PolicyFree · no accountEU AI ActISO/IEC 42001
AI Acceptable Use Policy
A policy for staff use of AI tools: permitted and prohibited uses, data handling, disclosure and reporting, with the prohibited practices drawn from the law.
What's inside
- Scope, roles and definitions
- Permitted and prohibited uses, the latter drawn from every recorded prohibited-practice duty
- Data, confidentiality and disclosure rules
- Reporting, review and enforcement, with placeholders
Preview
The sheets and sections of version v1, as built. Columns marked ▾ have a dropdown; ƒ is a formula.
Document outline (DOCX)
- 1. Purpose and scope
- 2. Definitions
- 3. Permitted uses
- 4. Prohibited uses
- 5. Data and confidentiality
- 6. Disclosure
- 7. Competence and training
- 8. Reporting and enforcement
- 9. Review
- Duties this policy serves
- Do not deploy or provide AI for prohibited practices
- Developers and deployers must not use AI to incite self-harm, harm to others or crime
- Governmental entities must not use AI for social scoring
- Governmental entities must not use AI for biometric identification from public data without consent where it infringes rights
- Developers and deployers must not use AI with the intent to unlawfully discriminate against a protected class
- Developers and distributors must not build AI intended to produce child sexual abuse material or unlawful sexual deepfakes
Duties this template covers (26)
Each is cited in the file with its source reference and a link back to the record.
- Establish accountability processes and a risk-management process (guardrails 1 and 2)
- Frontier developers must protect employees who report catastrophic-risk concerns
- Do not deploy or provide AI for prohibited practices
- Ensure AI literacy of staff operating AI systems
- Use high-risk AI as instructed, monitor it and inform affected people
- Providers must meet the full set of provider duties for high-risk AI
- Providers must supply conformity evidence and log access to authorities on request
- Non-EU providers must appoint an EU authorised representative for high-risk AI
- Deployers, distributors and importers must assume provider duties when they rebrand or substantially modify high-risk AI
- Law-enforcement deployers must obtain authorisation for post-remote biometric identification and report annually
- Providers of GPAI models must notify the Commission within two weeks of meeting the systemic-risk threshold
- Non-EU providers of GPAI models must appoint an EU authorised representative
Legal basis
Version history
| Version | Built | Dataset | What changed |
|---|---|---|---|
| v1 | 7c0835db52c1 | First version, built from dataset 7c0835db52c1. |
Only the latest version is served. A rebuild that changes the content adds a version; a rebuild that does not is skipped.
Frequently asked questions
- Is the AI Acceptable Use Policy free?
- Yes. Download the DOCX without an account, under CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.
- What is it generated from?
- Version v1 was built on 26 September 2026 from dataset 7c0835db52c1: 6 recorded duties are cited in it, drawn from 11 instruments. Every row that cites a duty links to the record, and the record links to the official source.
- How will I know when it changes?
- The library is rebuilt daily. When a change to the records reaches this template it gets the next version, a changelog in the version history below, an entry in the AI policy updates hub and the templates feed, and a line in the weekly digest for subscribers of the templates topic.
- Does completing it make us compliant?
- No. It is an informational resource, not legal advice; it helps produce the evidence a regulator, customer or auditor asks for. Whether a duty applies to you is a judgement the template cannot make.
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.
Frequently asked questions
- Is the AI Acceptable Use Policy free?
- Yes. Download the DOCX without an account, under CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.
- What is it generated from?
- Version v1 was built on 26 September 2026 from dataset 7c0835db52c1: 6 recorded duties are cited in it, drawn from 11 instruments. Every row that cites a duty links to the record, and the record links to the official source.
- How will I know when it changes?
- The library is rebuilt daily. When a change to the records reaches this template it gets the next version, a changelog in the version history below, an entry in the AI policy updates hub and the templates feed, and a line in the weekly digest for subscribers of the templates topic.
- Does completing it make us compliant?
- No. It is an informational resource, not legal advice; it helps produce the evidence a regulator, customer or auditor asks for. Whether a duty applies to you is a judgement the template cannot make.