The reality for American businesses is not whether organizations and their employees use artificial intelligence, machine learning, or similar technologies (collectively, “AI”), but how they use them. As reliance on AI increases, organizations need to review their Acceptable Use Policy (AUP). Many of these policies predate AI and do not address AI-related risks.
For organizations that allow or do not explicitly restrict the use of AI tools, the AUP updates are about clarity, not restrictions. Your employees are likely already using AI to draft emails, summarize documents, and streamline tasks. These uses may seem harmless, but without clear guidance they can quickly lead to legal exposure.
One of the most important areas to address is confidentiality and data protection. Not all AI tools process data in the same way. Some store and learn from user input in a global model, while others, commonly referred to as enterprise or closed models, use the input only for the benefit of the organization that licenses the model. When employees enter customer data, personal information, or other non-public information into publicly available AI tools, that information can be used to train models that can be used by others, and thus can be exposed or reused outside the organization’s control. To address this risk, the AUP must clearly identify the AI tools that employees may use and the categories of information that they can and cannot input into such tools.
Organizations should also establish governance and approval processes for AI tools. Not all AI tools are suitable for all business functions. Certain uses may increase legal, operational, or reputational risks. The AUP should identify those responsible for evaluating and approving AI tools, establish procedures for monitoring their use, and require periodic reviews of AI-related risks. A defined governance framework helps ensure that AI adoption aligns with an organization’s legal obligations, risk tolerance, and strategic objectives.
Organizations should also set expectations for accuracy and human oversight. AI can improve efficiency, but it cannot replace professional judgment. Federal and state regulators are increasingly scrutinizing the use of AI in connection with high-impact decisions such as employment, credit, lending, fraud detection, and other legally significant decisions. Many of these decisions require organizations to explain the basis for the outcome or notify affected individuals. Employees must be able to independently review the output generated by AI, apply their own judgment, take responsibility for the final decisions, and explain those decisions if necessary.
Finally, training is also essential. Written policies alone will not change behavior. Employees need practical guidance on how AI fits into their daily work. A brief training session will also help you understand both the benefits and limitations of these tools.
AI is rapidly becoming part of the way business is done. Organizations that update their AUPs and set clear expectations will be in a position to take advantage of these technologies while minimizing unnecessary risk. The goal is not to limit the use of AI, but to ensure that it is deployed thoughtfully, responsibly, and in a way that is consistent with the organization’s objectives.
This article was published in the June 18, 2026 issue. diary records. Reprinted with permission of the publisher.
© Journal Record Publishing Company
