AI Policy Maker

ChatGPT policy template

Free ChatGPT policy template for organisations

ChatGPT can help with drafting, summarising, analysis, research and everyday productivity. A clear policy helps staff understand which accounts are approved, what information must stay protected and when a person needs to check AI-assisted work before it is used.

Who this ChatGPT policy template is for

This guidance is for organisations that want staff to use ChatGPT in a controlled, useful and responsible way. It is relevant whether you are allowing limited personal-account use, piloting ChatGPT Team, using ChatGPT Enterprise, or considering ChatGPT Edu in an education setting.

  • Small businesses setting first rules for AI use
  • Schools, colleges and universities considering ChatGPT Edu or classroom support
  • Charities and public-facing organisations handling sensitive information
  • Professional services teams working with client material
  • IT, security and governance teams managing approved AI tools

What a ChatGPT policy should make clear

A useful ChatGPT policy should explain whether staff may use ChatGPT, what types of work it can support, what information must not be entered and how outputs should be checked before use.

It should also make clear that AI output can be incomplete, inaccurate or unsuitable. Accountability remains with the person and organisation using it, even where ChatGPT helped draft, summarise or analyse the work.

What to include in a ChatGPT policy template

  • Approved ChatGPT versions, accounts or workspaces
  • Rules for confidential, personal, customer, pupil, patient or client information
  • When staff may use ChatGPT for drafting, research, coding, summarising or analysis
  • Human review before outputs are shared, published, submitted or relied on
  • Rules for accuracy, copyright, records, transparency and disclosure
  • Examples of prohibited or higher-risk use
  • How staff should ask questions, report concerns or request a new use case

Personal accounts, Team, Enterprise and Edu

The right policy depends partly on which version of ChatGPT the organisation allows. Personal accounts can be convenient, but they may offer less visibility and control. Organisation-managed plans may provide stronger account management, administration and data controls, but they still need clear rules.

ChatGPT setup Policy considerations
Personal accounts Set strict limits on confidential information, personal data, customer material, credentials and source code.
ChatGPT Team Define approved users, permitted work, workspace ownership, review expectations and offboarding steps.
ChatGPT Enterprise Connect usage rules to security review, identity management, data controls, records and monitoring.
ChatGPT Edu Address assessment, safeguarding, pupil or student data, staff use, learner use and academic integrity.

Confidential information and personal data

The most important rule for many organisations is simple: staff should not paste confidential, personal or sensitive information into ChatGPT unless the tool, account and use case have been approved for that information.

A policy should give practical examples. Customer records, employee information, safeguarding notes, legal correspondence, financial data, commercial plans, credentials, system logs and source code may all need restrictions. Where personal data is involved, the policy should connect to wider AI and GDPR guidance.

Prompt security and safe use

Prompt security means thinking about what staff put into ChatGPT and what they do with the response. A prompt can reveal sensitive information even if no file is uploaded. An output can look polished while still being inaccurate, incomplete or inappropriate for the audience.

  • Remove names, identifiers, confidential details and customer material unless approved.
  • Check facts, tone, assumptions, copyright and suitability before using an output.
  • Keep records where AI materially supports important work or decisions.
  • Ask for help before using ChatGPT for higher-risk or unfamiliar work.

Acceptable and unacceptable ChatGPT use

Useful everyday support

Drafting a first version of a non-sensitive email, summarising public guidance, brainstorming questions for a meeting, or improving the structure of internal notes.

Needs extra care

Summarising client documents, analysing employee information, drafting external advice, preparing board material, or writing code that may affect live systems.

Usually not acceptable

Pasting confidential records, personal data, credentials, source code, security information or unpublished customer material into an unapproved account.

Requires human review

Any output that will be sent externally, used for decisions, added to a formal record, published, submitted to a customer or relied on by another person.

Disclosure, records and accountability

Staff should know when they need to be transparent about ChatGPT use. For routine drafting, disclosure may not always be necessary. For external, important, decision-supporting or sensitive work, the organisation may expect staff to explain that AI helped and confirm that the work has been reviewed.

Records matter where ChatGPT materially contributes to important work. That does not mean saving every prompt, but it may mean keeping enough context to explain what was used, who checked it and why the final output was accepted.

Why this should sit inside a wider AI policy

A ChatGPT-specific policy is useful, but most organisations use more than one AI tool. A broader AI usage policy can include ChatGPT alongside Microsoft Copilot, Gemini, Claude and other approved tools.

The free AI policy generator creates an editable policy that can cover approved tools, data rules, human review, prohibited use, staff responsibilities and practical governance in one place.

FAQ

Common questions about ChatGPT policies

What should a ChatGPT policy cover?

A ChatGPT policy should cover approved accounts, permitted uses, confidential information, personal data, prompt security, checking outputs, transparency, copyright, records and when staff should ask for approval.

Can staff use ChatGPT for work?

They can if the organisation allows it, but staff should follow clear rules about approved accounts, sensitive information, checking outputs and transparency.

Can staff enter confidential information into ChatGPT?

Staff should not enter confidential or sensitive information into ChatGPT unless the organisation has approved the tool, configuration and specific use case.

Is ChatGPT Team or Enterprise different from a personal account?

Organisation-managed versions may provide stronger administration, data controls and account management than personal accounts, but the policy still needs to explain approved use, data restrictions and review expectations.

Should ChatGPT Edu be covered by a policy?

Yes. Education settings should set clear rules for staff and learners, especially around assessment, safeguarding, pupil or student data, academic integrity and human review.

Can ChatGPT write final work for staff?

It can support drafting, but final responsibility should remain with a person who checks the content before it is used or shared.

What is prompt security?

Prompt security means thinking carefully about what is entered into AI tools, whether the prompt reveals sensitive information, and whether generated outputs could expose confidential, inaccurate or unsafe content.

Should staff disclose that ChatGPT was used?

Disclosure expectations depend on the work. Many organisations require disclosure for external, important or decision-supporting work, especially where transparency affects trust.

Does a ChatGPT policy need GDPR wording?

If staff may handle personal data, the policy should explain when personal data must not be entered, when approved tools are required, and when data protection review may be needed.

Can I customise the generated ChatGPT policy?

Yes. The generator creates an editable Word document so you can adapt the policy to your approved tools, data rules and review process.