Asia-Pacific.

Summarize with AI

AI-Powered Data Governance Platform

Secure, Govern, and Collaborate on Sensitive Data—All Within Microsoft 365

Further Reading

Related Insights

model-risk-management

Model Risk Management After SR 26-2, One Word at a Time

Supervisory guidance is a text before it is a framework, and the text changed on

Read More →
ai-policies-incident-response

AI Incident Reporting Duties, Sorted by the Date They Bind You

Almost everything written about AI incident reporting assumes Article 73 of the EU AI Act

Read More →
eu-ai-act-gpai

EU AI Act GPAI Rules: The Numbers You Have to Defend

Chapter V of the AI Act is a self-assessment regime wearing the clothes of a

Read More →

Summarize with AI

Transforming AI Risks into Strategic Assets.

Request a Personalized Demo

Our governance experts will walk you through the platform and help you map out your ISO 42001 or EU AI Act roadmap.