Employee AI Acceptable Use Policies: A Practical Drafting Guide for In-House Counsel
A clause-by-clause drafting guide for GCs to build an employee AI acceptable use policy covering shadow AI, data leakage, IP ownership gaps, tiered vendor approval, monitoring, enforcement, and NDA alignment.
Every growth-stage company is being asked the same question by boards, enterprise customers, and contract questionnaires: Do you have an AI policy? If your answer is no — or if you have a one-page memo that says "use AI responsibly" — you are exposed. Employees are already pasting confidential source code, client contracts, and unreleased financials into ChatGPT personal accounts, and most legal teams have no way to detect it, let alone stop it. This is the shadow AI problem, and it is not theoretical: between March 2023 and March 2024, the volume of corporate data employees entered into AI tools surged 485%, and 73.8% of ChatGPT sessions at work used personal accounts that lack enterprise privacy protections (Cyberhaven Q2 2024 AI Adoption and Risk Report).
This guide gives in-house counsel a clause-by-clause framework for drafting an employee AI acceptable use policy (AUP) that actually changes behavior — not one that collects dust in a shared drive. We cover the five drafting decisions that matter most: data classification and confidentiality, IP ownership of AI-generated work product, tiered vendor approval, monitoring and enforcement, and alignment with your existing confidentiality and NDA obligations. If you need a broader overview of AI policy components, our companion piece on building an AI use policy for general counsel walks through the seven structural sections every policy needs; this article goes deeper into the drafting mechanics.
Why You Need a Dedicated AI AUP — Not Just an IT Policy Add-On
Your existing acceptable use policy was written for email, web browsing, and maybe BYOD. It does not contemplate a tool that ingests your confidential data, trains on it, and serves your competitors a refined version of what your employees typed. Adding a line that says "AI tools are subject to existing IT policies" is not enough — it leaves every decision about what data can go into which tool to individual employee judgment, which is exactly how trade secrets end up in a public language model.
The NIST AI Risk Management Framework provides the structural anchor for your policy. The Govern function in the AI RMF calls for organizations to establish "policies, processes, procedures, and practices across the organization related to the mapping, measuring, and managing of AI risks" — and specifically requires that "legal and regulatory requirements involving AI are understood, managed, and documented" (Govern 1.1). An employee AUP is the operational document that delivers on that governance requirement. NIST released the framework in January 2023 as voluntary guidance, and it has become the de facto benchmark that regulators and auditors reference when evaluating whether a company has taken AI governance seriously (NIST AI RMF overview).
For Texas-based companies, aligning with NIST is not just best practice — it is a legal safe harbor. The Texas Responsible AI Governance Act (TRAIGA), effective January 1, 2026, provides that a person is not liable if they "substantially compl[y] with NIST's AI Risk Management Framework or similar, recognized standards" (Greenberg Traurig analysis of TRAIGA). While TRAIGA's consumer-facing provisions do not directly regulate employment contexts (the statute defines "consumer" as an individual "acting only in an individual or household context"), the safe harbor applies broadly to covered persons who develop or deploy AI systems in Texas. Building your AUP on the NIST Govern function positions you to claim that safe harbor if a regulatory inquiry ever touches your AI deployment.
Clause 1: Data Classification and Confidentiality Rules for Prompts
The first clause in your AUP should establish a simple but enforceable rule: no employee may input, upload, or disclose confidential or proprietary company information into any AI tool unless the tool is on the sanctioned list and the data classification permits that use. This means your policy must reference an existing data classification scheme — or create a minimal one inline.
At minimum, define three tiers:
- Public: Marketing materials, published documentation, publicly available data. May be used with any AI tool, including consumer-grade tools.
- Internal: Internal communications, non-public business strategies, operational data. May only be used with enterprise-tier AI tools that contractually prohibit training on customer data.
- Restricted: Trade secrets, customer personal data, source code not cleared for external use, attorney-client privileged material, unreleased financial data, HR records. May not be entered into any AI tool without written approval from Legal, and only into tools with executed DPAs and training prohibitions.
The Cyberhaven data tells you why this matters: in March 2024, 27.4% of corporate data employees entered into AI tools was classified as sensitive — up from 10.7% a year earlier. Legal documents comprised 2.4% of that sensitive data, and 82.8% of those legal documents went into risky personal AI accounts (Cyberhaven). Without a data classification clause, your policy cannot distinguish between an employee asking ChatGPT to proofread a press release and one pasting a draft acquisition agreement into a personal account.
Clause 2: IP Ownership of AI-Generated Work Product
Your AUP must address the ownership gap that AI creates. The U.S. Copyright Office's January 2025 report on AI copyrightability concluded that works generated entirely by AI are not copyrightable, and that prompts alone — even detailed iterative prompts — do not give a human enough control over the expressive output to establish authorship (U.S. Copyright Office, Copyright and Artificial Intelligence). This means that when an employee uses ChatGPT to draft a deliverable without substantial human creative modification, the company may have no copyright in the output — and your work-for-hire clause cannot assign a copyright that does not exist.
Your policy should include three drafting elements on this point:
- Define the boundary between AI-generated and AI-assisted work. AI-generated content (output produced by a tool with minimal human editorial direction) is treated differently from AI-assisted content (where an employee uses AI as a tool but makes perceptible creative choices in the final work). Only the latter is potentially copyrightable.
- Require human review and modification. State that employees must review, edit, and substantively modify AI-generated output before incorporating it into company deliverables, and that they are responsible for the accuracy and legality of the final product.
- Flag the trade secret fallback. Direct employees that AI-generated work product that cannot be copyrighted should be treated as a trade secret under company confidentiality protocols — access-controlled, labeled, and subject to NDA restrictions. Trade secret protection under the Defend Trade Secrets Act does not require human authorship, only that the information derives independent economic value from not being generally known and that the owner takes reasonable measures to maintain secrecy.
For a deeper analysis of the copyright gap, vendor assignment clauses, and the work-for-hire problem with AI outputs, see our companion article on IP ownership of AI-generated work product.
Clause 3: Tiered Vendor Approval — Sanctioned, Restricted, and Prohibited Tools
The single most common failure in AI policies is vagueness about which tools employees may use. Your AUP should establish an explicit three-tier vendor approval framework:
Tier 1: Sanctioned Tools
These are tools the company has procured through enterprise contracts, with executed Data Processing Agreements, contractual prohibitions on training with customer data, and appropriate security certifications (SOC 2, ISO 27001). Examples might include Microsoft 365 Copilot under an enterprise agreement or ChatGPT Enterprise. Employees may use these tools with Internal-classified data. The policy should name each sanctioned tool and the data tiers it is approved for.
Tier 2: Restricted Tools
These are tools that may be used only with Public-classified data and only after department-level approval. This category captures consumer-grade AI tools that have some utility for non-sensitive work (e.g., drafting a blog post from public information) but whose terms of service permit training on submitted data. The policy should state that any Restricted-tier tool may be elevated to Sanctioned only after Legal completes vendor due diligence and contract negotiation.
Tier 3: Prohibited Tools
These are tools explicitly banned from company use. This category should include any AI tool that does not offer enterprise data protection, any tool on a watchlist maintained by IT Security, and any new AI tool that has not been evaluated through the vendor approval process. The default rule is critical: any AI tool not on the Sanctioned or Restricted list is Prohibited by default.
The vendor approval workflow itself should be documented in the AUP or in an appendix. At minimum, it should specify who reviews vendor terms (typically Legal and IT Security), what certifications are required, what contractual provisions are mandatory (training prohibition, DPA, data residency), and how long the approval process takes. For guidance on the specific contract clauses to require — training data restrictions, output IP language, hallucination liability, and model deprecation — see our article on AI vendor agreement clauses.
Clause 4: Monitoring and Enforcement Without Killing Productivity
A policy that employees know is not enforced is a suggestion. But enforcement that blocks every AI tool and monitors every keystroke will drive usage further underground. The goal is visible, proportional enforcement that makes the sanctioned path easier than the shadow path.
Technical Controls
Deploy data loss prevention (DLP) tools that can detect AI tool traffic and flag sensitive data entering unapproved platforms. Configure network-level controls to block known Prohibited-tier AI tools. Route sanctioned AI tools through enterprise SSO so usage is attributable. The point is not to surveil employees — it is to make the approved path the path of least resistance.
Policy Enforcement Consequences
The AUP must state consequences for violations, and they should scale with intent and harm. An inadvertent first violation (an employee pastes an internal memo into ChatGPT not realizing it is a personal account) warrants a warning and retraining. A knowing violation (an employee uses a Prohibited tool with Restricted data after receiving training on the policy) warrants escalation to management and potential disciplinary action. A violation that results in a data breach or disclosure of trade secrets triggers the company's incident response plan and may result in termination. These consequences should be stated in the policy itself, not left to ad hoc management discretion.
Employee Attestation
Require employees to acknowledge the AUP in writing — ideally through an annual training module that includes scenario-based questions. Attestation creates a documented record that employees were informed of the rules, which is essential if you ever need to take disciplinary action or defend the company's position in a regulatory inquiry.
Clause 5: Alignment with Existing Confidentiality, NDA, and Privacy Obligations
Your AI AUP does not operate in a vacuum. It must explicitly cross-reference and align with your existing confidentiality agreements, employee NDAs, and applicable privacy laws. Three alignment points are critical:
Integration with Employee NDAs
Most employee confidentiality agreements were written before generative AI existed. They prohibit disclosure of confidential information to "third parties" — but employees may not understand that pasting a confidential document into ChatGPT constitutes a third-party disclosure. Your AUP should state that entering confidential information into any AI tool not on the Sanctioned list constitutes a breach of the employee's confidentiality obligations, and that AI tools are "third parties" for purposes of existing NDAs.
Customer and Partner Contract Obligations
If your company handles customer data under contracts that restrict disclosure or processing, entering that data into an AI tool may violate those contracts. Your AUP should require employees to verify that AI use is permitted under applicable customer agreements before processing customer data through any AI tool. For enterprise customer contracts that include data processing addenda, the AUP should cross-reference the DPA's subprocessor requirements — because many AI vendors qualify as subprocessors.
State Privacy Law Compliance
If your company monitors employee AI usage, that monitoring itself may collect personal data about employees — and state privacy laws increasingly apply to employee data. The California Consumer Privacy Act, as amended by the CPRA, removed the broad employee data exemption as of January 1, 2023, meaning that employee personal information collected through AI monitoring may be subject to consumer privacy rights (notice, access, deletion) under California law (SHRM overview of CCPA employer exemptions). Texas has its own framework: the Texas Data Privacy and Security Act (TDPSA), effective July 1, 2024, regulates the collection and processing of consumers' personal data, though it defines "consumer" as an individual acting in an individual or household context, which may exclude employment data the way TRAIGA does (Texas DIR overview of TDPSA). Even so, if your AI monitoring tools collect biometric identifiers or other sensitive data categories, state biometric privacy laws (including Texas's Capture or Use of Biometric Identifier Act, CUBI) may impose notice and consent requirements.
The practical takeaway: your AUP's monitoring provisions should be reviewed for compliance with applicable state privacy laws before deployment, and the policy should notify employees that AI usage may be monitored, consistent with applicable law.
Actionable Next Steps
If you are standing up an employee AI AUP from scratch, here is the sequence we recommend:
- Audit current usage. Before drafting the policy, find out what AI tools your employees are actually using. Work with IT Security to review network traffic, proxy logs, and SSO data. You cannot govern what you cannot see.
- Map your data classification scheme. If you do not have a formal data classification policy, build a simple three-tier version (Public, Internal, Restricted) as part of the AUP. The classification scheme is the backbone of the entire policy.
- Evaluate and tier your current AI vendors. For each tool employees are using, determine whether it meets Sanctioned-tier requirements (enterprise contract, DPA, training prohibition, security certifications). Tools that do not meet the bar go to Restricted or Prohibited.
- Draft the AUP using the five clauses above. Keep it under ten pages. Include the data classification rules, IP ownership guidance, vendor tier definitions, monitoring and enforcement provisions, and NDA/privacy alignment language.
- Align with NIST AI RMF Govern function. Document how each policy section maps to a NIST Govern subcategory. This creates the compliance record that supports TRAIGA's safe harbor and satisfies enterprise customer due diligence questionnaires.
- Roll out with training and attestation. Do not publish the policy and hope for the best. Deliver a short training module that walks employees through the data classification rules and the sanctioned tool list, and require written attestation.
- Review quarterly. The AI tool landscape changes faster than any technology we have seen. Your sanctioned and prohibited lists will be outdated within months if you do not have a refresh cadence. Assign ownership of the policy to a specific person — not "Legal" as a department.
Need help drafting or reviewing your company's employee AI acceptable use policy? We work with in-house counsel to build AI governance frameworks that hold up to board scrutiny, enterprise customer due diligence, and regulatory inquiry.