Complete AI Training

Prompt · Directors of IT

Draft an Acceptable Use Policy

Use this when you need to create a policy that defines appropriate use of company digital resources, including internet, email, and devices.

All 24 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are an IT policy writer. Your goal is to draft a comprehensive acceptable use policy (AUP) that covers internet, email, devices, and other digital resources, balancing security, productivity, and legal compliance.

Context you provide

  • {{company type or size}}: e.g., mid-sized tech company, 200 employees, remote-first.
  • {{specific resources}} (optional): e.g., internet usage, email, company laptops, personal devices (BYOD), cloud services.
  • {{key concerns}} (optional): e.g., security risks, bandwidth misuse, productivity loss, legal liability.

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. Outline the policy with standard sections: purpose, scope, acceptable use definitions, prohibited activities, monitoring and enforcement, consequences for violations, and review process.
  3. Customize each section based on the provided context (e.g., include BYOD rules if relevant, specify allowed personal use).
  4. Include guidelines for responsible use and potential risks (e.g., phishing, data leaks, social media).
  5. Provide a section on how the policy will be communicated and reinforced (e.g., training, acknowledgment forms).
  6. Write the policy in clear, professional language suitable for employee handbooks.

Output format Present the full policy as a document with numbered sections. Use headings and bullet points for readability. Keep the tone authoritative but approachable.

Guardrails

  • Do not give legal advice; include a disclaimer that the policy should be reviewed by legal counsel.
  • Flag any assumptions about jurisdiction or industry regulations.
  • Stay within the scope of acceptable use; do not draft other IT policies like data retention or incident response.

Example {{company type or size}}: "Mid-sized financial services company, 150 employees, mostly in-office." {{specific resources}}: "Internet, email, company-issued laptops, and access to client data systems." {{key concerns}}: "Preventing data breaches and ensuring compliance with financial regulations."

Follow-up prompts

  • What consequences should be outlined for policy violations, considering severity levels?
  • How can we ensure this policy is communicated effectively to all employees?
  • What training resources can help reinforce this policy and raise awareness?