Understanding and compliance with AI usage rules

This survey assesses how well employees know and follow the company’s AI usage rules: awareness, accessibility of materials, confidence about permitted use cases and data, common areas of uncertainty, and measures that can improve compliance (training, prompts, templates, integrations).

The "Understanding and compliance with AI usage rules" template checks how well employees actually know and follow the company's policy on using AI tools. It covers awareness, where people learned the rules, whether they were trained, and how confident they are about what data may be shared. Use it to find the gaps between a written policy and real day-to-day behavior.

What the “Understanding and compliance with AI usage rules” survey measures

The survey measures familiarity with the rules (from 'apply them regularly' down to 'didn't know rules exist'), the channels where people learned them (internal portal, policy documents, training, managers, security/legal, corporate announcements) and whether they completed onboarding on safe AI use. A confidence slider captures how sure people are about which data can be shared, and a permissibility matrix tests actual understanding by asking how allowed specific actions are — rephrasing text without internal data, pasting unmarked internal documents, including personal data, sharing internal source code, summarizing meeting notes. It also surfaces what makes compliance hard (rules hard to find, too generic, unclear which data is sensitive, differences between tools, no in-context prompts, fear of mistakes, conflict with work processes) and which improvements — one-page do's/don'ts, examples, a consultation channel, built-in warnings, short training, prompt templates, unified rules — would help most.

Who the “Understanding and compliance with AI usage rules” template is for

It fits security, compliance, legal and data-protection teams rolling out or auditing an AI policy, IT and enablement teams responsible for safe adoption, and HR/L&D measuring the impact of training. Any organization introducing generative AI and needing evidence that the policy is understood — not just published — will find it directly applicable.

How to adapt the template to your needs

Replace the permissibility scenarios with the exact actions your policy allows or forbids, so the matrix mirrors your real rules and exposes misconceptions. Add branching so anyone who selects 'didn't know rules exist' skips the detailed knowledge questions, and tailor the improvements list to options you can actually deliver. You can name your specific approved tools, add a question about which AI systems people use, or insert an open field for scenarios where employees weren't sure whether AI was allowed.

Questions and answer options

Question type: single choice.
Answer options:
— Very familiar and I apply them regularly
— Generally familiar, but not with all details
— I’ve heard about the rules but haven’t read them
— I don’t know where to find the rules
— I didn’t know there are rules
Question type: multiple choice.
Answer options:
— Internal portal/knowledge base
— Company policy/regulations in internal documents
— Training/course/webinar
— Manager/team lead/colleagues
— Security/legal/compliance team
— Announcements in corporate channels (email/chat)
Question type: single choice.
Answer options:
— Yes, I completed training/onboarding
— There was brief communication (memo/message)
— No, I have not
— I don’t remember
Question type: single-answer matrix.
Answer options:
— Use AI to rephrase text without including internal data
— Paste internal documents into a prompt without any confidentiality marking
— Include customers’/employees’ personal data in a prompt
— Share source code/code snippets from internal repositories with AI
— Use AI to prepare meeting summaries based on internal notes
Question type: multiple choice.
Answer options:
— The rules are hard to find
— The rules are too general and lack examples
— It’s hard to understand which data is considered sensitive
— It’s unclear how rules differ for different AI tools
— There are no quick prompts at the moment of use (in the interface/chatbot)
— Not enough time to figure it out
— I’m afraid of making a mistake and violating requirements
— The rules conflict with work tasks/processes
Question type: ranking.
Answer options:
— A short “do’s and don’ts” one-page guide
— Examples of common scenarios and permitted data
— A quick consultation channel (chat/form) with a clear SLA
— Built-in prompts and warnings in tools
— Regular short training (10–15 minutes)
— Ready-made prompt templates for safe tasks
— Unified rules for all AI tools in use

Similar survey templates

Frequently asked questions

By asking how allowed concrete actions are — pasting unmarked internal documents, including customer personal data, sharing internal code — you can compare employees' answers against your actual policy. Wide disagreement on any row pinpoints exactly where the rules are misunderstood and where communication needs to improve.
Awareness often depends on the channel. If most knowledge comes from colleagues or chat announcements rather than formal training or the policy document, it explains inconsistent understanding and tells you which channel to strengthen.
It separates 'thinks they know' from 'actually knows'. Cross-referencing high self-reported confidence with wrong answers on the permissibility matrix flags overconfident employees — a real compliance risk that a knowledge quiz alone would miss.
Yes — the barriers question captures fear of making a mistake, unclear sensitivity of data, and rules conflicting with work processes, revealing where uncertainty causes people to either over-restrict themselves or work around the policy.