Mist rising off still water at the edge of a dense treeline

Business practice

AI use policy.

Answer the AI question your enterprise customers, SOC 2 auditor and cyber insurer are all asking, with one document your team has actually signed. You get an AI acceptable use policy built for SaaS and AI companies: tools tiered, data classes in plain language, a named owner and a review date.

The security questionnaire asks whether you have a written AI acceptable use policy. There's no box for "we're working on it."

The question showed up without warning, and now it's everywhere: enterprise customers' security questionnaires and vendor reviews, your SOC 2 audit, the DPA a customer's legal team sends over, and your cyber insurance renewal. It's usually a yes or no field. Answering no doesn't fail you on the spot. It moves you into a category with more questions, a longer review, a slower deal and, at renewal, sometimes a different premium.

Within a few weeks the answer is yes, and it holds up when someone reads past the first page. Tools are tiered, data classes are defined, everyone on your team has acknowledged the policy in writing, and you can hand the whole thing to a security reviewer, an auditor or an underwriter without a cover note. The dread attached to that question goes away, and it stays away, because the policy has an owner and a review date.

The approach

Tier, classify, sign.

Tier.

Tools land in one of three tiers: sanctioned, permitted with conditions, and prohibited. A policy that bans everything gets ignored, and an ignored policy is worse than none, because it proves the rule is optional.

Classify.

The real question is never which tool. It's which data. Customer data, support tickets and call recordings, contracts and pricing, source code and API keys, and internal documents each get an explicit rule, written in language a new hire understands on the first read.

Sign.

A policy nobody acknowledged is a draft. Everyone on the team signs, the acknowledgments are filed where your auditor can find them, and the policy goes into onboarding, so the next hire signs it in their first week without anyone remembering to ask.

Mist rising off still water at the edge of a dense treeline

Recognize this

The question is already in your inbox.

  • An enterprise customer's security questionnaire asked about AI use, and you answered carefully.
  • You have a policy template saved somewhere that nobody has finished or circulated.
  • Your SOC 2 auditor asked how AI use is controlled, and the honest answer lives in a Slack thread.
  • Your team asks which tools are allowed and gets a different answer depending on who they ask.
  • A customer has started adding AI terms to their DPA or contract redlines.

The work

Four parts, and none of them optional.

The written policy

Scope, definitions, permitted and prohibited uses, review obligations, and what happens when the rule is broken. Written for your company, your customer contracts and your obligations, not a template with the name swapped in. Short enough that people finish it.

Tool tiering

A named list of the tools you sanction, the ones permitted under conditions, and the ones that aren't to be used with customer data. The list has an owner and a review date, because vendors change their terms and features all the time, and a tiering nobody revisits goes stale.

Acknowledgment and rollout

A signature page, a filing process, and a working session with the team so the policy is understood rather than merely distributed. Adoption is the deliverable. A signed page from someone who didn't read it protects nobody.

The review cadence

A named owner and a scheduled review date, so the policy stays accurate as tools change. This is the part that turns a document into governance, and it's the part most companies leave out.

Questions

Asked before, answered plainly.

Answer the question properly.

Book a first call