Most organizations now have some form of internal guidance on how employees may use artificial intelligence tools – but many of those documents would not hold up in litigation, a regulatory examination or a vendor audit. This alert outlines the structural and substantive elements that separate an enforceable corporate AI use policy from one that is merely aspirational.

Why this matters: For business leaders, IT and cybersecurity teams, legal and compliance professionals, procurement personnel, HR leaders and anyone responsible for evaluating or deploying AI tools, an AI use policy is no longer just an internal governance document. It can directly affect data security, intellectual property protection, regulatory compliance, vendor management, and the organization’s ability to defend its decisions if disputes or audits arise. As AI becomes embedded in everyday business operations, organizations that fail to establish enforceable controls may face heightened legal, operational and reputational risks.

Vendor Contracts: The Provisions You Should Not Omit

Before any AI tool lands on your organization’s approved-tool list, the underlying vendor agreement needs to contain specific contractual protections that go well beyond standard SaaS terms. At a minimum, the agreement should include an express model training opt-out: a binding commitment that customer data – including prompts, inputs and outputs – will not be used to train, fine-tune or improve the vendor’s foundation models or any third-party models. For many organizations, this one provision is critical. Without it, your confidential information can end up embedded in a model that serves your competitors.

The agreement should also require sub-processor disclosure, advance written notice of any material change to the sub-processor chain, and a contractual right to object or terminate. Data retention and deletion terms should set maximum retention periods for all inputs and outputs. Security baselines should require, at a minimum, an SOC 2 Type II report current within 12 months, along with additional requirements such as ISO 27001 certification and defined penetration testing cadences, scaled to the sensitivity of the data the tool will process. Breach notification timelines, generally ranging from 24 to 72 hours, must line up with your organization’s own incident-response service-level commitments.

Vendor agreements should also be no less restrictive than the confidentiality obligations in your existing NDAs and data processing agreements. If a vendor contract permits broader use of data than your client-facing data processing agreement allows, you have opened a compliance gap that no internal policy can cure.

Incident Response: Integrate, Do Not Isolate

AI-specific incidents belong in your existing breach-notification workflow. These include:

  • prompt injection attacks,
  • unauthorized data exposure through unapproved tools,
  • vendor-side breaches affecting stored prompts, and
  • the discovery that a vendor has trained on your proprietary data in violation of its contractual commitments.

A separate, siloed AI governance process only invites coordination failures and delays regulatory notification.

The practical steps are straightforward:

  • Add AI-specific incident categories to your existing classification taxonomy.
  • Map each category to the notification obligations that apply, whether under state breach-notification statutes, contractual commitments to affected clients or sector-specific regulatory reporting rules.
  • Spell out AI-specific forensic preservation requirements, including prompt and output logs, model version identification and API call records.
  • Assign triage responsibility to your existing incident-response team, with a defined escalation path to an AI governance committee for policy-level remediation.

Data Classification and the Default-Deny Principle

Your AI use policy should open with a prohibition: No AI tool may be used unless it appears on the approved list, and no data may be processed by an AI tool unless the data’s classification tier allows it. This default-deny architecture is the structural backbone of an enforceable policy.

Map your existing data classification tiers (for example, Public, Internal, Confidential and Restricted) to specific AI tool permissions:

  • Public data may flow to open-access tools.
  • Internal data requires approved-list tools with data los- prevention controls.
  • Confidential data demands enterprise-grade contractual protections, including no-training guarantees.
  • Restricted data may face an absolute prohibition on AI processing absent documented legal and security review.

Enforce these boundaries with technical controls.

IP Ownership: The Copyright Gap

Following the D.C. Circuit’s ruling in Thaler v. Perlmutter and the Copyright Office’s 2025 Part 2 Report, businesses have to confront a binary reality: purely AI-generated output is not copyrightable, while AI-assisted output may be protectable if there is enough human authorship in the selection, arrangement or creative modification. Your policy should:

  • define these two categories distinctly,
  • require employees to document their human creative contributions as the work is done, and
  • prohibit copyright registration filings for AI-assisted works without legal department review.

Where copyright protection is not available, steer your protection strategy toward trade secret, which reinforces, rather than undermines, your confidentiality controls.

Human Review and the Reasonable-Care Defense

Documenting risk-tiered, human-in-the-loop requirements is how you build litigation defenses. For any decision that may be a “consequential decision” definition – such as employment actions, credit determinations and insurance underwriting, –the policy should require human review before the decision takes effect. Decision logs should capture the tool used, the input provided, the output received, the reviewer’s identity and any changes the reviewer made. These records are your evidence of reasonable care.

From Aspiration to Enforceability

The single most important structural changes most organizations can make are also the simplest:

  • replace precatory language with mandatory obligations,
  • tie those obligations to existing disciplinary frameworks,
  • require documented employee attestation, and
  • build AI-specific provisions into binding instruments, including employment agreements, contractor MSAs, vendor contracts and incident-response plans.

A policy that lives only as a stand-alone PDF on an intranet page is usually hard to enforce. A policy woven into the organization’s contractual, operational and compliance framework is far more likely to hold up.

Recommended Next Steps

We recommend that clients take the following actions:

  1. Audit existing AI use policies against the structural enforceability criteria described above.
  2. Review all AI vendor agreements for the minimum contractual provisions identified in this alert, prioritizing model training opt-out language.
  3. Integrate AI-specific incident types into existing breach-notification playbooks.
  4. Implement or validate technical default-deny controls aligned to data classification tiers.
  5. Establish documented training and attestation programs sufficient to support a reasonable-care defense under current and forthcoming state AI legislation

Our Data Privacy and Technology Transactions teams are available to assist with policy drafting, vendor agreement negotiation, incident-response integration and compliance readiness assessments. To discuss how these developments apply to your organization’s specific risk profile, please contact to Chiara Portner, or your regular Lathrop GPM attorney.