Agency AI Policy Template
Use this template to create an internal policy governing how an organization evaluates, approves, uses, monitors, and manages artificial intelligence tools.
Policy Record
| Field | Value |
|---|---|
| Organization | [Organization Name] |
| Policy Title | [AI Acceptable Use Policy / AI Governance Policy] |
| Policy Owner | [Department, Executive Sponsor, IT, Legal, or AI Governance Lead] |
| Policy ID | [policy identifier] |
| Effective Date | [Month Day, Year] |
| Review Cycle | [Annual / Semiannual / As Needed] |
| Status | Draft |
| Audience | Employees, contractors, vendors, and authorized users |
| Last Reviewed | [Month Year] |
Purpose
This policy establishes expectations for responsible, secure, transparent, and accountable use of artificial intelligence tools and AI-enabled services.
Scope
This policy applies to:
- Employees
- Contractors
- Temporary staff
- Consultants
- Vendors using organizational systems or data
- Public-facing AI services operated on behalf of the organization
Policy Principles
- Human accountability remains in place.
- AI should support—not replace—authorized human judgment.
- Sensitive information must be protected.
- AI-generated outputs require appropriate review.
- AI use must comply with applicable law, policy, records, privacy, accessibility, and security requirements.
- Approved AI use cases must have a clear business purpose.
- Use of AI must support fairness, transparency, and public trust.
Approved Uses
Examples of generally approved uses may include:
- Drafting routine communications for human review
- Summarizing approved documents
- Organizing internal knowledge
- Creating training outlines
- Drafting checklists and workflow guides
- Supporting research and brainstorming
- Assisting staff with non-sensitive administrative tasks
Restricted Uses
The following uses require additional review, approval, or safeguards:
- Public-facing chatbots
- Procurement or contracting support
- Policy or legal research
- Use involving resident, customer, employee, student, patient, or vendor data
- Content affecting public services or program decisions
- Use involving financial, health, demographic, legal, or protected information
- AI-assisted communications presented as official guidance
Prohibited Uses
The organization prohibits:
- Uploading confidential, protected, or restricted information into unapproved AI tools
- Using AI to make final employment, benefits, eligibility, enforcement, disciplinary, or legal decisions without authorized human review
- Representing AI-generated content as verified when it has not been reviewed
- Using AI tools in a way that violates law, contract, policy, privacy, accessibility, or security requirements
- Using unapproved AI systems for official organizational work
Data Handling Requirements
Users must:
- Use only approved AI tools for organizational work.
- Follow applicable data-classification rules.
- Avoid entering confidential, protected, sensitive, or personally identifiable information unless formally approved.
- Review vendor data-retention, training, and deletion practices.
- Report suspected data exposure or misuse immediately.
Human Review Requirements
AI-generated content must be reviewed before it is:
- Sent externally
- Published publicly
- Included in official records
- Used in reports, recommendations, procurement documents, or decisions
- Relied upon for legal, compliance, financial, safety, or policy purposes
Approval Process
Step 1: Define the Use Case
Describe the business need, expected value, users, affected stakeholders, and proposed AI tool.
Step 2: Assess Risk
Review privacy, security, records, legal, operational, fairness, accessibility, and public-trust considerations.
Step 3: Review Vendor or Tool
Confirm that the tool meets organizational procurement, data, security, and governance requirements.
Step 4: Approve, Modify, or Decline
Document the decision, responsible owner, safeguards, and conditions for use.
Step 5: Monitor and Review
Periodically evaluate the tool, vendor, results, incidents, and continued suitability.
Staff Responsibilities
Staff are responsible for:
- Following this policy and related procedures
- Using approved AI tools appropriately
- Reviewing AI outputs before relying on them
- Reporting errors, incidents, suspected misuse, or data concerns
- Completing required AI training
- Seeking guidance when unsure whether a use case is permitted
Enforcement
Violations of this policy may result in removal of tool access, additional training, corrective action, contract remedies, or other appropriate responses.
Related OKF Resources
Revision History
| Version | Date | Change | Owner |
|---|---|---|---|
| 0.1 | [Month Year] | Initial draft | [Name or role] |