AI Acceptable Use & Governance Policy - California

California Compliance & Regulatory Updated September 27, 2026 Free Word and PDF

AI ACCEPTABLE USE & GOVERNANCE POLICY

Document field Approved entry
Organization [ORGANIZATION NAME]
Policy owner [NAME / ROLE]
Effective date and version [DATE / VERSION]
Approved by [NAME / ROLE]
Questions and incident contact [CONTACT]
Next review [DATE]

1. Purpose

This Policy establishes the principles, responsibilities, and controls for responsible use of artificial intelligence ("AI") and machine learning ("ML") technologies by [ORGANIZATION NAME].


2. Scope

This Policy applies to all employees, contractors, vendors, and partners who develop, deploy, procure, or interact with AI Systems on behalf of [ORGANIZATION NAME].


3. Definitions

  • AI System: Software that uses machine learning, statistical techniques, or logic-based approaches to generate outputs such as predictions, recommendations, or decisions.
  • High-Risk AI: An internal review tier assigned by the AI Steering Committee for uses with potentially significant effects on people, safety, finances, confidential data, or operations. This label does not decide whether a legal definition applies.
  • Human-in-the-Loop: A control requiring human review or intervention before an AI output is acted upon.

4. Governance Structure

4.1 AI Steering Committee. [ORGANIZATION NAME] maintains an AI Steering Committee responsible for approving AI initiatives, monitoring compliance, and reporting to executive leadership.
4.2 AI Product Owner. Each AI System has an owner accountable for lifecycle management, documentation, and performance monitoring.
4.3 Risk & Compliance. The Legal/Compliance team conducts impact assessments, ensures regulatory alignment, and maintains the AI inventory.
4.4 Technical Leads. Engineering/Data Science teams implement controls, testing, and monitoring.


5. Acceptable Use Principles

  • Lawful & Ethical Use: AI Systems must comply with applicable laws, contractual commitments, and ethical guidelines.
  • Purpose Limitation: Use AI only for approved purposes documented in the AI inventory.
  • Transparency: Provide meaningful information about AI involvement to affected individuals when required.
  • Human Oversight: Maintain appropriate human review based on risk tier.
  • Fairness & Non-Discrimination: Conduct bias testing and mitigation for High-Risk AI.
  • Security & Privacy: Protect Personal Data and sensitive business information throughout the AI lifecycle.
  • Accountability: Assign clear ownership and escalation paths for issues.

6. Prohibited Uses

The following uses are prohibited unless expressly authorized and lawful:

  • Real-time biometric identification in public spaces.
  • Emotion recognition or inference from sensitive data without explicit approval.
  • Automated decision-making that materially affects employment, credit, housing, or healthcare without documented assessments.
  • Generation or dissemination of deceptive or misleading content (deepfakes) without disclosure.
  • Training models on unlawfully obtained or non-compliant datasets.

7. AI Lifecycle Controls

7.1 Ideation & Intake. Submit AI projects through the intake process, including purpose, data sources, and expected outputs.
7.2 Risk Classification. Assign each AI System a risk tier (Minimal, Limited, High) with required controls per Appendix A.
7.3 Impact Assessments. Conduct AI Impact Assessments (AIIA) before deploying High-Risk AI, referencing regulatory frameworks.
7.4 Testing & Validation. Perform pre-deployment testing, including accuracy, robustness, bias, and cybersecurity assessments.
7.5 Deployment & Monitoring. Monitor performance metrics, drift, and incident reports. Maintain logs for audit.
7.6 Change Management. Reassess risk when models are retrained, fine-tuned, or when data sources change.
7.7 Decommissioning. Document steps for retiring AI Systems, including data retention and access controls.


8. Data Management & Privacy

  • Use Privacy Impact Assessments when processing Personal Data.
  • Apply data minimization, anonymization, or pseudonymization where feasible.
  • Respect consent, opt-out, and sensitive data requirements for applicable jurisdictions.
  • Coordinate with the Data Protection Officer for cross-border transfers.

9. Vendor & Third-Party Management

  • Perform due diligence on third-party AI vendors, including security reviews and contractual safeguards.
  • Require vendors to provide documentation on model training data, testing, and compliance.
  • Include audit and termination rights in vendor agreements.

10. Incident Response & Reporting

  • Report AI incidents, such as model failures, bias findings, or security events, within [HOURS] hours to the AI Steering Committee and Security Team.
  • Investigate incidents, implement corrective actions, and document lessons learned.
  • Notify regulators or affected individuals if legally required.

11. Training & Awareness

  • Provide annual training on responsible AI use to all relevant personnel.
  • Offer specialized training for developers, product owners, and compliance reviewers.
  • Maintain records of training completion.

12. Policy Violations

Violations of this Policy may result in disciplinary action up to and including termination of employment or contracts. Serious violations may be referred to regulatory authorities.


13. Review & Updates

The AI Steering Committee will review this Policy at least annually, or upon significant regulatory changes, technology updates, or incidents.


14. Regulatory Milestones Tracking

  • Maintain a regulatory register identifying each jurisdiction, sector,
    effective date, system, owner, required control, evidence, and status.

  • Do not copy a global AI-law milestone into this state policy without
    confirming that the organization, system, activity, and effective date are
    in scope.

  • Update this Policy before an applicable requirement takes effect and retain
    the official source used for the update.

15. California Applicability and Controls

The Legal/Compliance owner records the conclusion for each system and use before approval. A policy risk tier does not answer the CCPA's business or processing definitions.

Question System/use conclusion and official source Owner and required control
Is the Organization a covered CCPA business for this processing? [YES / NO / ANALYSIS; SOURCE] [OWNER / CONTROL]
Does the use involve consumer personal or sensitive personal information, a sale or share, or another regulated activity? [FACTS; SOURCE] [OWNER / CONTROL]
Is a risk assessment required before processing under 11 CCR § 7150(a)-(b)? [TRIGGER OR EXCEPTION; SOURCE] [ASSESSMENT, APPROVAL, AND RECORD]
Is ADMT used to make a significant decision under 11 CCR § 7200? [DEFINITION, DECISION, AND HUMAN ROLE; SOURCE] [OWNER / CONTROL]
Does another California or sector rule apply to this use? [RULE, COVERAGE, DATE, AND SOURCE] [OWNER / CONTROL]

For a covered CCPA business, Cal. Civ. Code § 1798.100 requires point-of-collection information, purpose and retention controls, appropriate recipient contracts when personal information is sold, shared, or disclosed as specified in subsection (d), and reasonable security. Map the exact statutory duties and any exceptions to each approved use before it begins.

Under the final CPPA regulations, a covered business must conduct a risk assessment before processing that presents significant risk under 11 CCR § 7150(a)-(b). The CPPA states that affected businesses must begin compliance by January 1, 2026. Record the particular trigger, assessment, reviewers, decision, and retention route in Appendix C.

Under 11 CCR § 7200, a business using ADMT to make a significant decision concerning a consumer must comply with the ADMT article by January 1, 2027 if already using it, or whenever it uses it on or after that date. For a covered use, implement the pre-use notice under § 7220, evaluate the opt-out and exceptions (including any qualifying human appeal) under § 7221, and prepare the access response under § 7222. Record the decision, notice, request methods, reviewer authority, and evidence. An AI-assisted workflow alone does not establish that this article applies.

The Steering Committee also requires testing for discrimination, security review, and incident handling for uses affecting employment, housing, credit, healthcare, or other protected contexts under the separate obligations identified in the register.


Appendix A - Risk Tier Controls

Internal tier Approval before use Minimum review and evidence
Minimal System owner Approved system/use, permitted data, output check, incident contact
Limited System owner and Security/Privacy Minimal controls plus data-flow review, vendor settings, testing, monitoring owner
High Steering Committee, Legal/Compliance, Security/Privacy, affected business owner Limited controls plus impact assessment, bias and performance testing, human-review route, notices/rights where applicable, rollback plan, periodic review

The Legal/Compliance owner separately determines every statutory classification. An internal tier neither creates nor removes a legal duty.

Appendix B - AI Inventory Template

System/version Owner Purpose and users Data categories and sources Jurisdictions Internal tier Required legal controls and source Approval/status/review date
[________] [________] [________] [________] [________] [________] [________] [________]

Appendix C - AI Impact Assessment Checklist

Assessment item Recorded answer or evidence
System, version, owner, purpose, affected people, and decision [________________________________]
Data categories, source, recipients, retention, and vendor configuration [________________________________]
CCPA business/processing scope and other applicable rules with current source [________________________________]
§ 7150 trigger or exception; assessment completed before processing if required [________________________________]
§ 7200 ADMT significant-decision analysis; § 7220 notice; § 7221 opt-out/exception; § 7222 access route, if applicable [________________________________]
Accuracy, security, privacy, bias, accessibility, and misuse risks [________________________________]
Mitigations, human reviewer authority, testing results, and residual risk [________________________________]
Monitoring measures, incident/rollback plan, review date, and record custodian [________________________________]
Business owner, Security/Privacy, and Legal/Compliance approval [________________________________]

California Sources

Insert Image

Insert Table

Watch Ezel in action (sample case)Choose a plan

All changes saved
Save
Export
Export as DOCX
Export as PDF
Generating PDF...
ai_acceptable_use_and_governance_policy_ca.pdf
Ready to export as PDF or Word
AI is editing...
Chat
Review

Draft it in the editor

The AI drafts each section from your answers and you review every word. Drafting from scratch takes hours; finish yours for $99 one time.

  • Built on this template
    Uses the California version and the statutes it cites.
  • Formatted like the template
    Captions, numbering and layout stay intact.
  • AI editing
    Rewrite any section from your own notes.
  • Export as PDF and Word
    Yours to review, sign, or file.
Secure checkout via Stripe
Need to customize this document?

About this template

Last updated
September 27, 2026
Citations checked
September 27, 2026
Jurisdiction
California
Category
Compliance & Regulatory

Legal authority

  • Cal. Civ. Code § 1798.100(a), (c)-(e)
  • Cal. Code Regs. tit. 11, § 7150(a)-(b)
  • Cal. Code Regs. tit. 11, § 7200
  • Cal. Code Regs. tit. 11, § 7220
  • Cal. Code Regs. tit. 11, § 7221
  • Cal. Code Regs. tit. 11, § 7222

Compliance documents are what regulated businesses use to prove they follow the rules that apply to their industry, whether that is privacy, anti-money-laundering, consumer protection, or sector-specific requirements. Regulators look for consistent policies, up-to-date records, and clear evidence of employee training. The cost of getting compliance paperwork right is almost always smaller than the cost of an enforcement action, fine, or public disclosure.

Not legal advice

This template is provided for informational purposes. We recommend having an attorney review any legal document before signing, especially for high-value or complex matters.

Checked against the law it cites

A reviewer verified this template's legal citations against the official source on September 27, 2026.

Cal. Civ. Code § 1798.100 (checked September 27, 2026): "A business that controls the collection of a consumer’s personal information shall, at or before the point of collection, inform consumers of the following:"

Cal. Code Regs. tit. 11, § 7150 (checked September 27, 2026): "Every business whose processing of consumers’ personal information presents significant risk to consumers’ privacy as set forth in subsection (b) must conduct a risk assessment before initiating that processing."

Cal. Code Regs. tit. 11, § 7200 (checked September 27, 2026): "A business that uses ADMT to make a significant decision concerning a consumer must comply with the requirements of this Article."

Cal. Code Regs. tit. 11, § 7220 (checked September 27, 2026): "A business that uses ADMT as set forth in section 7200, subsection (a), must provide consumers with a Pre-use Notice."

Draft your AI Acceptable Use & Governance Policy - California in the editor

Answer a few questions, let the AI editor draft each section from your answers, review it, and download Word and PDF. $99 one time, or $249 per month for every document and every Ezel app.