The Enterprise AI Acceptable Use Policy - Aligned to NIST AI RMF Govern and ISO 42001 A.2
An IT Acceptable Use Policy written in 2018 cannot govern AI in 2026. The named prohibited practices are different. The data-handling constraints are different. The vendor-tool universe is different. The escalation pathway is different. The literacy obligation is different. The penalty exposure is different. The Enterprise AI Acceptable Use Policy (AI AUP) is the operational instrument that translates EU AI Act Article 5, NIST AI RMF Govern, ISO/IEC 42001 Annex A.2, and the worker-rights overlay into language an employee, contractor, or vendor can read in fifteen minutes and a manager can enforce on Monday morning. This lesson is the playbook for drafting it: the section structure, the named tools allowlist, the prompt-input restrictions, the Article 14 human-oversight language, the escalation pathway, and the six mistakes that make audit-defensible AI AUPs different from the photocopied IT AUP most organizations still ship.
Why an AI AUP Must Be Separate From the IT AUP
The most common mistake in 2026 is amending the existing IT AUP with two AI paragraphs and calling it done. Schellman, A-LIGN, BSI, and KPMG ISO/IEC 42001 Stage 2 auditors flag this pattern in roughly two of every three first-time engagements. The reasons it fails are operational, not stylistic.
Different prohibited practices. The IT AUP prohibits things like sharing passwords, installing unapproved software, and using corporate equipment for illegal activity. The AI AUP must prohibit the eight Article 5(1)(a)-(h) categories: subliminal techniques, exploitation of vulnerabilities, social scoring, predictive policing solely from profiling, untargeted facial-image scraping, workplace and education emotion recognition, biometric categorization inferring sensitive attributes, and real-time remote biometric identification in public spaces by law enforcement. None of these are mentioned in any IT AUP written before 2024. They are also not optional: Article 5 has been in force since Feb 2, 2025, and Article 99(2) caps the penalty at €35M or 7% of global turnover.
Different data-handling constraints. The IT AUP says "do not share confidential data externally." The AI AUP must say "do not paste PII into a prompt that leaves the approved tenancy, do not paste PHI into any generative tool without DLP review, do not paste source code into a non-approved code-assistant without architecture sign-off, do not paste customer data into a prompt without a classification check." Prompt input is a new category of data egress that the IT AUP did not anticipate. ChatGPT, Claude, Gemini, Copilot, and a hundred shadow tools each have different data-residency commitments, different training-use defaults, and different log-retention policies. The AUP has to make the answers binary at the employee desk.
Different vendor-tool universe. The IT AUP allowlist is built around an approved software catalogue that changes a few times per year. The AI AUP allowlist changes monthly. New model releases, new enterprise tiers, new regional availability, new contractual terms, the AI vendor universe in 2026 is dynamic in a way the broader software universe is not. The AUP has to embed a refresh cadence (typically monthly review by the AI Officer, quarterly review by the AI Governance Committee, ad hoc updates on material vendor events).
Different escalation pathway. The IT AUP escalates to IT Security or to the help desk. The AI AUP escalates to the AI Officer (for tool requests, prompt-input questions, and disclosure-language questions) and to the AI Governance Committee (for ambiguous classification cases, Article 5 boundary questions, FRIA-trigger decisions, and incident-response coordination). The committee's existence is mandated under ISO 42001 clause 5 and embedded across NIST AI RMF Govern; the AUP is the document that makes the pathway visible to the workforce.
Different literacy expectation. Article 4 requires staff who deal with the operation and use of AI systems to have a sufficient level of AI literacy. The IT AUP refers to general security awareness training. The AI AUP must reference the four-tier AI literacy curriculum (executives/board, deployers/decision-makers, users/operators, affected workers/customers) and tie individual obligations to tier-appropriate training completion.
Different penalty exposure. The IT AUP backs up to general HR discipline and to security-incident exposure. The AI AUP backs up to Article 99(2) €35M/7% for Article 5 violations, Article 99(3) €15M/3% for most provider/deployer failures including Article 4 literacy and Article 26 deployer obligations, and Article 99(5) €7.5M/1% for misleading information to authorities. The exposure quantification is concrete enough that the audit committee should see it quarterly.
The AI AUP Section Structure
An audit-defensible AI AUP in 2026 has a stable section structure. The Commission's Article 50 draft guidelines, the NIST AI RMF Govern subcategories (especially Govern 1.1, 1.2, 1.5, 1.6), and ISO/IEC 42001 Annex A.2 controls (policies for AI) converge on roughly the same outline. Specific tools and prohibited-use entries differ by organization; the section structure does not.
Section 1 - Scope and Applicability
The AUP applies to employees, contractors, vendors operating on behalf of the organization, and any other person using AI systems on the organization's behalf or with the organization's data. The scope includes:
- AI systems procured from external vendors (e.g., Microsoft 365 Copilot, Anthropic Claude Enterprise, Google Workspace with Gemini, OpenAI ChatGPT Enterprise).
- AI systems built internally on top of GPAI or other foundation models.
- AI features embedded in existing enterprise software (e.g., Salesforce Einstein, Workday AI features, ServiceNow Now Assist, HubSpot AI tools).
- Personal-use AI tools accessed from corporate equipment or with corporate accounts (e.g., free ChatGPT used from a corporate browser session, Claude.ai used from a corporate device).
- Shadow-AI tools discovered through the 30-day discovery sprint that are pending evaluation.
The geographic scope explicitly includes the EU (where the AI Act applies), the U.S. (where state laws including Colorado SB 24-205, Texas TRAIGA HB 149, and NYC LL 144 apply), and any other jurisdiction where the organization operates. Multi-jurisdiction overlays are noted in the cross-walk appendix.
Section 2 - Definitions
The definitions section anchors the AUP in the regulatory vocabulary. The defined terms include:
- AI system: per Article 3(1) of the EU AI Act: "a machine-based system designed to operate with varying levels of autonomy, that may exhibit adaptiveness after deployment and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments."
- GPAI (General-Purpose AI Model): per Article 3(63): "an AI model, including where such an AI model is trained with a large amount of data using self-supervision at scale, that displays significant generality and is capable of competently performing a wide range of distinct tasks…"
- Provider, per Article 3(3): the entity that develops the AI system or has it developed and places it on the market or puts it into service under its own name.
- Deployer, per Article 3(4): a natural or legal person using an AI system under its authority, except where the AI system is used in the course of a personal non-professional activity.
- Prohibited practice: per Article 5(1): the eight categories of AI use prohibited under EU AI Act, in force since Feb 2, 2025.
- High-risk AI system, per Article 6 and Annex III: systems falling within the eight Annex III categories or used as a safety component of a product covered by Annex I.
- Sensitive data: PII, PHI, financial data (including PCI cardholder data and SOX-material financial information), trade secrets, source code, customer data, vendor data, and any data classified as confidential or restricted under the organization's data classification policy.
- Approved tool, an AI tool listed on the current AI Tool Allowlist published by the AI Officer; allowlist refresh cadence is monthly.
Section 3 - Prohibited Uses
Section 3 names what employees and contractors may not do with AI. The list is the Article 5(1)(a)-(h) prohibitions translated into operational language, plus a small set of organization-specific prohibitions.
Article 5(1)(a) - Subliminal techniques. No use of AI to deploy subliminal techniques, purposefully manipulative or deceptive techniques, with the objective or effect of materially distorting a person's behavior. Example: do not use AI to generate marketing content designed to bypass a customer's conscious decision-making, do not use AI in HR tools to nudge candidates into accepting offers through psychological manipulation.
Article 5(1)(b) - Exploitation of vulnerabilities. No use of AI to exploit any of the vulnerabilities of a person or group of persons due to their age, disability, or specific social or economic situation, with the objective or effect of materially distorting their behavior. Example: do not use AI to target elderly customers with deceptive offers, do not use AI to upsell financially vulnerable customers products they cannot afford.
Article 5(1)(c) - Social scoring. No use of AI for the evaluation or classification of natural persons based on their social behavior or known, inferred, or predicted personal or personality characteristics, where the social score leads to detrimental or unfavorable treatment unrelated to the contexts in which the data was originally generated. Example: do not build a "trustworthy employee score" that aggregates social-media signals, do not use AI to rank customers for differential treatment based on out-of-context behavior.
Article 5(1)(d) - Predictive policing from profiling. No use of AI to make risk assessments of natural persons to predict the risk of committing criminal offenses solely on profiling or assessing personality traits and characteristics.
Article 5(1)(e) - Untargeted facial-image scraping. No use of AI to create or expand facial recognition databases through the untargeted scraping of facial images from the internet or CCTV footage.
Article 5(1)(f) - Workplace and education emotion recognition. No use of AI systems to infer emotions of natural persons in the areas of workplace and education institutions, except where the use is intended for medical or safety reasons. Example: do not use AI emotion-recognition in performance reviews, do not use AI emotion-recognition in productivity monitoring, do not use AI emotion-recognition in interview scoring.
Article 5(1)(g) - Biometric categorization of sensitive attributes. No use of biometric categorization systems that categorize individually natural persons based on biometric data to deduce or infer their race, political opinions, trade union membership, religious or philosophical beliefs, sex life, or sexual orientation. Limited carve-outs apply for labelling or filtering of lawfully acquired biometric datasets and for law-enforcement purposes; the AUP references the policy team for any borderline analysis.
Article 5(1)(h) - Real-time remote biometric identification. No use of AI for the use of real-time remote biometric identification systems in publicly accessible spaces for the purpose of law enforcement (this typically applies to public-sector deployers; the AUP notes the prohibition for completeness).
Organization-specific prohibitions. Beyond Article 5, the AUP names:
- CBRN information generation. No use of AI to generate, refine, or operationalize information related to chemical, biological, radiological, or nuclear weapons. This aligns with the GPAI Code of Practice safety commitments and NIST AI 600-1 risk categories.
- CSAM generation. No use of AI to generate or refine child sexual abuse material. Cross-references applicable criminal law in every operating jurisdiction.
- Intentional discrimination. No use of AI to intentionally discriminate against protected classes under Title VII (U.S.), the Equality Act (U.K.), the EU Race Directive, or equivalent local laws.
- Unauthorized impersonation. No use of AI to impersonate any natural person without their explicit consent, except for clearly satirical or artistic contexts approved by Legal.
- Confidentiality circumvention. No use of AI to circumvent confidentiality obligations (e.g., re-prompting an external model to recover information that the policy classifies as restricted).
Section 4 - Approved-Tools Allowlist
The allowlist is the most-updated section of the AUP. It is published as an appendix or as a live web page linked from the AUP, with the AUP body referencing the current allowlist version.
A representative May 2026 allowlist for a mid-size enterprise:
- General-purpose conversational AI. Anthropic Claude Enterprise (via approved API gateway, with data-retention disabled and zero-data-retention contractual term active); OpenAI ChatGPT Enterprise (SSO-bound, data not used for training under the Enterprise terms).
- Productivity AI. Microsoft 365 Copilot Enterprise (M365 tenant-bound); Google Workspace Gemini Enterprise (Workspace tenant-bound, EU data-residency option enabled for EU employees).
- Code assistants. GitHub Copilot for Business (with public-code filter on); Cursor Pro (with privacy mode on); the internal Acme.dev IDE assistant (running on the internal model gateway).
- Image and creative AI. Adobe Firefly (commercial-safe model, C2PA marking enabled); Microsoft Designer (M365 tenant-bound); Canva Pro AI features (Canva Enterprise SSO-bound).
- Meeting AI. Microsoft Teams Copilot (M365 tenant-bound); Zoom AI Companion (Zoom Enterprise contract with data-retention disabled); Otter for Teams (Otter Enterprise contract).
- Specialized workflows. Harvey AI for Legal (Legal department only); GitHub Copilot Workspace for Engineering; HubSpot AI tools for Marketing (HubSpot Enterprise SSO-bound).
- Internal models. Acme Internal Assistant (RAG over corporate knowledge base, deployed on internal infrastructure, accessible via SSO).
Each entry on the allowlist carries metadata in the maintenance system: vendor name, tool name, contract reference, data-residency commitment, training-use commitment, log-retention period, allowed use cases, restricted use cases, owner (typically the AI Officer or a delegate), date added, last reviewed date. The AUP body does not duplicate this metadata; it references the live allowlist.
Allowlist refresh cadence. The AI Officer reviews the allowlist monthly. The AI Governance Committee reviews the allowlist quarterly with discussion of additions, removals, and ambiguous cases. Material vendor events (e.g., a new enterprise tier launching, a regulatory action against a vendor, a change to the vendor's training-use defaults) trigger ad hoc updates. Removals from the allowlist trigger a deprecation notice with a typical 30-day transition window, plus migration-path guidance for affected employees.
Section 5 - Prompt-Input Restrictions for Sensitive Data
Section 5 governs what may be entered into prompts. This is the section most often skipped or under-specified in first-pass AUPs.
PII restrictions. No PII (names, email addresses, phone numbers, addresses, government identifiers, account numbers) may be entered into a prompt unless: (a) the tool is on the approved allowlist with PII handling explicitly permitted in the tool's allowlist entry; (b) the use case is documented in the AI inventory; (c) the prompt has passed any DLP-required review for the specific use case. PII in conversation about external persons (e.g., customers, vendors, candidates) is treated more strictly than PII in conversation about the employee's own data.
PHI restrictions. No PHI (any individually identifiable health information under HIPAA, sensitive health data under GDPR Article 9) may be entered into any prompt unless: (a) the tool is on the approved allowlist with PHI handling explicitly permitted; (b) the tool has a signed BAA (Business Associate Agreement) covering the use; (c) the use case is documented and approved by the privacy office.
Financial-data restrictions. No SOX-material financial information (e.g., pre-release earnings figures, unreleased material business performance data), no PCI cardholder data (full card numbers, CVV, expiration with cardholder name), no insider information related to material non-public information about publicly traded securities may be entered into prompts. The list of restricted financial data categories is maintained by the CFO's office and referenced by the AUP.
Source-code restrictions. No proprietary source code may be entered into a non-approved code assistant. Approved code assistants are listed in the allowlist (GitHub Copilot for Business with public-code filter on; Cursor Pro with privacy mode on; the internal IDE assistant). Borderline cases (e.g., snippets of public-API integration code, generic algorithm questions) are resolved by the engineering lead in consultation with the AI Officer where the snippet contains proprietary logic.
Customer-data restrictions. No customer data classified as restricted or confidential under the organization's data classification policy may be entered into a prompt without a classification check and AI Officer sign-off for the use case. The default classification for customer data is restricted; reclassification requires documented justification.
Trade-secret and IP restrictions. No trade-secret information (e.g., proprietary algorithms, undisclosed product roadmaps, undisclosed M&A activity, undisclosed pricing strategies) may be entered into a prompt unless the tool is on the allowlist with trade-secret handling explicitly permitted and the use case is documented in the AI inventory.
Practical examples. The AUP includes a short series of concrete scenarios with clear answers:
- "Can I paste a customer email into ChatGPT Enterprise to ask Claude to draft a reply?": Only if the customer email does not contain PII beyond what is in the corporate CRM, the use case is documented, and the customer relationship is not flagged as restricted.
- "Can I paste my own salary data into Claude to ask about retirement projections?", Yes, self-PII is permitted in approved tools.
- "Can I paste a patient's diagnostic data into ChatGPT to ask about treatment options?", No, PHI is restricted in tools without a BAA.
- "Can I use Cursor to write code for the new pricing engine?", Yes, Cursor Pro with privacy mode is on the allowlist for source code.
Section 6 - Output-Handling Rules
Section 6 governs what employees do with AI outputs.
Article 50(1) - Chatbot disclosure. When deploying an AI system that interacts directly with external natural persons (customers, candidates, the public), the system must disclose to the user that they are interacting with an AI system, at the latest at the time of the first interaction, in a clear and distinguishable manner. The AUP names the typical disclosure language ("I'm Acme's AI assistant…") and the design pattern (first-message disclosure, persistent UI label).
Article 50(2) - Machine-readable marking of synthetic content. For any AI-generated synthetic audio, image, video, or text content distributed externally, the output must be marked in a machine-readable format and detectable as artificially generated. Approved markers include C2PA, SynthID, IPTC photo metadata, and provider-specific markers where they meet the technical standards in the Commission's Article 50 guidelines. Effective Dec 2, 2026 under the Omnibus VII acceleration.
Article 50(4) - Deepfake disclosure. Any AI-generated or manipulated image, audio, or video constituting a deepfake must be disclosed as artificially generated or manipulated. The disclosure must accompany the content. Limited carve-outs apply for artistic, satirical, or fictional works; carve-out invocation requires Legal sign-off.
Article 14 human-oversight expectation. Where the AI system is high-risk (Annex III §1-§8 categories or Annex I safety components), the deployer must ensure human oversight as required under Article 14. The AUP language: "Outputs from high-risk AI systems are advisory unless reviewed and accepted by an authorized human reviewer. The reviewer must have the competence, training, and authority to monitor the system, interpret its outputs, decide not to use the AI output, override the AI output, and intervene in or interrupt the system's operation." The specific oversight role per system is documented in the AI inventory and reinforced in tier-appropriate Article 4 literacy training.
Accuracy verification. AI outputs are not authoritative. Employees verify outputs against authoritative sources before acting on them. The AUP names typical verification expectations: factual claims verified against primary sources, code outputs reviewed before merge, customer-facing communications reviewed before send, legal-adjacent outputs reviewed by Legal before reliance.
Bias and fairness review. Where AI outputs influence decisions about people (hiring, promotion, lending, pricing, eligibility), the output is subject to the bias-review process documented in the AI Governance Operating Plan. Outputs that drive decisions in Annex III §4 (employment), §5(b) (creditworthiness), §5(c) (insurance), or other high-risk Annex III categories are subject to FRIA under Article 27 where the deployer obligation applies.
Section 7 - Escalation Pathway
Section 7 makes the escalation pathway visible to the workforce.
AI Officer queue. The AI Officer (or the designated team) is the first stop for: tool allowlist requests, prompt-input questions, output-handling questions, disclosure-language questions, vendor-evaluation requests, shadow-AI discovery reports. Standard SLA: 5 business days for routine requests, 2 business days for tool-blocking blockers, immediate for incidents.
AI Governance Committee. The AI Governance Committee handles ambiguous classification cases (Article 5 boundary questions, Annex III tier questions), policy-amendment requests, exception requests for non-allowlisted tools needed for time-limited use cases, and incident-response coordination for material AI incidents. The committee meets monthly; emergency convening within 2 business days for high-severity issues.
Privacy office. For PHI handling questions, GDPR Article 22 automated-decision questions, cross-border AI data-transfer questions, and DPIA / FRIA coordination questions.
Legal. For artistic-carve-out invocations (Article 50(4)), contract-language questions for AI vendor agreements, IP questions about AI-generated outputs, and disciplinary-process advice for AUP violations.
Security. For prompt-injection incidents, model-theft concerns, AI-related data-exfiltration incidents, and incident-response coordination for security-classified AI incidents.
Incident reporting. Employees report suspected AUP violations (their own or observed) through the standard incident-reporting channel. AUP violations involving Article 5 prohibitions, sensitive data leakage to non-approved tools, or material customer impact escalate to the AI Governance Committee within 24 hours and feed the Article 73 serious-incident-reporting decision tree where applicable.
Article 4 Literacy and Onboarding Integration
The AUP cannot stand alone. It integrates with the Article 4 literacy program and the broader employee lifecycle.
Article 4 literacy reference. The AUP references the four-tier AI literacy curriculum required under Article 4 of the EU AI Act. Every employee is assigned to a literacy tier appropriate to their role: Tier 1 (executives and board, 90-minute briefing), Tier 2 (deployers and decision-makers, 3-4 hour curriculum), Tier 3 (users and operators, 60-90 minutes), Tier 4 (affected workers and customers, brief notice). The AUP makes literacy-completion a condition of approved-tool access for Tiers 2 and 3.
Onboarding integration. Every new hire reviews the AUP during onboarding. The review includes: AUP reading, AUP acknowledgement, tier-appropriate literacy training, and any role-specific addenda (e.g., the engineering AUP addendum for code assistants, the marketing AUP addendum for generative-creative tools, the HR AUP addendum for HR AI tools).
Role-change integration. Role changes that move an employee into a higher-tier literacy bracket (e.g., individual contributor to manager, manager to head of function, head of function to executive) trigger AUP review and literacy-tier reassessment within 30 days of the role change.
Annual refresh. Every employee reviews the AUP annually with confirmation of acknowledgement. The annual refresh is timed to coincide with the broader annual compliance training cycle.
On-event refresh. Material regulatory events (e.g., Omnibus VII briefings, new Commission guidance on Article 50, new state laws like Colorado SB 24-205 or Texas TRAIGA, major vendor events) trigger an out-of-cycle AUP refresh with focused communication on the affected sections.
Incident Reporting and the Disciplinary Framework
Article 73 serious-incident reporting. The AUP cross-references the Article 73 serious-incident-reporting runbook. Where an AUP violation rises to the threshold of a serious incident (e.g., fundamental-rights infringement, material disruption to critical infrastructure, serious damage to property or environment, death or serious harm to health), the runbook drives reporting to the national market surveillance authority within the applicable deadlines (immediate for life/critical infrastructure, 2 days for fundamental-rights, 15 days for other serious incidents).
Article 26(4) deployer notification. Where the deployer becomes aware that a high-risk AI system poses a risk to health, safety, or fundamental rights at national level, the deployer informs the provider, the distributor, and the relevant national market surveillance authority. The AUP names this obligation and points to the operational runbook.
Disciplinary framework. Violations of the AUP are subject to disciplinary action under the standard HR disciplinary framework. The AUP names typical severity tiers:
- Tier 1 - Minor violations. Unintentional use of a non-allowlisted tool for low-sensitivity work, missing literacy completion past the deadline. Coaching plus required corrective training.
- Tier 2 - Moderate violations. Repeated minor violations, intentional bypass of approved-tool access, unintentional PII leakage to non-approved tool. Written warning plus mandatory retraining plus access review.
- Tier 3 - Serious violations. Intentional Article 5 prohibited-practice use, intentional PHI leakage, intentional disclosure of trade-secret information through prompts, deliberate circumvention of the allowlist or escalation pathway. Final written warning, suspension, or termination plus reporting through the standard HR disciplinary process.
- Tier 4 - Egregious violations. Intentional CSAM generation, intentional CBRN information generation, intentional discrimination, intentional fraud through AI. Termination plus law-enforcement referral as required by criminal law.
The disciplinary framework references the standard HR process and the works-council or union consultation requirements where applicable. In several EU Member States the works council must be consulted on any AI-related disciplinary framework that affects workers; the AUP names this consultation obligation explicitly and is reviewed by the works council before issuance and after each material amendment.
Cross-Walks and Multi-Jurisdiction Overlays
The AUP closes with a cross-walk appendix making the regulatory alignment explicit.
NIST AI RMF Govern. The AUP implements multiple Govern subcategories: Govern 1.1 (policies for AI), Govern 1.2 (policies for the lifecycle), Govern 1.5 (policies addressing third-party AI), Govern 1.6 (mechanisms for AI risk metrics tracking), Govern 2.1 (roles, responsibilities, lines of communication), Govern 3.2 (organizational practices for engaging with affected communities), Govern 5.1 (policies for AI-related grievances), Govern 6.1 (policies for high-risk decisions about people).
ISO/IEC 42001 Annex A. The AUP implements A.2 (policies for AI), A.2.2 (alignment with other policies), A.2.3 (review and update), A.3 (internal organization), A.4 (resources), A.5 (assessing impacts), A.6 (lifecycle), A.7 (data for AI systems), A.8 (information for interested parties), A.9 (use of AI systems), and A.10 (third-party relationships). The auditor's evidence package includes the AUP plus the supporting materials (allowlist, literacy curriculum, escalation pathway runbook).
EU AI Act articles. The AUP cross-references Articles 3 (definitions), 4 (literacy), 5 (prohibited practices), 6 and Annex III (high-risk), 14 (human oversight), 26 (deployer obligations), 27 (FRIA), 50 (transparency), 73 (serious-incident reporting), and 99 (penalties).
Multi-jurisdiction overlays. The cross-walk includes:
- NYC Local Law 144 (AEDT). Pre-deployment bias audits, candidate disclosure, retention requirements. The AUP integrates the LL 144 requirements where the organization deploys AEDT tools for hiring or promotion in NYC.
- Colorado SB 24-205. Consequential-decision AI tier with developer / deployer obligations on disclosure, risk management, and consumer notice. Effective Feb 2026 post the federal preemption stay (SB 189). The AUP integrates the Colorado obligations for any AI decisions affecting Colorado residents.
- Texas TRAIGA HB 149. Effective January 1, 2026. Disclosure and notice requirements with state-specific scope. The AUP integrates the Texas obligations for Texas-resident decisions.
- U.S. NLRA considerations. The National Labor Relations Act protects employee concerted activity. AI tools used in worker surveillance or worker discipline raise NLRA exposure; the AUP names the consultation expectation with the legal team and (where applicable) union representatives.
- EU works councils. Many EU Member States require works-council consultation on AI-related workplace policies. The AUP names the consultation obligation and the localization expectation for each Member State of operation.
- GDPR Article 22. Where AI is used for automated decision-making producing legal or similarly significant effects, GDPR Article 22 grants the data subject the right to obtain human intervention, express their point of view, and contest the decision. The AUP integrates the right-of-human-intervention obligation.
Six Common AUP Mistakes
Mistake 1 - Copying the IT AUP and Adding Two AI Paragraphs
The IT AUP cannot govern AI. The prohibited practices, data-handling constraints, vendor-tool universe, escalation pathway, literacy expectation, and penalty exposure are all different. An AI AUP must be drafted from scratch with the eight-section structure described above. Auditors flag the photocopied-IT-AUP pattern in roughly two of every three first-time ISO 42001 Stage 2 engagements.
Mistake 2 - Missing the Article 5 Cross-Reference
The prohibited-uses section must name the Article 5(1)(a)-(h) categories explicitly. Generic prohibitions ("do not use AI for unethical purposes") fail audit review and fail to give employees clear guidance. The cross-reference also establishes the €35M / 7% Article 99(2) penalty exposure for the audit committee.
Mistake 3 - No Specific Tools Allowlist
"Use only approved AI tools" without a published, named, maintained allowlist is unenforceable. The allowlist must name specific products with specific contract references, refresh monthly, and link from the AUP body. Without a named allowlist, employees default to whatever they can find on the open web, and shadow AI proliferates.
Mistake 4 - No Prompt-Input Restrictions
The AUP must say what may and may not be entered into prompts. PII, PHI, financial data, source code, customer data, and trade-secret information each have specific restrictions. Without prompt-input restrictions, the AUP cannot prevent the most common AI-related data-exfiltration incidents (employee pastes customer data into free ChatGPT, employee pastes source code into a non-approved code assistant, employee pastes PHI into a personal Claude account).
Mistake 5 - No Escalation Pathway
The AUP must name the escalation pathway: AI Officer for routine questions, AI Governance Committee for ambiguous cases, privacy / legal / security for specialized questions, incident-reporting channel for violations. Without a named pathway, employees either escalate to the wrong function or do not escalate at all, and the AUP becomes a document rather than an operating instrument.
Mistake 6 - A Static Policy That Does Not Refresh
The AI regulatory landscape, the vendor universe, and the technical baseline all change monthly. An AUP issued in 2024 without a refresh cycle is operating against an obsolete baseline. The AUP must have a named refresh cadence (typically annual policy review by the AI Governance Committee with material-event triggered ad hoc updates, monthly allowlist refresh by the AI Officer). Audit-defensible AUPs show the refresh evidence: version history, change log, on-event refresh memos, communication records.
Key Takeaways
- The AI AUP must be separate from the IT AUP. Different prohibited practices (Article 5), different data-handling constraints (prompt inputs), different vendor universe, different escalation pathway, different literacy expectation, different penalty exposure.
- The AUP has a stable eight-section structure. Scope and applicability; definitions; prohibited uses; approved-tools allowlist; prompt-input restrictions; output-handling rules; escalation pathway; literacy and onboarding integration. Plus the incident-reporting and disciplinary framework and the cross-walk appendix.
- The prohibited-uses section names Article 5(1)(a)-(h) explicitly plus organization-specific prohibitions (CBRN, CSAM, intentional discrimination, unauthorized impersonation, confidentiality circumvention).
- The allowlist names specific tools with refresh cadence. Monthly AI Officer review, quarterly AI Governance Committee review, ad hoc updates on material vendor events. Removals trigger a deprecation notice with a 30-day transition window.
- Prompt-input restrictions cover PII, PHI, financial data, source code, customer data, and trade-secret information. Without specific restrictions, the AUP cannot prevent the most common data-exfiltration incidents.
- Output-handling rules align with Article 50 and Article 14. Chatbot disclosure for direct interaction (50(1)); machine-readable marking for synthetic content (50(2), effective Dec 2, 2026 under Omnibus VII); deepfake disclosure (50(4)); human-oversight expectation for high-risk systems (14).
- The escalation pathway names AI Officer, AI Governance Committee, privacy, legal, security, and incident-reporting channels. SLAs are defined per channel.
- Onboarding, role-change, annual refresh, and on-event refresh embed the AUP in the employee lifecycle. Article 4 literacy completion is a condition of approved-tool access for Tiers 2 and 3.
- Cross-walks make alignment explicit. NIST AI RMF Govern subcategories, ISO/IEC 42001 Annex A.2 controls, EU AI Act articles, plus multi-jurisdiction overlays (NYC LL 144, Colorado SB 24-205, Texas TRAIGA, NLRA, EU works-council, GDPR Article 22).
- Six mistakes to avoid. Copying the IT AUP; missing Article 5 cross-reference; no specific tools allowlist; no prompt-input restrictions; no escalation pathway; static policy that does not refresh.
Skill.re