Governance & Audit
Writing an Acceptable Use Policy for Staff
· 10 minute read
Staff will use a language model this quarter whether you write a policy or not. An acceptable-use note that names approved tools, forbidden pastes and who may send is cheaper than a circular written after the leak.
A personal assistant in a secretariat pasted Tuesday's draft cabinet note into a public chatbot on a personal phone because the official machine blocked the site and the minister wanted plainer English by 6 p.m. The chatbot was free. The note was not. By Wednesday a paraphrase of a still-unapproved paragraph was circulating in a group the PA did not control. The department had an IT security policy from 2019 that mentioned USB drives and Facebook. It did not mention models. The inquiry therefore had to invent the offence after the fact.
This is a paste-ready way to write an acceptable use policy for staff who will touch official AI — and for staff who will try unofficial AI when the official path is slow. It is written for CIOs, chief secretaries' offices, PSU CHROs and registrars. The product is a short office order plus an annexure, not a 40-page ethics code nobody reads.
It is not legal advice. Conduct rules, official-secrets provisions where they apply, DPDP duties as they commence, CERT-In directions and your existing IT acceptable-use circular still sit underneath. This note only stops you from being silent while the paste happens.
What the AUP is for — and what it is not
The AUP is a staff-facing control. It tells a human what they may type, where they may type it, and what they must never paste. It is not the vendor contract, not the DPDP notice to citizens, not the model card, and not the SoD matrix. Those documents have other owners. If you try to make the AUP do all four jobs, staff will not read it and counsel will not defend it.
It is also not a ban on thinking. Officers will use language models the way they once used a well-read under-secretary: to shorten, to list, to compare. The policy should assume use and then fence the dangerous use. A total ban that you cannot enforce is how you get shadow AI with no logs.
Write it as an office order the head of department can sign in two pages, with a one-page annexure of approved tools. Anything longer belongs in a manual that the AUP points to.
The clauses that must exist
Name the approved systems. Brand names and URLs, on-prem or otherwise, and the official login path. If a tool is not on the list, it is unofficial even if a joint secretary likes it. Provide a route to add a tool — a ticket to IT and the DPO — so the list does not become a reason to sneak.
Name the forbidden pastes. Not 'sensitive data' as a vibe. Classes: unpublished noting, cabinet or board papers, passwords and keys, Aadhaar and other identifiers, caste and income certificates, medical and disability records, question papers and answer keys, citizen attachments, vendor commercials still under evaluation, and any file stamped secret or confidential under your existing classification. If a class is missing, staff will invent a justification.
Name the send rule. Drafting in an approved official agent is not the same as sending a citizen SMS, publishing a notice, or filing a noting. The AUP should say who may click send, and that an unofficial tool may never be used to originate an official communication.
| Staff action | Approved official agent | Public / unofficial chatbot |
|---|---|---|
| Rewrite a published circular in plainer language | Allowed, cite the circular number | Discouraged; if done, no unpublished file may travel with it |
| Draft a noting from a live citizen file | Allowed only on the official agent; no copy off the estate | Forbidden |
| Paste Aadhaar, caste, income, medical, marks | Forbidden unless the official workflow is built for that class | Forbidden |
| Question paper, answer key, moderation sheet | Forbidden on any network that is not the exam-cell isolation | Forbidden |
| Send / publish / sanction / pay | Officer only, on the system of record | Forbidden |
Devices, accounts, and the training lie
Personal phones are how unofficial paste happens. The AUP should say official files stay on official accounts and official devices, and that photographing a file to feed a personal chatbot is the same offence as mailing it to a personal inbox. If you cannot issue enough official devices, say so in the residual-risk note rather than pretending the sentence will hold.
Accounts are not family property. A login issued for the official agent is not to be shared with the outsourced data-entry bench, the intern, or the SI sitting in the corridor. Shared logins destroy the audit trail the rest of your governance needs.
Vendors will say prompts are not used for training. That sentence, even when true of the official agent, is often false of the unofficial tool the PA just opened. The AUP should state that staff must assume an unofficial public chatbot may retain, review or train, and that this assumption is why the paste is forbidden. Do not make staff parse a vendor blog.
- Approved tools listed by name, URL or on-prem path, and owning officer.
- A request path to add a tool, with DPO and CISO sign-off.
- A sentence on personal devices and photographed files.
- A sentence that unofficial tools are never the official record.
- A pointer to the incident path if a paste has already happened.
How to issue it so it sticks
Issue it as an office order, not as an intranet blog. Get the head of department or registrar to sign. Put it in joining kits. Put a one-screen reminder at first login of the official agent. Repeat it when a leak happens in another department — those weeks are when people actually read.
Train with examples from your own file types, not with a Silicon Valley deepfake video. A 20-minute walkthrough that shows a caste certificate, a draft noting, and a published gazette, and says which of the three may be pasted where, will outperform a two-hour ethics webinar.
Enforce proportionately. The first honest self-report of a mistaken paste should produce containment and coaching. A second paste after training, or a paste of a classified or exam artefact, is a conduct matter. If every breach is a hanging, you will get silence and more paste.
What law and guidance the AUP sits on
DPDP, once operational duties apply from 13 May 2027 for most remaining obligations, will care that the department as Data Fiduciary did not let staff become an unofficial processor pipeline to a foreign host. You do not need to wait until 2027 to forbid the paste. Purpose and security are not new ideas. The IT Act and your existing service rules already give you a hook.
CERT-In's 180-day log direction does not write your AUP. It does mean that if you run an official agent, you should be able to show who used it. An AUP without logs is a sermon.
The India AI Governance Guidelines of 5 November 2025 can be cited in the preamble as the reason leadership wants responsible use. Do not cite them as if they were a Gazette that created a new offence. They are guidelines.
Objections you will hear — and what to do with them
These are the lines that stall the file. Answer them in the room, then put the answer in the note. A spoken answer without paper will be forgotten by the next officer.
If we write this, we are admitting staff use unofficial tools.
They do. The file already knows. An AUP that names the behaviour is how you regain the official path. Silence is not deniability. It is an empty inquiry.
Legal will take six months to vet a policy.
Give legal a two-page order and a table, not a treatise. Ask for a one-week mark-up on forbidden classes and send rights. Do not wait for a perfect ethics code.
We already have an IT acceptable-use policy.
Read it. If it does not name models, unofficial chatbots, photographed files and send rights, it does not cover this. Issue an addendum. Do not pretend 2019 USB language is enough.
Banning unofficial tools will make us look anti-innovation.
Provide an official tool that can draft from published circulars on the LAN. Ban the unofficial paste of live files. That pairing is pro-control, not anti-innovation.
A two-week AUP you can circulate
Do not start with a committee of twelve. Start with the CIO, DPO, CISO and one administration officer. Expand the circulation after the draft exists.
- Days 1–3: pull the existing IT AUP, conduct rules and classification circular. List file classes your office actually handles.
- Days 4–6: write the two-page order and the approved-tool annexure. Include the request path to add a tool.
- Days 7–9: legal and administration mark-up. Keep the length. Fight every extra page.
- Days 10–12: head of department signs. Publish on the intranet. Put a login banner on the official agent.
- Days 13–14: 20-minute section-wise walkthrough with three real file types. Open a mailbox for honest self-reports.
How this shows up in the file
The file holds the signed order, the annexure of tools, the residual-risk note on personal devices, and the date of the first training. If those four are missing, you have a draft, not a policy.
Review the annexure when a tool is added or withdrawn. An AUP that still names a decommissioned chatbot is how staff justify the next unofficial site.
This article is informational field guidance for Indian public institutions, not legal, procurement, security-accreditation, academic-regulation or engineering advice. Confirm against the current Gazette, DPDP text and Rules, CERT-In direction, India AI Governance Guidelines, UGC/AICTE/NAAC notices, NEP documents, GFR, departmental manual and your counsel before you file it. Guidelines are not statute. Circulars move.
Questions this usually raises
- Can we ban all unofficial AI tools?
- You can forbid unofficial processing of official files and unpublished drafts. A total ban on staff using public tools for personal learning is harder to police and not the main risk. Fence the paste. Provide an official path.
- Does DPDP require an AI AUP?
- The Act does not use that phrase. A fiduciary still needs organisational measures so staff do not become an unofficial disclosure path. An AUP is one such measure. Most operational DPDP duties apply from 13 May 2027; do not wait for that date to stop the paste.
- Should the AUP allow use of public chatbots on published gazettes?
- You may permit it as a discouraged convenience if no unpublished material travels with the paste. Many offices still prefer the official agent so the habit stays in one place. Write the choice. Do not leave it implied.
- Who investigates a breach of the AUP?
- Use your existing conduct and incident path. CISO contains. Administration or vigilance inquires if the class of file requires it. The DPO assesses personal-data impact. Do not create a parallel AI court.
- How often should we revise the approved-tool list?
- Whenever a tool is added, withdrawn, or changes its hosting and training posture. At minimum, review with the quarterly governance agenda. A stale list is an invitation to shadow AI.
Sources
- Prcept AI — platform and sovereignty
- Digital Personal Data Protection Act, 2023 (India Code)
- CERT-In Directions under Section 70B, 28 April 2022 (PDF)
- India AI Governance Guidelines (PIB document, November 2025)
- Department of Administrative Reforms — Central Secretariat Manual of Office Procedure
- Central Vigilance Commission
- Ministry of Electronics and Information Technology