Announcing a Free AI Acceptable Use Policy Template, Built with Collin McKee and Endeavors AI

I’m making available a full AI Acceptable Use Policy template, and I wanted to put this out into the world alongside Collin McKee at Endeavors AI, because this template grew directly out of a conversation the two of us had recently on my podcast, Corruption, Crime and Compliance. If you haven’t seen that episode yet, you can watch it here: Corruption, Crime and Compliance with Collin McKee, Endeavors AI. We talked about exactly the problem this template is designed to solve: organizations adopting AI tools far faster than they’re building any governance around that adoption, and the real operational and legal exposure that gap creates.

Why This Template Exists

Every organization I talk to right now is somewhere on the same spectrum. Either employees are already using AI tools without any formal policy in place, which means an organization has zero visibility into what’s actually happening with its data, or leadership knows a policy is needed and hasn’t had the bandwidth to build one from scratch. This template is meant to close that gap. It’s a genuinely comprehensive starting point covering governance roles and ownership, permitted and prohibited uses, confidentiality and data classification rules, hallucination and accuracy verification requirements, vendor due diligence, intellectual property, bias and non-discrimination safeguards, incident reporting, and enforcement, all built around the same risk categories Colin and I discussed on the podcast.

What’s Included

The package includes the core AI Acceptable Use Policy document itself, along with two operative appendices designed to make the policy actually usable rather than just aspirational. Appendix A is a vendor due diligence checklist for evaluating any new AI tool before it’s approved. Appendix B is an AI incident report form for capturing and routing suspected violations the moment they’re discovered. And we’ve now added Appendix D, an Approved AI Tool List, which functions as the living register behind the policy itself. That register is the piece that actually operationalizes the policy day to day: it specifies exactly which tools are approved, for which use cases, at what maximum data classification, and with what required configuration settings, and it separately tracks AI features embedded inside software an organization already licenses, which is often the most common source of ungoverned AI use precisely because turning on an embedded feature doesn’t feel like adopting a new tool at all. The register also keeps a record of denied or retired tools, so the same request doesn’t get re-litigated from scratch every quarter, and it ties every entry to a reassessment date, because a vendor’s practices today aren’t a permanent guarantee of that vendor’s practices a year from now.

A Word on How to Use It

This is a template, not a finished policy, and it isn’t legal advice. It’s built to reflect common elements from current professional-responsibility guidance on generative AI, the NIST AI Risk Management Framework, and current vendor and litigation practice, but every organization adopting it needs to have qualified counsel tailor it to its specific jurisdiction, applicable regulatory framework, existing information security and privacy policies, and actual AI tool stack before putting it into use. The bracketed placeholders throughout the document mark exactly where that customization needs to happen.

Why I’m Pairing This With Endeavor AI

I wanted to release this alongside Collin McKee and his team at Endeavors AI because governance and adoption are two sides of the same problem. Endeavors AI works the adoption side with law firms and professional services firms, building AI workflow automation, client intake, and the internal systems that make AI usable in a practice without creating the exposure this policy is designed to prevent.

If you’re evaluating how to build real AI capability inside a regulated or mission-critical business, rather than just bolting on ungoverned tools, it’s worth a look at EndeavorsAI and its capabilities to assist organizations in building workflow automation and intake (particularly law firms and other professionals. You can also reach Collin directly at collin@endeavorsai.com.

Get the Template

The full AI Acceptable Use Policy, along with the vendor diligence checklist, incident report form, and the Approved AI Tool List register, is available now. Have your counsel adapt it to your organization’s specific risk profile and regulatory environment before adoption, but use it as the real starting point it’s meant to be. Governance shouldn’t be the thing that’s still on your to-do list a year after everyone in your organization has already started using AI on their own.

You may also like...