Skip to main content
AI Controls Catalog
AI-CTRL-016 Governance directive v1.0.0

AI Acceptable Use Policy and User Training

Authored by Emmanuel Guilherme Jr. · Last reviewed 2026-05-01

Objective

Maintain a published, enforceable AI Acceptable Use Policy and deliver role-appropriate AI literacy training to employees, contractors, and other authorized users.

Applicability

AI types
LLM, Agentic AI, Generative AI, Multi-modal, Traditional ML
Deployment models
SaaS, Self-hosted, Hybrid
Lifecycle stages
Strategy & Planning, Operation & Monitoring
Risk domains
People & Process, Governance
Regulatory regimes
EU AI Act, ISO 42001, Banking, Healthcare, Public sector
Company size
SMB, MidMarket, Enterprise

Rationale

EU AI Act Article 4 requires deployers to ensure AI literacy among staff. Most AI-related incidents in regulated enterprises involve employee actions (sensitive data pasted into consumer AI, over-reliance on hallucinated outputs, unauthorized tool installation). A documented policy plus actual training (not a once-a-year click-through) materially reduces likelihood and is a control that auditors and regulators specifically examine.

Control narrative

The organization publishes an AI Acceptable Use Policy covering: sanctioned-tool list with categories of permitted use, prohibited categories of data in any AI service, approved-use-case process, exception/risk-acceptance process, monitoring disclosure, escalation, and consequences for non-compliance. AI literacy training is required at onboarding and refreshed annually for all knowledge workers, with role-targeted modules for: engineers (secure coding with AI assistants), product/business (use-case intake), legal/compliance (AI in legal review), HR (AI in talent processes), and managers (responsible team adoption). Completion is tracked. Policy and training reference the AI System Inventory (AI-CTRL-001) and the Shadow AI Detection control (AI-CTRL-020).

Test of Design

Procedures

  1. Obtain the AI Acceptable Use Policy and confirm coverage of required sections.
  2. Confirm policy approval, publication, and accessibility to all employees.
  3. Confirm AI literacy training exists with role-targeted modules.
  4. Confirm training is required at onboarding and refreshed annually with tracking.
  5. Confirm policy and training reference the approved-tool list and exception process.

Inquiries

  • Who owns the AI AUP?
  • How is the sanctioned-tool list kept current?
  • How is training role-appropriate without being burdensome?
  • How is contractor training handled?

Inspections

  • AI Acceptable Use Policy.
  • Training curricula by role.
  • Sample of training completion records.
  • Policy attestation records (if applicable).

Test of Operating Effectiveness

Procedures

  1. Confirm the current policy is published and accessible.
  2. Sample employees and confirm onboarding training completion within the documented window.
  3. Sample employees and confirm annual refresh completion.
  4. Confirm completion rate aggregate metrics meet documented threshold.
  5. Inspect a sample of policy updates and confirm proper review and republication.
  6. For sampled exception requests, confirm process per policy.

Sample-size guidance

Population Employees in role-categories requiring training
Low risk 25 employees
Moderate risk 60 employees
High risk 150 employees or 100% of high-risk roles

Evidence requirements

Required

  • AI Acceptable Use Policy (current version) PDF/Word · At fieldwork
  • Training curricula by role PDF / LMS export · At fieldwork
  • Training completion records for sampled employees LMS export · Per sample

Supporting

  • Policy version history Document/repo · At fieldwork
  • Sanctioned-tool list with last-updated date Wiki/portal export · At fieldwork

Retention: 7 years for regulated environments; 3 years otherwise

Framework mappings

Framework References
ISO 42001 5.2, 7.3
NIST AI RMF GOVERN-3.1, GOVERN-4.1
EU AI Act Article 4
OWASP DSGAI DSGAI17
SOC 2 CC1.4, CC2.2
osfi_e21 Principle 1
nydfs_500 500.14

Related controls

Changelog
  • v1.0.0 · 2026-05-01 · Initial publication.

References