Resources / Free tool
Draft an AI policy your team can adapt.
Choose the controls relevant to your organization and download an editable Word document. Review the draft with your policy owners and legal team before adopting it.
Resources / Generator
Resources / Why this template
A practical starting point for your review.
The template brings approved use, responsibilities, monitoring, and response procedures into one draft. Adapt each section to your actual tools, deployment, obligations, and available controls.
Includes references to NIST AI RMF, the EU AI Act, and ISO/IEC 42001 to support your review. A generated policy does not establish compliance or replace legal advice.
Covers employee AI tools alongside applications and autonomous workloads, with ownership, approved use, budgets, and response procedures to adapt.
Distinguishes direct evidence, inferred conclusions, applied controls, and gaps, so a reader can see what supports each statement.
Microsoft Word .docx for legal and Markdown for engineering. Same content, both formats, no PDF lock-in.
Resources / What’s in the template
Eight sections to adapt.
Define the people, apps, and agents in scope. Include third-party assistants, embedded AI features, API workloads, and internal models. Assign owners for the uses your policy covers.
What each AI actor can use AI for, by role and data class. Drafting and brainstorming with non-sensitive data. Code generation with non-proprietary code. Summarization within approved tools. For agents: an approved model scope and a budget, not an open-ended mandate. Clear, role-aware, not absolutist.
Specify which data and uses your organization prohibits, including sensitive customer information, secrets, and restricted material. Confirm the applicable legal and contractual requirements with your legal and security teams.
Name approved providers and the review process for adding others. Record the relevant contract, retention, and deployment requirements, and update them when those arrangements change.
Name the sources you collect and the controls you apply. Gateway budgets and shutdowns apply to routed requests. Provider APIs can supply evidence without Gateway routing; provider access actions use separate supported integrations. State unresolved gaps and the scope of each control.
Adapt your incident-response process for AI use. Assign the people responsible for containment, investigation, escalation, and any required notifications.
Quarterly review of the provider list and coverage report. Annual policy refresh. Out-of-band review when a major new tool enters the company. Documented, with dates and owners.
Assign a policy owner, reviewers, and day-to-day responsibilities. Give autonomous workloads an accountable human owner, a defined scope, and an escalation process.
Put the policy into practice
Give each requirement a next step.
Some requirements need a technical control. Others need a document, a review, or a decision from an accountable owner. Tallin helps connect those requirements to their supporting records. Gateway enforcement applies to selected traffic routed through Tallin, not every clause in a policy.
Stop writing policy from scratch.
Download a draft to review with your team, then explore how Tallin connects policy requirements to evidence and follow-up.