Free Acceptable Use Policy Example and Templates
Six free acceptable use policy templates and examples for small business: full policy, short version, AI tool policy, BYOD, monitoring notice, DOCX.
Acceptable Use Policy Example and Templates
Six free acceptable use policy examples for small business, covering company email, internet, devices, software installs, personal use, and a dedicated AI section: a full policy, a one-page version, an AI acceptable use policy, a personal device addendum, an electronic monitoring notice with state add-ons, and an acknowledgment form. Download as DOCX.
The first acceptable use policy I ever wrote was two paragraphs long, and I wrote it the afternoon someone installed a free PDF converter on a shared office laptop and brought back a browser extension that redirected every search. Nothing catastrophic happened. What it exposed was that we had never told anyone what they could install, what they could use company email for, or that any of it was visible to us.
An acceptable use policy is the document that answers those questions once, for everyone, instead of case by case. It covers company computers and phones, the network and internet, email, software installs, personal use, company data, and now AI tools. It ends with a signature, because the acknowledgment is what turns a document into notice.
This page gives you six versions to download as Word files, free and without an email: a full acceptable use policy, a one-page version for a handbook, a standalone AI acceptable use policy, a personal device addendum, an electronic monitoring notice with state add-ons, and an acknowledgment form. They sit alongside your broader HR policy set and your employee handbook.
What an Acceptable Use Policy Covers
An acceptable use policy is a single written document that sets the rules for how employees may use company technology and company data. It defines the systems in scope, what counts as acceptable and prohibited use, how much personal use is allowed, who approves software, and that company systems may be monitored. It is delivered to every person who gets access and signed before access is granted.
The document goes by several names. Acceptable use policy, AUP, computer use policy, technology use policy, and IT acceptable use policy all describe the same thing, and most search results that call themselves an acceptable use policy sample are the same document in different clothing. The label matters less than the coverage.
What distinguishes a good example from a generic one is scope discipline. A strong policy is specific about the systems it covers and specific about the handful of rules that get broken most: installing software, moving company data somewhere personal, sharing a login, and now pasting confidential material into an AI tool. Everything else is supporting detail. If you are building out a wider set of documents, this policy sits next to your email policy and your social media policy, and the three overlap deliberately.
Which Systems Are in Scope
Scope is the section people skip and then regret. Name the systems explicitly, because a policy that says company equipment leaves out cloud accounts, personal phones logged into company email, and the AI assistant someone signed up for with a company card. Cover devices, network, accounts and software, and third-party tools.
The two boundaries worth stating plainly are personal devices and company data. A personal phone that receives company email is inside the policy for company data purposes even though the hardware is not company property. Company data stays inside company systems, whatever device it is viewed on. That framing keeps the policy practical without pretending you control a handset you do not own.
The other scope question is who the policy applies to. Contractors, interns, and temporary staff use the same systems and should sign the same acknowledgment. If you use a shared drive or a shared login for anything, list it, because shared access is where accountability quietly disappears. Your data protection policy handles the privacy obligations that sit underneath.
Personal Use: Drawing the Line
Pick one of three approaches and write it down: business use only, limited incidental use, or broad personal use permitted. All three are defensible. The failure mode is having no stated rule, because then every manager applies a different standard and the first enforcement action looks arbitrary.
Whichever you choose, the sentence that does the most work is the privacy one. Employees should have no expectation of privacy in anything created, stored, sent, or received on company systems, including personal content. The most common dispute I have seen is not about someone shopping online at lunch. It is about an employee who assumed a personal message sent from a company account was off limits.
Write the personal-use rule the way you actually intend to apply it. A policy that bans all personal use while everyone visibly checks their phone through a company hotspot teaches people that the document is decorative, and that lesson carries over to the rules that matter. It also helps to deliver the policy at onboarding rather than as an afterthought: FirstHR ships it as an onboarding step and captures the signature before credentials are issued. Applicant tracking is coming soon to FirstHR.
The AI Section Most Examples Skip
Add a dedicated AI section, or a standalone AI acceptable use policy, because almost every acceptable use policy example still in circulation predates everyday AI use at work. The rules that matter are narrow: approved tools only, a hard list of information that never goes into a prompt, human review of every output, and prior approval for high-risk uses.
Those numbers are the argument for writing the rules now. If half your team is using AI at least occasionally and you have never said which tools are approved or what data is off limits, the default policy is whatever each person decides is fine. In practice that means customer emails, candidate resumes, contract language, and occasionally payroll figures going into a consumer account with terms nobody read.
A ban is the tempting shortcut and the worst option, because people route around it and you lose visibility entirely. A short, specific standard gets followed. The one section that genuinely needs care is employment decisions: using AI to screen applicants, score candidates, or rank employees pulls in a growing set of state and city rules on automated employment decision tools, some requiring notice, consent, or a bias audit. Keep that on the approval list and read up on AI in HR before you deploy anything there.
The Monitoring Notice and State Law
Give notice that company systems may be monitored, and collect an acknowledgment. Employers can generally monitor activity on their own systems, but federal wiretap law bars intercepting electronic communications at 18 U.S.C. § 2511, and employers depend on the consent exception at § 2511(2)(d) and the business-extension carve-out inside the definition of an intercepting device at § 2510(5)(a). A signed acknowledgment is the cleanest way to establish that consent.
Three states go further and require a notice by statute. Connecticut requires prior written notice to affected employees describing the types of monitoring that may occur, plus a posted notice in a conspicuous place, under Connecticut General Statutes § 31-48d, and the posting itself counts as that written notice.
The Connecticut exception is narrower than most summaries suggest. It applies only where the employer has reasonable grounds to believe employees are engaged in conduct that violates the law, violates the legal rights of the employer or other employees, or creates a hostile workplace environment, and where monitoring may produce evidence of that misconduct.
Connecticut is also raising the bar. Public Act 26-73 rewrites section 31-48d effective October 1, 2026, and the notice must then also identify the specific locations on the premises where monitoring may occur, with carve-outs for airport premises and for security and employee safety purposes.
That act adds a second document. Every employee hired on or after the effective date must receive a plain language written statement, before starting work, describing which activities are prohibited and may be monitored without prior written notice. Build both into the onboarding packet rather than after the date lands.
Delaware takes a different approach at title 19, section 705, giving employers a choice between a daily electronic notice each time an employee accesses employer-provided email or internet service, or a one-time notice in writing or electronic form that the employee acknowledges in writing or electronically. Most small businesses take the one-time option and file the acknowledgment.
New York requires prior written notice upon hiring for employees subject to monitoring of phone, email, or internet access, written or electronic acknowledgment, and a posted notice, under Civil Rights Law § 52-c. Because the notice is tied to hiring, it belongs in your onboarding packet rather than in an annual policy refresh.
| State | What the statute requires | Citation | Civil penalty |
|---|---|---|---|
| Connecticut | Prior written notice to all affected employees of the types of electronic monitoring that may occur, plus a notice posted in a conspicuous place. From October 1, 2026, the notice must also give the specific locations where monitoring may occur, and each new hire gets a plain language statement on activity that may be monitored without notice. Exception where the employer reasonably believes employees are violating the law, violating legal rights, or creating a hostile workplace. | Conn. Gen. Stat. § 31-48d, as amended by P.A. 26-73 | Maximum $500 first offense, $1,000 second, $3,000 third and each subsequent |
| Delaware | Either an electronic notice each day the employee accesses employer-provided email or internet service, or a one-time notice in writing or electronic form acknowledged by the employee in writing or electronically. | 19 Del. C. § 705 | $100 for each violation |
| New York | Prior written notice upon hiring to employees subject to monitoring of telephone, email, or internet, with written or electronic acknowledgment, plus a notice posted in a conspicuous place. | N.Y. Civ. Rights Law § 52-c | Maximum $500 first offense, $1,000 second, $3,000 third and each subsequent |
The practical setup for a small business is straightforward: put a monitoring paragraph in the acceptable use policy, deliver a standalone monitoring notice, collect a signed acknowledgment, and post the notice where employees can see it. For the deeper detail, see the guide to employee monitoring laws and the standalone monitoring consent form.
Which Template Should You Use?
Start with the full policy if you have never written one, or the one-page version if you want a handbook section you can adopt this week. Add the AI policy in either case, add the personal device addendum only if people use their own phones or laptops for work, and always deliver the monitoring notice and the acknowledgment form.
6 Free Acceptable Use Policy Templates
Download all six as a single Word bundle or copy individual templates. The full policy is the core, the short version is the fast path, the AI policy handles the newest gap, the device addendum covers personal hardware, the monitoring notice carries the state add-ons, and the acknowledgment form captures the signature. Fill in your approved tools, your personal-use rule, and your reporting contact, and have US counsel review before you adopt.
Template 1: Acceptable Use Policy (Full)
The complete policy: scope and covered systems, the general standard, prohibited use, personal use with three options to choose from, passwords and access, software installs, email and internet, AI tools, company data, personal devices, monitoring, incident reporting, enforcement, a protected-rights clause, and an acknowledgment.
Template 2: Short Acceptable Use Policy
A concise, signable one-page version for a small or early-stage company, or to drop into the employee handbook as a single section. It keeps the software approval rule, the AI rule, the monitoring notice, and the protected-rights clause, and drops the rest.
Template 3: AI Acceptable Use Policy
A standalone AI acceptable use policy template covering approved tools, permitted uses, a hard list of information that never goes into a prompt, human review and accountability, disclosure, high-risk uses that need prior sign-off, and intellectual property. Adopt it on its own or attach it as an appendix.
Template 4: Personal Device (BYOD) Acceptable Use Addendum
For employees using a personal phone or computer for work: eligibility and approval, minimum device requirements, how company data may be used, what the company can and cannot see, removing company data on separation, reimbursement, and off-hours work by non-exempt employees.
Template 5: Electronic Monitoring Notice and Consent
A separate notice and consent form with a checklist of exactly what is monitored, the purpose, the no-expectation-of-privacy statement, and the boundary around personal accounts, plus ready add-on paragraphs for Connecticut, Delaware, and New York.
Template 6: Acceptable Use Policy Acknowledgment Form
A standalone form to record that each person received and agreed to the policy, with checkboxes for which documents were delivered and fields for the policy version, the delivery method, and the date access was granted.
An Acceptable Use Policy at Small Scale
A large company has a security team to write this policy, maintain the approved-software list, and review tool requests. A small business has an owner or an office manager doing all three between other work, usually after someone has already installed something they should not have. Here is what changes at that scale.
Deliver It Before You Grant Access
An acceptable use policy earns its keep at the moment access is granted, not at the moment it is written. The sequence is: adapt the version you need, have counsel review it, deliver it as an onboarding step before credentials are issued, capture the acknowledgment, and store it with the policy version.
The templates above work on their own. To run the delivery and signature without paper, FirstHR sends the acceptable use policy, the AI rules, and the monitoring notice as onboarding steps, captures each acknowledgment with built-in e-signature, and files the signed version through document management with the policy version on record. Employees can pull up the current version anytime through self-service, and training modules can run a short security and AI refresher when the policy changes. Applicant tracking is coming soon to FirstHR. FirstHR is an onboarding and HR platform, not an IT security product and not a law firm, so pair it with your IT provider and US counsel.
Frequently Asked Questions
What is an acceptable use policy?
An acceptable use policy, often shortened to AUP, is a written document that sets the rules for how employees may use company technology: computers, phones, networks, internet access, email, software, cloud accounts, and company data. It defines what is allowed, what is prohibited, how much personal use is acceptable, who may install software, how passwords and access are handled, and that company systems may be monitored. It usually ends with a signed acknowledgment that each employee returns before access is granted. In a small business the acceptable use policy is often the single technology policy that exists, which is why the versions on this page fold in email, internet, devices, software installs, AI tools, and the monitoring notice rather than splitting them into separate documents. This is general information, not legal advice.
What should an acceptable use policy include?
A complete acceptable use policy includes the purpose and who it applies to, a list of the systems and devices covered, a general standard of acceptable use, a specific list of prohibited activity, a personal-use rule, password and account security requirements, a software and installation approval process, rules for email and internet use, a section on AI and third-party tools, data and confidentiality handling, terms for personal devices used for work, a monitoring notice with a no-expectation-of-privacy statement, an incident reporting instruction, an enforcement statement, a clause preserving employee rights under applicable law, and an acknowledgment. The sections that small businesses most often leave out are the software approval process, the AI rules, and the monitoring notice, which are exactly the three that cause the most trouble later. This is general information, not legal advice.
Do we need a separate AI acceptable use policy?
You need the AI rules in writing, but whether they live in a separate document or inside the main acceptable use policy is a practical choice. A separate AI acceptable use policy is easier to update, easier to circulate on its own, and easier for employees to actually read, which matters because AI tools and vendor terms change quickly. Folding the rules into the main policy keeps everything in one place and one signature. Many small teams do both: a short AI section in the main acceptable use policy pointing to a standalone AI policy that carries the detail. Either way, the rules that matter are the same: approved tools only, a hard list of information that never goes into a prompt, human review of every output, and prior approval for high-risk uses. This page includes both the combined section and a standalone AI policy. This is general information, not legal advice.
Can an employer legally monitor employee email and internet use?
Generally yes on company systems, subject to federal and state rules and to any notice or consent requirement that applies. Federal wiretap law under the Electronic Communications Privacy Act prohibits intercepting electronic communications at 18 U.S.C. section 2511, but employers commonly rely on the consent exception at section 2511(2)(d) and on the business-extension carve-out written into the definition of an intercepting device at section 2510(5)(a). Several states add their own requirements. Connecticut, Delaware, and New York each require notice to employees. New York requires an acknowledgment, and Delaware requires one when the employer chooses the one-time notice instead of a daily notice. Some states also regulate recording of calls and require all-party consent, which is a separate question from monitoring notice. The safest practice for a small business is to state the monitoring clearly in the acceptable use policy, deliver a standalone notice, collect a signed acknowledgment, and post the notice. This is general information, not legal advice.
Which states require notice before electronic monitoring?
Connecticut, Delaware, and New York have the clearest employee-facing notice statutes. Connecticut General Statutes section 31-48d requires prior written notice describing the types of monitoring that may occur plus a posted notice in a conspicuous place, and Public Act 26-73 adds the specific monitored locations and a plain language statement for new hires effective October 1, 2026. Its exception is limited to conduct that violates the law, violates legal rights, or creates a hostile workplace. Delaware, at title 19 section 705, requires either an electronic notice each day the employee accesses employer-provided email or internet service, or a one-time written or electronic notice that the employee acknowledges. New York Civil Rights Law section 52-c requires prior written notice upon hiring to employees subject to monitoring of phone, email, or internet, written or electronic acknowledgment, and a posted notice. This is general information, not legal advice.
Should we allow personal use of company computers and internet?
That is a business decision, and all three common approaches are defensible as long as you write down which one you picked. Business use only is the strictest and fits regulated work, shared terminals, and shop-floor devices, but it is hard to enforce evenly because nearly everyone checks something personal during a shift. Limited incidental use, which permits reasonable personal use on breaks and outside working time, is what most small businesses actually practice and the easiest to apply consistently. Broad personal use works for salaried teams measured on output. Whichever you choose, pair it with a clear statement that personal content on company systems is not private, because the most common dispute is an employee who assumed a personal message on a company account was off limits. This is general information, not legal advice.
Can employees install their own software on company computers?
Most acceptable use policies say no, and that is the right default for a small business. Unapproved software creates real exposure: unlicensed copies, malware bundled with free downloads, browser extensions that read everything on a page, and cloud tools that store company data under terms nobody read. The rule that holds up is not a blanket ban with no path forward, which employees route around, but a short approval process: keep a list of approved applications, name one person who approves requests, and answer requests quickly. The same process should cover AI tools and any application that will connect to company email, files, or customer data. Slow approval is the main reason people install things quietly, so speed matters more than paperwork. This is general information, not legal advice.
How do we roll out an acceptable use policy that people actually follow?
Deliver it before access, collect a signature, and keep it short enough to read. The sequence that works is: adapt the template to your systems and your approved-tools list, have US counsel review it, send it as an onboarding step before credentials are issued, capture a signed or electronic acknowledgment, and file that acknowledgment with the policy version in the employee record. Then review the approved-tools list on a set schedule and re-collect acknowledgments whenever the policy materially changes. Two details make the difference in practice: name a real person to approve software and AI tool requests and have them respond quickly, and explain the reason behind the monitoring notice rather than only the rule. A policy people understand and signed gets followed far more often than a longer one nobody read. This is general information, not legal advice.