Skip to main content

General AI Policy

What is the General AI Policy?

Drata now includes a General AI Policy as part of our global policy template set. It gives you a ready-to-use starting point for governing AI use across your company — covering approved use, restricted data, human review, vendor diligence, and reporting — without requiring you to draft a policy from scratch or adopt a full AI governance framework right away.

This template is intentionally lightweight. It is not mapped to any framework or control by default, so it will not affect your existing compliance mappings or introduce new control requirements on its own.

📥 Get the template anytime. If you're an existing customer and want to use it, you can download it here! Upload the policy to your Policy Center like any other custom policy to start using it right away.


Prerequisites

  • A purchased framework is required to see it: The General AI Policy only appears in your Policy Center once your organization has at least one purchased framework (Drata-managed or custom). If no framework is purchased yet, the template is still provisioned in the background and will appear automatically once you purchase one.

  • Not mapped to a framework or control by default: The template ships with no framework or control associations (no chips).

  • Not automatically assigned for acknowledgment: Unlike some policies, the General AI Policy is not automatically pushed to all personnel for acknowledgment by default.


What can I do here?

Map it to a framework or control

Even though the General AI Policy isn't mapped to anything out of the box, you can map it to any framework or control your organization uses, the same way you would with any other policy.

Edit and customize the template

Use the General AI Policy as a starting point. Edit the content to reflect your organization's actual AI tools, approvals, and review process before publishing it to your team.

Assign it for acknowledgment (optional)

This template is not assigned to personnel by default. If you want employees to review and acknowledge it, assign it manually the same way you would any other unassigned policy.


Use cases / Best practices

Give your AI governance a head start

Rather than write an AI policy from scratch, use this template as a lightweight baseline covering approved use, restricted data, human review, vendor diligence, and reporting for AI tools used across your company.

Layer in a formal framework as you grow

This template is a starting point, not a full AI governance program. As your AI use cases and risk grow, map this policy to a relevant framework or control, or build out a more formal program such as ISO 42001 or AIUC-1.

Did this answer your question?