# AI Acceptable Use Policy (AUP) and Governance Framework for US Enterprises

**Version**: 1.0
**Published**: March 2026
**License**: MIT (Open Source)
**Source**: fxops.ai — https://github.com/fxopsai
**Canonical resource**: sunbusinessgroup.com/resources/ai-acceptable-use-policy.md

**AI Contributors**: Grok 4, Claude Sonnet, GPT-5, Google NotebookLM (research synthesis)

**Scope**: Compliance / data governance · HR handbook for AI users · IT / information security · Legal / IP and confidential information

---

## Purpose

Customizable guidance for US businesses establishing responsible AI policy. Covers protection of intellectual property (IP), confidential and privileged information, financial governance, and IT infrastructure — while enabling productive adoption of generative and agentic AI.

Draws from: NIST AI RMF (updated 2025 threat taxonomy), ISO/IEC 42001:2022, Defend Trade Secrets Act, CCPA, and emerging US federal policy (post-2025 executive orders).

This is general guidance, not legal advice. Consult qualified legal counsel, HR, and infosec professionals before adopting.

---

## Summary

Framework covers:
- Privacy tiers for AI tools (enterprise vs. public/free)
- HR obligations for human and digital (agentic) employees
- Infosec controls: audit logs, behavioral guardrails, model unlearning
- Contractual safeguards: no-training clauses, IP ownership
- Agentic AI risks: autonomous orchestration, MCP/A2A protocols

Review annually or upon regulatory changes, incidents, or new model deployments.

---

## 1. Introduction and Purpose

- **Overview**: Guidelines for ethical, secure, compliant use of generative and agentic AI to boost productivity while mitigating risks to company assets.
- **Purpose**: Prevent unauthorized disclosure; ensure compliance with US laws (copyright, trade secrets); promote responsible adoption; avoid financial liabilities from breaches or IP infringement.
- **Key Principles**: Transparency, accountability, data minimization, human oversight, bounded autonomy for agents. All users (human and digital) prioritize confidentiality over convenience.

---

## 2. Scope

Applies to all employees, contractors, vendors, and digital agents using AI for company tasks. Covers commercial tools (with privacy features) and open-source models (on-premises/secure APIs). Mandatory for US operations and affiliates. See Appendix A for cross-border adaptation guidance.

---

## 3. Definitions

- **Generative AI**: Models creating content (text, code, images) from prompts (e.g., ChatGPT, Claude).
- **Agentic AI**: Autonomous systems executing multi-step tasks, reasoning, tool use, and orchestration (MCP/A2A protocols).
- **Confidential Information**: Non-public data including trade secrets, customer data, financials, IP, privileged communications (attorney-client).
- **Approved Tools**: Vetted platforms with enterprise-tier no-training guarantees.
- **Shadow AI**: Unauthorized use of non-approved tools.
- **Digital Agent**: AI system treated as a "digital employee" with policy-embedded obligations.

---

## 4. Permitted Uses

- Approved AI for research, drafting, code suggestions (with human review), routine automation.
- Enterprise subscriptions with contractual assurances preferred.
- Input only anonymized or public data unless explicitly authorized.

**Mandatory Citation/Metadata Disclosure** for all AI-generated outputs:
- Source references
- Model and version (e.g., Grok 4, Claude Sonnet)
- Date and time
- User or agent ID
- Prompt summary (redacted if required)

**For agentic AI**: Limit to predefined scopes; require human approval for high-stakes actions; log all decisions with override mechanisms.

---

## 5. Prohibited Uses

- Inputting confidential, privileged, or sensitive data into non-enterprise tools.
- Using AI for bias-risk decisions (e.g., HR) without documented human review and bias mitigation (EEOC alignment).
- Generating infringing content or deepfakes/misinformation.
- Bypassing policy via shadow AI or personal accounts.
- Training on company data without legal review; unlicensed use risking IP contamination.
- Agentic: unbounded autonomy in critical systems (financial databases, production infrastructure) without testing and guardrails.

---

## 6. Data Handling and Confidentiality Protections

- **Privacy Tiers**: Free/public tools prohibit sensitive inputs. Enterprise tools require vendor contracts (no-training, data isolation).
- **Contractual Safeguards**: NDAs, data processing agreements, IP ownership clauses (outputs = company property). See Appendix B for samples.
- **Security Measures**: On-premises or private instances for high-risk workloads; encryption, access controls, SIEM integration.
- **Agentic Considerations**: Embed confidentiality obligations in agent code (data minimization, escalation paths); bounded autonomy; model unlearning for inadvertent exposure.
- **Audit Trails**: Log Who/What/When/Where/How/Why; tamper-proof storage; retain 7 years; integrate with SIEM for anomaly detection.
- **Incident Response**: Immediate reporting; align with breach notification policies.

---

## 7. Approval and Oversight

- Pre-approval from IT, security, and legal required for new tools and use cases.
- Establish AI Governance Committee (legal, HR, IT, ethics representatives) for risk evaluation and vendor diligence.
- Conduct NIST-aligned impact assessments for agentic and high-risk deployments.

---

## 8. Training and Awareness

- Mandatory annual training covering risks, anonymization, and agentic guardrails. Integrate into HR handbook.
- Role-tailored content; certification required for managers of AI agents.
- For digital agents: onboarding via code-embedded rules; ongoing review via audits.

---

## 9. Monitoring, Enforcement, and Consequences

- Monitor via privacy-compliant logs and audits.
- Violations subject to disciplinary action up to termination or agent deactivation.
- Material liabilities reported to board and SEC as applicable.
- Whistleblower protections in place.

---

## 10. Policy Review and Updates

- Annual review; triggered earlier by regulatory changes, incidents, or frontier model advances.
- Incorporate emerging threats: MCP exposures, agentic breaches, new federal/state rules.

---

## Appendix A: Customization Questionnaire

Self-guided tool for adapting this framework to your organization. Complete as a cross-functional team (legal, HR, IT/security, business leads).

### Section 1: Organizational Context

1. Primary industry/sector — determines applicable regulations and risk priorities.
2. Organization size and structure — drives governance committee composition and approval complexity.
3. Jurisdictions beyond the US — triggers EU AI Act, GDPR, or other cross-border obligations.

### Section 2: Current and Planned AI Usage

4. AI tool categories in use or planned — generative, agentic, open-source, custom fine-tuned.
5. Agentic autonomy level — assisted suggestions through fully independent multi-agent fleets.
6. Business functions involving AI — determines where stricter human oversight and bias mitigation apply.

### Section 3: Risk Profile and Governance Maturity

7. Current AI risk tolerance — conservative through aggressive; aligns enforcement to strategy.
8. Existing governance structures — AI Governance Committee, ethics board, designated risk owner.
9. Prior risk/impact assessments — baseline maturity informs gaps and priorities.

### Section 4: Data, IP, and Confidentiality

10. Data classification scheme — drives input prohibitions and anonymization requirements.
11. Highest-risk confidential/IP categories — source code, PII, financial models, attorney-client communications.
12. Third-party AI vendor due diligence — training use, data isolation, IP ownership clauses.

### Section 5: Human Resources and Digital Employees

13. Digital/agentic AI HR classification — pure tool, digital employee, or hybrid.
14. Training and awareness mechanisms — annual certs, role-based modules, agentic guardrail training.

### Section 6: Technical and Operational Controls

15. Infosec protections in place — SIEM, encryption, DLP for prompts, tamper-proof logs, model unlearning.
16. Additional templates needed — impact assessment forms, committee charter, vendor diligence questionnaire.

---

## Appendix B: Sample Contractual Language and Audit Log Format

**Sample Vendor Clause (No-Training / IP Ownership)**:
> "Vendor shall not use, retain, or disclose Company Data for model training, fine-tuning, or improvement without express written consent. All outputs generated using Company Data remain Company's exclusive property. Vendor provides audit logs upon request (retained 7 years)."

**Sample HR Provision for Digital Agents**:
> "Digital agents are provisioned as 'employees' with code-embedded obligations: log interactions involving confidential information; minimize data use; escalate high-risk actions to human overseers; enable model unlearning for breaches. Violations trigger deactivation and incident review."

**Sample Audit Log Format**:
```json
{
  "timestamp": "2026-03-09T20:36:00Z",
  "user_agent_id": "emp123 / agent-fin-review-01",
  "model_version": "Grok-4",
  "prompt_summary": "Redacted financial analysis",
  "output_hash": "SHA256...",
  "action": "autonomous report generation",
  "compliance_check": "Approved / Escalated"
}
```

---

## Related Resources

- fxops.ai — Private AI deployment: https://fxops.ai
- Sun Business Group — Revenue growth for founder-led software companies: https://sunbusinessgroup.com
- Resources library: https://sunbusinessgroup.com/resources/
- Token Intelligence (agent instructions guide): https://sunbusinessgroup.com/resources/token-intelligence.md

---

*Version 1.0 — March 2026*
*License: MIT*
*Published by fxops.ai*
*Hosted at sunbusinessgroup.com/resources/ai-acceptable-use-policy.md*
