What is an AI use policy?
An artificial intelligence use policy is an internal document setting out the principles and rules people must follow when using AI systems or tools within an organisation.
Its purpose is not to explain how AI works technically. Its purpose is to set clear expectations.
It should cover which tools may be used, for which purposes, what information may be entered, which uses require approval, which are restricted, when a person must intervene, how incidents should be reported and who may take particular decisions.
The policy should form part of the organisation’s AI governance system rather than operate as a standalone document. It can also align with a management system such as ISO/IEC 42001.
Why does a company need a policy?
Without clear rules, each person ends up deciding for themselves.
One employee may use a generative tool to summarise a document, another may enter confidential information, another may use AI to support a decision about a person, and someone else may purchase a solution without the organisation knowing it exists.
The issue is not only technological. It is a governance issue.
A policy provides a common baseline, identifies acceptable uses and shows when additional control is needed. It also reduces shadow AI: tools used without sufficient awareness by those responsible for governance.
Define the scope
Before drafting rules, make clear who and what the policy covers.
- employees and directors
- contractors and suppliers working under the organisation’s instructions
- corporate tools and external services
- generative AI and AI embedded in applications
- pilot projects and internal developments
Make the boundary practical
The scope must be clear enough to prevent uncertainty. A policy saying only that it applies to all artificial intelligence may sound comprehensive but prove unhelpful in practice.
Set principles for use
The policy can begin with a small set of principles guiding the use of AI.
- lawful use connected with professional activity
- respect for rights and applicable rules
- protection of information
- appropriate oversight and proportionality
- traceability where needed
- review of outputs before use
- human responsibility for decisions
Principles need practical rules
These principles do not replace specific rules. They provide a framework for situations the policy does not expressly anticipate.
State which tools are approved
One of the most common questions is: which AI tools may I use?
The policy should identify approved corporate tools, tools permitted for particular uses, those requiring prior authorisation, how to request a new tool and any restrictions on personal accounts or free services.
The list does not have to sit inside the policy. It can be maintained in a separate AI inventory or catalogue, provided people know where to check what is authorised.
Define restricted or prohibited uses
The policy should also state which uses are not allowed or require approval.
- entering confidential information into unapproved tools
- using AI to make automated decisions about people without authorisation
- creating misleading content or impersonating people
- using systems for purposes other than those approved
- circumventing established controls
- connecting external tools to corporate information without review
Adapt restrictions to real work
Restrictions should reflect the organisation’s actual activities rather than becoming a generic list disconnected from day-to-day work.
Regulate data and confidential information
A person may use an AI tool correctly from a functional perspective while still entering information that should not leave the corporate environment.
The policy should address personal data, confidential information, intellectual property, trade secrets, client documents, credentials, code, contracts and strategic information.
The rule must be clear enough for a user to understand what information may be entered into each type of tool.
Establish review and human oversight
AI can produce incorrect, incomplete or unsuitable outputs, so the policy should explain when a person must review a result before it is used.
An internal draft may need an ordinary review. An analysis supporting a decision about a person may require much stronger controls.
Certain outputs may need verification, approval, recorded evidence of review or oversight by a specified function, and should not be the sole basis for a decision.
Oversight should be proportionate to the use and risk.
Define roles and responsibilities
A policy works better when people know whom to contact.
It should clarify who approves tools, maintains the inventory, assesses risks, advises on privacy, reviews security, manages suppliers, coordinates training, receives incidents and decides exceptions.
Not every organisation needs new roles. Many responsibilities can sit within existing functions. The important point is to avoid rules without identifying who can interpret or apply them.

Include training and awareness
Publishing a policy on an intranet does not ensure that people can apply it.
It should be supported by training and communication. Not everyone needs the same level of knowledge.
Basic training may cover permitted uses, information that must not be entered, review of outputs, channels for requesting tools and incident reporting. People working with higher-impact systems may need specific training.
The policy and AI literacy should reinforce one another, while also taking account of the AI Act obligations for businesses.
Manage suppliers and external tools
Many AI tools used by companies come from external suppliers.
Before certain solutions are purchased or used, the policy can require a review of the supplier, purpose, data processing, contractual terms, security, documentation, limitations, integrations and service changes.
This prevents adoption decisions being based solely on whether a tool works technically.
Explain how to report incidents
The policy should explain what to do when something goes wrong, such as sensitive information being entered by mistake, a harmful result, unexpected behaviour, unauthorised use, a significant tool change or a supplier incident.
The user should know what to do and whom to inform. A simple, well-known channel is usually more useful than a complex process nobody remembers.
Document, review and update the policy
An AI policy should not be published and forgotten. Tools, suppliers, uses and the regulatory framework change.
The organisation should define the policy owner, approval date, version, periodic review, change process, communication of updates and management of exceptions.
The policy must remain a living document and retain appropriate evidence of reviews and decisions.
Common mistakes
Common mistakes include creating a policy that is too generic, banning everything by default, focusing only on generative AI, failing to connect the policy with the AI inventory, leaving responsibilities undefined and not updating the policy.
Statements such as ‘AI must be used responsibly’ are sound but do not guide real decisions. An excessively restrictive policy can also drive people towards tools outside corporate channels.
Creating a policy that is too generic
Statements such as ‘AI must be used responsibly’ may be sound in principle, but they do not provide enough guidance for real decisions.
Banning everything by default
An excessively restrictive policy may encourage people to use tools outside approved corporate channels.
Focusing only on generative AI
An organisation may use many other types of AI system, all of which need to fall within an appropriate governance framework.
Failing to connect the policy with the inventory
The rules should relate to the tools and systems the organisation actually uses.
Leaving responsibilities undefined
If nobody knows who approves, reviews or decides, the policy quickly loses its practical value.
Not keeping the policy up to date
A policy that does not evolve will eventually describe a reality that no longer exists.
A useful policy must be workable
The objective should not be a perfect document. It should be a set of rules that people can understand when facing a real situation.
Can I use this tool? May I enter this information? Do I need to review the output? Do I need approval? Whom should I tell if something happens?
If the policy helps answer those questions, it is becoming a genuine governance tool.
The sequence should be simple: which tools we use, which uses we permit, what information we protect, who decides, which controls we apply, and how we review and improve.
Does your organisation already have clear rules for using AI?
An effective policy should be based on the AI systems and real use cases within the organisation, rather than on a generic template.
Start the diagnostic →
Céntrika’s diagnostic can help you identify which governance, risk and compliance elements are already in place and where additional controls may be needed.
The assessment provides initial guidance and does not replace a specific evaluation.
