An acceptable-use policy you can actually edit
Shared methods · A shared method; linked tool guides explain the exact steps.
This page covers tools outside your selection. You can still read it. Find matching guides
A short template to adapt, with notes on why each clause is there and which ones are usually wrong for a smaller organisation.
Most AI policies fail the same way: too long to read, too vague to apply, and written to protect the organisation from its own staff. People skim them once and then decide by instinct.
A policy that gets followed is short, answerable in the moment, and honest about what it cannot control.
The template
Copy it. Cut half of it. The clause notes below say which half.
Using AI tools at [ORG]
1. Accounts. Use the accounts [ORG] provides. Do not use personal accounts for work material — they operate under different terms, and content may be retained and used differently.
2. What you may put in. Follow the data classification at [LINK]. If you are unsure which category something falls into, treat it as the more restrictive one and ask [ROLE].
3. What never goes in. Credentials and keys. [SECTOR-SPECIFIC CATEGORIES]. Anything under a confidentiality obligation that forbids third-party processing.
4. You own the output. Check it before it leaves you. You remain responsible for accuracy, for anything published, and for actions taken on your behalf by an agent you started.
5. Say when it matters. Follow the disclosure practice at [LINK]. Where a client, regulator or publisher requires disclosure, that requirement wins.
6. Agents and connected tools. Before granting a tool access to files, mail or systems, check with [ROLE]. Grant the narrowest access that does the job.
7. When something goes wrong. Tell [ROLE] the same day. Reporting a mistake made in good faith carries no penalty. Not reporting it does.
8. Questions. [ROLE], [CONTACT]. This document is reviewed on [DATE].
Why each clause is there
A clause you cannot explain is a clause to delete, so here is the reasoning for each one.
| Clause | Why it earns its place |
|---|---|
| 1 Accounts | The highest-value line in the document: enforceable, checkable, and it fixes the terms problem rather than restating it. Pair it with actually providing the accounts, or it becomes the clause people break first. |
| 2 Classification | Points at the scheme instead of containing it, so the scheme can change without reissuing the policy. The "treat it as more restrictive and ask" default matters more than the categories, because it gives people a safe move when the scheme does not cover their case. |
| 3 The absolute list | Keep it genuinely short. Twenty prohibitions get read as twenty suggestions; three or four categories that are always wrong get remembered. |
| 4 Ownership | Anthropic's own guidance places responsibility for actions taken on your behalf with you. Saying so in your own words heads off the "the AI did it" conversation. |
| 5 Disclosure | By reference, for the same reason as clause 2, and it defers to external requirements rather than trying to anticipate them. |
| 6 Agents | Newer than most templates and increasingly the clause that matters. An agent with connector access can act, and permissions granted once outlive the task. |
| 7 Blameless reporting | Without it you hear about problems late or never. Punishing disclosure produces less disclosure, which inverts what the policy was for. |
| 8 Review date | A policy with no expiry becomes wallpaper. |
Clauses usually worth cutting
A prohibition on "unauthorised tools" with no list of authorised ones. Unenforceable, and it reads as distrust.
Long definitions of AI. Nobody reads them and they date badly.
A blanket ban on confidential material where you have provided no compliant alternative. See Rolling out AI.
Quality requirements phrased as prohibitions. "Do not submit AI-generated work" fails as soon as the tool is genuinely useful. Clause 4 covers what you actually want, which is that someone checked it.
Anything you cannot check. A rule nobody can verify teaches people that rules here are decorative.
What goes wrong
Length. Beyond a page, compliance drops off sharply. Cut until it hurts.
Writing it for the auditor. The audience is a colleague deciding something in ten seconds.
Publishing it where nobody is. It has to be reachable from the moment of the decision, which is rarely the policy folder.
Never revisiting it. Clause 8 exists for this and is the clause most often left as a placeholder.
How to check it worked
Give the draft to three people who did not write it and ask each to decide a realistic case. Where they disagree, the policy is ambiguous exactly where it needed not to be, and their disagreement makes a better review than any read through the document.
Sources
- Updates to our Consumer Terms and Privacy Policy — Anthropic Tier 1 2026-08-31
- Use Claude Cowork safely — Anthropic Help Center Tier 1 2026-08-31
- AI Act implementation timeline — EU Artificial Intelligence Act Tier 3 2026-08-31
Something wrong with this page?
Say what you expected and what you got. That is usually the shortest route to a correction, and it goes on the public issue tracker so the fix is visible.