Fresh Mango Technologies logoFresh Mango AIA Fresh Mango Technologies Company

Governance

What is an AI Usage Policy?

What belongs in an AI usage policy, the clauses that matter most, common drafting mistakes, and how to roll it out so people actually follow it.

8 minute read · Written by the Fresh Mango AI team

What is an AI Usage Policy?

Definition

An AI usage policy is a short internal document that tells employees which AI tools are approved, what information may and may not be entered into them, what must be checked before AI-assisted output is used, and who is accountable for the result. It translates AI governance into instructions an ordinary employee can follow without legal training.

Key points

  • The best policies are two pages and readable in five minutes.
  • Approved-tool lists must be paired with provision — banning tools without offering an alternative creates shadow AI.
  • Accountability sits with the person who uses the output, always.
  • A policy nobody has been trained on is documentation, not control.

Why a dedicated policy is needed

Existing acceptable use, information security and data protection policies rarely answer the questions employees actually have about AI. Can I paste a client email into ChatGPT to draft a reply? Can I upload a contract to summarise it? Do I have to tell a client that AI helped produce a document? What happens if the output turns out to be wrong? Without explicit answers, staff make individual judgements, and those judgements diverge wildly across a workforce.

A dedicated AI usage policy resolves that ambiguity in language people can act on. It is also increasingly requested externally: client due diligence questionnaires, tender documents, insurer questions and professional body guidance now routinely ask whether an organisation has one. Being able to attach a clear, current policy has become a commercial asset in its own right.

What the policy should contain

Purpose and scope

Who it applies to — employees, contractors, temporary staff — and which activities are covered, including AI features embedded in tools people already use.

Approved tools

A named list of sanctioned platforms and the accounts to use, plus how to request approval for something new. Reviewed at least quarterly.

Permitted and prohibited data

Explicit categories. Typically prohibited without specific approval: personal and special-category data, client-confidential material, credentials, unpublished financials, safeguarding, health and legally privileged content.

Verification requirements

Facts, figures, citations, legal references and code must be checked against a primary source. Nothing goes to a client or regulator unreviewed.

Disclosure

When AI assistance must be declared — commonly in tenders, academic or regulated submissions, and where a client contract requires it.

Accountability

The employee who submits, sends or relies on AI-assisted output is responsible for it. AI is never an explanation for an error.

Prohibited uses

No fully automated decisions affecting individuals' rights, employment, credit or services without human review. No generating misleading content. No circumventing security controls.

Reporting and breach

How to report a suspected data exposure or a harmful output, and the consequences of deliberate breach.

Common drafting mistakes

The first is length. A twenty-page policy written in legal register will not change behaviour; a two-page policy with examples will. The second is prohibition without provision — banning consumer AI tools while offering no sanctioned alternative reliably pushes usage onto personal devices where it cannot be seen. The third is vagueness: 'use AI responsibly' gives no employee any useful guidance. The fourth is staleness, since tool capabilities and contractual terms change several times a year, so a policy without a review date decays quickly.

The fifth, and most damaging, is publishing without training. Circulating a policy by email and recording acknowledgements satisfies an audit checkbox and changes very little. Twenty minutes of role-specific walkthrough — here is the tool you should use, here is what you must never paste into it, here is what you must check — does far more.

Rolling it out so it sticks

Publish the policy alongside the sanctioned tools, not before them. Brief managers first so they can answer questions in their own teams. Include the key rules in induction for new starters. Put a short reminder in the tools themselves where possible. Review quarterly against your AI inventory, and update whenever you add a platform or a vendor changes its data terms.

We provide policy drafting, technical enforcement and staff briefing as part of the AI Governance & Security Project, and keep the policy current through the Quarterly AI Success Review.

Sources and further reading

Ready to Explore AI in Your Business?

Book a free 30-minute discovery session with an AI consultant, or request information and we will send the detail you need within one business day.

Recommended · Free · 30 minutes

Book a Free 30-Minute Discovery Session

  • Free 30-minute session
  • No obligation
  • Speak directly with an AI consultant
  • Discuss your business objectives
  • Explore practical AI opportunities
Book a Free 30-Minute Discovery Session

Opens our live booking calendar in a new tab — pick any slot that suits you.

Prefer not to book yet?

Request Information

Send a short enquiry and we will come back with the detail you need.

No sales sequence. A consultant replies within one working day.

FAQs

What is an AI Usage Policy — frequently asked questions

How long should an AI usage policy be?

Two pages is a good target for the staff-facing document. Detailed technical standards, risk assessment templates and the tool inventory can sit in supporting annexes for IT and compliance.

Should we ban ChatGPT and other public AI tools?

Rarely the right answer. Banning without providing a sanctioned alternative moves usage to personal accounts and devices where you have no visibility. Provide managed accounts, define red lines and enforce them.

Do we have to tell clients when we use AI?

It depends on your contracts, sector rules and the nature of the work. Many professional and public-sector tenders now require disclosure. The safest position is to define in the policy exactly when disclosure is required and to honour any client-specific term.

Who is responsible if AI produces an incorrect output?

The employee who used or sent it, and the organisation. That is why verification obligations and human review of consequential output must be explicit in the policy.

How often should the policy be reviewed?

Quarterly as a default, and immediately when you adopt a new tool, when a vendor changes its data handling terms, or when a relevant regulation or sector guideline is published.

Do contractors and temporary staff need to follow it?

Yes. Scope the policy to everyone who handles your data, and reference it in contractor agreements. Exposure through a third party is treated no differently by a regulator.

Decision brief

Turning this into a decision for your business

Straight answers to the five questions that decide whether an AI project is worth starting.

Why should I trust Fresh Mango AI?

Fresh Mango AI is the artificial intelligence practice of Fresh Mango Technologies, an IT, cyber security and cloud provider that has supported businesses since 2004 from offices in Ripon, Leeds, Skipton and Tortola in the British Virgin Islands. The same engineers who secure your identity, data and Microsoft 365 tenant advise on your AI adoption, so recommendations are grounded in what your estate can actually support rather than in vendor marketing.

What business outcomes will I achieve?

Clients typically release several hours per person per week on drafting, summarising, searching and reporting, shorten document and approval cycle times, and remove manual re-keying between systems. Every engagement starts by baselining the work involved so that the benefit is measured in hours released and cycle time reduced, not in licences purchased.

What are the risks if I do nothing?

Doing nothing is not a neutral position. Staff adopt consumer AI tools on their own, so company and client data leaves your control without record; competitors compress the cost of proposals, reporting and service delivery; and permission sprawl inside your file estate remains unaddressed, which becomes an incident the moment AI search is switched on. Delay also compounds the UK GDPR and EU AI Act governance work that will eventually be required of you anyway.

What happens next?

You book a free 30-minute discovery session. We ask about your objectives, systems and constraints, tell you honestly whether AI is the right answer, and set out a recommended first step — usually an AI Productivity & Readiness Assessment or an AI Governance & Security Project. You receive a written summary and a proposal only if there is a clear case for one.

How do I speak to somebody?

Book a free 30-minute discovery session with an AI consultant using our live booking calendar, or request information and we will reply within one business day. You can also call the UK office on +44 (0) 1765 606700 or the BVI office on +1 (284) 340 0466.

Start Your AI Journey

Talk it through with an AI consultant, or request written information — whichever suits you.

Your next step

Not Sure Where to Start?

Whether you're exploring AI for the first time or looking to scale existing AI initiatives, our specialists can help you identify practical opportunities and avoid common pitfalls.

Fresh Mango AI specialists reviewing an AI adoption plan with a business client
Book Free Discovery Session