A company AI usage policy tells staff which AI tools they may use, what information may go into them, and who is responsible for the output. Every Malaysian company with more than a handful of office staff needs one now, because the tools are already in use whether management approved them or not. Below is a one-page template you can copy, adapt and approve this week, followed by the reasoning behind each clause.
Not legal advice. This template is a practical starting point written by a training provider, not a law firm. Have your legal adviser or DPO review it, especially if you are in a regulated industry.
The template
[COMPANY NAME] ACCEPTABLE USE OF AI TOOLS POLICY
Version 1.0 | Owner: [Name, role] | Approved: [date] | Review: every 6 months
1. PURPOSE
We want staff to use AI tools to work faster and better, safely. This policy
sets out which tools are approved, what information may be used in them, and
who is accountable for the results.
2. SCOPE
All employees, contractors and interns using generative AI tools (for example
ChatGPT, Claude, Microsoft Copilot, Gemini, or AI features inside other
software) for company work, on company or personal devices.
3. APPROVED TOOLS
Only these tools may be used with company information:
- [e.g. Microsoft 365 Copilot, company tenant]
- [e.g. ChatGPT Business / Claude Team, company workspace]
Personal or free AI accounts may be used only with PUBLIC information.
New tools need approval from [IT / AI owner] before use.
4. INFORMATION RULES
GREEN (any approved tool): public information, published marketing,
your own drafts with no personal or confidential data.
AMBER (company workspace only): internal documents, financials,
non-sensitive employee or customer data needed for the task.
RED (never, unless a use case is approved in writing):
IC / passport numbers, bank details, health data, biometric data,
client-confidential documents, passwords and API keys,
unannounced results or price-sensitive information.
5. PERSONAL DATA (PDPA)
Processing personal data with AI must comply with the Personal Data Protection
Act 2010 as amended in 2024. Report any suspected data leak to [DPO / IT]
immediately so the company can meet its breach-notification duties.
6. HUMAN RESPONSIBILITY
AI output is a draft. The person who uses it is accountable for its accuracy.
Anything sent to a client, regulator, the public or the board must be checked
by a person. Do not present AI output as professional advice without review.
7. AUTOMATIONS AND AGENTS
Any AI agent or automation that runs without a person in the loop, or that
sends emails, updates records or moves money, must be registered with
[AI owner], have a named business owner, and be reviewed before go-live.
8. TRANSPARENCY
Tell customers when they are talking to an AI assistant. Label AI-generated
images and video used externally.
9. TRAINING
Staff must complete [AI basics training] before using AMBER information.
10. BREACHES
Breaches of this policy are handled under [disciplinary policy]. Honest
mistakes reported quickly will be treated as learning, not misconduct.
Questions: [contact]
Why each clause is there
Approved tools (clause 3). The biggest risk is not AI itself but staff pasting company data into personal accounts, where the company has no contract, no admin control and, on some consumer plans, no say over whether data is used for training. Business plans from OpenAI, Anthropic and Microsoft do not train on your content by default. Naming the approved tools is what moves people across.
Green, amber, red (clause 4). A traffic-light rule is easier to remember than a list of data categories. Tune the red list to your business: a clinic adds patient records, a law firm adds anything under privilege.
PDPA (clause 5). The Personal Data Protection (Amendment) Act 2024 came fully into force during 2025. Maximum fines rose to RM1 million, biometric data became sensitive data, and breach notification became mandatory: to the Commissioner within 72 hours where significant harm is likely, and to affected individuals after that. Companies holding data on more than 20,000 people must appoint a Data Protection Officer. Your AI policy must plug into that process. Our PDPA and AI compliance guide goes deeper.
Human responsibility (clause 6). This mirrors the accountability principle in Malaysia’s National Guidelines on AI Governance and Ethics (AIGE), published by MOSTI in 2024. The guidelines are voluntary, but they are what regulators and large customers point to.
Automations and agents (clause 7). This clause matters more every month. An AI assistant that drafts is low risk. An agent that sends emails or updates your accounting system on its own needs an owner and a review. Most companies we train discover several unregistered automations in the first week.
What is coming: the AI Governance Bill
Malaysia’s draft AI Governance Bill, led by the Ministry of Digital and the National AI Office, went to public consultation in July 2026. It proposes three risk tiers, with prohibited uses, high-risk systems needing assessments and human oversight, and lighter rules for everything else. In September 2026 the Digital Minister said the draft was complete and could be tabled in Q4 2026 or Q1 2027. A policy that already registers automations and keeps humans accountable will need little change. See our AI Governance Bill explainer.
Rolling the policy out in two weeks
- 1Fill in the bracketsName the approved tools, the AI owner and the DPO contact. Remove clauses that do not apply.
- 2Get one senior sign-offThe policy carries weight only if a director owns it.
- 3Run a 30-minute briefingWalk through the traffic lights with real examples from each department.
- 4Register existing automationsAsk every team to list AI tools and automations already in use. Expect surprises.
- 5Train before you open AMBER dataStaff who understand the tools make fewer mistakes than staff who only read the rules.
Every AITraining2U course ends with a governance module: approved tools, data rules and an agent register your team can adopt.
Next public class: 8–9 October 2026 at Worq KL Gateway · seats available
For a board-level view of AI risk and governance, see our AI governance guide for Malaysian enterprises and the AI Board and C-suite workshop.
HRD Corp claimable. AITraining2U is an HRD Corp registered training provider. Our public and in-house courses are claimable under the HRD Corp Claimable Courses (SBL-KHAS) scheme, and we prepare the grant paperwork with you. See HRDC-claimable AI training: courses, costs and how to claim.