Announcing a Free AI Acceptable Use Policy Template, Built with Collin McKee and Endeavor AI

I’m making available a full AI Acceptable Use Policy template, and I wanted to put this out into the world alongside Collin McKee at Endeavor AI, because this template grew directly out of a conversation the two of us had recently on my podcast, Corruption, Crime and Compliance. If you haven’t seen that episode yet, you can watch it here: Corruption, Crime and Compliance with Collin McKee, Endeavor AI. We talked about exactly the problem this template is designed to solve: organizations adopting AI tools far faster than they’re building any governance around that adoption, and the real operational and legal exposure that gap creates.

Why This Template Exists

Every organization I talk to right now is somewhere on the same spectrum. Either employees are already using AI tools without any formal policy in place, which means an organization has zero visibility into what’s actually happening with its data, or leadership knows a policy is needed and hasn’t had the bandwidth to build one from scratch. This template is meant to close that gap. It’s a genuinely comprehensive starting point covering governance roles and ownership, permitted and prohibited uses, confidentiality and data classification rules, hallucination and accuracy verification requirements, vendor due diligence, intellectual property, bias and non-discrimination safeguards, incident reporting, and enforcement, all built around the same risk categories Colin and I discussed on the podcast.

What’s Included

The package includes the core AI Acceptable Use Policy document itself, along with two operative appendices designed to make the policy actually usable rather than just aspirational. Appendix A is a vendor due diligence checklist for evaluating any new AI tool before it’s approved. Appendix B is an AI incident report form for capturing and routing suspected violations the moment they’re discovered. And we’ve now added Appendix D, an Approved AI Tool List, which functions as the living register behind the policy itself. That register is the piece that actually operationalizes the policy day to day: it specifies exactly which tools are approved, for which use cases, at what maximum data classification, and with what required configuration settings, and it separately tracks AI features embedded inside software an organization already licenses, which is often the most common source of ungoverned AI use precisely because turning on an embedded feature doesn’t feel like adopting a new tool at all. The register also keeps a record of denied or retired tools, so the same request doesn’t get re-litigated from scratch every quarter, and it ties every entry to a reassessment date, because a vendor’s practices today aren’t a permanent guarantee of that vendor’s practices a year from now.

A Word on How to Use It

This is a template, not a finished policy, and it isn’t legal advice. It’s built to reflect common elements from current professional-responsibility guidance on generative AI, the NIST AI Risk Management Framework, and current vendor and litigation practice, but every organization adopting it needs to have qualified counsel tailor it to its specific jurisdiction, applicable regulatory framework, existing information security and privacy policies, and actual AI tool stack before putting it into use. The bracketed placeholders throughout the document mark exactly where that customization needs to happen.

Why I’m Pairing This With Endeavor AI

I wanted to release this alongside Collin McKee and his team at Endeavor AI because governance and adoption are really two sides of the same problem, and Endeavor approaches the adoption side in a way I think more organizations need to understand. Endeavor builds proprietary, enterprise-grade AI systems that companies actually own, rather than rent, custom AI for manufacturing, distribution, supply chain, life sciences, defense, and other mission-critical, often regulated industries. Their pitch is straightforward: don’t rent your strategic AI advantage from a third party that doesn’t understand your business, build something proprietary that you control end to end. That philosophy lines up directly with a lot of what this policy template is trying to protect against, the risk of ungoverned, third-party AI relationships where an organization has limited visibility into how its own data is being used, retained, or trained on downstream.

If you’re evaluating how to build real AI capability inside a regulated or mission-critical business, rather than just bolting on ungoverned tools, it’s worth a look at Endeavor AI and what they’ve built for organizations across manufacturing, distribution, defense, and life sciences. You can also reach Collin directly at [email protected].

Get the Template

The full AI Acceptable Use Policy, along with the vendor diligence checklist, incident report form, and the Approved AI Tool List register, is available now. Have your counsel adapt it to your organization’s specific risk profile and regulatory environment before adoption, but use it as the real starting point it’s meant to be. Governance shouldn’t be the thing that’s still on your to-do list a year after everyone in your organization has already started using AI on their own.

You may also like...

Leave a Reply

Your email address will not be published. Required fields are marked *