A short, adoptable AI acceptable use policy for a Canadian organisation. Copy it, put your own name in the square brackets, cut what does not apply, and take it to whoever signs things. It is free and there is nothing to fill in first.
Before you use it
A template is a starting point, not a decision
This is a drafting aid, not legal advice, and we are not your lawyers. It will not fit every organisation as written. The value is not in adopting it unchanged — it is in the arguments you have while deciding which bits you disagree with.
If it would help to have someone independent read your version, we will do that for nothing. That offer has no catch and no follow-up sequence attached to it.
[ORGANISATION] — Acceptable use of artificial intelligence
Approved by [NAME, ROLE] on [DATE]. Next review [DATE + 12 MONTHS].
1. Why this exists
People at [ORGANISATION] are already using AI tools. This policy sets out which ones are approved, what may and may not be put into them, and who to ask when it is not obvious. It applies to every employee, contractor and volunteer, and it covers AI built into products we already license as well as tools someone signs up for separately.
2. Approved tools
Only tools on the approved list may be used for [ORGANISATION] work. The list is maintained by [ROLE] and is available at [LOCATION].
[List each approved tool, what it may be used for, and whether it may touch personal information. If the list is empty today, say so and set a date to fix it.]
Anyone may request that a tool be added. Requests go to [ROLE] and are answered within [N] working days. Using an unapproved tool for work is not a disciplinary matter in itself — not asking is.
3. What must never be entered into an AI tool
Unless a tool is explicitly approved for that category, do not enter:
- Personal information about identifiable people, including colleagues, clients and job applicants
- Health, financial or other sensitive personal information
- Anything covered by a confidentiality obligation to a client or partner
- Credentials, keys, tokens or configuration that would let someone into our systems
- Unpublished commercial information: pricing, bids, contracts, plans
If you are unsure whether something counts, it counts. Ask [ROLE].
4. Decisions about people
No decision that materially affects an individual may be made exclusively by automated processing without [ROLE] approving it in advance. This includes decisions about hiring, performance, credit, eligibility, pricing and access to services.
Where such a decision is approved, we must tell the person it was made that way, and on request tell them what personal information was used and the main reasons behind it, and give them a route to put their case to a person who can change the answer. In Quebec these are legal requirements under Law 25 and have been since September 2023.
5. Human responsibility for output
AI output is a draft, never a decision. The person who uses it owns it. Check facts, figures, citations and names before anything leaves [ORGANISATION]. Do not represent AI output as your own professional judgement where a client is relying on that judgement.
6. Client and contractual limits
Some clients prohibit AI processing of their information, or require notice. Before using an AI tool on client work, check the contract. Where we cannot tell, ask [ROLE] rather than assume.
7. Reporting
Tell [ROLE] promptly if you put something into an AI tool that you should not have, or if you see output that is wrong in a way that could cause harm. Reporting quickly is always the right call and will not be held against you. Nothing is fixed by staying quiet, and a great deal gets worse.
8. Who is responsible
- [ROLE] maintains the approved list, answers questions and reviews this policy annually.
- Managers make sure their teams have read it and know who to ask.
- Everyone is responsible for what they enter and for checking what comes back.
9. Review
This policy is reviewed at least every twelve months, and sooner if the law changes or we adopt a materially different tool. Record the review date even when nothing changes — an unreviewed policy and a reviewed one look identical until somebody asks.
Where this is heading: the federal government is consulting until 23 September 2026 on AI transparency — labelling AI-generated content, telling people when they are dealing with a machine, reporting AI incidents, and logging what AI agents do. None of it is law, and a policy written today does not need to anticipate it. But the inventory underneath it is the same one this policy asks you to keep. What the five proposals would mean in practice →
Send us your version
Adapt it, then send it over and we will read it properly and come back with what we would change. No charge, no obligation, and we will not add you to anything.