//Question

What belongs in an enterprise AI acceptable use policy?

Posted on 04th September, 2026

Harry

Harry

//Answer

Eleven sections, written so a non-technical employee can determine whether a specific action is permitted without asking. Most AI acceptable use policies fail that test because they state principles rather than rules, which leaves every judgment call to the individual and produces the shadow AI they were written to prevent.

  • Scope and definitions. What counts as an AI tool, including embedded features in approved software and browser extensions.

  • Approved tool tiers. A named list, not a category description, with the tier each tool sits in.

  • Data rules per tier. Which data classifications may enter which tier. This is the section employees actually consult.

  • Prohibited uses. Named and specific: consequential decisions about people, legal or medical advice to customers, generating code for regulated systems without review.

  • Disclosure requirements. When AI involvement must be labeled, internally and to customers.

  • Human review. Which output classes require review before use, and what review means.

  • Agent permissions. Who may connect an agent to a system, and who approves write access.

  • Coding assistant rules. Repository scope, secret handling, MCP server installation, and review requirements for generated code.

  • IP and records. Ownership of outputs, and retention obligations for AI-assisted work.

  • Incident reporting. What to report, where, and the explicit statement that reporting an unsanctioned tool carries no penalty.

  • Enforcement. What happens on violation, stated plainly.

Add a sanctioned alternative next to every prohibition, or the policy relocates usage to personal devices.

Akto Atlas provides the enforcement visibility a policy requires, showing which tools are actually in use and where usage falls outside the approved tiers.

A policy nobody can enforce is a document produced for an auditor. Write it to be checkable.

Comments