AI governance policy template, including who may approve licensing company data
This AI governance policy template covers approved tools, data classes, human review, vendor AI features and incidents, then adds the outbound section most policies lack: who may approve licensing company records to third parties for AI training, what de-identification is required first, and when the board must sign off. Adapt it with counsel before adopting it.
When a company needs this policy
A mid-market company needs a written AI policy as soon as employees use generative AI tools on company information, which in most offices is already happening. The policy usually gets drafted when something lands on the CFO's desk: a sponsor asking for an AI governance update, a customer security questionnaire about AI use, a software renewal that adds AI features to the vendor's terms, exit preparation, or an inquiry about licensing company data.
Most templates stop at inbound use, meaning what staff may put into AI tools. That leaves a gap. Nobody is named as the person who can approve sending company records out to train someone else's models, and that decision deserves the same discipline as any other use of a company asset.
The regulatory backdrop keeps moving. California's privacy agency lists regulations on risk assessments, cybersecurity audits and automated decisionmaking technology that took effect on January 1, 2026, with some compliance deadlines phased in from 2027 to 2028. Companies with EU customers or operations should also track the EU AI Act, whose application dates have been amended since adoption, so check the consolidated text. And FTC staff have stated that companies' promises not to use customer data for undisclosed purposes, such as training models, are enforceable wherever those promises are made (January 2024 staff post, not a rule).
This is general information, not legal, tax or financial advice. Confirm with your own counsel before adopting any policy.
Part A: the inbound policy
Replace each {placeholder} with your own details. Part A is a conventional acceptable use and governance section.
Part B: the outbound data clause
Part B governs the opposite direction: company records leaving the company for someone else's AI work. It does not decide whether to license; it decides who may say yes and on what evidence.
B9 matters more than it looks. Advisers, board members and sponsor representatives can be referral partners, and a written disclosure keeps the approval clean.
How to tailor the template
| Placeholder | Who usually fills it | Notes |
|---|---|---|
| {ai_policy_owner} | CFO, COO or general counsel | One accountable executive, not a committee |
| {approver_one}, {approver_two} | CEO and CFO | Two signatures stop one person approving their own project |
| {board_trigger} | Board or sponsor | Exclusive terms, multi-entity datasets and personal data are sensible triggers |
| {legal_reviewer} | General counsel or outside counsel | Must read customer contracts, not only the privacy notice |
| {deidentification_standard} | Counsel and privacy lead | Set per dataset; stricter where health or financial customer information is involved |
| {approved_tools_register} | IT or security lead | A living list showing the data class each tool is cleared for |
| {retention_period} | Finance and legal | At least the license term plus your normal contract retention |
Three company types need extra lines:
- PE-backed portfolio companies. Name the sponsor's representative as a consulted party and align {board_trigger} with the reserved matters in the shareholder agreement.
- Buy-and-build platforms. Apply Part B to every subsidiary and record which entity owns each dataset; integration archives such as M&A integration records often span several entities.
- Agencies, outsourcers and BPOs. State that client-owned records are outside Part B unless the client consents in writing.
Rollout timeline
| Week | Step | Owner |
|---|---|---|
| 1 | Fill placeholders, list the AI tools already in use, map data classes | {ai_policy_owner} |
| 2 | Counsel review, including a sample of customer contracts for Part B | {legal_reviewer} |
| 3 | Adoption by the board or audit committee | Board |
| 4 | Staff training and written acknowledgements | HR and IT |
| Every {review_frequency} | Review the tools register, incidents and any Part B approvals | {ai_policy_owner} |
What never to include in the policy
- Named data buyers or prices; those belong in individual agreements.
- A standing pre-approval for licensing records. Each license needs its own review under B2 and B3.
- Customer-facing promises the company cannot keep, such as never sharing any data in any form, if it may later license de-identified records.
- Examples copied from real customer records or tickets.
- Referral reward amounts or the commercial terms of any partner arrangement.
How Part B connects to a licensing decision
When a company does explore a license, the data rights documentation guide lists the paperwork B3 depends on, and board approval for a data license covers the step B2 triggers. The page on exclusive licenses and a future sale explains why exclusivity is a sensible board trigger. Project-heavy firms should read customer implementation project records before scoping, and what an AI data buyer is describes who sits on the other side of the agreement.
Next step
Adopt the policy, then use it. If a company you advise has years of its own records and a sponsor ready to run Part B, check who qualifies and register as a partner to introduce it, or have the company apply at sourcex.si/apply.
- Step 1Share your linkSend your personal link to a company you know.
- Step 2Company appliesThe company applies itself at /apply.
- Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
- Step 4You get your rewardYour share of SourceX fees becomes payable.
Common questions
Is an AI acceptable use policy the same as an AI governance policy?
Not quite. An acceptable use policy tells employees what they may and may not do with AI tools. A governance policy also assigns ownership, sets rules for vendor contracts and incidents, and decides how the company handles outbound use of its records. This template includes acceptable use in Part A and adds the outbound clause in Part B.
Who should own the AI policy at a mid-market company?
One accountable executive, often the CFO, COO or general counsel, with IT, security and legal supporting. The board or audit committee should receive a periodic report. Naming a single owner avoids a committee that meets rarely and approves nothing, and makes it clear who signs off on new tools and who answers when something goes wrong.
Does the outbound clause stop a company from licensing its data?
No. It decides who may approve a license and what evidence they need, not whether licensing is allowed. A documented approval with a rights review and an agreed de-identification standard is easier to defend in diligence than an informal decision. Companies that never plan to license can keep Part B as a simple prohibition.
Should vendor contracts let vendors train on company data?
The template's default is no, unless approved under the outbound section. Vendor training rights are a form of outbound data use, and broad rights granted to one vendor could also complicate an exclusive license later. Review data-use and retention terms at each renewal, since vendors often update their terms when they add AI features.
How often should the AI policy be reviewed?
At least once a year, and also whenever the company adopts a major new AI tool, a relevant regulation takes effect, an incident occurs or a licensing decision is made. California's 2026 regulations on automated decisionmaking technology and risk assessments are an example of a change that should prompt a review for the companies they cover.
Related pages
- M&A integration records: what serial acquirers hold and why AI buyers value them
- How to document data rights and provenance before licensing data for AI training
- Does a data license need board approval at a PE-backed company?
- Does an exclusive AI training license affect a future sale of the company?
- Customer implementation project records: what they are and why AI buyers value them
- What is an AI data buyer?
Free resources
- Time value of money calculator — Future and present value with optional regular payments.
- Business DSCR calculator — Debt service coverage from cash flow and loan terms.
- MCP ROI calculator — Estimate hours saved, implied savings and first-year ROI from MCP.
- All free tools · MCP resource center
By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09
Know a US company with valuable proprietary data?
Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.
Refer a company →I own a business
Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.
Start an assessment