---
title: "Acceptable-use policy (AUP)"
description: "The staff-facing rules for using AI tools: which tools are approved, which data classes may go where, duties to review and disclose outputs, logging, attestation before access and consequences."
canonical: https://aigovernanceengineer.com/glossary/acceptable-use-policy-aup
author: "Jorge García Aibar"
license: "CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/)"
doi: https://doi.org/10.5281/zenodo.22956197
version: "0.5.0"
updated: 2026-09-25
---

# Acceptable-use policy (AUP)

The staff-facing rules for using AI tools: which tools are approved, which data classes may go where, duties to review and disclose outputs, logging, attestation before access and consequences. It is enforced through a sanctioned gateway and discovery, not the handbook alone.

- Developed in: [ch. 12, Acceptable use of AI by staff](https://aigovernanceengineer.com/bok/governance-program#acceptable-use-of-ai-by-staff); [ch. 05, Pattern: Sanctioned AI Gateway](https://aigovernanceengineer.com/patterns/sanctioned-ai-gateway)
- Chapters: [ch. 05, Patterns](https://aigovernanceengineer.com/bok/patterns) · [ch. 12, Governance Program](https://aigovernanceengineer.com/bok/governance-program)
- In the glossary chapter: https://aigovernanceengineer.com/bok/glossary#t-acceptable-use-policy-aup

## Sources

Defined by this Body of Knowledge: the section it is developed in is the source.
