Clear Guidelines About What Employees Can & Cannot Do with AI
Artificial Intelligence tools are becoming more than ever essential to how SMEs operate daily, offering major gains in productivity, decision‑making, and customer services. To use these AI technologies safely and responsibly, all SMEs should establish and implement an AI Acceptable Usage Policy (AIAUP). Its purposes are to define how employees may use AI systems, what types of data can be shared, and the standards of cybersecurity, ethics, and compliance that must be upheld.
Written in compliance with the Resources and References 1 to 14 indicated at the end of this cybersecurity manuscript, this AIAUP ensures that AI is used in ways that protect company information, respect privacy, maintain regulatory compliance, and reduce operational risks. It also provides employees with clear guidance on appropriate usage cases, prohibited activities, and accountability expectations. By following carefully these principles, everyone is empowered to enable innovation while safeguarding our people, customers, and business operations.
An AI Acceptable Usage Policy is one of those documents that looks deceptively simple until you actually try to professionally write it. SMEs need something altogether compact, practical, and enforceable. Below is a clear template that you can adapt according to your daily operational needs. It is structured the way SMEs actually operate: clear responsibilities, operational guardrails, and concrete do-or-do-not rules. For clarity purposes, it should also be noted that an organization’s AIAUP may vary depending on an individual’s roles and responsibilities within the organization.
SECTION I
TWO CONTEXTS OF AI ACCEPTABLE USAGE POLICY FOR SMEs
CONTEXT 1 – Types of Traditional AI: Public AI, Private AI, Predictive AI & Generative AI
For Canadian SMEs, the context of an AIAUP is shaped by regulatory obligations, insurance-driven requirements, ethical standards, and the operational realities of small organizations deploying AI.
The policy is not generic—it depends on what type of AI system the SME is using (developer vs. deployer, public vs. enterprise model, predictive vs. generative) and the Canadian legal environment governing personal information, automated decision-making, and data residency.
The context of an AIAUP emerges from 4 converging forces:
1. Regulatory & Legal Environment (Canada-Specific)
Canadian SMEs must align their AI use with a patchwork of privacy and governance rules:
- PIPEDA governs personal information handling nationally. AI tools that process identifiable data fall under its consent, purpose limitation, and safeguarding requirements.
- PHIPA (Ontario), Quebec Law 25, and sectoral rules impose stricter obligations for health data, employee data, and cross-border transfers.
- Treasury Board Directive on Automated Decision-Making influences best practices for algorithmic transparency and human oversight, even for private-sector SMEs.
- Bill C‑27 / AIDA died in 2025, leaving no federal AI statute—but insurers and vendors now fill the gap with contractual requirements.
Implication of Regulatory and Legal Environment: An SME’s AIAUP must classify data types (PII, PHI, IP, privileged information) and restrict which AI systems may process them.
2. Insurance & Vendor Pressure (the real driver today)
Some Canadian cyber insurers and financial-sector vendors (FRFIs) now require:
- Written AI acceptable use policies
- Annual staff training
- Evidence of human review for client-facing outputs
- Disclosure of AI use in workflows
Here, this regulatory pressure is stronger than federal regulation. Insurers treat AI risk like they treat cloud computing risk: no usage policy, no renewal.
Implication
SMEs need enforceable policies with clear scope, tool tiers, prohibited uses, and review cadence.
3. Ethical & Standards-Based Expectations
Two major standards shape the context:
- CAN/DGSI 101: Ethical Design and Use of AI by SMEs provides minimum requirements for ethical AI design and use, including risk management, ethics-by-design, deployment controls, and monitoring.
- G7 Hiroshima AI Process (HAIP) guides trustworthy AI deployment for SMEs, distinguishing between AI developers and AI deployers. Most Canadian SMEs are deployers integrating third-party AI tools.
Implication
The AIAUP must embed ethical principles, risk controls, and monitoring aligned with DGSI 101 and HAIP.
4. Operational Realities of Canadian SMEs
Canadian SMEs face unique constraints:
- Limited IT/cybersecurity staff
- Rapid adoption of consumer AI tools (shadow AI)
- Need for productivity gains without privacy breaches
- Use of public models (ChatGPT, Gemini) vs. enterprise tenants
The 2026 Guidance of Fusion Computing notes that consumer AI tools often fail Canadian requirements due to data residency, retention defaults, and lack of Canadian DPAs.
Implication
Within an organization that uses chatbots and voicebots, the AIAUP must differentiate between approved vs. prohibited tools, require enterprise tenants, and mandate human review for all client-facing outputs.
Putting It Together: The Context Framework of an AIAUP
For Canadian SMEs, an AIAUP is located at the intersection of:
| Context Dimensions | What Does It Mean for Canadian SMEs? |
| Legal | Must comply with PIPEDA, PHIPA, Quebec Law 25; classify data; restrict AI handling of personal info. |
| Insurance | Cyber renewals require written AUPs, training, oversight, and disclosure. |
| Ethical Standards | DGSI 101 and HAIP principles require risk management, ethics-by-design, monitoring. |
| Operational Constraints | SMEs rely on third-party AI tools; must manage shadow AI, data residency, retention, and human review. |
| AI System Type | Policies differ for public vs. enterprise models, predictive vs. generative AI, developer vs. deployer roles. |
Why Does the AIAUP Depend on the AI System Being Used?
Because each AI system introduces different risks:
- Public models → data leaves Canada; retention unknown; prohibited for sensitive data.
- Enterprise tenants → contractual protections; allowed for internal workflows.
- Predictive AI → risk of automated decisions; requires transparency and human oversight.
- Generative AI → risk of hallucinations, IP leakage, and confidentiality breaches.
- AI developers → must meet DGSI 101 design and testing requirements.
- AI deployers → must manage integration, prompts, outputs, and disclosure.
Therefore, the AIAUP must be contextualized to the specific AI systems in usage by Canadian SMEs.
CONTEXT 2 – AIAUP for the Emergence of Agentic AI
The context of an AIAUP for Agentic AI is fundamentally different from Traditional AI because agentic systems act, not just predict or generate. They initiate tasks, make decisions, call tools, execute workflows, and interact with external systems. This creates a new class of operational, legal, ethical, and safety risks that Canadian SMEs must explicitly govern.
In a nutshell, Agentic AI introduces autonomy, tools usage, and environmental action, which reshape the governance landscape for Canadian SMEs.
1. Agentic AI = Systems That Act, Not Just Generate
Agentic AI can:
- Trigger workflows (e.g.: send emails, update CRM records, schedule meetings)
- Execute multi-step plans
- Call APIs and tools
- Monitor environments and act without direct prompts
- Make decisions with real-world consequences
Implication
AIAUP must define boundaries of autonomy, allowed actions, disallowed actions, and required human oversight.
2. Canadian Regulatory Context (PIPEDA, Quebec Law 25, PHIPA)
Agentic AI can inadvertently:
- Process personal information without explicit consent
- Move data across borders
- Create automated decision-making scenarios
- Trigger actions that qualify as “use” or “disclosure” under privacy law
Canadian SMEs must ensure:
- Consent for automated actions involving personal data
- Purpose limitation for autonomous workflows
- Data residency controls (especially Quebec Law 25)
- Human-in-the-loop for decisions affecting individuals
Implication
The AIAUP must restrict Agentic AI from acting on personal or sensitive data unless explicit safeguards exist and are implemented.
3. Operational Risk Context (SME Realities)
Agentic AI can:
- Send unintended communications
- Modify business systems
- Create financial commitments
- Interact with customers autonomously
- Escalate errors faster than humans can catch them
SMEs often lack:
- Dedicated AI safety teams
- Mature change-management processes
- Segmented environments
Implication
The AIAUP must enforce sandboxing, action whitelists, approval gates, and audit logging.
4. Ethical & Standards Context (DGSI 101, G7 Hiroshima AI Process)
Agentic AI touches multiple ethical domains:
- Autonomy vs. human control
- Transparency of agent actions
- Explainability of multi-step plans
- Accountability for autonomous decisions
DGSI 101 (Canada’s SME AI ethics standard) requires:
- Risk assessment
- Monitoring
- Human oversight
- Clear role definitions (developer vs. deployer)
Implication:
The AIAUP must embed ethical constraints and require documentation of agentic workflows.
5. Insurance & Vendor Requirements (2025–2026 Trend)
Cyber insurers now require:
- Written AI acceptable use policies
- Restrictions on autonomous actions
- Evidence of human review for external communications
- Disclosure of agentic AI in business processes
Vendors (Microsoft, Google, Salesforce) require:
- Action whitelists
- Tool-use permissions
- Logging and auditability
Implication
The AIAUP must align with insurer and vendor requirements to maintain coverage and platform access.
6. Technical Context: Agentic AI Requires Guardrails
Agentic AI introduces risks not present in generative AI:
- Runaway loops
- Tool misuse
- Prompt injection leading to unauthorized actions
- Environment manipulation
- Cross-system propagation
Implication
The AIAUP must define:
- Allowed tools
- Allowed environments
- Maximum autonomy levels
- Monitoring requirements
- Emergency stop mechanisms
Summary Table – Context of Agentic AIAUP for SMEs
| Context Dimensions | What Does It Mean for Agentic AIAUP |
| Legal | Must restrict autonomous actions involving personal data; require consent; enforce human oversight. |
| Operational | Must prevent unintended actions; require sandboxing, whitelists, approval gates. |
| Ethical | Must ensure transparency, accountability, and explainability of agent actions. |
| Insurance | Must document agentic workflows; restrict external communications; require human review. |
| Technical | Must define tool-use permissions, autonomy levels, logging, and kill-switches. |
| AI System Type | Policies differ for internal agents, customer-facing agents, API-calling agents, and workflow agents. |
Why Does Agentic AI Require a Different AUP?
Because Agentic AI basically does things. In reality, it can:
- Act
- Trigger
- Modify
- Commit
- Escalate
- Interact
Traditional AI only generates. Agentic AI executes.
This milestone digital technology shift completely changes the entire AI governance context.
SECTION II
SAMPLE OF AN AI ACCEPTABLE USAGE POLICY FOR SMEs
Below is a sample of an AI Acceptable Usage Policy tailored for SMEs. After this concise sample, we shall provide more detailed explanations about each section.
| AI ACCEPTABLE USAGE POLICY
Sample Policy for a Small and Medium‑Sized Enterprise (SME) |
| 1. Purpose
This policy establishes how Artificial Intelligence (AI) tools, systems, and services may be used within the organization. Its overarching goal is to ensure AI adoption enhances productivity, protects company data, and aligns with legal, ethical, and cybersecurity requirements. |
| 2. Scope
This AIAUP applies to:
|
3. Definitions
|
| 4. Acceptable Usage
Employees may use approved AI tools for:
All usage must comply with company cybersecurity, privacy, and data‑handling standards. |
| 5. Prohibited Usages
Employees MUST NOT use AI tools to:
|
6. Data Protection & Privacy Requirements
|
7. Cybersecurity Requirements
|
8. Intellectual Property & Content Ownership
|
9. Accuracy, Bias & Ethical Use
|
| 10. Vendor & Tool Approval
All AI tools must be:
|
| 11. Employee Responsibilities
Employees must:
|
12. Monitoring & Enforcement
|
| 13. AI Acceptable Usage Policy Review
This AIAUP will be reviewed annually or when significant changes occur in AI technology development and deployment, regulations, laws or business operations. |
| 14. User’s Acknowledgment
All users must confirm that they:
I undersigned, [First Name & Family name], hereby confirm that I have carefully read and well understood this AIAUP. Moreover, I agree to comply with ALL the requirements of this AIAUP and apply them to the best of my conscience and professional capacities. I also FULLY understand ALL the consequences pertaining to violations of this AIAUP.
First Name & Family Name
Signature of User Date of Policy Acknowledgement
N.B.: This AIAUP is a binding document. |
DETAILED EXPLANATIONS for each Section of the above sample of an AIAUP
- PURPOSE
What this section does: It explains why the policy exists and sets the tone for responsible AI adoption.
Template Text: The purpose of this policy is to define acceptable, safe, and responsible use of Artificial Intelligence (AI) technologies within the organization. This policy ensures that AI enhances productivity, supports innovation, and aligns with legal, ethical, and security requirements. It establishes clear expectations for employees and provides guardrails to prevent misuse, data leakage, and operational risks.
Explanation: SMEs often adopt AI quickly without governance. This section anchors the policy in risk reduction, compliance, and productivity — the three pillars that SMEs care about.
- SCOPE
What this section does: Clarifies who must follow the policy and what systems it covers.
Template Text: This policy applies to:
- All employees, contractors, interns, and third‑party service providers.
- All AI tools, systems, and services used for business purposes, including generative AI, predictive analytics, automation tools, and AI‑enabled features embedded in enterprise software.
- All company devices, networks, and accounts used to access AI tools.
Explanation: SMEs often forget contractors and embedded AI features (e.g., CRM automation). This section ensures no gaps.
- DEFINITIONS
What this section does: Removes ambiguity by defining key terms.
Template Text:
- AI System: Any software or service that performs tasks using machine learning (ML), natural language processing (NLP), automation, or similar IT technologies.
- Generative AI: AI that produces text, images, code, audio, or other content.
- Sensitive Data: Confidential, personal, regulated, proprietary, or customer‑related information.
- Public AI Tools: AI systems accessible on the open internet without enterprise controls.
- Approved AI Tools: AI systems vetted and authorized by the organization.
Explanation: Clear definitions prevent ambiguity by distinctly delineating essential terms/notions and they provide a common understanding amongst stakeholders – thereby avoiding anyone to claim they did not know that such and such system or application counted as an AI tool.
- ACCEPTABLE USAGE
What this section does: Defines what employees can do — essential for adoption and clarity.
Template Text: Employees may use approved AI tools for:
- Drafting documents, reports, presentations, and communications.
- Brainstorming ideas, summarizing information, or generating insights.
- Automating repetitive tasks such as formatting, data entry, or transcription.
- Supporting decision‑making using non‑sensitive datasets.
- Enhancing customer service through approved AI‑enabled platforms.
- Improving internal workflows, provided outputs are reviewed by a human.
All usage must comply with company cybersecurity, privacy, and data‑handling standards.
Explanation: This section encourages productive use while reinforcing human oversight.
- PROHIBITED USAGE
What this section does: Provides hard boundaries to prevent legal, ethical, and security risks.
Template Text: Employees must not use AI tools to:
- Input, upload, download or share sensitive data unless explicitly authorized and protected by contractual and technical safeguards.
- Generate discriminatory, harmful, misleading, or inappropriate content.
- Create deepfakes, impersonations, or deceptive content.
- Circumvent security controls, monitoring systems, or access restrictions.
- Make final business decisions solely based on AI output without human review.
- Use unapproved or personal AI tools for company work.
- Reverse‑engineer, jailbreak, or manipulate AI systems in ways that violate vendor terms.
Explanation: This section protects SMEs from the most common AI risks: data leakage, reputational harm, and compliance violations.
- DATA PROTECTION & PRIVACY REQUIREMENTS
What this section does: Ensures employees understand how data must be handled when using AI.
Template Text:
- Only approved AI tools may be used with company data.
- Sensitive or regulated data (PII, financials, customer records, health data) must never be entered into public AI systems.
- Employees must confirm whether an AI tool stores, trains on, or shares input data before use.
- AI outputs must be reviewed for accuracy, bias, and compliance before distribution.
- Data used for AI training or fine‑tuning must follow legal and contractual requirements.
Explanation: SMEs often underestimate how easily data can leak into AI training pipelines. This section prevents that.
- CYBERSECURITY REQUIREMENTS
What this section does: Aligns AI usage with cybersecurity practices.
Template Text:
- AI tools must be vetted by IT and Security before deployment.
- Access to AI systems must use company‑approved authentication methods.
- AI‑generated code must undergo standard security review and testing.
- Any suspected misuse, data leakage, or security incident involving AI must be reported immediately.
- AI integrations must follow secure API and network practices.
Clear & Concise Explanation: AI introduces new attack surfaces. This section ensures SMEs treat AI like any other enterprise system.
- INTELLECTUAL PROPERTY & CONTENT OWNERSHIP
What this section does: Protects the company from copyright and ownership disputes.
Template Text:
- Employees must ensure AI‑generated content does not infringe on copyrights or trademarks.
- AI outputs used in deliverables must be reviewed for originality.
- When required, employees must disclose AI‑assisted content to clients or partners.
- Employees must not claim personal authorship of AI‑generated content.
Clear & Concise Explanation: AI content can accidentally replicate copyrighted material. SMEs need explicit rules.
- ACCURACY, BIAS & ETHICAL USAGE
What this section does: Addresses the limitations and ethical risks of AI.
Template Text:
- AI outputs may contain errors or bias; employees must validate all critical information.
- AI must not be used to make decisions that materially affect employment, compensation, or customer rights without human oversight.
- Employees must avoid prompting AI systems to generate unethical, harmful, or discriminatory content.
- AI use must align with company values and ethical standards.
Clear & Concise Explanation: This section ensures AI does not become a source of discrimination or harm.
- VENDOR & TOOL APPROVAL
What this section does: Creates a formal process for approving AI tools.
Template Text: All AI tools must be:
- Evaluated by IT for security, integration, and operational risks.
- Reviewed by Legal/Compliance for data‑handling and contractual obligations.
- Approved by management before use in production workflows.
- Periodically re‑evaluated for compliance and performance.
Clear & Concise Explanation: SMEs often adopt tools informally; this section creates governance.
- EMPLOYEES RESPONSIBILITIES
What this section does: Clarifies what employees must do to comply.
Template Text: Employees must:
- Use AI tools responsibly and in alignment with this policy.
- Review AI outputs for accuracy, compliance, and appropriateness.
- Report any misuse or concerns to IT or Compliance.
- Complete required AI training modules annually.
- Follow all data‑handling and security protocols when using AI.
Clear & Concise Explanation: This section ensures employees understand their role in safe AI usage.
- MONITORING & ENFORCEMENT
What this section does: Explains how the company will enforce the policy.
Template Text:
- The company may monitor AI usage for security, compliance, and operational integrity.
- Violations may result in disciplinary action, including revocation of access, retraining, or termination depending on severity.
- Serious violations may result in legal action or reporting to regulatory authorities.
Clear & Concise Explanation: Clear consequences increase compliance and reduce misuse.
- POLICY REVIEW
What this section does: Ensures the policy stays current.
Template Text: This policy will be reviewed annually or when significant changes occur in AI technology, regulations, or business operations. Updates will be communicated to all employees.
Clear & Concise Explanation: AI evolves quickly; SMEs need periodic updates.
- USER’S ACKNOWLEDGEMENT
What this section does: Creates a formal record of employee agreement.
Template Text: All employees must acknowledge they have read, understood, and agree to comply with this policy. Acknowledgment may be collected through digital signature, HR systems, or onboarding documentation.
Clear & Concise Explanation: This section protects the company legally and operationally.
SECTION III
APPROVED & PROHIBITED AI TOOLS WITHIN SMEs
The organization shall establish and maintain a formal process for evaluating, approving, and governing the use of Artificial Intelligence tools and services.
- Establish and maintain a formal process for the evaluation, approval, and governance of Artificial Intelligence (AI) tools and services.
- Define and communicate a list of authorized AI tools that employees are permitted to use for business purposes.
- Identify and communicate AI tools and services that are prohibited due to security, privacy, compliance, ethical, or operational concerns.
- Conduct a risk-based assessment of AI tools before approval, including reviews of information security, privacy, data handling practices, regulatory compliance, third-party risks, and model reliability.
- Ensure that contractual, legal, and intellectual property considerations are evaluated prior to the adoption of any AI solution.
- Prohibit the entry of confidential, sensitive, proprietary, or regulated information into unauthorized AI systems.
- Provide employees with guidance and training on the appropriate use of approved AI tools.
- Review and re-evaluate approved AI tools on a regular basis, and whenever significant changes occur to the tool, its provider, applicable regulations, or organizational requirements.
- Monitor the use of AI tools to ensure compliance with organizational policies and approved use cases.
- Address the use of unauthorized AI tools in accordance with the organization’s information security and acceptable use policies.
SECTION IV
AUTHORIZED ACTIVITIES, PROHIBITED ACTIVITIES, AND INTELLECTUAL PROPERTY REQUIREMENTS
Only organization-approved enterprise AI tools may be used, and all AI-generated outputs must be reviewed by a human before being relied upon, published, or used for decision-making.
Authorized Uses
- Productivity tasks such as drafting emails, reports, presentations, meeting notes, and internal communications.
- Data analysis, business intelligence, and assistance with spreadsheets, queries, and reporting.
- Software development support, including code generation, documentation, testing, and approved security analysis.
- Customer support activities such as drafting responses, ticket management, and knowledge-base creation.
- Marketing and sales content development, subject to appropriate review and approval.
- Internal training, onboarding, policy development, and HR support activities.
- Brainstorming, research, content summarization, and first-pass drafting of SME-owned materials.
Key Conditions
- Only approved enterprise AI tools may be used.
- Confidential, regulated, customer, or sensitive information may only be processed in authorized environments with appropriate safeguards.
- Human review and oversight are mandatory.
- AI outputs must be validated for accuracy, compliance, intellectual property, and business suitability.
Prohibited or Restricted Uses
- Uploading sensitive, regulated, confidential, customer, financial, health, legal, or proprietary information into unauthorized AI tools.
- Using consumer-grade or unapproved AI solutions that lack appropriate security, privacy, or compliance controls.
- Allowing AI to make autonomous decisions regarding employment, legal, financial, safety-critical, or compliance matters.
- Generating deceptive, fraudulent, harmful, impersonation, or deepfake content.
- Using AI to circumvent security controls, develop malware, or perform unauthorized system analysis.
- Relying on AI as a substitute for professional legal, financial, medical, compliance, or engineering judgment.
- Uploading third-party intellectual property, copyrighted content, confidential partner information, or licensed materials without authorization.
- Publishing AI-generated content externally without appropriate human review and approval.
Intellectual Property Requirements
- AI is an assistive tool and does not replace human ownership, accountability, or review.
- All AI-generated content must undergo technical, intellectual property, and compliance reviews before external use.
- Organizations remain responsible for the accuracy, legality, and ownership of all AI-generated content.
- AI-generated content may only be considered organizational property when created using approved tools, reviewed by authorized personnel, and free of unauthorized third-party intellectual property.
SECTION V
ETHICAL & DEONTOLOGICAL USAGES OF AI
1. Ethical Foundations for AI in SMEs (Normative Principles)
Précised below are the core philosophical anchors that guide responsible AI usages:
A. Beneficence (Do Good)
AI must be used to enhance human capability, improve efficiency, reduce harm, and support fair outcomes.
B. Non‑Maleficence (Do No Harm)
AI must not create or amplify risks — physical, psychological, financial, or reputational.
C. Autonomy (Respect Human Agency)
AI should support human decision-making, not replace it. Humans remain accountable.
D. Justice (Fairness & Equity)
AI systems must avoid bias, discrimination, and unequal treatment.
E. Accountability (Moral & Operational Responsibility)
Only human beings — not algorithms — are accountable for outcomes, decisions, and consequences related to AI tools usages.
2. Deontological Principles (Duty‑Based Obligations)
Synopsized below are non-negotiable duties that employees and SMEs must uphold regardless of outcomes.
A. Duty of Truthfulness
AI must not be used to deceive, manipulate, or mislead individuals or groups.
B. Duty of Respect for Persons
AI must not violate dignity, privacy, or personal rights.
C. Duty of Confidentiality
AI must not be used to expose, infer, or exploit sensitive information.
D. Duty of Professional Integrity
Employees must not use AI to bypass expertise, fabricate credentials, or simulate authority.
E. Duty of Fair Conduct
AI must not be used to gain unfair advantage, distort competition, or exploit vulnerabilities.
3. Ethical AI Decision Framework – Deontological Checklist
Before using AI, ALL employees MUST CLEARLY ANSWER the following questions:
| Ethical AI Decision Framework – Deontological Checklist |
|
IMPORTANT: If any answer is “No,” the activity is prohibited.
SECTION VI
REGULAR TRAINING & AWARENESS RELATED TO AI USAGE WITHIN SMALL ORGANIZATIONS
1. Purpose of AI Training & Awareness in SMEs
AI governance only works if employees understand:
- What they are allowed to do
- What they must never do
- How to identify risks
- How to escalate issues
- How AI affects ethics, IP, privacy, and security
Training is not optional — it is the backbone of safe AI adoption.
2. Core Components of an SME AI Training Program
A. Foundational AI Literacy
Employees must understand:
- What AI is (and what AI is not)
- How generative AI works
- Limitations: hallucinations, bias, overconfidence
- Human‑in‑the‑loop requirements
- Approved vs. prohibited tools
B. Acceptable Use & Policy Awareness
Training covers:
- Authorized AI activities
- Strictly forbidden activities
- Data classification rules
- IP & content review workflows
- Ethical & deontological obligations
- Escalation paths for violations
C. Security & Privacy Awareness
Employees learn:
- Why sensitive data must never be uploaded?
- How AI tools can leak information?
- How to identify unsafe prompts?
- How to report suspicious AI behavior?
- How IT Security monitors AI usage?
D. Practical Skills Training
Hands‑on modules:
- How to write safe prompts?
- How to review AI outputs?
- How to detect bias or hallucinations?
- How to use enterprise AI tools effectively?
- How to validate AI-generated code or content?
E. Role‑Specific Training
Different roles require different depth:
- Managers: oversight, review, approvals
- IT Security: monitoring, incident response
- HR: ethical hiring, privacy, fairness
- Marketing: brand safety, IP compliance
- Developers: code review, licensing, model risk
SECTION VII
AI ACCEPTABLE USAGE POLICY ANNUAL REVIEW
1. Purpose of the Annual Review
The annual review ensures the AI Acceptable Usage Policy remains:
- Current with emerging technologies
- Aligned with legal, ethical, and regulatory changes
- Responsive to new risks (deepfakes, data leakage, model drift)
- Effective in guiding employee behavior
- Consistent with SME strategy and security posture
The annual review is the formal checkpoint that keeps the policy alive rather than static.
2. Annual Review Objectives
Each review cycle must accomplish the following:
A. Evaluate Policy Effectiveness
- Did employees follow the rules?
- Were violations detected?
- Did the policy prevent misuse?
- Are controls working?
B. Update Risk Assessments
- New AI tools
- New threat vectors
- New regulatory requirements
- New ethical considerations
- New IP and data protection risks
C. Refresh Approved & Prohibited Tools
- Add newly vetted enterprise tools
- Remove deprecated or unsafe tools
- Update restrictions based on vendor changes
D. Strengthen Oversight & Accountability
- Adjust roles and responsibilities
- Improve escalation paths
- Enhance monitoring and reporting mechanisms
E. Improve Training & Awareness
- Update training modules
- Add new case studies
- Reinforce weak areas identified in audits
RESOURCES AND REFERENCES
- Justin B. Bullock (ed.), Yu-Che Chen (ed.), Johannes Himmelreich (ed.) et al. The Oxford Handbook of AI Governance. Oxford University Press, 19 April 2024, 1104 pages. The Oxford Handbook of AI Governance | Oxford Academic
- Vincent C. Müller. Ethics of Artificial Intelligence and Robotics: The Standford Encyclopedia of Philosophy. Summer 2026 Edition. Standford University Press, 598 pages. Ethics of Artificial Intelligence and Robotics (Stanford Encyclopedia of Philosophy/Summer 2026 Edition)
- Tim-Dorian Knöchel, Konrad J. Schweizer, Oguz A. Acar, et al. Core Principles of Responsible Generative AI Usage in Research. Springer Nature Publishing, 14 October 2025, Volume 5, pages 6371-6377. Core principles of responsible generative AI usage in research | AI and Ethics | Springer Nature Link
- Ryan Abbott (ed.). Research Handbook on Intellectual Property and Artificial Intelligence. World Intellectual Property Organization (WIPO) Knowledge Repository, 26 September 2023, 498 pages. Research Handbook on Intellectual Property and Artificial Intelligence
- Jozefien Vanherpe & Nathalie A. Smuha. The Cambridge Handbook of Law, Ethics and Policy of Artificial Intelligence. Cambridge University Press, 6 February 2025, 983 pages. Artificial Intelligence and Intellectual Property Law (Chapter 11) – The Cambridge Handbook of the Law, Ethics and Policy of Artificial Intelligence
- Tiyyaba Furqan, Hamda M. Aleissaee, Nadirah Ghenimi et al. Global Laws Governing Intellectual Property Rights for AI-Generated Works. Springer Nature Publishing, 12 May 2026, Volume 6, Article No 449. Global laws governing intellectual property rights for AI-generated works | Discover Artificial Intelligence | Springer Nature Link
- Gergely Ferenc Lendvi, Peter Mezei & Annette Pogacsas. The State of AI and Intellectual Property – A Thematic Scientometric Assessment. Springer Nature Publishing, 8 June 2026, Volume 6, Article No 240. The state of AI and intellectual property – a thematic scientometric assessment | SN Social Sciences | Springer Nature Link
- William D’Alessandro. Deontology and Safe Artificial Intelligence: Philosophical Studies Collection. Springer Nature Publishing, 13 June 2025, Volume 182, pages 1681-1704. Deontology and safe artificial intelligence | Philosophical Studies | Springer Nature Link
- Jasper Kyle Katapang. Building the Ethical AI Framework for the Future: From Philosophy to Practice. Springer Nature Publishing, 9 February 2026, Volume 6, Article No 150. Building the ethical AI framework of the future: from philosophy to practice | AI and Ethics | Springer Nature Link
- Steven S. Gouveia (ed.). The Palgrave Handbook on the Ethics of Artificial Intelligence. Jointly published by the Institute of Philosophy, University of Porto, Porto, Portugal Springer Nature Publishing, 8 May 2026, 898 pages. The Palgrave Handbook on the Ethics of Artificial Intelligence | Springer Nature Link
- Thang Le Dinh, Manh‑Chiên Vu, Giang T.C. Tran. Artificial Intelligence in SMEs: Enhancing Business Functions Through Technologies and Applications. MDPI Open Access Journals – Volume 16, Issue 5, 18th May 2025. Artificial Intelligence in SMEs: Enhancing Business Functions Through Technologies and Applications
- World Economic Forum – Davos, Switzerland. Advancing Responsible AI Innovation: A 2025 Playbook for All Types of Organizations. 22nd September 2025. Advancing Responsible AI Innovation: A 2025 Playbook for All Types of Organizations | World Economic Forum
- IIENSTITU – Online Advanced IT Courses & Certifications for Small Businesses. Marco dela Cruz. AI Risk Assessment: SMEs’ Path to Compliance in 2026. 16th May 2026. AI Risk Assessment: SMEs’ Path to Compliance in 2026 – IIENSTITU
- I LIKE AI – AI Deontology, Ethics, Professional Practices & Policy Issue. Conducting an AI Risk Audit: A Simple Framework for SMEs. 3rd May 2025. Conducting an AI Risk Audit: A Simple Framework for SMEs – I LIKE AI
CONTRIBUTIONS
Special thanks for the financial support of the National Research Council Canada (NRC) and its Industrial Research Assistance Program (IRAP) benefitting innovative SMEs throughout the 10 provinces and 3 territories of Canada.
Eligible Canadian innovative SMEs can address their cybersecurity requirements by obtaining financial assistance for compliance readiness and certification audits. If you would like more information about NRC IRAP, please consult: About the NRC Industrial Research Assistance Program or reach out to your NRC IRAP Industrial Technology Advisor.
Newsletter Executive Editor:
Alan Bernardi, SSCP, PMP, Lead Auditor for ISO 27001, ISO 27701 and ISO 42001
B.Sc. Computer Science & Mathematics, McGill University, Canada
Graduate Diploma in Management, McGill University, Canada
Author-Amazon USA, Computer Scientist, Certified Professional Writer & Translator:
Ravi Jay Gunnoo, C.P.W. ISO 24495-1:2023 & C.P.T. ISO 17100:2015
B.Sc. Computer Science & Cybersecurity, McGill University, Canada
B.Sc. & M.A. Professional Translation, University of Montreal, Canada
References to products or services in this newsletter are for informational purposes only and do not constitute an endorsement, recommendation, or support of those products or services.
This content has been prepared to the best of our knowledge. While every effort has been made to ensure accuracy and clarity, we cannot guarantee that all information is complete, error‑free, or up to date. The views and information provided are intended for general purposes only.
This content is published under a Creative Commons Attribution (CC BY-NC) license.
