FirstHR

Free Acceptable Use Policy Example and Templates

Six free acceptable use policy templates and examples for small business: full policy, short version, AI tool policy, BYOD, monitoring notice, DOCX.

Nick Anisimov

Nick Anisimov

FirstHR Founder

Core HR
16 min

Acceptable Use Policy Example and Templates

Six free acceptable use policy examples for small business, covering company email, internet, devices, software installs, personal use, and a dedicated AI section: a full policy, a one-page version, an AI acceptable use policy, a personal device addendum, an electronic monitoring notice with state add-ons, and an acknowledgment form. Download as DOCX.

The first acceptable use policy I ever wrote was two paragraphs long, and I wrote it the afternoon someone installed a free PDF converter on a shared office laptop and brought back a browser extension that redirected every search. Nothing catastrophic happened. What it exposed was that we had never told anyone what they could install, what they could use company email for, or that any of it was visible to us.

An acceptable use policy is the document that answers those questions once, for everyone, instead of case by case. It covers company computers and phones, the network and internet, email, software installs, personal use, company data, and now AI tools. It ends with a signature, because the acknowledgment is what turns a document into notice.

This page gives you six versions to download as Word files, free and without an email: a full acceptable use policy, a one-page version for a handbook, a standalone AI acceptable use policy, a personal device addendum, an electronic monitoring notice with state add-ons, and an acknowledgment form. They sit alongside your broader HR policy set and your employee handbook.

TL;DR
An acceptable use policy sets the rules for how employees may use company devices, the network and internet, email, software, company data, and AI tools. It defines prohibited use, sets a personal-use standard, requires approval before new tools are adopted, and gives notice that systems may be monitored. Connecticut, Delaware, and New York require that notice by statute.

What an Acceptable Use Policy Covers

An acceptable use policy is a single written document that sets the rules for how employees may use company technology and company data. It defines the systems in scope, what counts as acceptable and prohibited use, how much personal use is allowed, who approves software, and that company systems may be monitored. It is delivered to every person who gets access and signed before access is granted.

The document goes by several names. Acceptable use policy, AUP, computer use policy, technology use policy, and IT acceptable use policy all describe the same thing, and most search results that call themselves an acceptable use policy sample are the same document in different clothing. The label matters less than the coverage.

What distinguishes a good example from a generic one is scope discipline. A strong policy is specific about the systems it covers and specific about the handful of rules that get broken most: installing software, moving company data somewhere personal, sharing a login, and now pasting confidential material into an AI tool. Everything else is supporting detail. If you are building out a wider set of documents, this policy sits next to your email policy and your social media policy, and the three overlap deliberately.

Which Systems Are in Scope

Scope is the section people skip and then regret. Name the systems explicitly, because a policy that says company equipment leaves out cloud accounts, personal phones logged into company email, and the AI assistant someone signed up for with a company card. Cover devices, network, accounts and software, and third-party tools.

Devices
Company laptops, desktops, and tablets
Company phones and hotspots
Removable storage and peripherals
Network and internet
Office Wi-Fi, wired network, and VPN
Website and browsing activity
Any internet access the company pays for
Accounts and software
Email, chat, calendar, and video
Cloud storage and business applications
Software installs, extensions, and licenses
AI and third-party tools
Approved AI assistants and AI features
Anything that connects to company data
New tools before they are adopted

The two boundaries worth stating plainly are personal devices and company data. A personal phone that receives company email is inside the policy for company data purposes even though the hardware is not company property. Company data stays inside company systems, whatever device it is viewed on. That framing keeps the policy practical without pretending you control a handset you do not own.

The other scope question is who the policy applies to. Contractors, interns, and temporary staff use the same systems and should sign the same acknowledgment. If you use a shared drive or a shared login for anything, list it, because shared access is where accountability quietly disappears. Your data protection policy handles the privacy obligations that sit underneath.

Personal Use: Drawing the Line

Pick one of three approaches and write it down: business use only, limited incidental use, or broad personal use permitted. All three are defensible. The failure mode is having no stated rule, because then every manager applies a different standard and the first enforcement action looks arbitrary.

Business use only
Strictest
Company systems are for company work, with exceptions only for emergencies or manager approval. Clean to write and hard to enforce fairly, because almost everyone checks something personal at some point. Best fit for regulated work, shared terminals, or shop-floor devices.
Limited incidental use
Most common
Reasonable personal use is allowed on breaks and outside working time, as long as it is lawful, does not interfere with work, and does not violate the prohibited-use rules. The privilege can be withdrawn. This is the version most small businesses actually live by.
Broad personal use
Most permissive
Personal use is allowed, subject to the prohibited-use rules and the monitoring notice. Works for salaried knowledge teams where the point is output, not screen time. Pair it with a very clear statement that nothing on company systems is private.

Whichever you choose, the sentence that does the most work is the privacy one. Employees should have no expectation of privacy in anything created, stored, sent, or received on company systems, including personal content. The most common dispute I have seen is not about someone shopping online at lunch. It is about an employee who assumed a personal message sent from a company account was off limits.

Write the personal-use rule the way you actually intend to apply it. A policy that bans all personal use while everyone visibly checks their phone through a company hotspot teaches people that the document is decorative, and that lesson carries over to the rules that matter. It also helps to deliver the policy at onboarding rather than as an afterthought: FirstHR ships it as an onboarding step and captures the signature before credentials are issued. Applicant tracking is coming soon to FirstHR.

Still Using Spreadsheets for Onboarding?
Automate documents, training assignments, task management, and track onboarding progress in real time.
See How It Works

The AI Section Most Examples Skip

Add a dedicated AI section, or a standalone AI acceptable use policy, because almost every acceptable use policy example still in circulation predates everyday AI use at work. The rules that matter are narrow: approved tools only, a hard list of information that never goes into a prompt, human review of every output, and prior approval for high-risk uses.

Half of US Employees Now Use AI at Work
In a survey of 23,717 US employees fielded February 4 to 19, 2026, Gallup found that half of employed American adults use AI in their role at least a few times a year, up from 46 percent the previous quarter, with 28 percent using it a few times a week or more and 13 percent using it daily (Gallup).

Those numbers are the argument for writing the rules now. If half your team is using AI at least occasionally and you have never said which tools are approved or what data is off limits, the default policy is whatever each person decides is fine. In practice that means customer emails, candidate resumes, contract language, and occasionally payroll figures going into a consumer account with terms nobody read.

Approved tools only
Name the tools employees may use and the account they must use them through. A free personal account and a company account often have different data-handling terms, and the difference is the whole point.
A hard list of what never goes in
Customer data, employee personal data, health information, payment data, credentials, source code, and anything under an NDA. Spell out the categories rather than saying be careful.
Human review of every output
The employee who uses the output owns it. Verify facts, figures, quotes, citations, and code before anything ships, and never send unreviewed output to a customer or a regulator.
Approval for high-risk uses
Employment decisions, personal data, recorded or transcribed meetings, and any tool that connects to company email or files need sign-off before use, not after.

A ban is the tempting shortcut and the worst option, because people route around it and you lose visibility entirely. A short, specific standard gets followed. The one section that genuinely needs care is employment decisions: using AI to screen applicants, score candidates, or rank employees pulls in a growing set of state and city rules on automated employment decision tools, some requiring notice, consent, or a bias audit. Keep that on the approval list and read up on AI in HR before you deploy anything there.

The Monitoring Notice and State Law

Give notice that company systems may be monitored, and collect an acknowledgment. Employers can generally monitor activity on their own systems, but federal wiretap law bars intercepting electronic communications at 18 U.S.C. § 2511, and employers depend on the consent exception at § 2511(2)(d) and the business-extension carve-out inside the definition of an intercepting device at § 2510(5)(a). A signed acknowledgment is the cleanest way to establish that consent.

Three states go further and require a notice by statute. Connecticut requires prior written notice to affected employees describing the types of monitoring that may occur, plus a posted notice in a conspicuous place, under Connecticut General Statutes § 31-48d, and the posting itself counts as that written notice.

The Connecticut exception is narrower than most summaries suggest. It applies only where the employer has reasonable grounds to believe employees are engaged in conduct that violates the law, violates the legal rights of the employer or other employees, or creates a hostile workplace environment, and where monitoring may produce evidence of that misconduct.

Connecticut is also raising the bar. Public Act 26-73 rewrites section 31-48d effective October 1, 2026, and the notice must then also identify the specific locations on the premises where monitoring may occur, with carve-outs for airport premises and for security and employee safety purposes.

That act adds a second document. Every employee hired on or after the effective date must receive a plain language written statement, before starting work, describing which activities are prohibited and may be monitored without prior written notice. Build both into the onboarding packet rather than after the date lands.

Delaware takes a different approach at title 19, section 705, giving employers a choice between a daily electronic notice each time an employee accesses employer-provided email or internet service, or a one-time notice in writing or electronic form that the employee acknowledges in writing or electronically. Most small businesses take the one-time option and file the acknowledgment.

New York requires prior written notice upon hiring for employees subject to monitoring of phone, email, or internet access, written or electronic acknowledgment, and a posted notice, under Civil Rights Law § 52-c. Because the notice is tied to hiring, it belongs in your onboarding packet rather than in an annual policy refresh.

StateWhat the statute requiresCitationCivil penalty
ConnecticutPrior written notice to all affected employees of the types of electronic monitoring that may occur, plus a notice posted in a conspicuous place. From October 1, 2026, the notice must also give the specific locations where monitoring may occur, and each new hire gets a plain language statement on activity that may be monitored without notice. Exception where the employer reasonably believes employees are violating the law, violating legal rights, or creating a hostile workplace.Conn. Gen. Stat. § 31-48d, as amended by P.A. 26-73Maximum $500 first offense, $1,000 second, $3,000 third and each subsequent
DelawareEither an electronic notice each day the employee accesses employer-provided email or internet service, or a one-time notice in writing or electronic form acknowledged by the employee in writing or electronically.19 Del. C. § 705$100 for each violation
New YorkPrior written notice upon hiring to employees subject to monitoring of telephone, email, or internet, with written or electronic acknowledgment, plus a notice posted in a conspicuous place.N.Y. Civ. Rights Law § 52-cMaximum $500 first offense, $1,000 second, $3,000 third and each subsequent
Notice Is Not the Same as Recording Consent
Monitoring notice laws and wiretap or recording consent laws are separate questions. A number of states require all-party consent to record a phone call or a conversation, which reaches call recording and some AI meeting assistants. Getting the monitoring notice right does not resolve the recording question, and a growing set of states also regulate location tracking and access to personal social media accounts. Confirm the rules for every state where you have employees. This is general information, not legal advice.

The practical setup for a small business is straightforward: put a monitoring paragraph in the acceptable use policy, deliver a standalone monitoring notice, collect a signed acknowledgment, and post the notice where employees can see it. For the deeper detail, see the guide to employee monitoring laws and the standalone monitoring consent form.

Which Template Should You Use?

Start with the full policy if you have never written one, or the one-page version if you want a handbook section you can adopt this week. Add the AI policy in either case, add the personal device addendum only if people use their own phones or laptops for work, and always deliver the monitoring notice and the acknowledgment form.

Acceptable Use Policy (Full)
The flagship
The complete policy: scope, general standard, prohibited use, personal use, passwords, software installs, email and internet, AI tools, company data, personal devices, monitoring, reporting, enforcement, a protected-rights clause, and an acknowledgment.
Short Acceptable Use Policy
One page
A concise, signable version for a small or early-stage company, or to drop into the employee handbook as a single section. Covers the essentials in one page and grows into the full policy later.
AI Acceptable Use Policy
The one most teams need now
A standalone AI acceptable use policy template: approved tools, permitted uses, a hard list of what never goes into a prompt, human review, disclosure, high-risk uses that need sign-off, and intellectual property.
Personal Device (BYOD) Addendum
Phones and laptops
For employees using a personal phone or computer for work: eligibility, minimum device requirements, how company data may be used, what the company can and cannot see, removing company data, reimbursement, and off-hours work.
Electronic Monitoring Notice
With state add-ons
A separate notice and consent form listing exactly what is monitored, why, and the no-expectation-of-privacy statement, plus ready add-on paragraphs for Connecticut, Delaware, and New York.
Acknowledgment Form
Ready to sign
A standalone form to record that each person received and agreed to the policy, with checkboxes for which documents were delivered and fields for the policy version and the date access was granted.
Match the Template to Your Situation
Never written one: the full Acceptable Use Policy. Need something adoptable immediately or a handbook section: the Short version. AI is the urgent gap: the AI Acceptable Use Policy, which stands on its own. People use personal phones or laptops for work: add the Personal Device Addendum. Employees in Connecticut, Delaware, or New York, or anywhere you monitor: the Electronic Monitoring Notice. Then use the Acknowledgment Form for all of them, and have US counsel review before adopting.

6 Free Acceptable Use Policy Templates

Download all six as a single Word bundle or copy individual templates. The full policy is the core, the short version is the fast path, the AI policy handles the newest gap, the device addendum covers personal hardware, the monitoring notice carries the state add-ons, and the acknowledgment form captures the signature. Fill in your approved tools, your personal-use rule, and your reporting contact, and have US counsel review before you adopt.

Download All 6 Acceptable Use Policy Templates
A full acceptable use policy, a one-page version, an AI acceptable use policy, a personal device addendum, an electronic monitoring notice with state add-ons, and an acknowledgment form. All as DOCX.

Template 1: Acceptable Use Policy (Full)

The complete policy: scope and covered systems, the general standard, prohibited use, personal use with three options to choose from, passwords and access, software installs, email and internet, AI tools, company data, personal devices, monitoring, incident reporting, enforcement, a protected-rights clause, and an acknowledgment.

Acceptable Use Policy (Full)
ACCEPTABLE USE POLICY
[Company Name]
Effective date: _ Policy owner: __
Last reviewed: _

1. PURPOSE AND SCOPE

This policy explains how employees of [Company Name] may use company technology:
computers, phones, networks, email, internet access, software, cloud accounts, and
company data. The goal is simple. Company systems exist to do company work, and
everyone who uses them needs to know the same rules.
This policy applies to all employees, contractors, interns, and temporary staff who
use company systems, whether on company equipment or on a personal device that
connects to company accounts, email, or data. It applies on site, at home, and while
traveling.

2. SYSTEMS AND DEVICES COVERED

"Company systems" includes, without limitation:
Company-owned computers, laptops, tablets, and phones
Company email, calendar, chat, and video accounts
The company network, Wi-Fi, VPN, and any internet access the company provides
Company file storage, cloud applications, and databases
Company data in any form, including customer, employee, and financial records
Personal devices used for company work or connected to company accounts
Company-issued credit cards, badges, and access credentials for those systems

3. GENERAL STANDARD OF ACCEPTABLE USE

Use company systems in a lawful, professional, and responsible way. Protect company
and customer information. Follow the same standards of conduct online that apply
everywhere else at work, including the policies on harassment, discrimination,
confidentiality, and data protection.
Every employee is responsible for what happens under their account. Do not share
credentials, do not let another person use your login, do not use an account that is
not yours, and do not access data you have no business reason to see.

4. PROHIBITED USE

The following are prohibited on company systems:
Any illegal activity, or use that violates company policy or a contract
Harassing, threatening, discriminatory, obscene, or violent content
Accessing, storing, or sending sexually explicit material
Downloading or sharing content in violation of copyright or license terms
Attempting to bypass security controls, filters, firewalls, or access limits
Installing or running unapproved software, browser extensions, or remote-access
tools on company devices
Connecting unapproved hardware or removable storage to company devices
Sending confidential company or customer data to a personal account or personal
device without written approval
Using company systems to run a separate business or a personal commercial venture
Misrepresenting yourself or the company, or sending anonymous or forged messages
Excessive personal use that interferes with work or degrades system performance

5. PERSONAL USE

[Choose the approach that fits your company and delete the others.]
Option A (limited incidental use): Reasonable, occasional personal use is permitted
during breaks and outside working time, as long as it is lawful, does not interfere
with work, does not consume significant system resources, and does not violate this
policy. The company may limit or withdraw this privilege at any time.
Option B (business use only): Company systems are provided for business use.
Personal use is not permitted except in an emergency or with manager approval.
Option C (broad personal use permitted): Personal use is permitted on company
systems, subject to the prohibited-use rules above and to the understanding that
anything stored or sent through company systems is not private.
Employees should have no expectation of privacy in personal content stored, created,
sent, or received on company systems. Personal use does not make that content
private. Keep genuinely private material on personal accounts and personal devices.

6. PASSWORDS, ACCESS, AND ACCOUNT SECURITY

Use strong, unique passwords, and use the company password manager if provided
Turn on multi-factor authentication wherever the company requires it
Never share a password, and never store passwords in plain text or on paper
Lock your screen when you step away, and secure devices when traveling
Report a lost or stolen device to [IT contact / manager] immediately
Do not use company passwords on personal accounts, or the reverse
Access only the systems and data your role requires

7. SOFTWARE, DOWNLOADS, AND INSTALLS

Only approved software may be installed on company devices. Before installing or
subscribing to any application, browser extension, cloud service, or AI tool that
will touch company data, submit a request to [IT contact / manager] for approval.
The company maintains a list of approved applications at [location]. Requests are
reviewed for security, licensing, and cost. Do not use unlicensed software, do not
sign up for a business tool with a personal account, and do not enter company payment
details for a service that was not approved.
Purchases of software or subscriptions follow the normal expense approval process.
Personal software may not be installed on company devices.

8. EMAIL, MESSAGING, AND INTERNET

Company email and messaging accounts are company property and are provided for
business communication. Write as though every message could be read by a customer, a
regulator, or a court, because it might be.
Do not open attachments or links from unknown senders; report suspected phishing to
[IT contact] rather than replying
Do not auto-forward company email to a personal address
Do not send confidential information to external recipients without approval and
appropriate protection
Do not use company email to sign up for personal services
Internet use may be filtered, logged, and reviewed; sites unrelated to work may be
blocked

9. ARTIFICIAL INTELLIGENCE AND THIRD-PARTY TOOLS

AI tools may be used for company work only when the tool is on the approved list and
the rules in the company AI acceptable use policy are followed. In summary:
Use approved AI tools only, through company accounts where provided
Never enter confidential company data, customer data, employee personal data,
protected health information, credentials, or source code into a tool that is not
approved for that data
Review and verify every AI output before using it; the employee remains responsible
for accuracy, quality, and appropriateness
Follow any disclosure rules the company sets for AI-assisted work product
Do not rely on AI output alone for an employment decision, a legal or financial
determination, or anything covered by regulation

10. COMPANY DATA AND CONFIDENTIALITY

Company and customer data stays in company systems. Do not copy company data to a
personal cloud account, personal email, or unapproved removable media. Do not
photograph screens containing confidential data. Follow the company data protection
and records retention rules, and return or delete company data on request.
Confidentiality obligations continue after employment ends. On separation, return all
company devices, badges, and materials, and do not retain copies of company data.

11. PERSONAL DEVICES

[If personal devices are allowed for work, state the conditions. For example:]
Employees may use a personal phone or computer for company work only with approval
and only if the device has a screen lock, current operating-system updates, and any
required security software. The company may require the ability to remove company
data from the device. See the personal device addendum for details.

12. MONITORING AND PRIVACY

Company systems are the property of [Company Name], and the company may monitor,
access, review, retain, and disclose anything created, stored, sent, or received on
them, to the extent permitted by law. This may include email and messages, internet
activity, files, application use, network traffic, and device activity.
Employees should have no expectation of privacy when using company systems, including
for personal use. The company will follow applicable federal and state notice and
consent requirements, and a separate electronic monitoring notice is provided where
required. [Confirm the requirements for every state where you have employees.]

13. REPORTING PROBLEMS

Report a suspected security incident, malware infection, lost device, phishing
attempt, or accidental disclosure to [IT contact / manager] immediately, even if you
think it was your mistake. Prompt reporting limits the damage, and the company will
not penalize an employee for reporting a good-faith concern promptly.

14. ENFORCEMENT

Violations of this policy may result in loss of access, disciplinary action up to and
including termination of employment, and, where the conduct is unlawful, referral to
law enforcement. The company may also seek to recover losses caused by a violation.

15. PROTECTED RIGHTS

Nothing in this policy is intended to restrict, and this policy will not be applied
to restrict, any right employees have under applicable law to discuss wages, hours,
or other terms and conditions of employment, to engage in protected concerted
activity, or to report suspected unlawful conduct to a government agency.

ACKNOWLEDGMENT

I acknowledge that I have received and read the [Company Name] Acceptable Use Policy,
that I understand it, and that I agree to follow it as a condition of using company
systems. I understand that company systems may be monitored and that I should have no
expectation of privacy in my use of them.
Employee signature: __ Date: _
Print name: __

DISCLAIMER: This is a sample template for general informational purposes only and is
not legal advice, and not a guarantee of compliance. Electronic monitoring, privacy,
and employee-rights laws vary by state and change over time. Have this policy
reviewed and adapted by qualified US employment counsel before adopting it.

Template 2: Short Acceptable Use Policy

A concise, signable one-page version for a small or early-stage company, or to drop into the employee handbook as a single section. It keeps the software approval rule, the AI rule, the monitoring notice, and the protected-rights clause, and drops the rest.

Short Acceptable Use Policy (One Page)
ACCEPTABLE USE POLICY (SHORT VERSION)
[Company Name]
Effective date: _
A concise, one-page acceptable use policy for a small or early-stage company, or to
drop into an employee handbook as a single section. Expand into the full policy as
the team and the tool stack grow.

POLICY STATEMENT

[Company Name] provides computers, phones, email, internet access, software, and
cloud accounts so employees can do their jobs. These systems, and everything on them,
belong to the company.
When you use company systems, you agree to:
Use them lawfully, professionally, and for company business
Protect company and customer information, and access only what your role requires
Use strong, unique passwords and multi-factor authentication where required, and
never share your login
Install only approved software, and request approval before adopting any new
application, browser extension, or AI tool that will touch company data
Keep confidential data inside company systems, and never move it to a personal
account or unapproved storage
Use approved AI tools only, keep confidential and personal data out of them, and
check every AI output before you rely on it
Report a lost device, a suspected phishing message, or any security incident to
[contact] immediately
Keep personal use reasonable and lawful [or: keep company systems for business use]
Company systems may be monitored, logged, and reviewed to the extent permitted by
law, including email, internet activity, files, and device use. Employees should have
no expectation of privacy when using company systems, including for personal use.
Nothing in this policy restricts any right employees have under applicable law to
discuss pay or working conditions, to engage in protected concerted activity, or to
report suspected unlawful conduct to a government agency.
Violations may result in loss of access and disciplinary action up to and including
termination of employment.

ACKNOWLEDGMENT

I acknowledge that I have received and read this Acceptable Use Policy and agree to
follow it as a condition of using company systems.
Employee signature: __ Date: _

DISCLAIMER: This is a sample template for general information only and is not legal
advice. Have it reviewed by qualified US employment counsel before adopting it.

Template 3: AI Acceptable Use Policy

A standalone AI acceptable use policy template covering approved tools, permitted uses, a hard list of information that never goes into a prompt, human review and accountability, disclosure, high-risk uses that need prior sign-off, and intellectual property. Adopt it on its own or attach it as an appendix.

AI Acceptable Use Policy
AI ACCEPTABLE USE POLICY
[Company Name]
Effective date: _ Policy owner: __
Use this as a standalone AI acceptable use policy, or attach it to the main
acceptable use policy as an appendix. It covers generative AI assistants, AI features
built into other software, and AI coding or writing tools.

1. PURPOSE

[Company Name] supports the responsible use of AI tools to do better work faster.
This policy sets the rules so that productivity does not come at the cost of
confidentiality, accuracy, or a customer relationship. It applies to every employee
and contractor who uses an AI tool for company work, on any device.

2. APPROVED TOOLS

Use only AI tools on the approved list maintained at [location], and use them through
the company account where one is provided. Before using any new AI tool for company
work, or turning on an AI feature inside an existing application, submit a request to
[IT contact / manager].
Approval considers what the vendor does with the data, whether the vendor trains
models on customer input, where data is stored, contract and security terms, and
cost. A free personal account is not a substitute for an approved company account,
because the data handling is usually different.
Approved tools:
Approved uses: _

3. WHAT YOU MAY USE AI FOR

[Adjust to your business. Typical approved uses include:]
Drafting, editing, summarizing, and rewriting internal documents
Brainstorming, outlining, and research starting points
Drafting code, with review, in approved development tools
Formatting, translating, and cleaning up your own work product
Preparing first drafts of customer-facing material for human review

4. WHAT YOU MAY NOT PUT INTO AN AI TOOL

Never enter the following into an AI tool that is not specifically approved for it:
Customer or client data of any kind, including names, contact details, and account
information
Employee personal data, including Social Security numbers, pay, medical
information, immigration documents, and performance records
Protected health information, financial account numbers, or payment card data
Passwords, API keys, tokens, or other credentials
Company confidential information: unreleased products, pricing models, strategy
documents, contracts, source code, and trade secrets
Anything covered by a confidentiality or nondisclosure obligation to a third party
If you are unsure whether information is confidential, ask before you paste it.
Removing a name is not always enough to make data anonymous.

5. REVIEW, ACCURACY, AND ACCOUNTABILITY

The employee who uses AI output is responsible for it. AI tools produce confident
text that can be wrong, out of date, biased, or fabricated, including invented
sources, citations, and figures.
Verify every fact, figure, quote, citation, and calculation before use
Review AI-generated code before it is committed or deployed
Never send AI output to a customer, a regulator, or a court without human review
Do not present AI output as independent research or as your own original analysis
where the company requires disclosure

6. DISCLOSURE

[Choose your approach.] Employees must disclose AI assistance when [for example:
producing customer-facing deliverables, published content, research, or code
contributions], by [noting it in the document, the ticket, or the commit message].
Routine drafting assistance on internal documents does not require disclosure.

7. HIGH-RISK USES THAT REQUIRE APPROVAL

The following require prior written approval from [owner / HR / counsel], because
they carry legal or regulatory exposure:
Any use that influences an employment decision, including screening applicants,
scoring candidates, evaluating performance, or selecting employees for
termination. Several jurisdictions regulate automated employment decision tools,
and some require notice, consent, or a bias audit.
Any use involving personal data of customers or employees
Any use that produces a legal, financial, medical, or safety determination
Recording, transcribing, or summarizing a meeting or a call. Recording consent
rules vary by state, and some states require all-party consent.
Any tool that will connect to company email, files, calendars, or a customer system

8. INTELLECTUAL PROPERTY

Do not upload third-party copyrighted material into an AI tool without the right to
do so. Be aware that AI output may not be protectable and may resemble existing
work. Work product created for the company, with or without AI assistance, belongs to
the company under the normal terms of employment.

9. MONITORING AND ENFORCEMENT

Use of AI tools through company systems may be logged and reviewed, to the extent
permitted by law, and is subject to the company acceptable use policy and electronic
monitoring notice. Violations may result in loss of access and disciplinary action up
to and including termination of employment.

10. QUESTIONS

AI tools change quickly. If a situation is not covered here, ask [contact] before
proceeding rather than guessing. This policy will be reviewed at least [annually].

ACKNOWLEDGMENT

I acknowledge that I have received and read the [Company Name] AI Acceptable Use
Policy and agree to follow it when using AI tools for company work.
Employee signature: __ Date: _

DISCLAIMER: This is a sample template for general information only and is not legal
advice. AI, privacy, recording-consent, and automated employment decision laws vary
by state and city and are changing quickly. Have this policy reviewed by qualified US
employment counsel before adopting it.
Companies Using FirstHR Onboard 3x Faster
Join hundreds of small businesses who transformed their new hire experience.
See It in Action

Template 4: Personal Device (BYOD) Acceptable Use Addendum

For employees using a personal phone or computer for work: eligibility and approval, minimum device requirements, how company data may be used, what the company can and cannot see, removing company data on separation, reimbursement, and off-hours work by non-exempt employees.

Personal Device (BYOD) Acceptable Use Addendum
PERSONAL DEVICE (BYOD) ACCEPTABLE USE ADDENDUM
[Company Name]
Effective date: _
Use this addendum when employees use a personal phone, tablet, or computer for
company work. It attaches to the main acceptable use policy and does not replace it.

1. ELIGIBILITY AND APPROVAL

Using a personal device for company work is a privilege that requires approval from
[manager / IT]. Some roles and some data types are not eligible. The company may
withdraw approval at any time and may require the employee to use a company device
instead.
Approved device(s): ___
Approved uses: [ ] Email [ ] Calendar [ ] Chat [ ] Files [ ] Other: ___

2. MINIMUM DEVICE REQUIREMENTS

An approved personal device must have:
A passcode, PIN, or biometric screen lock, with automatic lock enabled
A current, supported operating system with security updates applied
Device encryption enabled where available
Any security or device-management software the company requires
No jailbreak, root, or modified operating system

3. HOW COMPANY DATA MAY BE USED ON THE DEVICE

Access company data only through approved applications and accounts
Do not save company files to a personal cloud account or personal photo library
Do not use a personal messaging app for company business unless approved
Do not let family members or anyone else use the device while company accounts are
signed in
Do not back up company data to a personal backup service

4. MONITORING AND PRIVACY ON A PERSONAL DEVICE

The company does not seek access to personal content on a personal device. The
company may, to the extent permitted by law, access, monitor, and manage the company
applications, accounts, and data on the device, and may collect limited device
information needed for security, such as operating-system version and compliance
status.
[If you use mobile device management, describe exactly what it can and cannot see and
do. Be specific. Vague language here is what makes employees distrust the program.]

5. REMOVING COMPANY DATA

The employee agrees that the company may remove company data and company accounts
from the device when employment ends, when approval is withdrawn, or when the device
is lost, stolen, or compromised. [State whether this is a selective wipe of company
data only or a full device wipe, and get counsel input on the full-wipe option.]
Report a lost or stolen device to [contact] immediately.

6. COSTS AND REIMBURSEMENT

[State your approach. Note that some states require reimbursement of necessary
business expenses, which can include a reasonable share of a personal phone or
internet bill when the device is required for work. Confirm the rule in every state
where you have employees.] The company will [reimburse $______ per month / reimburse
approved documented costs / not reimburse personal device costs].

7. WAGE AND HOUR

Non-exempt employees must record all time worked, including time spent on company
email or messages on a personal device outside scheduled hours. Do not perform work
on a personal device outside your schedule without prior approval.

ACKNOWLEDGMENT

I acknowledge that I have received and read this Personal Device Addendum, that I
agree to follow it, and that I consent to the company managing and removing company
data and accounts on my personal device as described above.
Employee signature: __ Date: _
Device model and phone number: ______

DISCLAIMER: This is a sample template for general information only and is not legal
advice. Expense reimbursement, privacy, and wage-and-hour rules vary by state. Have
this addendum reviewed by qualified US employment counsel before adopting it.

Template 5: Electronic Monitoring Notice and Consent

A separate notice and consent form with a checklist of exactly what is monitored, the purpose, the no-expectation-of-privacy statement, and the boundary around personal accounts, plus ready add-on paragraphs for Connecticut, Delaware, and New York.

Electronic Monitoring Notice and Consent
ELECTRONIC MONITORING NOTICE AND CONSENT
[Company Name]
Effective date: _
Give this notice to every employee before monitoring begins, and to every new hire at
the start of employment. Collect a signed or electronic acknowledgment and keep it in
the employee record. Post the notice where employees can see it.

NOTICE OF ELECTRONIC MONITORING

[Company Name] provides computers, phones, email, internet access, network, and other
systems for business use. The company may monitor, intercept, access, review, record,
retain, and disclose activity on those systems at any time and by any lawful means,
with or without further notice.
Monitoring may include, without limitation:
[ ] Company email sent, received, and stored
[ ] Chat and instant messaging on company systems
[ ] Internet and website activity over company networks or devices
[ ] Files stored on company devices and company cloud storage
[ ] Application and software use, including AI tools
[ ] Network traffic and security logging
[ ] Telephone calls and voicemail on company lines
[ ] Video surveillance in [list areas; do not monitor restrooms, changing areas, or
other private areas]
[ ] Location or GPS data from company vehicles or company devices during work time
[ ] Keystroke, screen, or productivity monitoring software
[ ] Badge and physical access records
Purpose: the company monitors to protect company and customer information, maintain
security and system performance, meet legal and contractual obligations, and confirm
that company systems are used consistent with company policy.
No expectation of privacy: employees should have no expectation of privacy in
anything created, stored, sent, or received on company systems, including personal
messages and personal files kept on those systems. Marking a message personal does
not make it private.
Personal accounts and devices: the company does not monitor personal social media
accounts or personal devices that are not used for company work, and does not request
personal account passwords. Where a personal device is approved for company work, the
company may access and manage the company data and company applications on it as
described in the personal device addendum.
Questions about this notice go to [contact].

STATE ADD-ONS

Include the paragraph for each state where you have employees, and confirm current
requirements with counsel.
CONNECTICUT. Connecticut law requires employers that engage in electronic monitoring
to give prior written notice to all affected employees describing the types of
monitoring that may occur, and to post a notice in a conspicuous place readable by
employees. Effective October 1, 2026, Public Act 26-73 also requires the notice to
identify the specific locations on the premises where monitoring may occur (with
carve-outs for airport premises and for security and employee safety purposes), and
requires each employee hired on or after that date to receive, before starting work, a
plain language written statement of the activities that are prohibited and may be
monitored without prior written notice. Add: "In accordance with Connecticut General
Statutes section 31-48d, this notice describes the types of electronic monitoring
[Company Name] may conduct and the specific locations where it may occur: [list
locations]. A copy is posted at [location]."
DELAWARE. Delaware law requires an employer that monitors or intercepts telephone
transmissions, electronic mail, or internet usage to either give an electronic notice
each day the employee accesses employer-provided email or internet service, or to give
a one-time notice in writing or in electronic form that the employee acknowledges in
writing or electronically. Add: "In accordance with title 19 of the Delaware Code,
section 705, this is your notice of electronic monitoring. Your acknowledgment below
serves as the required acknowledgment."
NEW YORK. New York law requires private employers that monitor or intercept telephone
conversations, email, or internet access to give prior written notice upon hiring to
employees subject to monitoring, obtain written or electronic acknowledgment, and post
the notice in a conspicuous place. Add: "In accordance with New York Civil Rights Law
section 52-c, you are advised that any and all telephone conversations or
transmissions, electronic mail or transmissions, or internet access or usage by an
employee by any electronic device or system may be subject to monitoring at any and
all times and by any lawful means. A copy of this notice is posted at [location]."
OTHER STATES. Requirements change. Confirm the current rule in every state where you
have employees before you begin monitoring, and note that recording and wiretap
consent rules are separate from monitoring notice rules.

EMPLOYEE ACKNOWLEDGMENT AND CONSENT

I, __ (print name), acknowledge that I received and read this
Electronic Monitoring Notice. I understand that [Company Name] may monitor my use of
company systems as described, that I should have no expectation of privacy in that
use, and I consent to that monitoring as a condition of using company systems.
Employee signature: __ Date: _
Delivered by: [ ] In person [ ] Email [ ] Electronic acknowledgment
Posted notice location: __

DISCLAIMER: This is a sample notice for general information only and is not legal
advice. Electronic monitoring, wiretap, and recording-consent laws vary by state and
change over time. Have this notice reviewed by qualified US employment counsel and
confirm the requirements for every state where you have employees.

Template 6: Acceptable Use Policy Acknowledgment Form

A standalone form to record that each person received and agreed to the policy, with checkboxes for which documents were delivered and fields for the policy version, the delivery method, and the date access was granted.

Acceptable Use Policy Acknowledgment Form
ACCEPTABLE USE POLICY ACKNOWLEDGMENT FORM
[Company Name]
Use this form to record that an employee received and agreed to the acceptable use
policy. Collect it before access is granted, and again after any material update.
Keep the signed form in the employee record.

EMPLOYEE ACKNOWLEDGMENT

I, __ (print name), acknowledge that:
I have received the [Company Name] Acceptable Use Policy dated ____________.
I have read and understand it, and I have had the opportunity to ask questions.
I understand that company computers, phones, networks, email, internet access,
software, cloud accounts, and data are company property provided for business use.
I understand that I may install only approved software and must request approval
before adopting any new application or AI tool that will touch company data.
I understand the rules on personal use that apply at [Company Name].
I understand that company systems may be monitored, logged, accessed, and reviewed
to the extent permitted by law, and that I should have no expectation of privacy in
my use of them, including personal use.
I understand that I must report a lost device, a suspected phishing message, or any
security incident promptly.
I understand that violating this policy may result in loss of access and
disciplinary action up to and including termination of employment.
I agree to follow this policy as a condition of using company systems.
Documents received:
[ ] Acceptable Use Policy [ ] AI Acceptable Use Policy
[ ] Electronic Monitoring Notice [ ] Personal Device Addendum
Employee signature: __ Date: _

FOR COMPANY USE

Delivered by: __ Date delivered: _
Method: [ ] Wet signature [ ] Electronic signature
Policy version: _ Filed in employee record: [ ] Yes
Access granted on: _ Granted by: __

DISCLAIMER: This is a sample form for general information only and is not legal
advice. Adapt it to your company, your state requirements, and your recordkeeping
practices.

An Acceptable Use Policy at Small Scale

A large company has a security team to write this policy, maintain the approved-software list, and review tool requests. A small business has an owner or an office manager doing all three between other work, usually after someone has already installed something they should not have. Here is what changes at that scale.

Most acceptable use policy examples online are written for an IT department you do not have
Search the term and you land on security-vendor templates and university IT documents built around network segmentation, incident response tiers, and a security team that reviews requests. A small business has none of that. It has an owner or an office manager who approves the software, one shared drive, a handful of laptops, and a group of people who install whatever helps them get the job done. The version that actually works at that scale names the systems in plain language, sets one rule for software approval, one rule for personal use, and one clear monitoring notice, then gets signed. These templates are written to that standard rather than to an enterprise security framework.
The tool stack changed faster than the policy did, and AI is the gap
Most acceptable use policies in circulation predate everyday AI use at work, so employees are pasting customer emails, candidate resumes, contract language, and sometimes payroll data into whatever assistant is open in another tab. That is not malice, it is the absence of a rule. The fix is not a ban, which people route around, but a short written standard: which tools are approved, what categories of information never go into a prompt, who reviews the output, and which uses need sign-off first. The AI acceptable use policy on this page is built to be adopted on its own, because for a lot of small teams that is the single most urgent piece of the whole document.
An unsigned policy does not give you the monitoring notice or the consent you were counting on
The reason a small business writes this policy is usually to be able to look at a company account when something goes wrong, and to have set expectations before that day arrives. That protection comes from delivery and acknowledgment, not from a file sitting in a shared folder. A policy that was sent, signed, versioned, and stored is one you can rely on; one nobody signed is not, and in the states with an electronic monitoring notice law the acknowledgment is the requirement. This is the people side FirstHR is built for: the acceptable use policy and the monitoring notice ship as onboarding steps before access is granted, built-in e-signature captures each acknowledgment, document management stores the signed version with the policy version on record, the self-service portal keeps the current version available, and training modules can run a short security and AI refresher alongside. Applicant tracking is coming soon to FirstHR. To be clear about scope, FirstHR is an onboarding and HR platform, not an IT security product and not a law firm, and it does not configure your devices, filter your network, run payroll, or administer benefits. The templates below work on their own; FirstHR is how you deliver, sign, and store them.

Deliver It Before You Grant Access

An acceptable use policy earns its keep at the moment access is granted, not at the moment it is written. The sequence is: adapt the version you need, have counsel review it, deliver it as an onboarding step before credentials are issued, capture the acknowledgment, and store it with the policy version.

Adapt the version you need
Pick the full policy or the short one, add the AI and monitoring pieces, fill in your approved tools, your personal-use rule, and your reporting contact, then have US counsel review.
Deliver before access
Send the policy, the AI rules, and the monitoring notice as an onboarding step, so every new hire receives them before credentials are issued rather than weeks later.
Capture the signature
Collect a signed or electronic acknowledgment from every person, which sets expectations and provides the acknowledgment some state monitoring laws require.
Store, review, and re-sign
File the signed acknowledgment with the policy version, review the approved-tools list on a set schedule, and re-collect signatures whenever the policy materially changes.

The templates above work on their own. To run the delivery and signature without paper, FirstHR sends the acceptable use policy, the AI rules, and the monitoring notice as onboarding steps, captures each acknowledgment with built-in e-signature, and files the signed version through document management with the policy version on record. Employees can pull up the current version anytime through self-service, and training modules can run a short security and AI refresher when the policy changes. Applicant tracking is coming soon to FirstHR. FirstHR is an onboarding and HR platform, not an IT security product and not a law firm, so pair it with your IT provider and US counsel.

Key Takeaways
An acceptable use policy is one written document covering company devices, network and internet, email, software installs, company data, personal use, and AI tools.
Name the systems in scope explicitly, including cloud accounts and personal devices that touch company email or data.
Pick one personal-use approach and state it, then pair it with a plain statement that nothing on company systems is private.
Add a dedicated AI section: approved tools only, a hard list of what never goes into a prompt, human review of output, and approval for high-risk uses.
Connecticut, Delaware, and New York require an electronic monitoring notice, New York requires an acknowledgment, and Delaware requires one unless it sends a daily notice instead.
The signed acknowledgment collected before access is granted is what turns the document into notice; have US counsel review. This is general information, not legal advice.

Frequently Asked Questions

What is an acceptable use policy?

An acceptable use policy, often shortened to AUP, is a written document that sets the rules for how employees may use company technology: computers, phones, networks, internet access, email, software, cloud accounts, and company data. It defines what is allowed, what is prohibited, how much personal use is acceptable, who may install software, how passwords and access are handled, and that company systems may be monitored. It usually ends with a signed acknowledgment that each employee returns before access is granted. In a small business the acceptable use policy is often the single technology policy that exists, which is why the versions on this page fold in email, internet, devices, software installs, AI tools, and the monitoring notice rather than splitting them into separate documents. This is general information, not legal advice.

What should an acceptable use policy include?

A complete acceptable use policy includes the purpose and who it applies to, a list of the systems and devices covered, a general standard of acceptable use, a specific list of prohibited activity, a personal-use rule, password and account security requirements, a software and installation approval process, rules for email and internet use, a section on AI and third-party tools, data and confidentiality handling, terms for personal devices used for work, a monitoring notice with a no-expectation-of-privacy statement, an incident reporting instruction, an enforcement statement, a clause preserving employee rights under applicable law, and an acknowledgment. The sections that small businesses most often leave out are the software approval process, the AI rules, and the monitoring notice, which are exactly the three that cause the most trouble later. This is general information, not legal advice.

Do we need a separate AI acceptable use policy?

You need the AI rules in writing, but whether they live in a separate document or inside the main acceptable use policy is a practical choice. A separate AI acceptable use policy is easier to update, easier to circulate on its own, and easier for employees to actually read, which matters because AI tools and vendor terms change quickly. Folding the rules into the main policy keeps everything in one place and one signature. Many small teams do both: a short AI section in the main acceptable use policy pointing to a standalone AI policy that carries the detail. Either way, the rules that matter are the same: approved tools only, a hard list of information that never goes into a prompt, human review of every output, and prior approval for high-risk uses. This page includes both the combined section and a standalone AI policy. This is general information, not legal advice.

Can an employer legally monitor employee email and internet use?

Generally yes on company systems, subject to federal and state rules and to any notice or consent requirement that applies. Federal wiretap law under the Electronic Communications Privacy Act prohibits intercepting electronic communications at 18 U.S.C. section 2511, but employers commonly rely on the consent exception at section 2511(2)(d) and on the business-extension carve-out written into the definition of an intercepting device at section 2510(5)(a). Several states add their own requirements. Connecticut, Delaware, and New York each require notice to employees. New York requires an acknowledgment, and Delaware requires one when the employer chooses the one-time notice instead of a daily notice. Some states also regulate recording of calls and require all-party consent, which is a separate question from monitoring notice. The safest practice for a small business is to state the monitoring clearly in the acceptable use policy, deliver a standalone notice, collect a signed acknowledgment, and post the notice. This is general information, not legal advice.

Which states require notice before electronic monitoring?

Connecticut, Delaware, and New York have the clearest employee-facing notice statutes. Connecticut General Statutes section 31-48d requires prior written notice describing the types of monitoring that may occur plus a posted notice in a conspicuous place, and Public Act 26-73 adds the specific monitored locations and a plain language statement for new hires effective October 1, 2026. Its exception is limited to conduct that violates the law, violates legal rights, or creates a hostile workplace. Delaware, at title 19 section 705, requires either an electronic notice each day the employee accesses employer-provided email or internet service, or a one-time written or electronic notice that the employee acknowledges. New York Civil Rights Law section 52-c requires prior written notice upon hiring to employees subject to monitoring of phone, email, or internet, written or electronic acknowledgment, and a posted notice. This is general information, not legal advice.

Should we allow personal use of company computers and internet?

That is a business decision, and all three common approaches are defensible as long as you write down which one you picked. Business use only is the strictest and fits regulated work, shared terminals, and shop-floor devices, but it is hard to enforce evenly because nearly everyone checks something personal during a shift. Limited incidental use, which permits reasonable personal use on breaks and outside working time, is what most small businesses actually practice and the easiest to apply consistently. Broad personal use works for salaried teams measured on output. Whichever you choose, pair it with a clear statement that personal content on company systems is not private, because the most common dispute is an employee who assumed a personal message on a company account was off limits. This is general information, not legal advice.

Can employees install their own software on company computers?

Most acceptable use policies say no, and that is the right default for a small business. Unapproved software creates real exposure: unlicensed copies, malware bundled with free downloads, browser extensions that read everything on a page, and cloud tools that store company data under terms nobody read. The rule that holds up is not a blanket ban with no path forward, which employees route around, but a short approval process: keep a list of approved applications, name one person who approves requests, and answer requests quickly. The same process should cover AI tools and any application that will connect to company email, files, or customer data. Slow approval is the main reason people install things quietly, so speed matters more than paperwork. This is general information, not legal advice.

How do we roll out an acceptable use policy that people actually follow?

Deliver it before access, collect a signature, and keep it short enough to read. The sequence that works is: adapt the template to your systems and your approved-tools list, have US counsel review it, send it as an onboarding step before credentials are issued, capture a signed or electronic acknowledgment, and file that acknowledgment with the policy version in the employee record. Then review the approved-tools list on a set schedule and re-collect acknowledgments whenever the policy materially changes. Two details make the difference in practice: name a real person to approve software and AI tool requests and have them respond quickly, and explain the reason behind the monitoring notice rather than only the rule. A policy people understand and signed gets followed far more often than a longer one nobody read. This is general information, not legal advice.

Ready to transform your onboarding?

7-day free trial No credit card required
Start Your Free Trial