Skip to content

Template

AI Use Policy Template

Boards are being asked to oversee AI before anyone has written down the rules. This model policy gives your organization a starting point: what AI may be used for, what data may never go into it, and who is accountable. Read it here, download the editable Word file, or print it.

Organization type

Swaps the content, guidance, and download to fit your board.

Corporate board — model policy for employee and organizational use of AI

Organization

 

Policy owner

 

Approved by board on

 

Next review date

 

  1. 1. Purpose and scope

    State why the policy exists: to capture the value of AI while protecting the company, its customers, and its people. Define scope broadly — all employees, officers, contractors, and any AI tool used for company work, including generative AI, embedded AI features in existing software, and AI used by vendors on the company's behalf.

    • Policy applies to:
    • Definition of AI tools covered:
  2. 2. Approved tools and permitted uses

    Maintain a register of approved AI tools and the uses permitted for each. Distinguish clearly between encouraged uses (drafting, summarizing, analysis of public data), uses requiring approval (anything touching customer, employee, or financial data), and prohibited uses.

    • Permitted without approval:
    • Requires written approval:
    • Prohibited:
  3. 3. Data protection and confidentiality

    The core rule: no confidential, proprietary, personal, or material non-public information may be entered into a public AI tool. State it plainly, give examples, and cover customer data, trade secrets, financial projections, and board materials.

  4. 4. Accuracy, review, and human accountability

    AI output is a draft, never a decision. Require human review of any AI-generated content used in decisions, external communications, or filings — and state that accountability for the final work product stays with the person, not the tool.

  5. 5. Intellectual property and attribution

    Address ownership of AI-assisted work product, the copyright uncertainty around AI-generated content, and when use of AI must be disclosed to customers or counterparties.

  6. 6. Vendors and third-party AI

    Require due diligence on AI features embedded in vendor software: what data the vendor's AI trains on, where data is stored, and what the contract says about it. AI risk arrives through the supply chain as often as through the front door.

  7. 7. Incident reporting and enforcement

    Define what counts as an AI incident (data entered into an unapproved tool, AI output published without review, a vendor AI breach), how employees report one, and the consequences of policy violations. Make reporting safe — you want to hear about near misses.

  8. 8. Policy review and ownership

    Name the executive owner of the policy, the committee with board-level oversight, and an annual review cycle. AI practice is moving faster than annual — plan for interim updates.

Approved AI tools register

ToolApproved usesData classification allowedBusiness ownerReview date
     
     
     
     

Guidance notes

  • Write the prohibited-uses list in plain language with examples — 'no customer data in public AI tools' beats a paragraph of definitions.
  • The policy is only as good as the approved-tools register. Keep it current and easy to find.
  • Board materials belong in the data-protection section explicitly — directors and executives are already pasting board papers into AI tools.
  • Pair this policy with board-level oversight: a committee charter, a risk assessment, and a standing agenda item.
  • Adopt by board or committee resolution, record it in the minutes, and review at least annually.

Before you adopt this policy

Legal counsel review is recommended
Have qualified legal counsel licensed in your state or jurisdiction review and adapt this material before your board adopts or relies on it.
Educational model language only
This is a general model provided for educational purposes. It is not legal, tax, accounting, compensation, or compliance advice, and it does not create an attorney-client or advisory relationship.
Tailor to your governing documents and law
Align it with your articles of incorporation, bylaws, applicable state corporate or nonprofit statutes, employment law, and any regulatory requirements that apply to your organization.
Adopt and record formally
Approve the process by board vote or resolution, record it in the minutes, keep sensitive material confidential, and review it annually.

This resource is provided for educational purposes only and does not constitute legal, tax, accounting, compensation, or compliance advice, nor does it create an attorney-client or advisory relationship. Adapt it to your organization's governing documents and applicable law, and have qualified legal counsel review it before your board adopts or relies on it.

Want help putting AI governance in place?

A policy is the beginning of AI oversight, not the end. If your board could use a confidential conversation about AI governance, risk, or board readiness, I'd be glad to talk.

Request a consultation