AI Acceptable Use & Governance Policy - California
AI ACCEPTABLE USE & GOVERNANCE POLICY
| Document field | Approved entry |
|---|---|
| Organization | [ORGANIZATION NAME] |
| Policy owner | [NAME / ROLE] |
| Effective date and version | [DATE / VERSION] |
| Approved by | [NAME / ROLE] |
| Questions and incident contact | [CONTACT] |
| Next review | [DATE] |
1. Purpose
This Policy establishes the principles, responsibilities, and controls for responsible use of artificial intelligence ("AI") and machine learning ("ML") technologies by [ORGANIZATION NAME].
2. Scope
This Policy applies to all employees, contractors, vendors, and partners who develop, deploy, procure, or interact with AI Systems on behalf of [ORGANIZATION NAME].
3. Definitions
- AI System: Software that uses machine learning, statistical techniques, or logic-based approaches to generate outputs such as predictions, recommendations, or decisions.
- High-Risk AI: An internal review tier assigned by the AI Steering Committee for uses with potentially significant effects on people, safety, finances, confidential data, or operations. This label does not decide whether a legal definition applies.
- Human-in-the-Loop: A control requiring human review or intervention before an AI output is acted upon.
4. Governance Structure
4.1 AI Steering Committee. [ORGANIZATION NAME] maintains an AI Steering Committee responsible for approving AI initiatives, monitoring compliance, and reporting to executive leadership.
4.2 AI Product Owner. Each AI System has an owner accountable for lifecycle management, documentation, and performance monitoring.
4.3 Risk & Compliance. The Legal/Compliance team conducts impact assessments, ensures regulatory alignment, and maintains the AI inventory.
4.4 Technical Leads. Engineering/Data Science teams implement controls, testing, and monitoring.
5. Acceptable Use Principles
- Lawful & Ethical Use: AI Systems must comply with applicable laws, contractual commitments, and ethical guidelines.
- Purpose Limitation: Use AI only for approved purposes documented in the AI inventory.
- Transparency: Provide meaningful information about AI involvement to affected individuals when required.
- Human Oversight: Maintain appropriate human review based on risk tier.
- Fairness & Non-Discrimination: Conduct bias testing and mitigation for High-Risk AI.
- Security & Privacy: Protect Personal Data and sensitive business information throughout the AI lifecycle.
- Accountability: Assign clear ownership and escalation paths for issues.
6. Prohibited Uses
The following uses are prohibited unless expressly authorized and lawful:
- Real-time biometric identification in public spaces.
- Emotion recognition or inference from sensitive data without explicit approval.
- Automated decision-making that materially affects employment, credit, housing, or healthcare without documented assessments.
- Generation or dissemination of deceptive or misleading content (deepfakes) without disclosure.
- Training models on unlawfully obtained or non-compliant datasets.
7. AI Lifecycle Controls
7.1 Ideation & Intake. Submit AI projects through the intake process, including purpose, data sources, and expected outputs.
7.2 Risk Classification. Assign each AI System a risk tier (Minimal, Limited, High) with required controls per Appendix A.
7.3 Impact Assessments. Conduct AI Impact Assessments (AIIA) before deploying High-Risk AI, referencing regulatory frameworks.
7.4 Testing & Validation. Perform pre-deployment testing, including accuracy, robustness, bias, and cybersecurity assessments.
7.5 Deployment & Monitoring. Monitor performance metrics, drift, and incident reports. Maintain logs for audit.
7.6 Change Management. Reassess risk when models are retrained, fine-tuned, or when data sources change.
7.7 Decommissioning. Document steps for retiring AI Systems, including data retention and access controls.
8. Data Management & Privacy
- Use Privacy Impact Assessments when processing Personal Data.
- Apply data minimization, anonymization, or pseudonymization where feasible.
- Respect consent, opt-out, and sensitive data requirements for applicable jurisdictions.
- Coordinate with the Data Protection Officer for cross-border transfers.
9. Vendor & Third-Party Management
- Perform due diligence on third-party AI vendors, including security reviews and contractual safeguards.
- Require vendors to provide documentation on model training data, testing, and compliance.
- Include audit and termination rights in vendor agreements.
10. Incident Response & Reporting
- Report AI incidents, such as model failures, bias findings, or security events, within [HOURS] hours to the AI Steering Committee and Security Team.
- Investigate incidents, implement corrective actions, and document lessons learned.
- Notify regulators or affected individuals if legally required.
11. Training & Awareness
- Provide annual training on responsible AI use to all relevant personnel.
- Offer specialized training for developers, product owners, and compliance reviewers.
- Maintain records of training completion.
12. Policy Violations
Violations of this Policy may result in disciplinary action up to and including termination of employment or contracts. Serious violations may be referred to regulatory authorities.
13. Review & Updates
The AI Steering Committee will review this Policy at least annually, or upon significant regulatory changes, technology updates, or incidents.
14. Regulatory Milestones Tracking
-
Maintain a regulatory register identifying each jurisdiction, sector,
effective date, system, owner, required control, evidence, and status. -
Do not copy a global AI-law milestone into this state policy without
confirming that the organization, system, activity, and effective date are
in scope. -
Update this Policy before an applicable requirement takes effect and retain
the official source used for the update.
15. California Applicability and Controls
The Legal/Compliance owner records the conclusion for each system and use before approval. A policy risk tier does not answer the CCPA's business or processing definitions.
| Question | System/use conclusion and official source | Owner and required control |
|---|---|---|
| Is the Organization a covered CCPA business for this processing? | [YES / NO / ANALYSIS; SOURCE] | [OWNER / CONTROL] |
| Does the use involve consumer personal or sensitive personal information, a sale or share, or another regulated activity? | [FACTS; SOURCE] | [OWNER / CONTROL] |
| Is a risk assessment required before processing under 11 CCR § 7150(a)-(b)? | [TRIGGER OR EXCEPTION; SOURCE] | [ASSESSMENT, APPROVAL, AND RECORD] |
| Is ADMT used to make a significant decision under 11 CCR § 7200? | [DEFINITION, DECISION, AND HUMAN ROLE; SOURCE] | [OWNER / CONTROL] |
| Does another California or sector rule apply to this use? | [RULE, COVERAGE, DATE, AND SOURCE] | [OWNER / CONTROL] |
For a covered CCPA business, Cal. Civ. Code § 1798.100 requires point-of-collection information, purpose and retention controls, appropriate recipient contracts when personal information is sold, shared, or disclosed as specified in subsection (d), and reasonable security. Map the exact statutory duties and any exceptions to each approved use before it begins.
Under the final CPPA regulations, a covered business must conduct a risk assessment before processing that presents significant risk under 11 CCR § 7150(a)-(b). The CPPA states that affected businesses must begin compliance by January 1, 2026. Record the particular trigger, assessment, reviewers, decision, and retention route in Appendix C.
Under 11 CCR § 7200, a business using ADMT to make a significant decision concerning a consumer must comply with the ADMT article by January 1, 2027 if already using it, or whenever it uses it on or after that date. For a covered use, implement the pre-use notice under § 7220, evaluate the opt-out and exceptions (including any qualifying human appeal) under § 7221, and prepare the access response under § 7222. Record the decision, notice, request methods, reviewer authority, and evidence. An AI-assisted workflow alone does not establish that this article applies.
The Steering Committee also requires testing for discrimination, security review, and incident handling for uses affecting employment, housing, credit, healthcare, or other protected contexts under the separate obligations identified in the register.
Appendix A - Risk Tier Controls
| Internal tier | Approval before use | Minimum review and evidence |
|---|---|---|
| Minimal | System owner | Approved system/use, permitted data, output check, incident contact |
| Limited | System owner and Security/Privacy | Minimal controls plus data-flow review, vendor settings, testing, monitoring owner |
| High | Steering Committee, Legal/Compliance, Security/Privacy, affected business owner | Limited controls plus impact assessment, bias and performance testing, human-review route, notices/rights where applicable, rollback plan, periodic review |
The Legal/Compliance owner separately determines every statutory classification. An internal tier neither creates nor removes a legal duty.
Appendix B - AI Inventory Template
| System/version | Owner | Purpose and users | Data categories and sources | Jurisdictions | Internal tier | Required legal controls and source | Approval/status/review date |
|---|---|---|---|---|---|---|---|
| [________] | [________] | [________] | [________] | [________] | [________] | [________] | [________] |
Appendix C - AI Impact Assessment Checklist
| Assessment item | Recorded answer or evidence |
|---|---|
| System, version, owner, purpose, affected people, and decision | [________________________________] |
| Data categories, source, recipients, retention, and vendor configuration | [________________________________] |
| CCPA business/processing scope and other applicable rules with current source | [________________________________] |
| § 7150 trigger or exception; assessment completed before processing if required | [________________________________] |
| § 7200 ADMT significant-decision analysis; § 7220 notice; § 7221 opt-out/exception; § 7222 access route, if applicable | [________________________________] |
| Accuracy, security, privacy, bias, accessibility, and misuse risks | [________________________________] |
| Mitigations, human reviewer authority, testing results, and residual risk | [________________________________] |
| Monitoring measures, incident/rollback plan, review date, and record custodian | [________________________________] |
| Business owner, Security/Privacy, and Legal/Compliance approval | [________________________________] |
California Sources
About this template
- Last updated
- September 27, 2026
- Citations checked
- September 27, 2026
- Jurisdiction
- California
- Category
- Compliance & Regulatory
Legal authority
- Cal. Civ. Code § 1798.100(a), (c)-(e)
- Cal. Code Regs. tit. 11, § 7150(a)-(b)
- Cal. Code Regs. tit. 11, § 7200
- Cal. Code Regs. tit. 11, § 7220
- Cal. Code Regs. tit. 11, § 7221
- Cal. Code Regs. tit. 11, § 7222
Compliance documents are what regulated businesses use to prove they follow the rules that apply to their industry, whether that is privacy, anti-money-laundering, consumer protection, or sector-specific requirements. Regulators look for consistent policies, up-to-date records, and clear evidence of employee training. The cost of getting compliance paperwork right is almost always smaller than the cost of an enforcement action, fine, or public disclosure.
Not legal advice
This template is provided for informational purposes. We recommend having an attorney review any legal document before signing, especially for high-value or complex matters.
Checked against the law it cites
A reviewer verified this template's legal citations against the official source on September 27, 2026.
Cal. Civ. Code § 1798.100 (checked September 27, 2026): "A business that controls the collection of a consumer’s personal information shall, at or before the point of collection, inform consumers of the following:"
Cal. Code Regs. tit. 11, § 7150 (checked September 27, 2026): "Every business whose processing of consumers’ personal information presents significant risk to consumers’ privacy as set forth in subsection (b) must conduct a risk assessment before initiating that processing."
Cal. Code Regs. tit. 11, § 7200 (checked September 27, 2026): "A business that uses ADMT to make a significant decision concerning a consumer must comply with the requirements of this Article."
Cal. Code Regs. tit. 11, § 7220 (checked September 27, 2026): "A business that uses ADMT as set forth in section 7200, subsection (a), must provide consumers with a Pre-use Notice."
Draft your AI Acceptable Use & Governance Policy - California in the editor
Answer a few questions, let the AI editor draft each section from your answers, review it, and download Word and PDF. $99 one time, or $249 per month for every document and every Ezel app.