Understanding and compliance with AI usage rules
The "Understanding and compliance with AI usage rules" template checks how well employees actually know and follow the company's policy on using AI tools. It covers awareness, where people learned the rules, whether they were trained, and how confident they are about what data may be shared. Use it to find the gaps between a written policy and real day-to-day behavior.
What the “Understanding and compliance with AI usage rules” survey measures
The survey measures familiarity with the rules (from 'apply them regularly' down to 'didn't know rules exist'), the channels where people learned them (internal portal, policy documents, training, managers, security/legal, corporate announcements) and whether they completed onboarding on safe AI use. A confidence slider captures how sure people are about which data can be shared, and a permissibility matrix tests actual understanding by asking how allowed specific actions are — rephrasing text without internal data, pasting unmarked internal documents, including personal data, sharing internal source code, summarizing meeting notes. It also surfaces what makes compliance hard (rules hard to find, too generic, unclear which data is sensitive, differences between tools, no in-context prompts, fear of mistakes, conflict with work processes) and which improvements — one-page do's/don'ts, examples, a consultation channel, built-in warnings, short training, prompt templates, unified rules — would help most.
Who the “Understanding and compliance with AI usage rules” template is for
It fits security, compliance, legal and data-protection teams rolling out or auditing an AI policy, IT and enablement teams responsible for safe adoption, and HR/L&D measuring the impact of training. Any organization introducing generative AI and needing evidence that the policy is understood — not just published — will find it directly applicable.
How to adapt the template to your needs
Replace the permissibility scenarios with the exact actions your policy allows or forbids, so the matrix mirrors your real rules and exposes misconceptions. Add branching so anyone who selects 'didn't know rules exist' skips the detailed knowledge questions, and tailor the improvements list to options you can actually deliver. You can name your specific approved tools, add a question about which AI systems people use, or insert an open field for scenarios where employees weren't sure whether AI was allowed.
Questions and answer options
Answer options:
— Very familiar and I apply them regularly
— Generally familiar, but not with all details
— I’ve heard about the rules but haven’t read them
— I don’t know where to find the rules
— I didn’t know there are rules
Answer options:
— Internal portal/knowledge base
— Company policy/regulations in internal documents
— Training/course/webinar
— Manager/team lead/colleagues
— Security/legal/compliance team
— Announcements in corporate channels (email/chat)
Answer options:
— Yes, I completed training/onboarding
— There was brief communication (memo/message)
— No, I have not
— I don’t remember
Answer options:
— Use AI to rephrase text without including internal data
— Paste internal documents into a prompt without any confidentiality marking
— Include customers’/employees’ personal data in a prompt
— Share source code/code snippets from internal repositories with AI
— Use AI to prepare meeting summaries based on internal notes
Answer options:
— The rules are hard to find
— The rules are too general and lack examples
— It’s hard to understand which data is considered sensitive
— It’s unclear how rules differ for different AI tools
— There are no quick prompts at the moment of use (in the interface/chatbot)
— Not enough time to figure it out
— I’m afraid of making a mistake and violating requirements
— The rules conflict with work tasks/processes
Answer options:
— A short “do’s and don’ts” one-page guide
— Examples of common scenarios and permitted data
— A quick consultation channel (chat/form) with a clear SLA
— Built-in prompts and warnings in tools
— Regular short training (10–15 minutes)
— Ready-made prompt templates for safe tasks
— Unified rules for all AI tools in use