AI use policy (acceptable AI use)
Which AI tools people may use, for what, with which data, what must be checked by a person, and what must never be entered or relied on.
How the register reads it
| Also called | generative AI policy, AI acceptable use, use of AI tools |
|---|---|
| Family | AI and automated decisions |
| Document type | Policy. The regimes ask for the content, not the label; a line pasted as a standard, procedure, plan or schedule is placed here with the label noted. |
| Expected owner | The AI governance lead (CTO, CDO or head of data science). |
| Review cadence | Annual (the register's default: the clauses say planned intervals and on significant change, and do not fix a period). |
| On the gap list when | ISO 42001 is ticked and no line resolves to it (ISO 27001 requires it too, inside a parent document, so it does not list it separately). |
| Template | Ai acceptable use policy. |
Which standards require it, and what each expects it to contain
4 requiring clauses, 2 regimesShown on a register for the regimes you tick; with none ticked, ISO 27001 is applied. Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim.
ISO/IEC 27001:2022
ISO 27001 5.10 Acceptable use of information and other associated assetsDefine and enforce rules for how information and assets may be used and handled.
What the ISO 27002 guidance expects the document to say: Requires rules for acceptable use, and procedures for handling information and its associated assets, to be identified, documented and put into effect.
Common gap: Policy not reviewed or updated regularly
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO/IEC 42001:2023
ISO 42001 A.2.2 AI policyThe organization shall document a policy for the development, deployment, or use of AI systems that aligns with the organization's strategic direction.
Common gap: Does the AI policy address AI-specific concerns beyond restating IT policy?
Source: ISO/IEC 42001:2023
ISO 42001 A.9.2 Processes for responsible use of AI systemsThe organization shall define and document processes for the responsible use of AI systems, including processes for the use by employees of AI systems provided by third parties.
Source: ISO/IEC 42001:2023
ISO 42001 A.9.4 Intended use of the AI systemThe organization shall ensure that the AI system is used according to the intended uses of the AI system and its accompanying documentation.
Common gap: Is off-label use detected and addressed?
Source: ISO/IEC 42001:2023
Do this for every document on your list
Paste the list and get this reading for every document at once, with the owner and cadence against each, the clauses quoted, and the documents the regimes expect that the list does not carry. Eight documents free, no account.
Build a registerAI system impact assessment procedure · Automated decision-making procedure