Working Model

Working Model / Notes

AI acceptable use policy template for Tennessee companies (full text, quick start, rollout plan)

An AI acceptable use policy tells employees which AI tools they may use, what data they may put into them, who checks the output, and when to disclose AI help. Below is a complete AI acceptable use policy template a Tennessee company can adopt this month, reflecting the Tennessee Information Protection Act, the ELVIS Act, HIPAA, and the NIST AI framework, plus a one-page version and a rollout plan.

This is an operator's template, not legal advice. Have a Tennessee attorney review the final policy before you publish it.

Your people are already using AI, with or without a policy. Metro Nashville adopted a four-page policy on April 15, 2024 and expanded it to ten sections by July 3, 2026 (revision history; Nashville Scene). A generic AI policy template or generative AI policy for employees pulled from a vendor site will not mention the Tennessee laws that apply to you.

What Tennessee laws should an AI policy reflect?

Five, plus one national framework.

Law or framework Who it reaches What your AI use policy should say Source
Tennessee Information Protection Act (effective July 1, 2025) Tennessee businesses with over $25 million in revenue that process personal information of 175,000 or more Tennessee consumers a year (or 25,000 or more with over half of revenue from selling it). Exempt: HIPAA entities, GLBA banks, nonprofits, employment data. Consumers may opt out of profiling used "in furtherance of decisions producing legal or similarly significant effects." Document a data protection assessment before such profiling or before processing sensitive data. A NIST Privacy Framework program is an affirmative defense. Attorney General enforcement, 60-day cure, up to $7,500 per violation. TN Attorney General; Davis Wright Tremaine
ELVIS Act (signed March 21, 2024; effective July 1, 2024) Anyone using a person's name, photograph, voice, or likeness commercially without consent, including AI simulations "readily identifiable" as that person No AI-generated voice or likeness of any real person without written consent, your own CEO included. Class A misdemeanor plus civil liability. Gov. Lee; Proskauer
HIPAA Covered entities and business associates No protected health information in any AI tool without a signed business associate agreement. HHS: using a cloud vendor for ePHI without a BAA "is in violation of the HIPAA Rules," even if encrypted. HHS on business associates; HHS on cloud
SB 1580 (signed April 1, 2026; effective July 1, 2026) Anyone who develops or deploys an AI system Never represent a chatbot as a qualified mental health professional. A Consumer Protection Act violation, up to $5,000 per violation, with a private right of action. Troutman
Metro Nashville policy ISM-20 (adopted April 15, 2024; revised July 3, 2026) Metro staff, contractors, and vendors; a reference model for everyone else Approved-tools list, risk assessment before use, no confidential data in tools not purpose-built for Metro, human review of all output, disclosure when AI materially shaped official work, no fully automated consequential decisions, opt out of model training, and a public registry of 24 tools as of July 1, 2026. Nashville.gov; Metro AI Use Registry
Tennessee AI Advisory Council action plan (November 2025) State agencies; a signal of where expectations are heading Endorses "the NIST AI RMF 1.0 and Generative AI Profile statewide as voluntary benchmarks," human-in-the-loop review of consequential decisions, a named official for AI risk, and impact assessments for high-impact systems. TN AI Advisory Council
NIST AI Risk Management Framework 1.0 (January 26, 2023; Generative AI Profile July 26, 2024) Voluntary national reference Organize the program around Govern, Map, Measure, and Manage; test systems against NIST's seven trustworthiness characteristics. NIST; NIST AI 100-1

Many 50 to 1,000-person Tennessee companies, especially B2B firms, sit below the TIPA thresholds, and TIPA exempts employment data; the template bans fully automated consequential decisions anyway, because Metro, the state council, and NIST all point the same way. If you touch patient data, the BAA question decides which tools you can use at all.

The AI acceptable use policy template

Copy the text below into your handbook. Bracketed fields are yours to fill. The boxes explain why each section exists and the mistake it prevents; delete them before publishing.

1. Purpose and scope

[Company] permits the use of artificial intelligence tools to do better work faster, within the limits set here. This policy applies to all employees, contractors, temporary staff, and vendors acting on [Company]'s behalf. It covers every AI tool, whether standalone, embedded in software we already use (Microsoft Copilot, Zoom AI Companion, CRM and EHR features), or connected through APIs and agents, on any device, whenever company data is involved.

Why: Scope is where policies leak. Prevents: Treating "AI" as ChatGPT only while the meeting bot goes ungoverned.

2. Definitions

AI system: software that generates content, predictions, recommendations, or decisions from data, including generative AI and machine learning. AI-assisted output: any text, image, audio, video, code, analysis, or decision produced with help from an AI system. Approved tool: one listed in the [Company] AI tool register with a data tier. Consequential decision: one with legal or similarly significant effects on a person, such as hiring, discipline, pay, credit, housing, or health care. Policy owner: [title], responsible for this policy and the register.

Why: Enforcement fails on vague terms. Prevents: Arguing after an incident whether a "summary" counts as output.

3. Approved tools and how a tool gets approved

Only approved tools may be used for company work. The register at [location] shows each tool, its owner, data tier, and approval date. To request a tool, submit [form] to the policy owner with the business use, data involved, and vendor terms. The policy owner, [IT lead], and [legal or compliance contact] decide within [10] business days using the criteria in section 9. Approval is limited to the stated use, account type, and data tier. AI features that appear inside existing software are new tools and need approval before use.

Why: Metro's 2026 revision added exactly this: an approved list and a risk assessment before any tool touches Metro credentials. Prevents: A blanket "use good judgment" nobody can audit.

4. Data classification and what may go where

Every user must know the class of information before entering, uploading, transcribing, or connecting it to an AI system.

Data class Examples Tier 1 (enterprise contract, no training on our data, SSO) Tier 2 (approved consumer accounts) Unapproved
Public Published marketing, public pricing Yes Yes Yes
Internal Meeting notes, drafts, process docs Yes No No
Confidential Contracts, customer lists, pricing strategy, source code, unreleased plans Only tools approved for Confidential No No
Regulated PHI, PII (SSNs, dates of birth, account numbers), cardholder data, employee records Only tools with a signed BAA or data processing agreement covering that data No No

Credentials, API keys, and passwords never go into any AI tool. When in doubt, treat data as Confidential.

Why: It keeps you out of an HHS enforcement letter. Prevents: A biller pasting a patient note into a personal chatbot to "clean it up."

5. Prohibited uses

Users may not use AI systems to: (a) make a consequential decision without meaningful human review; (b) create or alter a real person's voice, image, or likeness without that person's written consent; (c) represent an AI system as a licensed professional of any kind, including a mental health professional; (d) generate discriminatory, harassing, deceptive, or unlawful content; (e) circumvent security controls; (f) produce production code without review under [engineering standard]; (g) enter data above a tool's approved tier.

Why: Items (b) and (c) come straight from the ELVIS Act and SB 1580. Prevents: Marketing cloning the founder's voice for a radio spot.

6. Human review and accountability

You own what you send. Every AI-assisted output used in a deliverable, record, or decision must be reviewed by a person qualified to judge it before use. AI-generated facts, citations, calculations, translations, and code are presumed unverified until checked. For consequential decisions, a named person must be able to explain the decision without reference to the tool.

Why: Metro's rule is blunt: users "shall remain responsible for all prompts submitted, outputs used, and work products created with GenAI assistance." Prevents: "The AI said so."

7. Disclosure

Internally, routine drafting help needs no disclosure. Users tell their manager when AI materially shaped a deliverable, produced content used verbatim, generated images, audio, or video, or performed analysis that informs a decision. Externally, [Company] discloses AI use when a contract requires it, when AI-generated media appears in client-facing work, or when client data was processed by an AI vendor. AI-generated media is labeled. Chatbots and voice agents identify themselves as automated.

Why: Clients are asking; a stated rule beats an improvised one. Prevents: A client learning about AI-generated analysis from someone other than you.

8. Intellectual property and licensing

Users may not enter third-party content into an AI system beyond what its license permits. AI-assisted work product created for [Company] belongs to [Company] to the extent the law allows. Before publishing AI-generated text, images, or code, users check for verbatim reproduction of identifiable sources and honor any license attached to generated code. Trade secrets are Confidential data; entering them into an unapproved tool may forfeit legal protection.

Why: Trade secret status depends on reasonable confidentiality measures. Prevents: Losing a claim to your own pricing model because it was pasted into a free tool.

9. Vendor and procurement requirements

Before approval, every AI vendor must provide: (a) a contractual commitment not to train on [Company] data, or a documented opt-out enforced at the account level; (b) written data processing terms covering retention, deletion, and sub-processors; (c) a signed BAA before any PHI is processed; (d) SSO or MFA; (e) a current security attestation (SOC 2 Type II or equivalent); (f) export and deletion of our data on exit; (g) disclosure of embedded AI features. Existing vendors adding AI features are reviewed the same way.

Why: Most exposure enters through a contract nobody read. Prevents: A "free upgrade" in your scheduling software that ships call recordings to a third-party model.

10. Security and account settings

Company work happens in company accounts through SSO and MFA; personal accounts are prohibited for company data. Where a tool offers it, users turn off chat history, model training, and data sharing, and set retention to [30] days. Integrations, plugins, browser extensions, and agents get least-privilege access, are logged, and never get broad access to email, files, code, or databases without approval for that use and tier. Meeting recording and transcription tools follow [Company] consent rules.

Why: Settings are policy in practice. Prevents: Two years of Confidential prompts in a departed employee's personal account.

11. Incident reporting

Report within 24 hours to [contact] if: Confidential or Regulated data went into an unapproved tool or above its tier; an AI-assisted output containing an error or harmful content reached a client, patient, or the public; an AI-generated voice or likeness was used without consent; or a vendor reports a breach. Good-faith reports will not be punished. [Company] assesses notification duties under HIPAA, Tennessee breach law, and contracts.

Why: Tennessee's breach statute allows 45 days from discovery to notify, per Baker Donelson, so silence is the expensive option. Prevents: People hiding a paste out of fear.

12. Training

All users complete AI use training within [30] days of hire and annually; [HR or policy owner] tracks completion. Users who handle Regulated data, approve tools, or make consequential decisions complete role-specific training.

Why: An untaught policy is a liability document, not a control. Prevents: Signing the acknowledgment without understanding the tiers.

13. Enforcement

Violations are handled under [Company]'s disciplinary policy, up to and including termination; contractor and vendor violations under contract terms, up to and including termination. Knowingly entering Regulated data into an unapproved tool or creating unauthorized voice or likeness content is serious misconduct.

Why: Consequences make the rest real. Prevents: Uneven treatment across departments.

14. Review cadence

The policy owner reviews the tool register quarterly and this policy annually, and sooner when a new law takes effect, a new category of tool appears, or an incident occurs. Changes are approved by [leadership body] and communicated to all users.

Why: Tennessee has passed AI-related law in 2024, 2025, and 2026, so an AI usage policy ages fast. Prevents: A 2024 policy still in force in 2027.

15. Acknowledgment

I have read and understand the [Company] AI Acceptable Use Policy dated [date]. I agree to follow it and to report incidents as described.

Name: ______________________ Signature: ______________________ Date: __________

The one-page quick start: ten rules if you need something by Friday

Post these, have everyone sign, and adopt the full policy within 90 days.

  1. Use only tools on the approved list, in company accounts, through SSO.
  2. Nothing Confidential or Regulated goes into a tool not approved for that data. No PHI without a signed BAA.
  3. Never enter passwords, keys, or credentials.
  4. Turn off training and chat history wherever the tool allows.
  5. You own what you send. Check every fact, number, citation, and line of code before it goes out.
  6. No AI decisions about people (hiring, pay, discipline, credit, care) without a named human who can explain them.
  7. No AI voices, faces, or likenesses of real people without their written consent.
  8. Chatbots say they are chatbots. No AI system is ever presented as a licensed professional.
  9. Tell your manager when AI materially shaped a deliverable; label AI-generated media for clients.
  10. Report a slip within 24 hours to [contact]. Good-faith reports are never punished.

How to roll out an AI use policy in an EOS-style leadership team

Week 1, the Level 10 meeting. Five minutes, not fifty. Make the policy a 90-day Rock owned by one person, usually the Integrator or ops leader. Add "AI policy acknowledgment %" to the scorecard with a 100% target.

Week 2, a 60-minute working session. The Rock owner brings the template and the team makes five decisions: which tools are Tier 1 and Tier 2 today; who the policy owner is; the client disclosure rule; the retention setting; and how strict enforcement will be. Send the draft to your attorney.

Week 4, ratify and publish. Approve at the L10, publish to the handbook, and open the tool register with what you already pay for. Expect to find tools nobody approved: the meeting bot, the CRM's writing assistant, a browser extension.

Weeks 5 to 8, train every department in 45 minutes. Five minutes on why (the HHS BAA rule and the Metro registry are real examples); ten minutes sorting examples from your own business into the four data classes; ten minutes on the register and how to request a tool; fifteen minutes hands-on, where each person does a real task in a Tier 1 tool and reviews the output against section 6; five minutes on disclosure and incident reporting, then sign. Our AI training program covers the policy in its first session and may be reimbursable through the Tennessee IWT grant.

Every quarter, 20 minutes at the quarterly. Review tool requests, incidents, vendor term changes, and new law. Two dates to watch: the AI Advisory Council's annual report each December 31, and the General Assembly session each winter and spring, which has produced AI legislation three years running.

Companies without a CTO often hand sections 3, 9, and 14 to a fractional Chief AI Officer; this post explains when that fits.

How Working Model can help

The template is free; request the editable .docx version at the form below. Our leadership team AI working session (half day on-site, from $6,500) ends with the five decisions made and the tool register started; the AI Fluency Program (four weeks, from $18,000, IWT-eligible up to $25,000) trains your teams on it. The free AI readiness scorecard takes ten minutes.

The short version

An AI acceptable use policy template is only useful if it names your tools, data classes, owner, and consequences, and reflects the laws that apply to you. Tennessee AI policy has changed every year since 2024, so an AI policy for companies here needs a review date as much as a signature. Make the five decisions, get an attorney's review, train everyone in 45 minutes, and review it each quarter. For what larger Nashville employers are doing, see what Nashville's AI rollouts mean for mid-market companies.

Frequently asked questions

Does the Tennessee Information Protection Act apply to my company?

Only if you do business in Tennessee, exceed $25 million in annual revenue, and process personal information of at least 175,000 Tennessee consumers a year (or 25,000 while earning over half your revenue from selling data). HIPAA entities, GLBA institutions, nonprofits, and employment data are exempt. Many mid-market firms, especially B2B, fall below the thresholds.

Can employees use ChatGPT or Copilot under this AI use policy?

Yes, if the account is on the approved list at the right data tier. An enterprise Copilot or ChatGPT seat with SSO, a no-training commitment, and retention controls can be Tier 1. A free personal account is Tier 2 at best, limited to public information. The policy governs the account and its contract, not the brand.

Do I need a business associate agreement to use AI with patient data?

Yes. HHS is explicit that a vendor that creates, receives, maintains, or transmits electronic PHI on your behalf is a business associate, and that using one without a BAA violates the HIPAA Rules, even when the data is encrypted. If a vendor will not sign, the tool is not approved for Regulated data.

What are good AI policy examples to compare against?

Metro Nashville's ISM-20 policy is the best local example: public, plain, and expanded in July 2026 after two years of use. The NIST AI Risk Management Framework and its Generative AI Profile are the national reference the Tennessee AI Advisory Council recommends. Both are linked above, and the template borrows their structure.