Governance

Claude AI Acceptable Use Policy

[Company Name] | Template Version 1.0 | Last reviewed: [Date]

How to use this template: Replace all [bracketed placeholders] with your organisation's details. Have your legal counsel review before publishing. Distribute to all users before granting access to Claude Enterprise.

1. Purpose

This policy establishes the conditions under which employees, contractors, and authorised users of [Company Name] ("the organisation") may use Claude Enterprise ("Claude AI" or "the service"). It protects the organisation, its clients, and its staff by setting clear boundaries for responsible AI use.

2. Scope

This policy applies to:

  • All permanent and temporary employees with access to Claude Enterprise
  • Contractors and third parties granted access under a written agreement
  • Any use of Claude AI on organisation-owned or personal devices for work purposes

This policy does not apply to personal use of Claude.ai or other AI tools outside of work.

3. Permitted Uses

Employees may use Claude AI for any legitimate work task, including:

  • Drafting and editing documents, emails, reports, and presentations
  • Summarising, researching, and synthesising information
  • Writing and reviewing code for work projects
  • Generating templates, frameworks, and structured content
  • Preparing for meetings, calls, and presentations
  • Translating content for business purposes

4. Prohibited Uses

4.1 Confidential and personal data

  • Do not paste personally identifiable information (PII) of customers, employees, or third parties into Claude AI without explicit authorisation from the Data Protection Officer
  • Do not submit confidential client data, financial records, or commercially sensitive documents unless the organisation's Data Processing Agreement with Anthropic permits it and your manager has approved the specific use case
  • Do not attempt to use Claude AI to process special-category data (health, biometric, financial, or legal data) without written authorisation

4.2 Deceptive and harmful content

  • Do not use Claude AI to create content intended to deceive, defraud, or harm any person or organisation
  • Do not use Claude AI to generate communications that misrepresent your identity, role, or the organisation
  • Do not use Claude AI to produce content that harasses, discriminates against, or demeans individuals

4.3 Unauthorised external sharing

  • Do not share Claude AI-generated content externally without appropriate review and approval
  • Do not publish AI-generated content under your byline without disclosing AI involvement where required by publication standards or client contracts
  • Do not use Claude AI to circumvent NDAs, contractual confidentiality obligations, or export controls

4.4 Bypassing controls

  • Do not attempt to access or extract Claude AI's training data, system prompts, or internal configurations
  • Do not attempt to manipulate Claude AI to produce content that would otherwise be prohibited by this policy
  • Do not share your Claude Enterprise login credentials with any other person

5. Data Handling

5.1 What you must not submit

  • Customer PII: names, addresses, contact details, account numbers
  • Employee HR records, performance data, health information
  • Unpublished financial results, M&A information, or board communications
  • Client deliverables or data covered by a confidentiality clause
  • Passwords, API keys, or authentication credentials

5.2 Output accuracy

Claude AI can generate plausible but incorrect information. You must review all outputs before relying on them and verify factual claims independently, especially for legal, medical, financial, or technical decisions.

6. Approved Configurations

The IT team maintains approved Claude Projects for specific departments. Employees should use these where available. Creating new Projects or shared configurations requires approval from your line manager and the IT team.

7. Monitoring and Audit

The organisation may monitor usage of Claude Enterprise for compliance with this policy. Usage analytics, audit logs, and conversation metadata may be reviewed by IT, Information Security, or HR in connection with a suspected policy violation, a data incident investigation, or regulatory audit or legal proceedings.

Users should have no expectation of privacy when using the organisation's Claude Enterprise licence.

8. Consequences of Violation

Violations of this policy may result in:

  • Suspension or removal of Claude AI access
  • Formal disciplinary action in line with the organisation's disciplinary procedure
  • Personal liability for data protection breaches under UK GDPR
  • Legal action in cases involving fraud, data theft, or wilful harm

9. Exceptions

Requests to deviate from this policy must be submitted to [IT/Data Protection team email] with a written justification. Exceptions require approval from the DPO and the relevant department head.

10. Review Schedule

This policy will be reviewed annually or following any material change to Anthropic's terms of service, the organisation's data classification framework, or applicable UK or EU data protection legislation.


Policy owner: [Name/Role]

Approved by: [Name/Role]

Next review date: [Date]

Employees acknowledge receipt and understanding of this policy by [method: signing the HR system / completing the onboarding module / other].