Your team is already using AI โ the real question is whether there are rules for it. This free, editable template gives your firm a complete AI Acceptable Use Policy: which tools are approved, what client data can never go into them, and the human-oversight and security controls that keep you covered. Fill in the blanks, drop it in your handbook, done.
This template is general information, not legal advice. Review it with your counsel or compliance advisor before relying on it.
A starting stack of enterprise-grade AI tools โ Copilot, ChatGPT Enterprise, Claude Team, and industry tools โ plus a clear list of what's off-limits.
An explicit "never paste this into public AI" list: SSNs, tax returns, financials, client names, engagement letters, and more.
Human review of AI output, MFA, access control, incident reporting, and a vendor-review checklist before any new tool gets approved.
Regulatory context prewired โ NY SHIELD Act, SEC Reg S-P, DFS Part 500, IRC ยง7216, ABA Rule 1.6 โ so accounting, advisory, insurance, and law firms can adapt it fast.
A policy is the starting point. If you want help vetting the AI tools your team already uses โ or locking down the accounts and client data behind them โ that's what we do for firms across New York, New Jersey, and Connecticut.