AIWE

Guides · Updated October 4, 2026

What should an AI acceptable use policy include?

The short answer

An AI acceptable use policy should say who it covers, which tools are approved and how new ones are approved, what information may go into them, which work needs human review, whether AI may be used in employment decisions, how recordings and notetakers are handled, who owns the work, what happens when the rules are broken, and when the policy is reviewed. Each employee should acknowledge it in writing.

1. Who and what it covers

Employees, contractors and temporary staff, on company devices and personal ones, whenever they are doing company work. Define AI tools broadly enough to include assistants built into software you already use.

2. Approved tools, and how to get a new one approved

List the approved tools and the account or plan each one must be used on. Name the person who approves new tools and say how long a request should take, so people ask instead of working around it.

3. Information rules

Sort information into a few plain categories (public, internal, confidential, personal) and say which categories may go into which tools. This is the section that prevents most of the damage.

4. Human review and disclosure

Say which work a person must check before it leaves the company, and when customers or clients must be told that AI was used. Some client contracts already require this.

5. AI in employment decisions

Say whether AI may be used to screen, rank or evaluate applicants and employees. If it may, say what notice is given, who reviews the outcome, and how unfair results are checked. In Ontario, employers with 25 or more employees must say in public job postings whether AI is used to screen, assess or select applicants. In Quebec, people must be told when a decision about them is made by automated processing alone.

6. Recordings, notetakers and monitoring

Say whether meeting assistants may join calls, and require that everyone on the call is told before recording starts. In Ontario, an employer with 25 or more employees must already have a written policy on electronic monitoring of employees; if AI tools monitor employees, that policy should say so.

7. Ownership and confidentiality

Confirm that work produced with AI on the job belongs to the company, and that confidentiality duties apply to what is typed into a tool exactly as they apply to an email.

8. Breaches and how they are handled

Say how employees report a mistake, such as information entered into the wrong tool, and that reporting quickly is expected and treated fairly. Then say what happens when the rules are broken deliberately.

9. Ownership of the policy and its review date

Name the person responsible and set a review date, at least yearly. Tools and laws in this area change faster than most policies.

Sources

This guide is general information for employers in Canada, not legal advice. Standard Practice is not a law firm. Laws change and depend on the province where your employees work; take advice from an employment lawyer on your own situation.

See where AI meets your business

The free AI Workplace Exposure Assessment takes 7 to 10 minutes. It asks about your kind of work and returns an exposure score, the findings behind it and your first actions. No sales call.