Generative AI policy template download - Corsica Technologies

Generative AI Policy Template

Originally published January 9, 2024. Completely refreshed September 8, 2026.

Chances are, your team is already using AI. The only question is whether potentially exposing the company to the risks associated with ungoverned AI usage. A clear generative AI policy tells employees which tools are approved, which data can go into them, and who’s accountable for what AI produces. 

Our free template gives you the structure and language to get started. Updated for 2026, it covers: 

  • A two-tier data classification approach (not a blanket ban) 
  • An approved-tools process that addresses shadow AI 
  • Agentic AI and automation 
  • Output review and accountability 
  • Roles, enforcement, and definitions your lawyers will expect 

Ready to download the template?

What Is an AI policy? 

An AI policy is a formal document that defines how an organization’s employees may use artificial intelligence tools. At minimum, it specifies which AI tools are approved, what types of company data may be entered into them, who’s responsible for reviewing AI-generated output, and how violations are handled. A good AI policy enables productive AI use rather than banning it. The goal is to establish healthy guardrails, not roadblocks. 

Most organizations need an AI policy for three reasons: employees are already using AI tools whether or not one exists, sensitive data entered into consumer AI tools may leave the organization’s control, and AI-generated errors become the organization’s errors the moment they reach a customer, regulator, or court. 

How do I use this AI policy template? 

Our AI policy template is easy to use. Simply download it, replace the highlighted placeholders with your organization’s details, and have your legal counsel review the policy before adoption. If you need help applying it to the real world, our AI governance consulting team assists with policy creation, framework selection, and AI implementation. 

Note: This policy template does not constitute legal advice. Your lawyers will need to approve any final policy documents that you develop. We offer this template for informational purposes only.

What should be included in an AI policy? 

A complete generative AI policy covers eight areas. Our template includes ready-to-customize language for each: 

Section 

What it does 

Authority and purpose 

Anchors the policy to your security program and applicable regulations (HIPAA, CMMC, GLBA, state AI laws) 

Scope 

Applies the policy to employees, contractors, and AI features embedded in other software 

Roles and responsibilities 

Defines who owns the policy, the approved-tools list, and enforcement 

Acceptable use and data protection 

Maps your data classification tiers to permitted AI tools 

Approved tools and shadow AI 

Establishes a request-and-review process for new AI tools, extensions, and notetakers 

Agentic AI 

Sets approval, least-privilege, and human-oversight requirements for AI agents 

Output review and accountability 

Makes humans accountable for AI-assisted work product 

Monitoring, incident response, and training 

Covers logging, AI-specific incidents like prompt injection, and awareness 

 

Why do blanket AI bans fail? 

The single most important decision in an AI policy is how it treats company data — and this is where most policies get it wrong. A blanket ban (“never put company information into AI”) gets ignored, because it makes the tools useless. Unlimited permission creates real exposure. The workable answer is a tiered model that maps your existing data classification to AI tool types: 

  1. Restricted or confidential data never enters any generative AI tool. No exceptions. 
  2. Internal-use data may enter an approved enterprise AI tool — for example, Microsoft Copilot accessed through your organization’s own Microsoft 365 tenant — where your data isn’t used to train external models and stays inside your security boundary. It may not enter any other AI tool. 
  3. All other data may enter any approved AI tool. 

 

This is the model we use internally at Corsica, and it’s the model built into the template. It works because it gives employees a clear, memorable rule for every situation — and because the enterprise-tenant distinction, not the tool’s brand name, is what actually determines where your data goes. (Deciding between enterprise options? See our comparison of Microsoft Copilot vs. ChatGPT.) 

Do we need to update our AI governance policy to account for AI agents? 

In most cases, yes. Two gaps sink most AI policies written before 2025. 

Shadow AI is AI use your policy doesn’t see: personal ChatGPT accounts used for work, AI features quietly added to SaaS products you already license, browser extensions, and AI meeting notetakers joining calls uninvited. The template addresses this with an approved-tools list and a lightweight request process, so the answer to “can I use this new tool?” is “ask,” not “hide it.” 

Agentic AI — AI systems that plan and execute multi-step tasks with limited supervision — raises questions a chatbot-era policy never considered: What can an agent access? Under whose identity does it act? Which actions require a human sign-off? The template requires explicit approval before deployment, least-privilege access under a distinct agent identity, human review for consequential actions, and the ability to shut an agent down. For a deeper look at governing agents at scale, see our coverage of Microsoft Agent 365. 

How do we write an AI policy? 

Use our free AI policy template download or follow this process. (Hint: You’ll end up following this process to fill out our policy template.) 

  1. Inventory current AI use. Survey teams and check network logs — you’ll find more tools in use than you expect. 
  2. Map your data classifications to AI tiers. If you don’t have a data classification policy, that’s step zero. 
  3. Customize the template. Replace the placeholders, name your approver, and list your initial approved tools. 
  4. Get legal and leadership review. Your counsel validates regulatory language; leadership signals that the policy enables AI use rather than punishing it. 
  5. Train, then review annually. A policy nobody has read protects nobody, and AI moves too fast for set-and-forget. Our template builds in an annual review requirement. 

 

An AI policy is one piece of a larger governance program — framework selection (NIST AI RMF, ISO/IEC 42001), risk assessment, and technical controls complete the picture. Our guides to AI governance and AI governance frameworks cover the rest. 

How is this AI policy template better than others? 

Most AI policy templates are written by and for HR teams, and they read like conduct policies. This one was built by an IT and cybersecurity team — the same team that runs a 24/7 SOC and implements AI governance for mid-market organizations in regulated industries. It’s structured the way security policies are structured, speaks in data classification terms your IT team already uses, and covers the threats an HR template won’t: shadow AI, prompt injection, DLP, and autonomous agents. 

Should my AI policy ban ChatGPT? 

Not necessarily. Rather, the policy should distinguish account types instead. Consumer and free-tier AI accounts are typically prohibited for business data because inputs may leave your control, while enterprise tools accessed through your corporate tenant can be approved for internal-use data. The distinction that matters is the tenant and data handling terms, not the product name. 

Do mid-sized companies need an AI policy? 

Yes. Mid-market organizations face the same data exposure and regulatory obligations as enterprises — often under frameworks like HIPAA, CMMC, or GLBA — but with smaller security teams, which makes clear rules and an approved-tools list more important, not less. 

What is an AI acceptable use policy? 

An AI acceptable use policy is the section of an AI policy (or a standalone document) that defines the permitted business uses of AI tools, the data that may be entered into them, and prohibited uses such as processing confidential information in consumer tools or generating misleading content. In our template, this is Section 1 of the Policy Statement. 

Ready to go beyond the template?

Our AI governance consulting team helps mid-market organizations select frameworks, implement controls, and roll out AI safely — or start with our free AI Readiness Assessment. 

Contact Us Now →

Moving forward with AI- Corsica Technologies
AI Policy Template - FREE Download - Corsica Technologies

Ready to download the template?

Ready to talk to an expert?

We’ll respond within 1 business day, or you can grab time on our calendar.