AACE International is committed to maintaining a safe and secure environment for all employees and organizations we partner with through the responsible use of Artificial Intelligence (AI) technology.
To achieve this, we have implemented an Acceptable Use of AI Tools Policy outlining the principles and guidelines that AACE International staff must adhere to when using AI capabilities. The policy aims to ensure that all AACE International employees use AI systems that align with the organization's values, policies, and standards. It applies to everyone at AACE International who uses AI systems to perform their work.
The policy provides guidelines for the appropriate use of AI tools in the workplace, particularly when handling the organization's and its customers' and partners' personal, sensitive, and confidential information. It outlines the dos and don'ts of using AI tools, given their increasing prevalence in day-to-day work.
The policy aims to ensure that all AACE International employees use AI tools safely and securely. The policy requires employees to follow security best practices, such as evaluating security risks and safeguarding confidential data when using AI tools.
This policy brief and purpose, scope, definitions, and security best practices are detailed below:
Purpose
Our Acceptable Use of AI Tools policy applies to the appropriate and secure use by any employee of AACE International of any third-party or publicly available AI Tools, especially with personal data, sensitive data and proprietary organization information.
As equity, bias, discrimination and trust issues arise with AI tools we use, we also will rely on this policy to guide our use of appropriate AI in our workplace.
Scope of the Policy
The use of AI tools has revolutionized the way we work. These tools have the potential to automate tasks, improve decision-making, and provide valuable insights into our operations. However, their use also poses new information security and data protection challenges. To mitigate these risks, this policy guides employees on using AI tools safely and securely, especially when sharing potentially sensitive organization information including any personal information, sensitive data and proprietary organization information (copyright and trade secret protected materials).
Definitions
Generative AI is AI that can learn from and mimic large amounts of data to create new content based on inputs or prompts, such as text, images, music, audio, and videos. Generative AI is powered by foundation models (large AI models) that can multi-task and perform out-of-the-box tasks, such as summarization, Q&A, classification, and more.
Large Language Model (LLM) is a type of language model notable for its ability to achieve general-purpose language understanding and generation. LLMs acquire these abilities by using massive amounts of data to learn billions of parameters during training and consuming large computational resources during their training and operation. LLMs are artificial neural networks pre-trained using self-supervised and semi-supervised learning.
Machine Learning is a branch of artificial intelligence that enables computers to learn from data and perform tasks normally requiring human intelligence. Machine learning algorithms use statistical methods to find patterns in data and make predictions or decisions based on inputs or prompts. Machine learning primarily focuses on making decisions based on historical inputs instead of generating new responses.
Security Best Practices
- All employees must follow these security best practices when using AI tools:
- Use of reputable AI tools: Employees shall only use AI tools that have been approved by the IT department or its designee. AI tools used by employees must meet our security and data protection standards.
- Approved AI Tools:
- ChatGPT Enterprise/Business
- Microsoft Copilot for Microsoft 365
- Microsoft Copilot Chat
- Betty / Dot AI (internal)
- Other AI applications approved by IT
- Consumer AI services may not be used with AACE confidential information unless specifically approved by IT.
- Use of Enterprise AI Services: Whenever available, AACE employees should use Enterprise or Business versions of AI services rather than free consumer accounts because they provide stronger privacy, security, and administrative controls.
- Evaluation of AI tools: The evaluation of new AI tools is the responsibility of the IT department. This includes reviewing the tool's security features, terms of service, and privacy policy.
- Protection of confidential data: Employees must not upload or share any personal, proprietary, or protected data without prior approval from the appropriate department, which includes the IT department or its designee. This includes data related to employees, customers, or partners.
The following table provides guidance:
Data Type Allowed in Approved AI?
Public website content Yes
Marketing copy Yes
Meeting agendas Yes
Internal procedures With approval
Member Personally Identifiable Information (PII) No
Publicly released Recommended Practices With approval
Employee HR records No
Financial information No
Passwords/API Keys Never
Copyrighted unpublished AACE material Only AI platforms approved by AACE International (see below for more details)
-
- If the content has not been publicly released and is protected by AACE's copyright, employees should only use an AI platform that has been approved by AACE's IT department and provides enterprise-grade security and privacy protections. It should never be entered into a public or personal AI account.
- Protection of AACE Intellectual Property: Employees must not upload unpublished AACE International publications, draft Recommended Practices (RPs), the TCM Framework, board materials, committee documents, source code, or other copyrighted or proprietary materials into unapproved AI tools. Such content may only be used with AI platforms approved by AACE International's IT department and Executive Director.
- Access control: Employees must not give access to AI tools outside the organization without prior approval from the appropriate department or manager and subsequent processes as required to meet security compliance requirements. This includes sharing login credentials or other sensitive information with third parties.
- Review AI-Generated Output: Employees must review output for accuracy and relevance before using the results of generative AI. That includes generated natural language and code.
- Evaluate discrimination, equity, bias, and trust concerns: As discrimination, equity, bias, and trust issues arise with AI tools, it is the responsibility of staff to bring these issues to their supervisor. Further, it is the responsibility of the IT department to evaluate and make recommendations to the organization on using or refusing to use the AI tool, as appropriate with the policies of AACE International regarding discrimination, bias, equity, and inclusion.
- Secure Use of AI for Software Development
- Employees using AI tools to generate, modify, or review software code must adhere to the following requirements:
- AI-generated code must be reviewed, tested, and validated by the employee before it is implemented or deployed.
- Employees must not submit passwords, API keys, encryption keys, authentication tokens, certificates, connection strings, or other sensitive credentials into AI tools.
- AI-generated code must comply with applicable AACE International security standards, coding practices, licensing requirements, and applicable legal obligations.
- Employees are responsible for ensuring AI-generated code does not introduce security vulnerabilities, malicious functionality, copyright infringement, or licensing conflicts.
- AI-generated code must be tested in an appropriate development or testing environment before being deployed to production systems.
- AI may assist with software development, but employees remain fully responsible for the quality, security, functionality, and maintenance of any code they implement.
Acceptable Use of AI Technology
- Employees should exercise sound judgment and apply the same standards of professionalism, confidentiality, and ethical conduct when using AI as they would when performing work without AI assistance.
- The use of generative AI tools should be limited to business-related purposes and aligned with AACE International's standards.
- All assets created using generative AI systems must be professional and respectful. Employees should avoid using offensive or abusive language and engaging in any behavior that could be considered discriminatory, harassing, or biased when applying generative techniques.
- Staff should not share any personal, confidential or sensitive information with AI technology, including but not limited to passwords, certificates, personally identifiable information (PII), secrets, and tokens.
- Multi-factor authentication should be in place across all third-party tools and technologies used for generative AI services.
- Generative AI systems must comply with all applicable laws and regulations, including data protection and privacy laws.
- AACE International reserves the right to review and monitor all communications shared with generative AI systems, including but not limited to messages, prompts, attachments, and files. AI usage may be monitored through enterprise administrative tools, logging, or audits, where available.
- Employees and other authorized users may not use AI meeting assistants, automated transcription services, or AI notetaking tools during AACE International meetings except as permitted by the Acceptable Use Policy for AI Notetaking Tools During AACE International Meetings.
In using AI technology,
- Employees must not use AI technology to:
- Upload or disclose confidential, proprietary, or personally identifiable information (PII) into unapproved AI systems.
- Upload unpublished AACE International intellectual property into unapproved AI systems.
- Share passwords, API keys, access tokens, encryption keys, or other security credentials.
- Circumvent AACE International security controls or policies.
- Generate or distribute fraudulent, misleading, defamatory, or intentionally deceptive content.
- Create content that is discriminatory, harassing, offensive, or otherwise violates AACE International policies.
- Violate copyright, licensing agreements, or applicable laws and regulations.
- Make employment, certification, or other organizational decisions solely based on AI-generated recommendations without appropriate human review.
- Use AI for personal business or other non-business purposes that violate AACE International's Acceptable Use Policy.
Policy Compliance
Employees are expected to comply with this Acceptable Use of AI Policy and all related AACE International information security and data protection policies.
Failure to comply with this policy may result in disciplinary action, up to and including termination of employment, as well as the revocation of access to AACE International systems and AI technologies, consistent with applicable policies and procedures.
Suspected violations of this policy should be reported promptly to an employee's supervisor or the IT department.
Training and Education
AACE International provides a collaborative learning environment. Employees will keep updated with the ongoing AI use and adoption changes. Staff should check with their supervisors for available training resources.
Updates and Review
This Acceptable Use of AI Tools Policy will be updated periodically to reflect the dynamic and changing nature of the use of AI tools in our sector. Changes to this policy will be informed by the potential risks and biases that these tools can interject into our work and by changing cybersecurity recommendations.
|
Version
|
Date
|
Approved By
|
|
1.0
|
July 23, 2026
|
Mike Kobylka (Executive Director/CEO)
|