AI usage policy template
Most AI policies are a PDF that circulates once and is never opened again — which is a problem, because this is the rare document whose value is entirely in being current. This one is a working document: eight short sections, checkboxes that mean something, and a progress gauge that shows how much of it your organisation has actually decided. Fill it in below, in your browser, with no account and nothing leaving your machine.
Opens the real app with the template already loaded. No sign-up, no upload, no install.
The policy, in full
This is the actual template, not a summary of it — the eight sections below are what opens when you click above. It is deliberately short. A policy that takes a quarter to write is a policy that governs nothing for a quarter, in a field that moves faster than that.
1. Scope — who and what it covers
Who it applies to (staff, contractors, interns), which tools are covered, and a version and date.
The trap is the middle term. Policies get written for “employees” and the heaviest AI users in a small company are frequently the freelancers and the interns — the two groups nobody onboarded and nobody told. The second trap is the version line: without a date, nobody can say which version they agreed to, and every later argument about who knew what becomes unresolvable.
2. Approved tools
- Tool 1 — approved for what
- Tool 2 — approved for what
- Personal accounts — allowed or not, decided
Note the phrasing: approved for what, not simply approved. “We use Claude” is not a rule; “Claude for drafting and summarising, never for anything that goes to a customer without a human pass” is.
And the personal-accounts line is the one that decides whether the whole document works. Banning AI outright is the option that performs worst in practice: the work still gets done with AI, on personal accounts, on personal devices, with company data, and with zero visibility. Deciding it explicitly — either way — beats leaving it unsaid.
3. Data rules
- Never paste — customer personal data, credentials, contracts
- What may be pasted, in plain words
- Where the data goes, and whether it trains a model
“Do not paste confidential information” is the sentence that appears in almost every AI policy and enforces nothing, because no two people classify the same document the same way. Name the categories instead. Three concrete nouns beat a paragraph of principle.
The second line matters as much as the first and is usually missing: a policy that only says never leaves people guessing on everything else, and guessing resolves in favour of whatever is quickest. Write down what is fine — public marketing copy, your own code, anonymised extracts — and the prohibition becomes usable.
The third line is a procurement question, not a staff one, and it has a real answer per tool: consumer tiers and business tiers frequently differ on whether prompts are retained or used for training. Someone has to look it up once and write the answer here.
4. Accountability
- Whoever publishes AI output owns it
- Output touching money, law or safety is reviewed by a named human
The first line exists to close one specific sentence: “the AI got it wrong.” That is not a defence anyone will accept from you — not a client, not a regulator, not a court. Writing it down in advance is what stops it being tried.
The second line is where most policies go soft. “Reviewed by the team” means reviewed by nobody. The word that does the work is named: a person, not a function. This is the same failure as an AI pilot with no owner, and it fails the same way — silently, and only visibly once something has already shipped.
5. Disclosure
- When we tell a client that AI was involved
- The rule for candidates, and for public content
Client disclosure is usually the part people think of, and usually the least urgent: most clients assume it already. The two that get forgotten are the two where expectations are moving fastest.
Candidates — if AI touches screening, ranking or interview summarisation, that is a decision about a person, and several jurisdictions now treat it differently from drafting an email. Public content — every platform you publish on has its own rule about labelling synthetic media, and they do not agree with each other. One line each, decided once, saves a scramble later.
6. Skills
- Everyone trained once, with real examples
- A shared prompt library exists
This section is in the template because a policy that forbids without teaching produces exactly one outcome: shadow usage. People do not stop using a tool that saves them two hours; they stop telling you about it.
“With real examples” is load-bearing. Training on toy prompts transfers nothing. Training on the actual documents someone writes every week is what turns a rollout into a habit — and it is also, in practice, how a policy gets read.
If you operate in the EU, staff AI literacy has moved from good practice to an explicit expectation under the AI Act. Check what applies to your organisation — that is the kind of question this template is designed to surface, not to answer.
7. Incidents
- Where to report a bad AI outcome
- Who can suspend a tool
Without a reporting path, you find out about the bad outcome from the client. With one, you find out from the person who noticed. The path has to be somewhere people already are — a channel, an address — and it has to be blameless in fact and not only in wording, or it will be used once.
The second line is the one nobody thinks about until the morning they need it: when a tool starts behaving badly, who is allowed to say stop, today, without a meeting?
8. Review
- Reviewed every six months
- Read by legal or the DPO
Six months is not a ritual, it is a bet about how fast the ground moves — and in this field it is an optimistic one. An AI policy dated eighteen months ago is worse than no policy, because it provides assurance that is no longer true: the tools it approves may have changed their data terms, and the tools people actually use may not be in it at all.
This is also the strongest argument for the document being editable rather than a PDF. A review is only cheap if the thing being reviewed can be changed in five minutes by the person who noticed.
Fill it in here
Below is the real application, running in this page with the template already open. Click a node and type. Tab adds a child, Enter adds a sibling, and ticking a checkbox moves the progress gauge in the toolbar — which is the fastest honest answer to “how far along is our AI policy?”
The AI usage policy, editable — nothing is uploaded, no account
.tabtree file to your disk, and automatic backup to a folder. Those
unlock with the licence.
Getting it adopted, not just written
- Fill sections 2 and 3 alone, first. Approved tools and data rules are 80% of the document and the only two that change anyone's Monday. Bringing a blank policy to a meeting produces a discussion about the policy.
- Take section 3 to whoever owns the customer data. The line about whether prompts are retained or train a model is usually not yours to answer, and it is the one that quietly decides which tools survive the list.
- Name humans in section 4 in the room. If nobody will take review duty for output touching money or law, that is the finding — write it down rather than assigning it to “the team”.
- Book the review before you publish it. Section 8 is the only one that protects the other seven, and it is the only one that costs nothing today.
A practical note on rollout: press F5 and the document becomes a presentation, one slide per section. It is the same document again — useful when the policy needs a ten-minute readout at an all-hands rather than an attachment nobody opens.
Why this is not a PDF
A policy you cannot edit gets superseded by reality within a quarter and keeps being circulated anyway. This one is a document you keep: the open decisions are checkboxes, the progress gauge shows how much has actually been decided, and the six-month review is a change rather than a rewrite.
That last part is the actual design decision. TabTree is one HTML file — you double-click it and it runs, offline, with no account and no server. An AI policy names your tools, your data categories, your incidents and your people; it is exactly the kind of document that should not be sitting in someone else's database while you write it. Nothing here is uploaded, and you can prove it by turning off your Wi-Fi before you start.
Free forever: all six views, all 87 templates, ten maps synced across your devices, and image, video and PDF export. Pro is $9/month for unlimited sync, AI credits and the Claude connector — 14 days free, no card.
Common questions
What should an AI usage policy contain?
Eight things, and they fit on one page: who it applies to and which tools are covered; which tools are approved and whether personal accounts are allowed; what may never be pasted and what may; who owns AI output once it ships; when a client, a candidate or a reader is told AI was involved; what training everyone has had; where a bad outcome gets reported and who can suspend a tool; and the date of the next review. If it does not name a person for each of those, it is a statement of intent.
Do we need one if we only use a single tool?
The number of tools is not what creates the exposure — pasted data and unreviewed output are. One approved tool with a clear rule about customer data and a named reviewer for anything touching money, law or safety is a real policy. Banning everything is the version that performs worst, because the usage simply moves to personal accounts.
Is the template free?
Yes, and it opens in the demo above with nothing uploaded and no account. The demo holds back only the exports and the saving. The same is true of every other framework the app ships — the AI adoption framework, the Business Model Canvas, the Lean Canvas and the rest are all on the frameworks page. If you would rather see the app first, the set-up guide covers the backup folder and sharing.