AI Acceptable Use Policy and User Training
Authored by Emmanuel Guilherme Jr. · Last reviewed 2026-05-01
Objective
Maintain a published, enforceable AI Acceptable Use Policy and deliver role-appropriate AI literacy training to employees, contractors, and other authorized users.
Applicability
- AI types
- LLM, Agentic AI, Generative AI, Multi-modal, Traditional ML
- Deployment models
- SaaS, Self-hosted, Hybrid
- Lifecycle stages
- Strategy & Planning, Operation & Monitoring
- Risk domains
- People & Process, Governance
- Regulatory regimes
- EU AI Act, ISO 42001, Banking, Healthcare, Public sector
- Company size
- SMB, MidMarket, Enterprise
Rationale
EU AI Act Article 4 requires deployers to ensure AI literacy among staff. Most AI-related incidents in regulated enterprises involve employee actions (sensitive data pasted into consumer AI, over-reliance on hallucinated outputs, unauthorized tool installation). A documented policy plus actual training (not a once-a-year click-through) materially reduces likelihood and is a control that auditors and regulators specifically examine.
Control narrative
The organization publishes an AI Acceptable Use Policy covering: sanctioned-tool list with categories of permitted use, prohibited categories of data in any AI service, approved-use-case process, exception/risk-acceptance process, monitoring disclosure, escalation, and consequences for non-compliance. AI literacy training is required at onboarding and refreshed annually for all knowledge workers, with role-targeted modules for: engineers (secure coding with AI assistants), product/business (use-case intake), legal/compliance (AI in legal review), HR (AI in talent processes), and managers (responsible team adoption). Completion is tracked. Policy and training reference the AI System Inventory (AI-CTRL-001) and the Shadow AI Detection control (AI-CTRL-020).
Test of Design
Procedures
- Obtain the AI Acceptable Use Policy and confirm coverage of required sections.
- Confirm policy approval, publication, and accessibility to all employees.
- Confirm AI literacy training exists with role-targeted modules.
- Confirm training is required at onboarding and refreshed annually with tracking.
- Confirm policy and training reference the approved-tool list and exception process.
Inquiries
- Who owns the AI AUP?
- How is the sanctioned-tool list kept current?
- How is training role-appropriate without being burdensome?
- How is contractor training handled?
Inspections
- AI Acceptable Use Policy.
- Training curricula by role.
- Sample of training completion records.
- Policy attestation records (if applicable).
Test of Operating Effectiveness
Procedures
- Confirm the current policy is published and accessible.
- Sample employees and confirm onboarding training completion within the documented window.
- Sample employees and confirm annual refresh completion.
- Confirm completion rate aggregate metrics meet documented threshold.
- Inspect a sample of policy updates and confirm proper review and republication.
- For sampled exception requests, confirm process per policy.
Sample-size guidance
| Population | Employees in role-categories requiring training |
|---|---|
| Low risk | 25 employees |
| Moderate risk | 60 employees |
| High risk | 150 employees or 100% of high-risk roles |
Evidence requirements
Required
- AI Acceptable Use Policy (current version) PDF/Word · At fieldwork
- Training curricula by role PDF / LMS export · At fieldwork
- Training completion records for sampled employees LMS export · Per sample
Supporting
- Policy version history Document/repo · At fieldwork
- Sanctioned-tool list with last-updated date Wiki/portal export · At fieldwork
Retention: 7 years for regulated environments; 3 years otherwise
Framework mappings
| Framework | References |
|---|---|
| ISO 42001 | 5.2, 7.3 |
| NIST AI RMF | GOVERN-3.1, GOVERN-4.1 |
| EU AI Act | Article 4 |
| OWASP DSGAI | DSGAI17 |
| SOC 2 | CC1.4, CC2.2 |
| osfi_e21 | Principle 1 |
| nydfs_500 | 500.14 |
Related controls
Changelog
- v1.0.0 · 2026-05-01 · Initial publication.