Checklist · Free Resource

AI Policy Quick-Start Checklist

12 things every organization should have in place before their next AI tool deployment. Use the checkboxes to track your progress.

Version: June 2026 Applies to: Any organization deploying AI tools Review: Quarterly recommended
Take the free audit →

Your progress

0 of 12 items complete

Critical — address first
1
Critical

Written AI Acceptable Use Policy (AUP) exists

A documented policy defining what employees may and may not do with AI tools — including which tools are approved, what data can enter them, and how outputs should be handled. Not a prohibition — a real policy with three tiers: permitted, requires approval, prohibited.

2
Critical

Designated AI Platform Administrator

A named individual with defined responsibilities for AI governance: maintaining the approved tools list, reviewing exceptions, keeping the policy current, and receiving incident reports. Without an owner, no other policy measure works.

3
Critical

All employees have reviewed and acknowledged the AUP

Training without sign-off is not enforceable. All employees who use AI tools should have reviewed the policy and signed (or digitally acknowledged) it. This is your audit evidence.

4
Critical

Approved AI tools list maintained and communicated

A documented list of AI tools approved for use, the conditions of approval (e.g., "approved for internal use only — no client data"), and the process to request approval for additional tools. Anything not on the list is unapproved.

Important — complete within 30 days
5
Important

Data classification rules for AI tool use defined

A clear definition of what types of data may or may not enter AI tools. Use concrete terms employees understand: "client names with account numbers," "Social Security numbers," "internal salary information" — not just "sensitive data."

6
Important

AI vendor data processing agreements (DPA) executed

For each approved AI tool, a data processing agreement or equivalent is in place. This ensures the vendor is contractually bound to protect your data, not use it to train their models, and notify you of breaches. Consumer tiers rarely include these.

7
Important

AI vendor security documentation reviewed

SOC 2 Type II report reviewed for each approved vendor. Key items to verify: data residency, model training policy for customer inputs, breach notification timeline, subprocessor list. For regulated industries, also check relevant compliance certifications (HIPAA, FedRAMP, etc.).

8
Important

AI security awareness training completed by all users

All employees who use AI tools have completed training covering: what risks AI tools pose, which tools are approved, what data is prohibited, how to recognize a potential AI-related incident, and how to report one. Training should be documented with completion records.

9
Important

AI incident response procedure documented

What should an employee do if they accidentally input prohibited data into an AI tool, receive a suspicious AI-generated output, or discover an unapproved AI tool in use? The answer should be in writing. This connects to your overall incident response plan.

Standard — ongoing program
10
Standard

AI output review process for client-facing work

A documented process for reviewing AI-generated outputs before they are used in client communications, deliverables, or decisions. Who reviews? What do they check? How is review documented? This protects against accuracy errors and unwanted disclosures.

11
Standard

AUP reviewed by legal counsel or AI-focused attorney

Your AI Acceptable Use Policy should be reviewed by an attorney familiar with AI governance — not just standard IT counsel. This is especially important for regulated industries. Even a one-time review provides meaningful protection and credibility with examiners.

12
Standard

Policy review schedule established

AI tools and regulations both change fast. A quarterly review cadence is recommended. At minimum, the policy should be reviewed annually — and any time a significant new regulation, enforcement action, or AI capability emerges that changes the risk landscape. Put it on the calendar.

Want Help With Every Item on This List?

The BulldogAI $250 AI Success Kit includes a custom AUP, security awareness training module, and employee onboarding guide — everything on this checklist, built for your organization.

Start with the Free Audit →