
An AI Acceptable Use Policy, or AUP, is the document that tells employees which AI tools they can use, on which data, with what controls, and what happens when the rules are broken. A good SMB AUP is short, plain-English, tied to concrete examples, and revisited every month based on real-world usage. The AUP is the cornerstone artifact of an AI governance program — and it is the first deliverable the VCAIO produces inside a TaaS engagement.
How MSPs Ship an AI Acceptable Use Policy in Phase 1 of TaaS
For MSPs, the AUP is often the easiest first deliverable to ship in a new TaaS engagement — and the easiest one to ship badly. A bad AUP is long, written in legal English, and disconnected from the tools employees actually use. It gets signed during onboarding and then ignored.
A good SMB AUP includes seven sections.
-
Approved tools list. Named tools, with the categories: approved, conditional, blocked. Include the consumer alternatives explicitly — if Claude is approved but Claude.ai personal accounts are blocked, say so.
-
Allowed data classifications by tool. Map each approved tool to the data sensitivity tiers it can handle (Public, Internal, Confidential, Restricted, Regulated). Be specific.
-
Prohibited use cases. Not what’s allowed — what’s not. Examples: pasting client contracts into consumer chat, using AI to write performance reviews without disclosure, generating customer-facing content without human review.
-
Disclosure rules. When employees must say AI was involved — for example, in customer communications, legal filings, or vendor proposals.
-
Incident response. What to do when a sensitive document is exposed to a non-approved tool. Who to call. How fast.
-
Training requirement. What training is mandatory, on what cadence. Tied to the Copilot 101/102/201/202 curriculum or equivalent.
-
Review cadence. When the AUP gets revisited (every Council, fully rewritten annually).
What to leave out: vague principle statements (“we use AI responsibly”), references to laws the SMB doesn’t operate under, and clauses copied from someone else’s AUP without testing against the client’s actual workflows. The AUP should be three to five pages, not twenty.
The TaaS phasing is built around the AUP lifecycle. Phase 1 produces the first draft against the client’s stated policies and observed environment. Phase 3 revises it once Copilot Quick Wins have shipped and actual usage patterns have emerged. Every Monthly AI Council reviews the AUP against new tool categories, new shadow AI findings, and new employee questions.
What Makes an AI Acceptable Use Policy Real for SMB Employees
For SMB leadership, the test of whether you have a real AUP is whether your employees can summarize it from memory. If they cannot, the AUP is not operating — it is a compliance prop.
Three things make an AUP operative inside an SMB:
-
Specific tools, not categories. Naming ChatGPT, Claude, Copilot, Gemini, and Perplexity individually is more useful than “generative AI tools.” Employees know the products, not the categories.
-
Concrete examples. “Don’t paste a signed contract into ChatGPT” lands. “Don’t process Restricted-classification data with unapproved tools” doesn’t.
-
A visible owner. The AUP should name the VCAIO (or the equivalent role) as the responsible person. When employees have a question, they need a name to ask.
The AUP is the single most important governance artifact your AI practice produces. It is also the artifact most likely to drift, because the AI landscape moves faster than the policy review cycle. The discipline of revisiting the AUP every month in the AI Council is what keeps it real.
How Lemhi Standardizes AI Acceptable Use Policy Delivery for MSPs
Lemhi standardizes the AUP delivery so every TaaS client gets a current, environment-matched policy without the MSP rewriting from scratch.
-
AUP template library. Standardized templates the VCAIO tailors to the client’s tool inventory and data classifications. Phase 1 ships the first draft inside the engagement charter.
-
Phase 3 revision flow. Once Copilot Quick Wins ship and real-world usage data emerges, the platform surfaces the gaps for the VCAIO to address in the revised AUP.
-
Council integration. The Monthly AI Council includes a standing AUP review block. New tool categories, new shadow AI findings, and new employee questions all feed the next revision.
-
Sensitivity-label and conditional-access coordination. The Continuous Scanner detects misalignments between the AUP and the technical environment, surfacing them to the PSA queue for remediation.
-
Training tie-in. The AUP feeds the Copilot 101/102/201/202 curriculum, so what employees are taught matches what the policy requires.
The AUP works because the practice runs it. Lemhi sells the practice.




