The one-page AI acceptable-use policy template — adapt it for your firm, then get it in front of your team this week. Below the template, three reasons AI policies fail after they're published, and how to avoid each one.
This template pairs with the four-section policy framework — read that first if you want the reasoning behind each section before filling in the blanks below.
This template is a starting point, not a finished document. Fill in the bracketed sections with your firm's actual information. For regulated industries — healthcare, financial services, legal — have your relevant counsel review the final version before it goes live. This is general governance guidance, not legal advice, and your industry's specific requirements may call for additional provisions this template doesn't include.
The One-Page AI Policy Template
[FIRM NAME] · AI Acceptable Use Policy
Version [1.0] · Effective [DATE] · Review Date [DATE + 12 months]
Purpose
[Firm Name] uses AI tools to improve the quality and efficiency of our work. This policy tells every member of our team what tools are approved, what data can and can't go into those tools, what review is required before AI-assisted work leaves the firm, and what to do when something isn't clear. Following this policy is how we use AI responsibly — for our clients and for ourselves.
Section 1 — Approved AI Tools
The following AI tools are approved for work use, on the specified account tiers:
- [Tool Name] — [Business/Enterprise Plan] — approved for [specific use cases]
- [Tool Name] — [Business/Enterprise Plan] — approved for [specific use cases]
Free consumer accounts of any AI tool are not approved for use with any work-related data. Any tool not on this list requires approval from [designated person/role] before use.
Section 2 — Data Rules
Before using an AI tool, determine which category your data falls into:
Internal brainstorming · editing non-confidential text · general research · creating templates with no client specifics · summarizing publicly available information.
Internal business data · non-client-specific financial projections · internal strategic documents · [add your firm's specific yellow-category data].
Client names combined with any other client data · client financial records · health information of any kind · legal matter details · personnel records · anything marked confidential · passwords or credentials · [add your firm's specific red-category data].
When in doubt, treat data as RED until you've checked with [designated person/role].
Section 3 — Human Review Requirement
The following AI-assisted outputs require human review before leaving the firm. Review must be documented in [CRM / project management system / shared doc] with the reviewer's name and date:
- All client-facing emails, reports, proposals, and deliverables
- Any submission to a regulator, court, or official body
- Any analysis that directly influences a client decision or recommendation
- [Add your firm's specific output types]
Review means checking the output for accuracy, verifying any facts or citations, and confirming the content is appropriate for the intended audience. The person who reviews is accountable for the content — not the AI tool.
Section 4 — When You're Not Sure
If a situation arises that this policy doesn't clearly address:
- Contact: [Name / Role] via [email / message / phone]
- Expected response time: [within one business day]
- Default rule if approval can't be reached in time: do not use AI for that task. Proceed without it until guidance is received.
All team members confirm receipt and understanding of this policy as part of onboarding and at each annual review. This policy will be reviewed and updated at least once per year, or whenever significant changes occur in AI tool usage or applicable regulations. Questions about this policy go to [designated person/role].
Three Things That Make AI Policies Fail After They're Published
Dropping a policy document in a shared drive and calling it done produces a policy that doesn't change behavior. The team needs to hear two things from leadership: why this matters specifically to this firm and its clients, and what's different now versus before. A 15-minute all-hands covering those two points increases adoption meaningfully — and costs almost nothing.
The framing that works: "This protects our clients and protects all of us. Here's the specific situation we're preventing." Concrete beats abstract — if you can use an example from your own firm's audit, without identifying individuals, use it.
A policy that says "stop using unapproved tools" without providing approved ones drives usage underground. People need AI tools to do their work effectively. Removing the unauthorized option without replacing it with something better doesn't create compliance — it creates a situation where compliance and productivity feel like opposites. Productivity usually wins.
The policy launch should be accompanied by access to at least one well-configured approved tool. It doesn't have to be perfect. It has to be available, usable, and demonstrably easier to use than the workaround.
AI tools evolve faster than almost any other technology category right now. A policy written in January that names specific approved tools may be significantly outdated by July — because those tools have updated their data practices, because new tools have emerged that the team wants to use, or because a regulation has changed that affects what's required.
The review cadence that works for most professional services firms: annually scheduled, plus an ad hoc review whenever a new tool becomes available that the team wants to use, or when a regulatory development affects your industry. The annual review doesn't need to be intensive — 30 minutes to check whether the approved tools list is current, whether the data categories still make sense, and whether anything in your regulatory environment has shifted.
Ask Jordan
I want to build this policy for our firm — we're a 14-person financial planning practice. But I'm stuck on Section 1. I don't actually know which AI tools are appropriate for our regulatory environment. How do I evaluate that?
Good question to get specific on. For a financial planning practice, there are four things I'd check on any tool before adding it to an approved list: does it have a signed Data Processing Agreement available, does it operate under SOC 2 or equivalent certification, what does its data retention policy say for business accounts specifically, and does it explicitly prohibit using your prompts for model training on the paid tier? Every tool in The Promptory vault has been evaluated on those criteria.
The firms that will look back on this year as the year they got ahead of AI governance are the ones who wrote the policy this month — not a perfect policy, a real one. Shadow AI is a solvable problem. An AI policy is a manageable document. The gap between where most firms are and where they need to be is smaller than it looks.
If you want help evaluating your current tool stack against a firm's specific regulatory context, that's exactly what a free Jordan session is built for.