# GENERATIVE ARTIFICIAL INTELLIGENCE POLICY **(Small and Medium-Sized Business Template)** **Template version:** 1.0 **Effective as of [EFFECTIVE DATE]** > **Template note:** Bracketed text in ALL CAPS (e.g., `[COMPANY NAME]`) must be customized before adoption. See the [Customization Guide](../../CUSTOMIZATION_GUIDE.md) for a complete checklist. This policy is one component of AI governance, not the whole of it: adopting organizations should align it to a broader AI governance program, such as one structured around the [NIST AI Risk Management Framework](https://www.nist.gov/itl/ai-risk-management-framework). This template is provided for informational purposes only and does not constitute legal advice. Each organization should review and adapt this policy with its own counsel before adoption. # 1. Purpose and Scope [COMPANY NAME] (the "Company") recognizes that generative AI tools ("AI Tools") can enhance productivity and the quality of the Company's products and services, but also present risks to confidentiality, trade secrets, data security, privacy, accuracy, intellectual property, and the Company's contractual and legal obligations. This Generative Artificial Intelligence Policy (the "Policy") establishes mandatory requirements for the responsible use of AI Tools by all Company officers, employees, independent contractors, and other personnel (together, "Personnel"). Except where a provision specifies otherwise, references in this Policy to AI Tools also encompass Background AI, AI Notetakers, and Agentic AI Tools, whether or not they are generative. You must agree to this Policy to maintain access to Company-provided AI Tools. This Policy applies to all Company-related activities, whether performed on Company premises, remotely, or on personal devices. Personnel must comply with the laws and regulations applicable to the Company's operations, including those identified in **Appendix B**. If you are unsure of your obligations, please contact the Administrator of this Policy. # 2. Definitions - **"Administrator":** the administrator of this Policy is [ADMINISTRATOR NAME], the [ADMINISTRATOR TITLE] of the Company, and may be contacted at [ADMINISTRATOR EMAIL]. - **"Agentic AI Tools":** AI Tools capable of performing multi-step tasks, making autonomous decisions, or taking actions without direct human intervention for each step. - **"Approved AI Tools":** AI Tools specifically vetted and approved by the Company, as listed in **Appendix A**. Only Company-issued enterprise licenses may be used. If you are granted access by the Administrator to a tool not included on **Appendix A**, the tool is deemed approved for use in connection with Company business once that approval is confirmed in writing, subject to this Policy. - **"Background AI":** Software used by the Company that incidentally includes AI features, as identified in the non-exhaustive list set forth in **Appendix A**. These platforms do not train on customer data without explicit consent. All Background AI output must be reviewed for accuracy. - **"Confidential Information":** All non-public information relating to the Company or its customers, vendors, and business partners, including trade secrets, financial information, business plans and strategy, product roadmaps, source code, pricing, customer lists and data, personnel information, and any information received under a nondisclosure or confidentiality obligation. - **"Inputs":** All data, information, prompts, documents, or other content submitted to an AI Tool by Personnel. - **"Outputs":** All results, responses, content, or materials generated by an AI Tool in response to Inputs. - **"Sensitive Information":** Confidential Information, personal data, Material Nonpublic Information ("MNPI"), and any information subject to contractual, regulatory, or legal protection. - **"Work Product":** Materials created by Company Personnel in the course of Company business, including documents, analyses, code, designs, marketing materials, and communications. # 3. Core Principles ## 3.1 Legal and Regulatory Compliance All AI use must comply with applicable laws and regulations, including consumer protection laws (such as prohibitions on unfair or deceptive practices), privacy and data protection laws, intellectual property laws, employment and anti-discrimination laws, and any industry-specific regulations applicable to the Company's business. Personnel must maintain basic competence in the AI Tools they use, understand their limitations, and stay current with the legal requirements identified in **Appendix B** as they apply to their role. ## 3.2 Customer, Vendor, and Partner Commitments The Company has endeavored to ensure that its customer, vendor, and partner agreements appropriately address the Company's use of AI. Personnel must honor all contractual commitments regarding confidentiality, data handling, and AI use, including any agreements that restrict the use of counterparty data with AI Tools or require disclosure or consent. When a contract is silent and the use of AI with counterparty data could reasonably be material to the counterparty, consult the Administrator before proceeding. Do not use AI in a manner that would breach a nondisclosure agreement or waive trade secret protection. ## 3.3 Data Security and Privacy Company Personnel should comply with all Company policies and use appropriate safeguards (encryption, secure passwords, multi-factor authentication) consistent with the Company's data security policies. Personnel should use AI Tools responsibly, including by adhering to the following: use reasonable judgment in inputting only the minimum information necessary, including using de-identified, redacted, or hypothetical data where feasible; avoid inputting Sensitive Information into AI Tools, as such data is subject to heightened regulatory protections and poses elevated security risks. ## 3.4 Approved Tools Only The Company permits AI Tool usage exclusively through Company-approved enterprise accounts. The use of non-approved AI tools, personal AI accounts, free-tier AI chatbots, AI tools which train on customer data, or consumer-tier subscriptions for ANY Company business is strictly prohibited and is grounds for termination of employment or engagement. To request an exception or evaluation of a new AI Tool, contact the Administrator. # 4. Mandatory Verification of AI Outputs All Personnel must independently fact-check and verify everything generated by AI Tools before relying on it for a business decision or submitting it to any supervisor, customer, regulator, or other recipient. This includes all factual assertions, figures, calculations, dates, names, quotations, citations and references, and code. AI Tools can generate fabricated ("hallucinated") content that appears legitimate but is fictitious, and can produce plausible-looking but incorrect analysis. All output must be meticulously verified. In each instance: - Verify all factual assertions, statistics, and citations against primary or authoritative sources. - Review all AI-generated or AI-assisted code, calculations, and data analysis before it is deployed, published, or relied upon. - Do not present AI-generated content as original Work Product without human review. Where a contract, law, or regulation requires disclosure of AI use, include an appropriate AI-use disclosure in the form approved by the Administrator or supervisor, as appropriate. - Do not publish or distribute AI-generated content externally (including marketing materials, product descriptions, and customer communications) without review for accuracy, intellectual property concerns, and compliance with advertising and consumer protection laws. **Failure to verify AI-generated Work Product before submission or reliance is grounds for discipline, up to and including termination of employment or engagement.** # 5. Tool-Specific Usage Guidelines ## 5.1 Non-Enterprise Tools The Company vets and provisions enterprise AI tools for Company Personnel and requires that Personnel only use Company enterprise tools for Company business and Work Product. Accordingly, Personnel are prohibited from using personal or unapproved non-enterprise AI tools for any Company business or Work Product without the Administrator's approval. At minimum, for personal non-Company use, we strongly recommend that all Personnel use a paid account with training disabled. If there are any tools that you would like the Company to provision as an enterprise tool, please contact the Administrator. ## 5.2 Enterprise AI Workspaces (e.g., Foundational LLMs) **Permissible uses:** General-purpose enterprise AI workspaces (e.g., foundational LLMs like ChatGPT and Claude) may be used for drafting communications and documents, brainstorming, summarizing publicly available information, marketing and business development content, research assistance, coding assistance, and internal administrative documents or workflows. Approved AI Tools that are cleared for use with Confidential Information in Appendix A may be used with Confidential Information subject to the conditions in Appendix A and this Section 5.2. **Specific Workspace Use Cases:** A. **On-device or agentic use cases (e.g., Claude Cowork):** To enable these use cases, please contact the Administrator. Personnel may be required to undertake additional training to access such features. B. **Connectors:** Personnel may request that the Administrator enable Connectors to other Company enterprise tools. C. **Document storage:** Personnel may draft and store Work Product within approved AI workspaces, but must ensure that any material documents are saved to the Company's systems of record ([DOCUMENT/FILE MANAGEMENT SYSTEM]). D. **Shared or collaborative AI workspaces:** May be enabled on a project-by-project or customer-by-customer basis, with the approval of the Administrator. ## 5.3 Background AI Background AI platforms (i.e., software that runs passively or incidentally includes AI features as part of broader functionality, such as productivity, communications, document management, scheduling, marketing, CRM, or workflow tools) may be used consistent with this Policy. A non-exhaustive list of currently-used Background AI platforms is set forth in **Appendix A**. All AI-generated content must be reviewed for accuracy. ## 5.4 Third-Party Data and Customer-Facing AI Do not input information received from customers, vendors, or partners under confidentiality obligations into any AI Tool unless the tool is approved for Confidential Information and the applicable agreement permits it. Where the Company deploys AI in customer-facing contexts (such as chatbots, AI-assisted support, or AI-generated content delivered to customers), the deployment must be approved by the Administrator, must be accurate and not misleading, and must include any disclosure of AI use required by applicable law or contract. Document material AI-use disclosures to customers in the customer file or CRM. # 6. AI Notetakers and Transcription Tools AI-powered notetaking and transcription tools ("AI Notetakers") pose risks to confidentiality and wiretap and recording law compliance. These tools process audio through third-party servers, creating permanent records that may be discoverable in litigation. Accordingly, Company Personnel may not use AI Notetakers not provisioned by the Company. ## 6.1 Consent Requirements Obtain informed, affirmative consent from all participants before activating any AI Notetaker, regardless of the jurisdiction in which any participant is located and regardless of whether applicable wiretap or recording law would require single-party or all-party consent. Many AI Notetakers announce their presence automatically; that announcement alone is not sufficient, and silence does not constitute consent. For external communications (customers, vendors, partners), disclose the intended use in advance and obtain affirmative consent. Treat all resulting recordings, transcripts, and derived work product as Confidential Information, and store, transmit, and dispose of them in accordance with the Company's data security protocols. The Company adopts this all-party consent standard as a matter of policy, which may be stricter than the consent required by applicable law. ## 6.2 Data Security and Approved Tools Use only Company-approved AI Notetakers, as identified in Appendix A. Personal accounts, free-tier services, and any other third-party or consumer-grade notetaking or transcription tools are prohibited for Company communications. For external communications, [APPROVED AI NOTETAKER] is the only approved AI Notetaker and may be used only after advance disclosure and consent in accordance with Section 6.1. Personnel must review, correct, and approve any summaries, minutes, or action items generated by AI Notetakers before internal or external circulation or archiving. Transcripts, recordings, and any derived work product must remain at all times within the Company's controlled environment: store them in the Company's systems of record, disable automatic cloud storage and third-party integrations, and do not export, forward, sync, or otherwise transmit them to any vendor cloud, personal device, personal account, or external service. Third-party integrations that would transmit these materials outside the Company's enterprise environment must remain disabled. ## 6.3 Recording by External Parties Be aware that external participants may record or transcribe meetings with their own AI tools, and such records may later be disclosed or discoverable. Do not discuss the Company's most sensitive matters (trade secrets, MNPI, privileged communications with counsel) in meetings where an unapproved AI Notetaker is active; if a counterparty insists on recording, escalate to the Administrator and document the Company's position in writing. # 7. Agentic AI Tools Obtain prior written consent from the Administrator before using any Agentic AI Tools. Agentic AI Tools must be configured to request human confirmation before executing state-changing actions (such as sending communications, modifying records, executing transactions, or changing system configurations); an Agentic AI Tool that cannot be configured to require such human confirmation may not be used for state-changing actions absent a specific written exception from the Administrator. Prohibited uses include: autonomous access to Sensitive Information without authorization; unattended tasks involving customer data unless Company-approved and configured to halt on error; and chaining multiple Agentic AI Tools without written approval. If an Agentic AI Tool takes unauthorized action, immediately cease use and report to the Administrator. # 8. Prohibition on AI Use in Employment Decisions AI Tools may not be used in connection with any Company employment decision without the prior written approval of the Administrator and confirmation of compliance with applicable law, including (where applicable) NYC Local Law 144's requirements for bias audits, public disclosure, and advance notice to candidates, state anti-discrimination and AI-disclosure laws, and, as a best practice, the standards set forth in the EU AI Act (Regulation (EU) 2024/1689, Annex III, point 4) for AI uses that would be classified as high-risk in the employment context. This restriction covers recruiting, selecting, or evaluating candidates, as well as decisions affecting promotion, compensation, performance evaluation, discipline, termination, or task allocation based on individual behavior or traits. Permitted administrative uses, such as drafting job descriptions, scheduling, or generating HR templates, are allowed only if the AI output does not inform or contribute to an employment decision. # 9. Oversight, Enforcement, and Administration ## 9.1 Governance and Contacts The Administrator oversees AI policies, compliance, tool evaluation, and training. [Optional: The Company's AI Governance Committee, chaired by the Administrator, performs these functions.] The Administrator is responsible for maintaining Appendix A, evaluating new tools, and aligning this Policy with the Company's broader AI governance program (see the note in the Acknowledgment section). ## 9.2 Monitoring, Security, and Incident Response The Company reserves the right to monitor and audit all use of Company systems, Company accounts, and Company-provisioned AI Tools, including prompts, Inputs, and Outputs. Only authorized Personnel with proper credentials may access AI Tools; do not share credentials. AI access will be revoked upon termination. Report any AI incident (violation of this Policy, security breaches, material errors, or disclosure of Confidential Information) immediately to the Administrator. ## 9.3 Disciplinary Action **The following violations are grounds for termination of employment or engagement:** - Use of any non-approved AI tool, personal AI account, or consumer-tier subscription for Company business; - Failure to fact-check and verify AI-generated Work Product before submission to any recipient or reliance in any business decision; - Inputting Confidential Information into any non-approved AI Tool; and - Misuse of Company AI Tools for non-Company business. Other violations may result in disciplinary action up to and including termination of employment or engagement. ## 9.4 Training and Policy Administration Personnel must complete the required AI training before being granted access, covering this Policy, data security, hallucination and accuracy risks, applicable legal requirements, and tool-specific guidance. This Policy will be reviewed periodically and updated as necessary. The Company reserves the right to modify this Policy at any time with or without notice. # Acknowledgment I acknowledge that I have received, read, understood, and agree to comply with this Generative Artificial Intelligence Policy. I understand that: (1) the Company owns all Inputs and Outputs created in connection with Company business, and all such Inputs and Outputs are Company records subject to the Company's legal holds, discovery obligations, and regulatory requests, except as otherwise provided by contract or applicable law; (2) use of non-approved AI tools for Company business is grounds for termination of employment or engagement; (3) I must independently fact-check and verify all AI-generated Work Product before submission or reliance, and failure to do so is grounds for termination of employment or engagement; and (4) violations may result in disciplinary action, including termination and personal liability. Signature: _______________________________________________ Date: ____________________________________________________ Printed Name: ____________________________________________ Title / Position: ________________________________________ > **Governance note for adopting organizations:** This Policy governs individual conduct. It does not by itself constitute an AI governance program. Organizations should also inventory their AI systems and use cases, assess and prioritize risks, assign accountability, measure outcomes, and review and update controls over time, for example by aligning to the four functions of the NIST AI Risk Management Framework (Govern, Map, Measure, Manage) and its Generative AI Profile (NIST-AI-600-1), or to a comparable framework such as ISO/IEC 42001. See the repository [README](../../README.md) and [Customization Guide](../../CUSTOMIZATION_GUIDE.md). # Appendix A: Approved AI Tools and Background AI Platforms *Effective as of [EFFECTIVE DATE].* > **Template note:** Replace the entries below with the tools your organization has actually vetted, licensed, and approved. The entries shown are illustrative examples, not endorsements. ## Approved AI Tools **[GENERAL-PURPOSE AI TOOL 1] (Enterprise Plan) — [VENDOR].** *Example: ChatGPT Enterprise — OpenAI.* Approved for drafting, analysis, research, coding assistance, and business content. May be used with Confidential Information subject to: (i) supervisor approval; (ii) compliance with any applicable customer, vendor, or partner agreement; and (iii) compliance with Section 5.2 of the Policy. All output must be independently verified. **Accounts which are not part of the Company's Enterprise plan may not be used.** **[GENERAL-PURPOSE AI TOOL 2] (Enterprise Plan) — [VENDOR].** *Example: Claude Enterprise — Anthropic.* Approved for drafting, analysis, research, coding assistance, and business content. May be used with Confidential Information subject to: (i) supervisor approval; (ii) compliance with any applicable customer, vendor, or partner agreement; and (iii) compliance with Section 5.2 of the Policy. All output must be independently verified. **Accounts which are not part of the Company's Enterprise plan may not be used.** **[INDUSTRY/FUNCTION-SPECIFIC AI TOOL] — [VENDOR].** *Example: an AI tool specific to your industry or a business function such as design, support, or development.* Approved for [DESCRIBE APPROVED USES], subject to compliance with this Policy. ## Approved AI Notetakers **[APPROVED AI NOTETAKER]** *(Example: Zoom AI Companion)* — the only AI Notetaker approved for external communications, subject to the consent and data-handling requirements of Section 6. ## Background AI Platforms The following platforms incidentally include AI features and may be used consistent with the Policy. All AI-generated output must be reviewed for accuracy. *(Replace with your organization's actual software stack; examples shown.)* - [OFFICE PRODUCTIVITY SUITE] *(e.g., Microsoft 365 / Copilot or Google Workspace / Gemini)* — AI-powered content generation, suggestions, and task automation - [VIDEOCONFERENCING PLATFORM] *(e.g., Zoom AI Companion)* — meeting summarization, action item capture, and smart scheduling - [PROJECT MANAGEMENT TOOL] *(e.g., ClickUp, Asana, Monday)* — AI-powered task summarization, task creation, and writing assistance - [CRM / MARKETING PLATFORM] *(e.g., HubSpot, Salesforce)* — AI features for marketing, sales, and customer service - [ACCOUNTING / FINANCE TOOL] *(e.g., QuickBooks)* — AI-assisted categorization, reporting, and forecasting - [DOCUMENT WORKFLOW TOOL] *(e.g., PandaDoc, DocuSign)* — AI-enhanced document creation and workflow management # Appendix B: Legal and Regulatory Considerations *Effective as of [EFFECTIVE DATE].* > **Template note:** This appendix is a non-exhaustive starting point, drafted as of June 2026. AI law is changing rapidly and varies by state, industry, and country. Edit this appendix with your counsel to reflect where you operate, what data you handle, and what industry rules apply to you, and assign someone to keep it current. Personnel should be aware that the Company's AI use may implicate, among other things: - **Consumer protection law:** The FTC Act and state analogs prohibit unfair or deceptive practices, including false or unsubstantiated claims about AI capabilities, undisclosed AI-generated endorsements or reviews, and deceptive AI-generated content. - **Privacy and data protection law:** State comprehensive privacy laws (e.g., California's CCPA/CPRA and similar laws in a growing number of states) impose obligations on the collection and processing of personal information, including in some cases specific rules for automated decision-making and profiling. If the Company handles data of EU/UK residents, the GDPR/UK GDPR apply. - **Employment and anti-discrimination law:** Laws regulating AI in hiring and employment decisions, including NYC Local Law 144 (bias audits and notice for automated employment decision tools), Illinois' AI-in-employment provisions, and emerging state AI statutes. Note that some state AI laws are in flux (for example, Colorado's AI legislation has been substantially revised and its effective date delayed, with litigation ongoing); consult counsel for current status. - **Intellectual property:** Copyright protection for AI-generated works is limited; AI outputs may incorporate or resemble third-party protected material; and inputting third-party content into AI tools may raise infringement or license-compliance issues. Trade secret protection can be undermined by disclosure to AI tools that lack adequate confidentiality protections. - **Wiretap and recording laws:** State all-party consent statutes apply to AI notetakers and transcription tools (see Section 6). - **EU AI Act:** If the Company places AI systems on the EU market or its AI use affects persons in the EU, Regulation (EU) 2024/1689 imposes phased obligations, including for general-purpose AI and high-risk systems. - **Industry-specific regulation:** [LIST ANY APPLICABLE SECTOR RULES — e.g., HIPAA for health data, GLBA for financial data, FERPA for education records, FDA rules for regulated products, state insurance or professional licensing rules.] --- *This template is adapted from the open-source Generative Artificial Intelligence Policy published by Falcon Rappaport & Berkman LLP ("FRB") and is dedicated to the public domain under [CC0 1.0](https://creativecommons.org/publicdomain/zero/1.0/); attribution is appreciated but not required. It is not legal advice. Organizations adopting this template are responsible for tailoring it to their own operations, jurisdictions, tools, and risk tolerance, for verifying all legal references, and for embedding it in a broader AI governance program. If you would like attorneys to review your customized policy or advise on your AI governance program, FRB is available to help: visit [ai.frblaw.com](https://ai.frblaw.com) or email [ai@frblaw.com](mailto:ai@frblaw.com). Reaching out does not create an attorney-client relationship.*