AI acceptable use policy for a professional firm
The six sections a short firm AI policy needs, sample wording for each, and a one to two page model policy you can adapt.
King & Company
In short
A firm AI policy gets followed when it is short and describes the approved way to do the work: which workspace to use, which documents may go into it, who reviews output before a client sees it, who may connect the AI to email or the document system, what clients are told, and how to report a mistake. Put the enforceable parts in the workspace's admin settings and let the policy point to them. The model policy at the end is a starting draft, and regulated firms should have counsel review it.
An AI acceptable use policy for a professional firm works when it is short and when it describes the approved way to do the work before it lists what is off limits. It needs six sections: approved tools and accounts, what may go in, review before work reaches a client, connectors and agents, client disclosure, and how to report a mistake.
A template written for a generic employer tends to read as a list of prohibitions. This article walks through each section with wording a brokerage, accounting, insurance, or advisory firm can adapt, and ends with a model policy of about a page and a half. It is a working draft from people who build AI workflows inside firms. It is not legal advice, and a firm with regulatory obligations should have counsel review its version.
Why does an AI policy get ignored?
A policy that says "never put client data into AI" asks staff to stop doing something useful and offers nothing in its place, so the work can continue on whatever account is closest. In a Thomson Reuters survey of 538 professionals at tax and audit firms in 40 countries, gathered in March and April 2026, 35% said they use AI tools their firm has not authorized for work. Unauthorized use is the outcome a prohibition is written to prevent, and it happens where the firm has no contract and no record.
The second reason is vocabulary. A template that refers to "sensitive data" leaves an analyst to decide alone whether a rent roll counts. A policy written in the firm's own document types removes that guess.
Write the approved path first, then the limits
Open the policy with what staff should do: which workspace to sign in to, with which account, for which work. The limits then read as the edges of a path that exists. This order also forces the firm to make the decision the policy depends on, which is to provide an approved workspace under a contract the firm has signed. Our guide to secure AI workflows for confidential client data covers how to choose and configure that workspace.
Section 1: Approved tools and accounts
Name the tools. The Journal of Accountancy's July 2026 article on AI policy, written by a risk consultant at Aon, recommends that firms consider limiting use to authorized tools and keep a maintained list of approved ones. Keep that list on a separate page so it can change without reissuing the policy.
Sample wording: "Client and firm work is done in the firm's AI workspace, signed in with your firm account. Personal AI accounts are not used for client work. AI features inside software the firm already licenses are approved only if they appear on the approved tools list."
That last sentence matters because an AI feature added to a product the firm already pays for is a separate data path with its own terms.
Section 2: What may go in, sorted by the documents your firm handles
Two or three classes are enough. What makes them usable is the examples column, written with documents your staff handle every week. The same Journal of Accountancy article recommends restricting entry of personal, confidential, or proprietary information into AI tools; the table is how a firm turns that principle into a rule someone can apply in ten seconds. The example below is illustrative, and each firm should set its own lines with counsel.
| Class | Rule | Examples a brokerage would list | Examples an accounting firm would list |
|---|---|---|---|
| Open | Approved workspace, no extra steps | Published listings, public market reports, the firm's own templates | Published guidance, firm templates, blank checklists |
| Client confidential | Approved workspace only, inside the client or deal project | Rent rolls, signed leases, offering memoranda under NDA, client emails | Trial balances, client statements, engagement correspondence |
| Restricted | Only in a workflow the AI lead has approved for that data | Personal financial statements, tenant bank details | Tax returns and supporting documents, Social Security numbers, payroll records |
Section 3: Review and sign-off before work reaches a client
For tax work, the professional standard is already written down. A February 2024 article in The Tax Adviser, an AICPA publication, notes that under the Statements on Standards for Tax Services, Section 1.4.7, the tax practitioner employing tools remains responsible for the completed work product, and the Journal of Accountancy article recommends documenting in the client file the prompts used, how the output was verified, and who performed the review.
A policy turns that into a list of work product and a named role for each. A lease abstract is checked against the lease by the analyst who owns the deal. A tax research memo is checked against the primary authority by a manager. A proposal is read by the partner who will sign it. If the firm already has a review point for that document, put the AI review at the same point, with the same person. We go into the design of that step in how to design the human review step in an AI workflow.
Sample wording: "AI output is a draft. Before any AI-assisted work goes to a client, the reviewer named for that work type checks it against the source documents and notes the review in the file."
Section 4: Connectors, agents, and who may turn them on
This section is easy to leave out, because it covers what the AI can reach instead of what staff type into it. An AI workspace that can read a mailbox, search the document system, or update the CRM carries different risk from one that only sees what a person pastes into it, and the policy should say who decides.
In the workspace itself, the decision often already sits with an administrator. In Claude, for example, on Team and Enterprise plans an Owner or Primary Owner must enable Google Workspace connectors at the organization level before individual users can authenticate. The same documentation says Claude can send, reply to, and forward email from Gmail, asks for approval by default before each of those actions, and that on Team and Enterprise plans owners decide whether members can allow those actions to run without asking each time.
So the policy needs three sentences: who approves a new connector, which actions always need a person's approval (sending, deleting, writing to a system of record), and who may build or run an agent that works unattended. Our article on AI agent permissions and governance covers the read, write, and send decisions in detail.
Section 5: Client disclosure and engagement letters
Decide what the firm tells clients and write it down once, so that each partner is not answering the question differently. The Journal of Accountancy article suggests firms consider adding disclosure language to all engagement letters saying AI tools may be used in providing services. Tax preparers have a further constraint, because Section 7216 limits a preparer's ability to disclose or use taxpayer information. A brokerage should check its NDAs and listing agreements for confidentiality terms that reach third-party tools. The wording belongs to counsel; the policy only needs to say where the standard language lives and that client-specific restrictions override the general rule.
Section 6: Reporting a mistake
Someone will paste the wrong document into the wrong tool. The policy should make reporting it the easy choice: who to tell, how fast, and what to include. The Journal of Accountancy article recommends designating an AI lead or committee to address incident reports. Say in the policy that a prompt report is the expected behavior and is treated that way.
Put the enforceable parts in settings and point the policy at them
A sentence in a policy cannot stop anyone from signing in with a personal email address, and a setting can. The parts of the policy that can be enforced by configuration should be, and the policy should name the setting so staff know the rule is real.
Using Claude as the example again: single sign-on is available on Team and Enterprise plans, and an owner can require it. The Enterprise plan adds audit logs and custom data retention controls, and its role-based permissions let an owner set each connector tool to always allow, needs approval, or blocked inside a custom role that is then assigned to groups. Other vendors have their own equivalents, and the features differ by plan, so check current documentation before you write a setting into the policy.
With that split, the policy describes how the firm works and the settings do the enforcing. None of this makes a firm compliant with anything on its own.
Which obligations does the policy attach to?
A firm that already has obligations should hang the AI policy on them. The FTC Safeguards Rule defines coverage by a business's activities and lists tax preparation firms among its examples. The FTC's guidance describes elements that include designating a Qualified Individual, a written risk assessment, training staff, monitoring service providers, keeping the program current, and a written incident response plan. For a covered firm, the AI policy lines up with several of those elements: an AI vendor that handles customer information is a candidate for service provider oversight, AI training can sit inside staff training, and Section 6 above feeds the incident response plan. The page also notes an exemption from certain provisions for institutions holding information on fewer than five thousand consumers, so confirm with your counsel or compliance lead whether the rule covers your firm and which parts apply. We cover the tax-specific rules in the FTC Safeguards Rule, IRS Publication 4557, and Section 7216.
For firms that want a recognized frame, the NIST AI Risk Management Framework is voluntary, was released on January 26, 2023, and gained a Generative AI Profile (NIST AI 600-1) on July 26, 2024. Its Govern function calls for policies and procedures to be in place and for roles and responsibilities to be documented and clear, which is what a short policy with a named AI lead provides.
Rolling it out: train on real work, then revisit on a schedule
A policy that arrives as an emailed PDF is easy to file unread. Introduce the policy in a working session where staff run one real task in the approved workspace: an analyst abstracts a lease from a closed deal, a senior drafts an organizer from last year's file. The data classes and the review step make sense once people have used them on a document they recognize.
The Journal of Accountancy article recommends a signed acknowledgement from employees, spot checks, engagement reviews, and feedback loops, and describes these policies as "a living part of your risk management framework." Set a review date when you adopt it, and review sooner when the firm adds a tool, turns on a connector, or has an incident. If you would like help building the approved path the policy describes, get in touch.
A model policy to adapt
Adapt the bracketed parts. Have counsel review the result before adoption.
1. Purpose. [Firm] encourages the use of AI for firm and client work, done in the approved way described here. This policy applies to all partners, employees, and contractors.
2. Approved tools and accounts. Work is done in the firm's AI workspace, [name], signed in with your firm account through the firm's sign-on. Personal AI accounts are not used for client work. Other tools, including AI features inside software the firm already uses, are approved only if they appear on the approved tools list kept by the AI lead at [location]. To request a tool, ask the AI lead.
3. What may go in. Open material (public information and firm templates) may be used freely in the approved workspace. Client confidential material (for our firm: [examples]) is used only in the approved workspace, inside the project for that client or deal. Restricted material (for our firm: [examples]) is used only in a workflow the AI lead has approved for it. If a client agreement sets a tighter rule, the client agreement governs. If you are unsure which class a document falls in, ask before you use it.
4. Review before delivery. AI output is a draft. Before AI-assisted work goes to a client, the reviewer named for that work type in [schedule] checks facts, figures, and citations against the source documents and records the review in the client file. The person who signs the work is responsible for it.
5. Connectors and agents. Only the AI lead may approve connecting the AI workspace to email, the document system, the CRM, or any other firm system. Sending a message, deleting a record, and writing to a system of record require a person's approval each time unless the AI lead has approved otherwise in writing. Unattended agents are built and run only with the AI lead's approval.
6. Client disclosure. The firm's standard engagement language on AI use is kept at [location]. Do not make other commitments to a client about AI use without the engagement partner's agreement. Honor any client instruction that restricts AI use on their files.
7. Reporting. If you entered something into a tool that this policy does not permit, or AI-assisted work reached a client with an error, tell the AI lead, [name and contact], the same day. Say what was entered and where, and leave the conversation in place. Prompt reports are expected and will be treated as the right thing to do.
8. Settings and ownership. Sign-on, connector permissions, and retention are configured in the workspace's admin settings, which the AI lead maintains and documents at [location]. The AI lead owns this policy, reviews it every [interval], and reviews it sooner when a tool or connector is added or an incident occurs.
9. Acknowledgement. Each person signs to confirm they have read this policy and completed the firm's working session on it.
Common questions
How long should an AI acceptable use policy be?
One to two pages is enough for most firms. A policy that fits on two pages can be read in a staff meeting and remembered at a desk, and the detail that changes often, such as the list of approved tools and the admin settings, can live in a separate page the policy points to.
Should we ban personal AI accounts for work?
For client work, yes, provided the firm gives staff an approved workspace first. A ban with no approved alternative can push the work onto personal accounts, where the firm has no contract, no administrator, and no record.
Do we need client consent to use AI on their files?
That depends on your engagement terms, your profession's rules, and the regulations that apply to the data, so it is a question for your counsel. A July 2026 Journal of Accountancy article suggests firms consider adding disclosure language to engagement letters, and tax preparers have separate limits on disclosure and use of taxpayer information under Section 7216.
Who should own the AI policy at a small firm?
Name one partner or senior manager as the AI lead, and pair that person with whoever is responsible for the firm's information security program. The lead approves tools and connectors, receives incident reports, and brings the policy back for review on a schedule.
What should staff do if they pasted something they should not have?
Tell the AI lead the same day, say what was entered and in which tool, and leave the conversation in place until the lead has looked at it. The policy should say plainly that a prompt report is treated as the right thing to do, because a mistake the firm knows about can be handled and one it does not know about cannot.