AI Acceptable Use Policy – Why is it important to have one?

What is an Acceptable Use Policy?

An Acceptable Use Policy (AUP) is a formal document, usually an annex or a part of a contract, that outlines the permissible and prohibited uses of AI within an organization. You can have one for using Large Language Models (LLMs) within your organization. AUPs have the advantage of setting clear guidelines and standards for the ethical, legal, and secure use of AI.

In general, AUPs ensure that all stakeholders understand their responsibilities and the boundaries within which they must operate, providing the clarity they need

What should an AI Acceptable Use Policy contain?

An AUP should be a comprehensive and adaptable set of clear guidelines that align with the specific needs of your organization. It can address both internal use by employees and external use by customers in particular cases.  The AUP should cover the following key elements, each essential to maintaining ethical, secure, and compliant AI practices within your organization.

Scope

Depending on the needs and specific circumstances, the AUP can be scoped to regulate employee and customer use of AI. It can also be tailored separately for each group’s use of AI. The AUP may need to explicitly include a list of technologies constituting AI on a case-by-case basis.

The AUP represents the backbone of the entire policy since it delineates the boundaries and responsibilities for using AI. It ensures that employees and customers understand their obligations and the limits of using AI within your organization.

Prohibited uses

The AUP must explicitly outline prohibited uses of AI to prevent misuse and fundamental rights risks. Prohibited activities might include generating explicit, fraudulent, abusive, or deceptive content. Also, using AI that promotes discrimination, fraud, hate, harassment, terrorism, or otherwise violates the law or industry-specific regulations.

For employees, this means refraining from using AI tools to manipulate data, bypass security protocols, or engage in unethical practices.

For users, restrictions on using AI services for illegal activities, infringing on intellectual property rights or deploying AI in ways that could harm other individuals or society.

By clearly defining these prohibitions, the AUP safeguards your organization from legal liabilities, ethical breaches, and reputational damage, ensuring responsible and lawful use of AI technologies. You can review Kevin Klyman’s partial taxonomy of violative uses from developers for guidance on this topic.

Acceptable uses

The acceptable uses of AI should be determined on a case-by-case basis. Acceptable uses should be clearly defined and promoted by your organization. Some common examples of acceptable use of AI might include automating data analysis in scientific research and optimizing supply chain logistics in manufacturing. Your employees might also widely use AI to generate content for emails, presentations, reports, and customer service communications, as well as to automate routine tasks.

For customers, acceptable AI use must be considered equally on a case-by-case basis and should closely align with the company’s specific products or services.

The acceptable uses will vary significantly depending on whether the company is developing AI or utilizing it to enhance its offerings or to deliver services.

Governance

Effective governance is crucial for the successful implementation and management of an Acceptable Use Policy (AUP). Companies may require robust AI Governance Frameworks to oversee the use of AI and ensure it complies with its AI AUPs and other Policies.

Establishing clear lines of accountability helps maintain oversight and ensures that AI is used responsibly and ethically across the organization. Additionally, governance should facilitate transparent communication and provide a mechanism for reporting and addressing potential violations of the AUP.

A tailor-made AI Governance Framework can help your organization achieve its strategic goals, ethical standards, and legal obligations. This, in turn, will build trust among your stakeholders.

Input considerations

Your organization should establish rules to determine the accuracy, integrity, and relevance of input data for AI model training. Your organization must also ensure the legality of the data you are processing, as copyright infringements are becoming more common in AI model training.

Mandate that employees vet and approve any input data according to established guidelines. This prevents the AI from processing biased, inaccurate, illegal, or harmful data, which could lead to flawed or unethical outputs.

For your customers, the AUP might clarify the importance of providing accurate and compliant data when interacting with AI systems, ensuring that their contributions do not compromise the integrity of the AI’s outputs. It might also highlight that no personal data should be included in the input of the AI Model.

Additionally, the policy should include provisions for regular reviews of data sources to maintain ongoing compliance and data integrity. By addressing input considerations thoroughly, the AUP helps ensure that AI systems function reliably and ethically, reducing the risk of unintended consequences.

Outputs considerations

In Europe and North America, AI-generated content is generally not eligible for copyright protection unless there is a significant degree of human involvement in its creation. Securing IP rights requires more than just using AI to generate content due to the high bar for copyrightability. Therefore, it is important to establish a clear Acceptable Use Policy (AUP) that addresses and attributes AI outputs.

Organizations should take specific measures to enhance the copyrightability of AI-generated content. These include incorporating IP elements like brand names and logos into AI-generated outputs. Actively involve human creativity and document the human role in the creation process. These steps protect the organization’s intellectual property and ensure compliance with legal standards in AI use.

Moreover, the AUP should address the prevention of bias, inaccuracies, and unreliability in AI-generated outputs. It should also establish procedures to ensure that outputs do not include illegal content or violate any prohibited uses outlined in the policy.

Data protection and privacy

The AUP might include rules for your employees, such as refraining from inputting personal or sensitive data into AI systems. Anonymize or pseudonymize data used in AI models to reduce privacy risks. Training should be provided to ensure employees understand and follow these guidelines, maintaining privacy standards in their tasks.

For users, the AUP might advise against submitting personal data to AI platforms without a clear understanding of how it will be used and secured. It might also promote transparency in how AI systems process user data. Allowing users to stay informed and exercise control over their personal information

Companies will have to conduct regular audits and reviews to ensure compliance with data protection regulations. While promptly reporting and addressing any legal breaches.

Security, accuracy, and bias

Effective AUPs address the critical issues of security, accuracy, and bias in AI systems tailored to the organization’s needs. Security measures include regular assessments, data encryption, and strict access controls. The aim of an Acceptable Use Policy (AUP) is to protect AI systems from unauthorized access and cyber threats.

Accuracy is essential for maintaining trust in AI outputs. The AUP could require regular testing and validation of AI models to ensure they produce reliable results. We expect employees to verify and cross-check AI outputs, especially in areas where accuracy is crucial.

Bias in AI systems can lead to unfair outcomes, damaging both individuals and the organization. The AUP might include provisions for regular audits to detect and mitigate bias. Incorporating human oversight, such as a human-in-the-loop approach, can help ensure that AI decisions are fair, ethical, and aligned with organizational values.

Liability and indemnities

It is crucial to define responsibility for errors, misuse, or legal violations due to AI’s unintended consequences.

For employees, AUPs might specify the extent of their responsibility when using AI systems, including guidelines on risk mitigation. If an employee’s misuse leads to harm, the policy should outline the consequences. It should also clarify the organization’s liability stance.

For clients, the AUP might establish clear terms regarding their responsibility to utilize AI services provided by the company. This includes an outline of the limits of the company’s liability and any indemnities the user must agree to. Protecting the organization from legal and financial repercussions due to misuse or unforeseen AI behavior is essential.

Ensure your AI practices are compliant—contact the Symmetry team for professional guidance.

2024-09-24T19:58:39+01:00August 21st, 2024|AI, Uncategorized|