AI governance policy template, including who may approve licensing company data

This AI governance policy template covers approved tools, data classes, human review, vendor AI features and incidents, then adds the outbound section most policies lack: who may approve licensing company records to third parties for AI training, what de-identification is required first, and when the board must sign off. Adapt it with counsel before adopting it.

When a company needs this policy

A mid-market company needs a written AI policy as soon as employees use generative AI tools on company information, which in most offices is already happening. The policy usually gets drafted when something lands on the CFO's desk: a sponsor asking for an AI governance update, a customer security questionnaire about AI use, a software renewal that adds AI features to the vendor's terms, exit preparation, or an inquiry about licensing company data.

Most templates stop at inbound use, meaning what staff may put into AI tools. That leaves a gap. Nobody is named as the person who can approve sending company records out to train someone else's models, and that decision deserves the same discipline as any other use of a company asset.

The regulatory backdrop keeps moving. California's privacy agency lists regulations on risk assessments, cybersecurity audits and automated decisionmaking technology that took effect on January 1, 2026, with some compliance deadlines phased in from 2027 to 2028. Companies with EU customers or operations should also track the EU AI Act, whose application dates have been amended since adoption, so check the consolidated text. And FTC staff have stated that companies' promises not to use customer data for undisclosed purposes, such as training models, are enforceable wherever those promises are made (January 2024 staff post, not a rule).

This is general information, not legal, tax or financial advice. Confirm with your own counsel before adopting any policy.

Part A: the inbound policy

Replace each {placeholder} with your own details. Part A is a conventional acceptable use and governance section.

Part B: the outbound data clause

Part B governs the opposite direction: company records leaving the company for someone else's AI work. It does not decide whether to license; it decides who may say yes and on what evidence.

B9 matters more than it looks. Advisers, board members and sponsor representatives can be referral partners, and a written disclosure keeps the approval clean.

How to tailor the template

PlaceholderWho usually fills itNotes
{ai_policy_owner}CFO, COO or general counselOne accountable executive, not a committee
{approver_one}, {approver_two}CEO and CFOTwo signatures stop one person approving their own project
{board_trigger}Board or sponsorExclusive terms, multi-entity datasets and personal data are sensible triggers
{legal_reviewer}General counsel or outside counselMust read customer contracts, not only the privacy notice
{deidentification_standard}Counsel and privacy leadSet per dataset; stricter where health or financial customer information is involved
{approved_tools_register}IT or security leadA living list showing the data class each tool is cleared for
{retention_period}Finance and legalAt least the license term plus your normal contract retention

Three company types need extra lines:

  • PE-backed portfolio companies. Name the sponsor's representative as a consulted party and align {board_trigger} with the reserved matters in the shareholder agreement.
  • Buy-and-build platforms. Apply Part B to every subsidiary and record which entity owns each dataset; integration archives such as M&A integration records often span several entities.
  • Agencies, outsourcers and BPOs. State that client-owned records are outside Part B unless the client consents in writing.

Rollout timeline

WeekStepOwner
1Fill placeholders, list the AI tools already in use, map data classes{ai_policy_owner}
2Counsel review, including a sample of customer contracts for Part B{legal_reviewer}
3Adoption by the board or audit committeeBoard
4Staff training and written acknowledgementsHR and IT
Every {review_frequency}Review the tools register, incidents and any Part B approvals{ai_policy_owner}

What never to include in the policy

  • Named data buyers or prices; those belong in individual agreements.
  • A standing pre-approval for licensing records. Each license needs its own review under B2 and B3.
  • Customer-facing promises the company cannot keep, such as never sharing any data in any form, if it may later license de-identified records.
  • Examples copied from real customer records or tickets.
  • Referral reward amounts or the commercial terms of any partner arrangement.

How Part B connects to a licensing decision

When a company does explore a license, the data rights documentation guide lists the paperwork B3 depends on, and board approval for a data license covers the step B2 triggers. The page on exclusive licenses and a future sale explains why exclusivity is a sensible board trigger. Project-heavy firms should read customer implementation project records before scoping, and what an AI data buyer is describes who sits on the other side of the agreement.

Next step

Adopt the policy, then use it. If a company you advise has years of its own records and a sponsor ready to run Part B, check who qualifies and register as a partner to introduce it, or have the company apply at sourcex.si/apply.

  1. Step 1Share your linkSend your personal link to a company you know.
  2. Step 2Company appliesThe company applies itself at /apply.
  3. Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
  4. Step 4You get your rewardYour share of SourceX fees becomes payable.

Common questions

Is an AI acceptable use policy the same as an AI governance policy?

Not quite. An acceptable use policy tells employees what they may and may not do with AI tools. A governance policy also assigns ownership, sets rules for vendor contracts and incidents, and decides how the company handles outbound use of its records. This template includes acceptable use in Part A and adds the outbound clause in Part B.

Who should own the AI policy at a mid-market company?

One accountable executive, often the CFO, COO or general counsel, with IT, security and legal supporting. The board or audit committee should receive a periodic report. Naming a single owner avoids a committee that meets rarely and approves nothing, and makes it clear who signs off on new tools and who answers when something goes wrong.

Does the outbound clause stop a company from licensing its data?

No. It decides who may approve a license and what evidence they need, not whether licensing is allowed. A documented approval with a rights review and an agreed de-identification standard is easier to defend in diligence than an informal decision. Companies that never plan to license can keep Part B as a simple prohibition.

Should vendor contracts let vendors train on company data?

The template's default is no, unless approved under the outbound section. Vendor training rights are a form of outbound data use, and broad rights granted to one vendor could also complicate an exclusive license later. Review data-use and retention terms at each renewal, since vendors often update their terms when they add AI features.

How often should the AI policy be reviewed?

At least once a year, and also whenever the company adopts a major new AI tool, a relevant regulation takes effect, an incident occurs or a licensing decision is made. California's 2026 regulations on automated decisionmaking technology and risk assessments are an example of a change that should prompt a review for the companies they cover.

Free resources

By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09

Know a US company with valuable proprietary data?

Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.

Refer a company →

I own a business

Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.

Start an assessment