An AI acceptable-use policy doesn't need to be long to be useful. It needs to answer the questions staff and reviewers actually ask: which tools are approved, what data can go into them, and who to check with when something's unclear.
Scope
State plainly which AI tools the policy covers and who it applies to. A short scope section prevents the most common confusion — staff assuming a personal tool they already use is automatically covered.
Approved tools
List the tools currently approved for use, and note that anything not on the list requires review before adoption. This is the section most likely to change, so keep it separate from the rest of the policy for easy updates.
Data handling rules
Spell out what categories of information may and may not be entered into an AI tool — for example, procurement-sensitive data, personal information, or anything under a nondisclosure agreement. Concrete examples work better here than abstract categories.
Review cadence
Set a simple, recurring point to revisit the tool list and rules — quarterly is common for a small organization. This keeps the policy from going stale as new tools appear.
Who to ask
Name a single point of contact for questions about whether a tool or use case is covered. Ambiguity is where most policy violations happen, usually without any intent to cause harm.
Related: Secure AI Adoption for Small Government Contractors · What CMMC Readiness Documentation Looks Like · Professional & Administrative Support capability