Build a board-ready risk heatmap in minutes — free, no account required

Open tool

Policy & Governance

Acceptable AI Use and Prohibited Practices Policy

What this control does

Define organisational rules for acceptable AI use, prohibited practices and escalation.

How to implement

Set out which AI uses are allowed, restricted or prohibited within the organization and how personnel should obtain advice. Assign a policy owner and connect the policy to procurement, development and deployment approvals. Describe escalation and enforcement actions for unapproved use. Give staff examples relevant to their work and keep the policy aligned with the current prohibition screening. A policy supports the linked restrictions but does not replace technical controls, monitoring or legal assessment.

Suggested timing and triggers

At initial approval; after material regulatory or use changes; periodic review, with an annual cycle as a suggested starting point.

Evidence examples

Approved acceptable-use policy and version history Role-specific communications and acknowledgements Links to use-case approvals and screening records Records of exceptions, enforcement and corrective actions

How to check this control

Choose a policy restriction and trace it to an approval check or operational safeguard. Ask a relevant user how to obtain advice. Check that a recent policy change reached the affected teams.

Recognized by G2 as a Leader

Trusted by customers and rated highly across all categories

Acceptable AI Use and Prohibited Practices Policy | EU AI Act Suggested Control | Tracker Networks