Pentest Today.
security policy

AI Acceptable Use Policy

ai-acceptable-use.md·ISO 42001 · Annex A

Generate an AI Acceptable Use Policy covering approved tools, what data may go into them, prohibited uses, and the review of AI-assisted output before it ships.

What's in the policy

Sets the rules for staff using AI tools: what may be pasted into them, what must never be, and who approves new tools.

✓Approved AI tools and how a new one gets approved
✓Data classes permitted and prohibited as input
✓Customer data and secrets handling rules
✓Review requirements for AI-assisted output
✓Prohibited uses and enforcement
Mapped toISO 42001NIST AI RMFSOC 2 (CC1.1)

What the document actually says

These are the standing requirements every generated copy of the document is written from — the clause text itself, not a description of it. The document you receive is drafted on top of them: it expands on them and fills the current-state detail from your intake, and the generator is instructed to keep them, to state them fully, and never to claim a certification or invent a fact you did not supply.

Where the line sits on customer and secret data

- Only **approved AI tools** are used for company work; new tools are requested and reviewed before use. - **Restricted or confidential data — including customer data, secrets, and personal data — is not entered into an AI tool** unless that specific tool is approved for that data class and contractual protections (e.g., no-training, retention limits) are in place. - Users **critically review AI output** before relying on it; AI assists but does not replace required human judgment, and users remain accountable for their work. - AI-generated code is reviewed and tested to the same standard as human-written code before it reaches production.
ISO 42001 Annex A · SOC 2 CC1.1 — the sharpest line in the document: restricted or confidential data stays out of an AI tool unless that specific tool is approved for that data class, with no-training and retention terms already in place, and AI code is held to the same bar as anyone's.

What's off-limits outright

- Using AI to generate content that is illegal, infringes third-party rights, or violates company policy. - Relying on AI output for consequential decisions without human review. - Bypassing this policy by using personal accounts or unapproved tools for company work.
ISO 42001 Annex A · SOC 2 CC1.1 — three bars stated outright: unlawful or rights-infringing generation, an unreviewed AI output driving a consequential decision, and routing company work through a personal account to dodge the policy.

What the auditor asks for alongside it

Whether the data-class rule actually stops a customer record from reaching an AI tool, not just that the sentence exists.
The AI Customer Data Handling Statement, generated from the same customerDataToAi answer this document's rule is written against. It states in one line whether customer data reaches an AI tool at all — the fact a reviewer checks the staff rule against, not the rule restated.
Evidence that AI-generated code is actually reviewed to the same bar as anything else before it ships.
Your pull-request history, read against the Secure SDLC Policy's peer-review gate — the same gate this document's code clause points to instead of duplicating. There is no separate, lighter review lane for a commit because a model wrote the first draft; the reviewer's comment is the record either way.
Which tools staff are actually allowed to use, so 'approved AI tools' names a list rather than a category.
The AI Vendor / Subprocessor Summary, which lists the same vendors the sibling AI Vendor Review Policy inventories in full. This document sets the staff-facing half of the rule — nothing goes in until the tool is on that list.
The answer a customer receives when they ask whether your staff use AI tools at all.
The drafted response to that question. Phrased around 'AI tools' or 'AI features' rather than the bare word 'policy', it resolves to the AI-tools-usage topic and is written from the aiToolsUsed and aiFeaturesInProduct answers — the same two fields behind the AI Usage Inventory.

Where these documents go stale

This document's rules read the same on the day they are approved and the day someone routes around them, and the two are hard to tell apart from the policy alone. An approved-tool list is really one browser tab away from an unapproved one — a consumer AI product staff already use at home is a paste away from seeing a customer record, and nothing in the sentence stops that except whether anyone is paying attention. New tools arrive faster than the review meant to gate them: a team trials a coding assistant for a sprint before anyone checks whether it is approved for the repositories it can now read. The code-review clause is the other soft spot — a change flagged 'AI-assisted' can quietly get treated as lower-risk and reviewed less carefully, which is exactly backwards from what the clause requires. Re-validate by sampling recent AI-assisted commits against the review record, not by re-reading the rule.

From intake to enterprise-ready in three moves
01

Tell us about your stack

Answer a short intake — cloud, data types, tools. No agents to install.

02

We generate a tailored draft

Not a blank template: a document written for your environment and pre-mapped to controls.

03

Review, edit, and share

Export it or attach it straight to an enterprise security review or questionnaire.

AI Acceptable Use Policy, answered

What is an AI acceptable use policy?

An AI acceptable use policy states which AI tools staff may use for company work, what data may and may not go into them, and what review AI-assisted output owes before anyone relies on it. It is the staff-facing companion to the AI Governance Policy, written for the person opening the tool rather than the program behind it.

What data can't be entered into an AI tool?

Restricted or confidential data — customer data, secrets, and personal data — unless the specific tool being used is approved for that data class and no-training and retention terms are already in place. The rule is written against the tool and the data class together, not against AI use in general.

Does this cover AI coding assistants?

Yes. AI-generated code is required to be reviewed and tested to the same standard as human-written code before it reaches production — no separate, lighter bar for a commit because a model wrote the first draft. The review gate itself lives in the Secure SDLC Policy; this document sets the expectation that AI output owes it.

How is this different from the general Acceptable Use Policy?

The Acceptable Use Policy sets conduct rules for any company system — devices, credentials, incidental personal use, and what monitoring the company reserves — and mentions AI only to point here. This document is where the specifics live: which tools staff may use, which data classes each one may see, and what review AI output owes before anyone relies on it.

Who decides which AI tools are approved?

A new tool has to be requested and reviewed before use — the same review gate the AI Governance Policy names an owner for. This document sets the staff-facing rule that only approved tools are used for company work; who runs that review and records the decision is that other policy's job.

Does using an approved AI tool remove the need to check its output?

No. Users are required to critically review AI output before relying on it — approval covers the tool and the data it may see, not a guarantee about what it produces. AI assists but does not replace required human judgment, and the person who relied on the output stays accountable for it.

How does Pentest Today generate the policy?

Answer a short intake about your stack and we generate a tailored draft — not a blank template — pre-mapped to the controls your framework requires. You review, edit, and export it.

Can I edit the generated policy?

Yes. Every document is a starting draft you can edit, brand, and export. It's written to be review-ready but stays fully under your control.

Free · no account

Start your Pentest

Our agent swarm and human experts test your endpoints and deliver an audit, fast.

Generate your full security policy pack.

Get the ai acceptable use policy plus everything else an enterprise security review asks for — generated from your real environment.