What should an AI acceptable use policy cover in 2026?
Approved tools by data class, banned data, approval routes, logging, output verification, AI literacy training and consequences, plus a capable sanctioned alternative.
A credible AI acceptable use policy in 2026 covers seven things: which tools are approved and which are banned, by name and by data class; what data may never enter an external AI service; who approves new AI uses and how; what is logged and who can inspect it; how outputs must be verified before anyone relies on them; training that meets the EU AI Act's AI literacy duty; and consequences. The policies that actually work add an eighth element: a sanctioned alternative capable enough that staff use it instead of their phones.
The question matters in 2026 because AI use inside organisations is now pervasive, approved or not, and the acceptable use policy is the first artefact a regulator, a client audit or a tribunal asks for. A policy written in 2023 about a chatbot experiment does not describe the embedded, agentic AI staff now touch daily.
Which tools should the policy approve or ban?
Named tools against named data classes, because blanket categories fail in both directions. A total prohibition on AI is unenforceable when AI is embedded in the office suite, the browser and the CRM, and an instruction to use good judgement is not a policy. The workable form is explicit: this service is approved for public material, that one for internal material, nothing external for the protected classes listed below, and the sanctioned internal route for everything else. Public services such as ChatGPT, Claude, Gemini and Microsoft 365 Copilot each sit wherever the organisation's data analysis places them, tool by tool, not as one undifferentiated category.
What data must never enter an external AI service?
The policy should name the classes, because staff cannot apply a principle they have to derive at speed.
- Personal data, including anything about colleagues, customers or the public.
- Client-confidential material and anything covered by contractual confidentiality.
- Legally privileged material.
- Inside information and market-sensitive material.
- Safeguarding records and anything concerning vulnerable people.
The list does the work a definition cannot. A member of staff pasting a document under deadline pressure needs a rule that matches the moment, not a test that requires legal analysis.
Who approves a new AI use and how?
A named owner with a short route. Shadow AI thrives where the official answer is silence, so the policy should say who decides, what information a request needs, and how quickly an answer arrives. The decision should be recorded, because next year's audit question is why a use was allowed, and the organisation wants a better answer than nobody remembers. An approval route that takes months is functionally a ban, and bans have a known failure mode.
What should be logged, and who reviews it?
The policy should state what is recorded about AI use, who can inspect it, and what triggers a review. A rule nobody can check is a suggestion. Logging also protects the employee, not just the employer: a member of staff who followed the policy can show it, and a disputed output can be traced to what was actually asked. The uncomfortable truth is that logging is only fully available on the routes the organisation controls, which is another reason the sanctioned route matters more than the ban list.
What rules should govern AI outputs?
Three, at minimum. Verification before reliance: an output is a draft until a human has checked it against the sources that matter. No fabricated citations: any reference an AI produces is confirmed to exist before it leaves the building. Attribution: where the organisation's professional, regulatory or client obligations require disclosing AI assistance, the policy says so, and where they do not, it says who decides. Output rules protect against the failure that makes headlines, which is rarely the data leak and usually the confident invention nobody checked.
Does the policy need a training section?
Yes, and not as an aspiration. Article 4 of the EU AI Act requires providers and deployers to ensure a sufficient level of AI literacy in staff who operate and use AI systems, and it has applied since 2 February 2025 for organisations in scope. The acceptable use policy is where that duty touches daily behaviour, so the policy should require role-appropriate training before use and keep the records that prove it happened. What sufficient literacy involves is a subject in its own right; the policy's job is to make the training mandatory and evidenced.
Why do ban-only policies fail?
Because the work still has to be done. A policy that only forbids does not remove the demand for drafting, summarising and answering; it relocates that demand to personal phones and home accounts, where the organisation has no logging, no data control and no visibility. The credible policy pairs its restrictions with a sanctioned route that is genuinely capable, and the strongest version runs inside the organisation's own perimeter. On Mickai, a Sovereign Intelligence Operating System running offline on operator-owned hardware, every action is written to a sealed usage record, which turns the policy from aspiration into something enforceable and provable: the approved route is the auditable route.
“A policy that only bans produces shadow AI, and a policy that provides a capable sanctioned route produces evidence.”
What that sanctioned route looks like in our architecture is set out at /sovereign-ai, and the film at /film shows the interface staff would actually use.
Frequently asked questions
Is banning ChatGPT at work enough?
No. A ban without a capable alternative moves the usage to personal devices, where the organisation loses logging, data control and any ability to enforce the policy. The evidence of a working policy is not zero AI use; it is AI use flowing through the sanctioned, recorded route.
How do I stop staff using AI on their personal phones?
Enforcement alone cannot, because the organisation cannot see personal devices. The practical answer is to make the sanctioned route better than the shadow route: capable, fast, permitted for real work and clearly safe to use. Restriction handles the data classes that must never leave; provision handles everything else.
Do we have to update our AI policy for the EU AI Act?
Organisations in scope of the EU AI Act should ensure the policy reflects the Article 4 AI literacy duty, which has applied since 2 February 2025, and should keep training records alongside usage records. The policy is also the natural place to fix accountability for tracking the obligations that arrive on later timelines.
What consequences should an AI policy set?
The same graduated consequences the organisation applies to data-handling breaches, applied consistently, because an unenforced rule undermines the whole policy. Consistency requires evidence of what actually happened, which is why the logging section and the consequences section depend on each other.
How often should an AI acceptable use policy be reviewed?
On a defined cycle and on triggers: a new tool class, an incident, a regulatory change or a material change in how the organisation uses AI. The tool landscape and the legal timeline are both moving through 2026 and 2027, so a policy without a review mechanism is already out of date.