AI Compliance
AI Acceptable Use Policy Template for Regulated Firms
An AI acceptable use policy template you can adopt this month: data rules by tool tier, an approved-tool register, industry variants and a 90-day rollout plan.
In this article
- Why most AI acceptable use policies fail
- What regulators already require, whether or not they mention AI
- The AI acceptable use policy template
- How to verify what each vendor actually does with your data
- Industry variants: what to change for your sector
- A 90-day rollout plan that ends in controls
- The hard cases every policy forgets
- Honest trade-offs: when a template is the wrong answer
- What to do this week
- Frequently asked questions
- Sources
A usable AI acceptable use policy template is short, specific and enforceable: it names which tools people may use, which classes of data may go into each one, what human review is required before output leaves the building, and what happens when someone breaks the rule. Most of the templates circulating online fail on the second item. They say "do not share confidential information with AI tools" and stop, which leaves every judgment call to the individual employee at the moment they are busiest.
This article gives you the whole document, section by section, with draft language you can adapt. It also gives you the two things a template alone cannot: a matrix that maps your data classes to tool tiers, and a 90-day rollout plan that ends with technical controls rather than a signed PDF nobody reads.
Below you will find the policy outline, the data rule, how to build and verify an approved-tool register from vendors' own published terms, variants for banking, insurance, healthcare and professional services, the clauses that cover AI in hiring, and the mistakes that make policies unenforceable.
None of this is legal advice. Have your own counsel or compliance team review the final document against the laws of the states you operate in.
Why most AI acceptable use policies fail
The evidence says policies are losing ground to the behavior they are supposed to govern.
IBM's Cost of a Data Breach Report 2026 puts the global average cost of a breach at $4.99 million, a 12% increase over the prior year and a record high. Cybersecurity Dive's reporting on the same study found the share of security incidents involving shadow AI more than doubled year over year to 43%, that more than two-thirds of organizations said they had no governance processes in place to limit shadow AI, and that 92% of organizations which suffered attacks on their AI models had failed to properly control access to those models. Only about four in ten said they limited access to their AI systems at all.
Meanwhile the usage curve is steep. Verizon's 2026 Data Breach Investigations Report, published May 19, 2026, found frequent AI tool use by employees surged from 15% to 45% of employees in a single year, and that shadow AI is now the third most common non-malicious data-leakage activity it tracks. Help Net Security's summary of the same report notes that 67% of users accessing AI services on corporate devices were signed in with non-corporate accounts.
Read those two findings together and the failure mode is obvious. The problem is not that employees have not been told to be careful. It is that a policy with no approved alternative, no technical enforcement and no visible consequence is a suggestion.
Key takeaway: A policy becomes real when three things exist alongside it: a sanctioned tool that is genuinely better than the unsanctioned one, a control that blocks the alternatives, and a log that shows who did what.
What regulators already require, whether or not they mention AI
Small and mid-sized companies in regulated industries sometimes wait for an "AI rule" before writing anything. The duties already exist in rules written before generative AI shipped, and they are technology-neutral by design.
Financial institutions. The FTC Safeguards Rule at 16 CFR 314.4 requires a documented risk assessment identifying "reasonably foreseeable internal and external risks" to customer information, access controls that authenticate users and restrict access to what is necessary, encryption of customer information in transit and at rest, reasonable steps to "select and retain service providers that are capable of maintaining appropriate safeguards" with contractual commitments to do so, security awareness training updated to reflect identified risks, and a written incident response plan. An unapproved AI tool receiving customer information is a service provider you did not select, assess or contract with.
Health care. The HIPAA Security Rule at 45 CFR 164.308 makes four implementation specifications flatly required: risk analysis, risk management, a sanction policy applying "appropriate sanctions against workforce members who fail to comply with the security policies and procedures," and information system activity review. The security awareness and training standard is also required. A sanction policy that does not mention the most common way staff currently move PHI outside sanctioned systems is incomplete.
Broker-dealers. FINRA's Regulatory Notice 24-09, published June 27, 2024, states that FINRA intends its rules "to be technologically neutral and to function dynamically with evolutions in technology," and reminds firms that under Rule 3110 a member "must have a reasonably designed supervisory system tailored to its business." Where generative AI touches supervision, policies and procedures "should address technology governance, including model risk management, data privacy and integrity, reliability and accuracy of the AI model." FINRA's 2026 Annual Regulatory Oversight Report adds effective practices including formal review and approval procedures and ongoing monitoring that includes "storing prompt and output logs for accountability," and it flags autonomous agents acting "beyond the user's actual or intended scope and authority."
Law and accounting firms. ABA Formal Opinion 512, issued July 29, 2024, addresses Model Rules 1.1, 1.4, 1.5, 1.6, 1.9(c), 1.18(b) and 5.1. As The Bar Examiner summarizes, a client's informed consent is required before inputting information relating to the representation into a self-learning generative AI tool, and "boilerplate waivers will not suffice." Supervisory lawyers must have clear policies and training, and lawyers billing hourly "must only bill for their actual time."
Everyone, as a framework. NIST's AI Risk Management Framework, version 1.0 released January 26, 2023, organizes the work into Govern, Map, Measure and Manage, with a Generative AI Profile (NIST AI 600-1) released July 26, 2024. NIST notes the framework is currently being revised under the White House AI Action Plan, so treat the version number as something to check rather than cite from memory. The Govern function is where an acceptable use policy lives.
If you employ anyone in the EU. Article 4 of the EU AI Act, applicable since February 2, 2025, requires providers and deployers to "take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf." Training stops being optional.
The AI acceptable use policy template
Use the twelve sections below in order. Replace the words "the Company" with your legal entity name, and delete sections that genuinely do not apply to you rather than leaving them vague. Aim for three to five pages. Anything longer gets skimmed.
1. Purpose
This policy sets out how personnel may use artificial intelligence tools in the course of their work for the Company. It exists so that the Company can benefit from these tools without exposing customer data, regulated data, confidential business information or the Company's legal position to unnecessary risk. It applies alongside, not instead of, the Company's information security, privacy, records retention and code of conduct policies.
2. Scope
Name the people and the situations. The common gap is contractors and personal devices.
This policy applies to all employees, officers, contractors, temporary staff, interns and volunteers of the Company, and to any third party using Company data or Company systems. It applies to work performed on Company-managed devices and on personal devices, and to work accounts and personal accounts alike whenever Company data is involved.
3. Definitions
Define four terms and no more: AI tool, generative AI, AI agent, and Company data. The definition of AI agent matters because the controls differ: an agent that can take actions in other systems is a different risk from a chat window that only produces text.
An AI tool is any software feature or service that uses machine learning or a language model to generate, classify, summarize, transcribe, translate, recommend or decide. This includes features embedded in software the Company already licenses. An AI agent is an AI tool that can take actions in other systems, such as sending messages, writing to records, running code or making purchases, without a person performing each step.
4. The data rule
This is the section that does the work. Everything else supports it.
Write the rule as a table, not a paragraph. The tiers describe contractual and technical conditions, not brand names, so the rule survives a change of vendor.
| Tool tier | What qualifies | Public | Internal | Confidential | Regulated |
|---|---|---|---|---|---|
| Tier 0 | Personal or free consumer accounts; any tool not on the register | Allowed | Prohibited | Prohibited | Prohibited |
| Tier 1 | Company-paid business or enterprise plan, signed data processing agreement, admin controls, data excluded from model training | Allowed | Allowed | Named approval per use case | Prohibited |
| Tier 2 | Tier 1 plus a business associate agreement or zero data retention, audit logging and regional data handling as required | Allowed | Allowed | Allowed | Named approval per use case |
| Tier 3 | Model running in the Company's own cloud tenant or on Company hardware, no data leaving the boundary | Allowed | Allowed | Allowed | Allowed |
Two details make this enforceable. First, "named approval" means a specific person approves a specific use case and the approval is recorded in the register, not that the employee decides they have approval. Second, the four data classes must match the classification scheme you already use for everything else. If you do not have one, write a one-page version first; a policy that references classes nobody can name is decoration.
5. The approved-tool register
Personnel may use only AI tools listed on the Company's approved-tool register. The register is maintained by the policy owner and records, for each tool: the vendor, the plan or tier purchased, the highest data class permitted, whether a data processing agreement and business associate agreement are in place, whether customer data is excluded from model training, the retention period, the business owner, the date of last review, and any use-case restrictions.
Keep the register in a place everyone can read without asking permission. A register people cannot see produces the exact behavior you are trying to stop.
6. Requesting a new tool
Requests go to the policy owner using the AI tool request form and receive a written decision within five business days. The request states the business problem, the data classes involved, the vendor and plan, and the proposed business owner. The policy owner reviews vendor data handling terms, security documentation and contract terms before approving.
Commit to a response time in the document. The single best predictor of shadow AI is a request path that takes a month.
7. Prohibited uses
Be concrete. Each line should name a thing someone has actually been tempted to do.
Personnel must not: enter any data above the permitted class for the tool; use personal AI accounts for Company work; use AI output as the sole basis for a decision affecting a customer's money, coverage, care, credit, employment or legal position; present AI-generated material as the work of a named person where attribution matters; use AI to generate code that is committed without human review; circumvent authentication, rate limits or monitoring; use AI to profile individuals or infer protected characteristics; or connect AI agents to production systems without written approval and logging.
Microsoft documents a related restriction in its own product: Copilot applies filters against what it calls workplace harms and restricts generative AI from making "inferences, judgments, or evaluations about an employee's performance, attitude, internal or emotional state, or personal characteristics." Borrowing that line for your own policy is sound practice whichever tools you use.
8. Human review and disclosure
A person accountable for the work must review and verify any AI-assisted output before it is relied on or sent outside the Company. Review includes checking factual claims, figures, citations and calculations against a source. Where AI assistance is material to a deliverable, disclose it to the client or counterparty in the manner specified by the relevant business unit.
FINRA's 2026 report defines hallucination as "instances where the model generates information that is inaccurate or misleading, yet is presented as factual information," which is a useful phrasing to quote in training. For professional services, map this section to the obligations in your own rules of conduct: Formal Opinion 512's position that boilerplate consent is insufficient means the disclosure rule has to name who obtains consent and how.
9. AI in employment and other consequential decisions
This section is separate because the legal exposure is different and the rules are moving.
Illinois amended its Human Rights Act effective January 1, 2026 to prohibit employers from using AI that has the effect of subjecting employees to discrimination in covered employment decisions, to prohibit using zip codes as a proxy for protected classes, and to require notice to employees when AI is used in recruitment, hiring, promotion, renewal, selection for training, discharge, discipline, tenure or the terms and conditions of employment, with the Illinois Department of Human Rights directed to adopt further rules, as Morgan Lewis summarizes. Colorado took a different path: SB26-189, signed May 14, 2026, repealed and reenacted the state's earlier AI act with a framework built around automated decision-making technology in consequential decisions, applying from January 1, 2027.
AI tools may not be used to screen, rank, score or recommend decisions about applicants or employees unless the tool is on the approved register for that purpose, the business owner has documented the decision criteria, a person makes the final decision, required notices have been issued, and the Company retains records of inputs, outputs and the human decision.
10. Logging, monitoring and records
The Company logs use of approved AI tools, including the user, the tool, the timestamp and, where the tool supports it, prompts and outputs. Logs are retained in line with the Company's records retention schedule and the requirements applicable to the business records involved. The Company monitors managed devices and networks for use of unapproved AI services. Monitoring is limited to protecting Company and customer data and is applied consistently.
Say plainly that monitoring happens and why. FINRA's effective practices include storing prompt and output logs for accountability; HIPAA's information system activity review is a required specification. Logging is not optional in a regulated setting, and announcing it is both fairer and more effective than discovering it later.
11. Incident reporting
Personnel must report within 24 hours any instance of data being entered into a tool above its permitted class, any suspected exposure of Company or customer data through an AI tool, and any AI output that caused or nearly caused a wrong decision affecting a customer. Reports go to the security contact and are handled under the Company's incident response plan. Good-faith reports will not result in sanctions for the reporting individual.
That last sentence is the whole point of the section. Without it you get silence, and your mean time to detection becomes the vendor's breach notification letter.
12. Accountability, sanctions and review
The policy owner is named here, with a named reviewer for approvals and exceptions. Violations may result in disciplinary action up to and including termination, consistent with the Company's sanction policy and applicable law. This policy is reviewed at least every six months and whenever a tool is added, a vendor changes its data handling terms, or a new legal requirement takes effect. Date of last review and next review date appear on the first page.
How to verify what each vendor actually does with your data
The tier table above depends on facts about vendors, and those facts live on vendor pages that change. Check them yourself and record the date you checked. As of October 2026, here is what the four largest enterprise providers publish about their business offerings.
| Vendor and plan | What the vendor states | Notable limits worth reading |
|---|---|---|
| Microsoft Copilot (commercial) | "Prompts, responses, and data accessed through Microsoft Graph aren't used to train foundation LLMs, including those used by Microsoft Copilot." Copilot services have opted out of Azure OpenAI abuse monitoring, which includes human review of content. Compliance offerings include GDPR, ISO 27001, HIPAA and ISO 42001. | Copilot "only surfaces organizational data to which individual users have at least view permissions," so your existing permission sprawl becomes an AI problem. Anthropic models offered as a subprocessor are currently excluded from the EU Data Boundary. |
| OpenAI API | "Data sent to the OpenAI API is not used to train or improve OpenAI models (unless you explicitly opt in to share data with us)." Abuse monitoring logs are "retained for up to 30 days, unless longer retention is required by law." | Zero Data Retention "excludes customer content from abuse monitoring logs" and is available on specific endpoints subject to per-endpoint limitations, so check that the endpoints your application uses are covered. |
| Anthropic commercial | "We will not use your chats or coding sessions to train our models, unless you choose to participate in our Development Partner Program." | Consumer plans are governed by a separate policy, which is exactly why Tier 0 exists in the table. |
| Gemini for Google Workspace | "Your content is not used for any other customers. Your content is not human reviewed or otherwise used for Generative AI model training outside your domain without permission." Certifications listed include SOC 1/2/3, ISO/IEC 27001, 27701, 27017, 27018 and 42001, plus FedRAMP High. | "The AI follows your existing Google Workspace permissions. If you don't have permission to see a file, the AI can't see it or use it either." Same permission-inheritance caveat as Copilot. |
Two conclusions follow. First, the enterprise plans of the major platforms generally do state that business content is excluded from model training, which means a blanket ban on all AI is harder to justify than a tiered rule. Second, both Microsoft and Google tell you plainly that their assistants inherit your existing file permissions. If your SharePoint or Drive has an over-shared folder containing salary data, deploying an assistant turns a latent problem into a searchable one. Run a permissions cleanup before the rollout, not after.
If your conclusion is that no third-party tier is acceptable for your most sensitive work, the next question is what a private deployment costs; we compared the economics in private LLM versus ChatGPT Enterprise.
Industry variants: what to change for your sector
The twelve sections stay the same. These are the edits.
Banking and credit unions. Add a clause stating that any AI tool influencing credit, pricing, fraud or AML decisions is a model subject to your model risk management program, with validation and ongoing monitoring, and may not be deployed outside it. Add fair lending testing to the employment and consequential decisions section. Add a line on third-party risk referencing your vendor management program, because an AI subprocessor added by an existing vendor is a change you need to detect. We covered the supervisory expectations in what changed for bank AI under the revised model risk guidance.
Insurance carriers and MGAs. Add a clause tying the policy to your AI systems program, and extend the data rule to cover underwriting, rating, marketing, claims and fraud detection explicitly, since those are the regulated insurance practices that draw examiner attention. Require that any AI influencing a regulated decision be inventoried with documentation, data lineage and bias analysis. The NAIC AI model bulletin checklist sets out the evidence file in detail.
Health care providers and vendors. Add: no PHI in any tool without a business associate agreement, full stop; a named rule for ambient documentation and AI scribes covering patient consent, who may enable them and where transcripts live; and a cross-reference to your HIPAA risk analysis, which must be updated when a tool is added, not annually. Our HIPAA-compliant AI development checklist explains why a signed BAA is the start of the work rather than the end of it.
Law and accounting firms. Add a confidentiality clause that requires evaluating disclosure risk before any client information is entered, a client-consent procedure that is not boilerplate, a billing clause stating that time saved by AI is not billed as time worked, and a supervision clause covering paralegals, administrative staff and contract reviewers. Conflicts checking matters too: a tool that retains one client's information and surfaces it in another matter is a problem that no amount of careful prompting fixes.
Broker-dealers and registered investment advisers. Add a communications clause: AI-assisted material that reaches a customer is a communication subject to your content standards and principal review. Add a books-and-records clause covering prompts and outputs. Add an explicit prohibition on AI agents transacting or submitting orders without human approval, which is the failure mode FINRA singled out.
A 90-day rollout plan that ends in controls
Sequencing matters more than the document. Enforce before you enable and you push usage onto personal phones. Enable before you measure and you cannot show a regulator what changed.
Days 1 to 30: find and measure. Pull AI service domains from firewall, proxy and DNS logs. List AI applications appearing in your identity provider. Search expense reports and corporate cards for AI subscriptions. Then ask every team, in writing and with explicit amnesty, what they already use and what for. You will find more than the logs show, because the personal-account traffic Verizon measured often runs over mobile networks. Classify your data if you have not. Name one accountable owner and one reviewer. The output is an inventory with a count, which becomes your baseline.
Days 31 to 60: publish and enable. Approve two or three tools that are better than what people are already using on their own, including the paid tier rather than the free one. Publish the policy and the register together; a policy without a register is an unfunded mandate. Train everyone in about 30 minutes using your own near-miss examples, not generic slides, and collect attestations. Open the request path and commit to five business days.
Days 61 to 90: enforce and review. Now turn on controls: block unapproved AI domains at the network layer, restrict consumer sign-ins on managed devices, configure tenant restrictions so only your organization's instance is reachable, add data loss prevention rules for your highest-risk patterns, and enable logging. Add AI questions to vendor due diligence and renewal checklists. Run one tabletop exercise on a disclosure incident. Report usage, exceptions and incidents to the board, owner or audit committee, and put the next review date in the calendar.
Key takeaway: Approve a better tool first, block the alternatives second. Doing it the other way round is why so many AI bans show up in logs as a sudden drop in corporate AI traffic and no drop at all in AI use.
The hard cases every policy forgets
Meeting note-takers and transcription bots. These capture content you never classified, often join through someone's personal account, and sometimes email transcripts to external addresses. Decide explicitly: allowed or not, who consents, where transcripts are stored, how long they are kept, and which meeting categories are off limits. In clinical, legal and HR settings, treat them as prohibited unless they are on the register under a signed agreement.
AI features in software you already bought. Your CRM, help desk, HR platform and document system are all shipping AI features, frequently enabled by default and sometimes powered by a subprocessor you have not assessed. Add a standing task to review release notes for AI features in your top ten applications, and a contract clause requiring notice of new subprocessors.
Coding assistants. Two distinct risks: proprietary code leaving, and generated code entering. Verizon's DBIR found source code to be the most common data type submitted to external generative AI models. Your policy needs a review requirement for generated code, a dependency and license check, and a rule about whether code containing credentials or customer data may ever be pasted into a tool. The answer should be no, with a secrets scanner enforcing it.
Agents that take actions. An agent with write access to production is a different control problem from a chat window. Require an approval gate for the actions that matter, scoped credentials rather than a shared admin account, an allow-list of tools the agent can call, and logs of every action with the identity that triggered it. FINRA's warning about agents acting beyond intended scope is the risk in one sentence. We wrote about the governance that production agents need in from AI pilot to production.
Customer-facing output. If AI drafts anything a customer reads, decide who signs off, what gets disclosed, and what happens when the output is wrong. This is the clause most likely to be tested in a complaint.
Honest trade-offs: when a template is the wrong answer
A template is a starting point for a document, not a governance program. There are situations where adopting one unchanged makes things worse.
If you have no data classification scheme, the tier table has nothing to attach to, and you will end up with a policy whose central rule is unusable. Spend a week classifying first.
If you cannot enforce anything technically, think carefully about how absolute to make the prohibitions. A policy that forbids something you cannot detect, and that everyone knows you cannot detect, trains people to treat the whole document as theater. Start with the prohibitions you can actually see and widen the scope as controls arrive.
If AI is already embedded in a regulated decision, a use policy is not sufficient on its own. You need model inventory, validation, monitoring and the evidence file your regulator expects. The use policy governs people; a model governance program governs systems, and examiners ask for both.
And if your real question is whether a specific workflow should use AI at all, the policy will not answer it. That is an assessment question, and the honest answer is sometimes no.
What to do this week
Three steps, in this order, produce more risk reduction than a month of drafting.
- Measure. Pull one month of AI domain traffic from your proxy or firewall and count distinct services and users. You now have a number to put in front of leadership.
- Decide the data rule. Fill in the tier table for your four data classes. Have one conversation with counsel about the regulated row.
- Approve one tool and publish both documents. A three-page policy and a one-page register beat a twenty-page policy that is still in review.
Then put the review date in the calendar and treat vendor terms as something to re-verify, not something you learned once.
If you want a second pair of eyes on the regulated parts of the policy, the vendor terms behind your tier definitions, or the controls that make it enforceable, our AI compliance specialists do this work for companies in banking, insurance and healthcare, and a free discovery call is the fastest way to find out whether your draft holds up. You can also talk to a specialist about a specific tool you are trying to decide on, or start from the Fleurant AI home page to see where AI governance fits with the rest of the build.
Frequently asked questions
What should an AI acceptable use policy contain?
Twelve things: purpose, scope, definitions, a data classification rule that says which data class may go into which tool tier, an approved-tool register, a request path for new tools, prohibited uses, human review and disclosure rules, rules for AI in employment decisions, logging and monitoring, incident reporting, and sanctions plus a review date. Everything else is commentary.
Do small companies really need a written AI policy?
If you handle protected health information, nonpublic personal financial information, privileged client files or card data, yes. The FTC Safeguards Rule, the HIPAA Security Rule and FINRA supervision rules all expect written policies, documented risk assessment and workforce training, and none of them has a small-business exemption that removes those duties. The policy is also the cheapest control you can deploy.
Should we just ban AI tools instead?
A ban mostly moves the activity to personal phones where you cannot see it. Verizon's 2026 Data Breach Investigations Report found frequent AI use by employees jumped from 15% to 45% of employees in a single year, and that most people reaching AI services from corporate devices were signed in with non-corporate accounts. Approve a good tool, then block the rest at the network and tenant level.
Is our data used to train the model?
It depends entirely on the plan you are on, so check the vendor's own page rather than assuming. As of October 2026, Microsoft states that Copilot prompts, responses and Graph data are not used to train foundation models; OpenAI states that API data is not used for training unless you opt in; Anthropic states it will not use commercial chats or coding sessions for training unless you join its Development Partner Program; and Google states Workspace content is not human reviewed or used for model training outside your domain without permission. Consumer and free tiers are a different question.
Who should own the AI acceptable use policy?
One named accountable owner, usually the CISO, IT director, general counsel or compliance officer, with a second named reviewer who approves new tools and exceptions. Committees without a named owner produce policies that nobody updates. Put both names and the review date in the document itself.
How do we handle AI meeting note-takers and transcription bots?
Treat them as a separate, explicit clause, because they capture content you never classified and often join meetings through an individual's personal account. Decide whether recording is allowed at all, who must consent, where transcripts are stored, how long they are kept, and which meeting types are off limits. In healthcare and legal settings, assume prohibited unless the tool is on the approved register under a signed agreement.
How often should the policy be reviewed?
Put a hard date in the document and review it at least every six months, plus whenever you add a tool, a vendor changes its data terms, or a new state law takes effect. Vendor terms change quietly: a plan that excluded your data from training last year may offer a different default this year, and your policy is only as accurate as its last check.
Sources
- Cost of a Data Breach Report 2026, IBM
- As data breaches grow costlier, ungoverned AI creates new risks, Cybersecurity Dive
- Vulnerability exploitation is now the top breach entry point industry-wide, 2026 DBIR finds, Verizon
- Lessons for organizations from the Verizon 2026 Data Breach Investigations Report, Help Net Security
- 16 CFR 314.4: Elements of an information security program (FTC Safeguards Rule), Legal Information Institute, Cornell Law School
- 45 CFR 164.308: Administrative safeguards (HIPAA Security Rule), Legal Information Institute, Cornell Law School
- Data, Privacy, and Security for Microsoft Copilot, Microsoft Learn
- Your data and OpenAI (API data controls, retention and Zero Data Retention), OpenAI
- How do you use personal data in model training?, Anthropic
- Generative AI in Google Workspace Privacy Hub, Google Workspace
- Regulatory Notice 24-09: FINRA Reminds Members of Their Obligations When Using Generative Artificial Intelligence and Large Language Models, FINRA
- 2026 FINRA Annual Regulatory Oversight Report: Generative AI, FINRA
- Generative Artificial Intelligence Tools: ABA Formal Opinion 512 Provides Needed Guidance on the Benefits and Burdens of Lawyers' Use of GAI, The Bar Examiner, National Conference of Bar Examiners
- AI Risk Management Framework, National Institute of Standards and Technology
- Illinois Passes New Law to Address AI in the Workplace, Morgan, Lewis & Bockius LLP
- SB26-189: Consumer Protections for Automated Decision-Making Technology, Colorado General Assembly
- Article 4: AI Literacy, EU Artificial Intelligence Act, EU AI Act Explorer, Future of Life Institute