Agency AI Policy Template
Use this template to create an internal policy governing how an organization evaluates, approves, uses, monitors, and manages artificial intelligence tools.
Policy Record
| Field | Value |
| Organization | [Organization Name] |
| Policy Title | [AI Acceptable Use Policy / AI Governance Policy] |
| Policy Owner | [Department, Executive Sponsor, IT, Legal, or AI Governance Lead] |
| Policy ID | [policy identifier] |
| Effective Date | [Month Day, Year] |
| Review Cycle | [Annual / Semiannual / As Needed] |
| Status | Draft |
| Audience | Employees, contractors, vendors, and authorized users |
| Last Reviewed | [Month Year] |
Purpose
This policy establishes expectations for responsible, secure, transparent, and accountable use of artificial intelligence tools and AI-enabled services.
Scope
Policy Principles
Human accountability remains in place.
AI should support—not replace—authorized human judgment.
Sensitive information must be protected.
AI-generated outputs require appropriate review.
AI use must comply with applicable law, policy, records, privacy, accessibility, and security requirements.
Approved AI use cases must have a clear business purpose.
Use of AI must support fairness, transparency, and public trust.
Approved Uses
Examples of generally approved uses may include:
Drafting routine communications for human review
Summarizing approved documents
Organizing internal knowledge
Creating training outlines
Drafting checklists and workflow guides
Supporting research and brainstorming
Assisting staff with non-sensitive administrative tasks
Restricted Uses
The following uses require additional review, approval, or safeguards:
Public-facing chatbots
Procurement or contracting support
Policy or legal research
Use involving resident, customer, employee, student, patient, or vendor data
Content affecting public services or program decisions
Use involving financial, health, demographic, legal, or protected information
AI-assisted communications presented as official guidance
Prohibited Uses
The organization prohibits:
Uploading confidential, protected, or restricted information into unapproved AI tools
Using AI to make final employment, benefits, eligibility, enforcement, disciplinary, or legal decisions without authorized human review
Representing AI-generated content as verified when it has not been reviewed
Using AI tools in a way that violates law, contract, policy, privacy, accessibility, or security requirements
Using unapproved AI systems for official organizational work
Data Handling Requirements
Users must:
Use only approved AI tools for organizational work.
Follow applicable data-classification rules.
Avoid entering confidential, protected, sensitive, or personally identifiable information unless formally approved.
Review vendor data-retention, training, and deletion practices.
Report suspected data exposure or misuse immediately.
Human Review Requirements
AI-generated content must be reviewed before it is:
Sent externally
Published publicly
Included in official records
Used in reports, recommendations, procurement documents, or decisions
Relied upon for legal, compliance, financial, safety, or policy purposes
Approval Process
Step 1: Define the Use Case
Describe the business need, expected value, users, affected stakeholders, and proposed AI tool.
Step 2: Assess Risk
Review privacy, security, records, legal, operational, fairness, accessibility, and public-trust considerations.
Confirm that the tool meets organizational procurement, data, security, and governance requirements.
Step 4: Approve, Modify, or Decline
Document the decision, responsible owner, safeguards, and conditions for use.
Step 5: Monitor and Review
Periodically evaluate the tool, vendor, results, incidents, and continued suitability.
Staff Responsibilities
Staff are responsible for:
Following this policy and related procedures
Using approved AI tools appropriately
Reviewing AI outputs before relying on them
Reporting errors, incidents, suspected misuse, or data concerns
Completing required AI training
Seeking guidance when unsure whether a use case is permitted
Enforcement
Violations of this policy may result in removal of tool access, additional training, corrective action, contract remedies, or other appropriate responses.
Revision History
| Version | Date | Change | Owner |
| 0.1 | [Month Year] | Initial draft | [Name or role] |