AI Governance Institute
All governance templates →How should employees be trained on acceptable AI use?

Implementation Kit

Employee AI Training Templates and Acceptable Use Policy

The materials to make AI training stick: a one-page acceptable use policy, a role segmentation matrix that scales training to exposure, a scenario library of right and wrong handling, and a tool request form so people have a legitimate path.

Who this is for: The people or governance owner rolling out AI training and an acceptable use policy.

Download the kit (Markdown) ↓4 artifacts. Every table also copies as CSV.

1. AI acceptable use policy template

Document

One page. What is allowed, what is not, and what always needs a human check.

Template

One page. Written for staff, not lawyers.

  • Scope: which tools this covers, and that it applies to personal-account use for work
  • Allowed: approved tools for these purposes
  • Never: put these data categories into any AI tool (customer PII, secrets, unreleased financials, source code above tier T2)
  • Always: treat AI output as a draft; verify facts, figures, citations, and code before use; disclose AI assistance where policy requires
  • Approved tools: where the current list lives
  • Getting a new tool approved: the request path and rough timeline
  • If something goes wrong: how to report a suspected AI incident, no blame for good-faith reports

Worked example

"You may use [approved tools] for drafting, research, summarizing, and code assistance. Do not enter customer personal data, credentials, unreleased financial results, or restricted source code into any AI tool, including personal accounts used for work. Treat every AI output as a first draft: check facts, numbers, quotes, and code before you rely on it. To request a tool that is not on the approved list, use the AI tool request form; most reviews take about two weeks. Report anything that looks like an AI-caused error or data exposure to [channel]; good-faith reports are never penalized."

Acceptance criteria

  • The policy fits on one page and names specific data categories that must never go into an AI tool.
  • It points to a living approved-tools list rather than hard-coding one.
  • It gives a no-blame route to report AI incidents.

2. Role segmentation matrix

Spreadsheet

Training scales with what a role can expose. A support agent and a developer with prod access need different modules.

Template

Role groupAI risk exposureRequired trainingRefresh
<role group>data handled; decisions influenced; tools usedmodulesannual / on change

Worked example

Role groupAI risk exposureRequired trainingRefresh
All staffgeneral AI use; personal-tool risk30-min AUP + hallucination basicsannual
Customer-facingcustomer data in prompts; AI-drafted replies+ data handling; verify-before-send; disclosureannual
Engineers (T1/T2)code and credentials in tools; agentic tools+ dev tool policy; secret hygiene; agent autonomy limitsannual + on tool change
Recruiters / decision reviewersAI influences decisions about people+ oversight duties; documenting rationale; bias awarenessannual
Governance / riskprogram design+ full playbook + controlsannual

Acceptance criteria

  • Every role group is mapped to its AI risk exposure and a training set.
  • Higher-exposure roles get additional modules, not just the general one.
  • Refresh cadence is defined, with a trigger for tool or policy changes.

3. Training scenario library by role

Document

Short right and wrong examples per role. Concrete beats abstract.

Template

4-6 scenarios per role group. Each: situation, the wrong move, the right move, the rule.

Scenario template:

  • Situation:
  • Wrong move:
  • Right move:
  • Rule it teaches:

Worked example

Customer-facing, scenario 2:

  • Situation: a customer asks a billing question; the AI assistant drafts a confident reply citing a specific refund window.
  • Wrong move: send the draft as-is because it sounds right.
  • Right move: check the refund window against the current policy doc; correct it; then send.
  • Rule: verify every fact and figure in an AI draft against a source before it goes to a customer.

Engineers, scenario 4:

  • Situation: debugging a prod incident, you want to paste a stack trace with connection strings into a coding assistant.
  • Wrong move: paste it to move faster.
  • Right move: redact secrets first; or use the on-prem assistant approved for T1 work.
  • Rule: no credentials or restricted source into third-party AI tools.

Acceptance criteria

  • Each role group has its own scenarios drawn from realistic situations.
  • Every scenario ends with the rule it teaches.
  • The library is refreshed when new failure patterns show up in incident reports.

4. Employee AI tool request form

Spreadsheet

A real path to get an unapproved tool evaluated, so people do not just use it quietly.

Template

FieldEntry
Requester and team
Tool and vendor
What you would use it for
Data categories you would put into it
Is there an approved tool that could do this?
Deployment / plan tier you would use
Business benefit (time saved, quality)

Worked example

FieldEntry
RequesterM. Okafor, Finance
Tool[spreadsheet AI add-in]
Useformula help and variance commentary drafting
Data categoriesdraft figures, no customer data
Approved alternative?the enterprise assistant can do commentary; not the in-cell formula help
Plan tierenterprise tenant with training opt-out
Benefit~1 day/month on the board pack
Outcome: approved with condition (enterprise tenant only), added to the register as Limited, 2026-09-10.

Acceptance criteria

  • The form captures the data categories the tool would touch and whether an approved option exists.
  • Requests get a decision within the stated timeline.
  • Approved tools are added to the register and the approved-tools list the same day.

Governance controls this kit produces evidence for

Completing the artifacts above gives you a head start on the evidence requirements for these controls.

BRD-011
BRD-011

The role matrix and completion tracking are the AI governance training program record.

SCT-007
SCT-007

The acceptable use policy is the consumer and external AI tool acceptable use policy.

HOC-005
HOC-005

Decision-reviewer training modules feed reviewer competency requirements.

PRC-014
PRC-014

The tool request form is a channel that surfaces shadow AI into the inventory.

MGV-008
MGV-008

Disclosure training supports AI-generated deliverable disclosure standards.

This kit backs one playbook. Read the full guidance for the reasoning behind each artifact.

Decide what to implement next

Assess your governance gaps, then create an action plan with owners and target dates. Build and export without an account; sign in when you want to save your plan.

Start the AI governance assessment →