Guides · Updated October 4, 2026
What should an AI acceptable use policy include?
The short answer
An AI acceptable use policy should say who it covers, which tools are approved and how new ones are approved, what information may go into them, which work needs human review, whether AI may be used in employment decisions, how recordings and notetakers are handled, who owns the work, what happens when the rules are broken, and when the policy is reviewed. Each employee should acknowledge it in writing.
1. Who and what it covers
Employees, contractors and temporary staff, on company devices and personal ones, whenever they are doing company work. Define AI tools broadly enough to include assistants built into software you already use.
2. Approved tools, and how to get a new one approved
List the approved tools and the account or plan each one must be used on. Name the person who approves new tools and say how long a request should take, so people ask instead of working around it.
3. Information rules
Sort information into a few plain categories (public, internal, confidential, personal) and say which categories may go into which tools. This is the section that prevents most of the damage.
4. Human review and disclosure
Say which work a person must check before it leaves the company, and when customers or clients must be told that AI was used. Some client contracts already require this.
5. AI in employment decisions
Say whether AI may be used to screen, rank or evaluate applicants and employees. If it may, say what notice is given, who reviews the outcome, and how unfair results are checked. In Ontario, employers with 25 or more employees must say in public job postings whether AI is used to screen, assess or select applicants. In Quebec, people must be told when a decision about them is made by automated processing alone.
6. Recordings, notetakers and monitoring
Say whether meeting assistants may join calls, and require that everyone on the call is told before recording starts. In Ontario, an employer with 25 or more employees must already have a written policy on electronic monitoring of employees; if AI tools monitor employees, that policy should say so.
7. Ownership and confidentiality
Confirm that work produced with AI on the job belongs to the company, and that confidentiality duties apply to what is typed into a tool exactly as they apply to an email.
8. Breaches and how they are handled
Say how employees report a mistake, such as information entered into the wrong tool, and that reporting quickly is expected and treated fairly. Then say what happens when the rules are broken deliberately.
9. Ownership of the policy and its review date
Name the person responsible and set a review date, at least yearly. Tools and laws in this area change faster than most policies.
Sources
- Ontario: requirements related to publicly advertised job postings (Employment Standards Act)
- Ontario: written policy on electronic monitoring of employees (Employment Standards Act)
- Quebec: Act respecting the protection of personal information in the private sector (CQLR c. P-39.1), s. 12.1
- Privacy commissioners of Canada: Principles for responsible, trustworthy and privacy-protective generative AI (December 2023)
This guide is general information for employers in Canada, not legal advice. Standard Practice is not a law firm. Laws change and depend on the province where your employees work; take advice from an employment lawyer on your own situation.