AI Acceptable Use & Governance Policy - New York
AI ACCEPTABLE USE & GOVERNANCE POLICY
1. Purpose
This Policy establishes the principles, responsibilities, and controls for responsible use of artificial intelligence ("AI") and machine learning ("ML") technologies by [ORGANIZATION NAME].
2. Scope
This Policy applies to all employees, contractors, vendors, and partners who develop, deploy, procure, or interact with AI Systems on behalf of [ORGANIZATION NAME].
3. Definitions
- AI System: Software that uses machine learning, statistical techniques, or logic-based approaches to generate outputs such as predictions, recommendations, or decisions.
- High-Risk AI: An internal review tier for systems with potentially significant effects on rights, safety, or finances; this label does not decide whether a legal definition applies.
- GPAI: General-purpose AI models or foundational models with broad applicability.
- Human-in-the-Loop: A control requiring human review or intervention before an AI output is acted upon.
4. Governance Structure
4.1 AI Steering Committee. [ORGANIZATION NAME] maintains an AI Steering Committee responsible for approving AI initiatives, monitoring compliance, and reporting to executive leadership.
4.2 AI Product Owner. Each AI System has an owner accountable for lifecycle management, documentation, and performance monitoring.
4.3 Risk & Compliance. The Legal/Compliance team conducts impact assessments, ensures regulatory alignment, and maintains the AI inventory.
4.4 Technical Leads. Engineering/Data Science teams implement controls, testing, and monitoring.
5. Acceptable Use Principles
- Lawful & Ethical Use: AI Systems must comply with applicable laws, contractual commitments, and ethical guidelines.
- Purpose Limitation: Use AI only for approved purposes documented in the AI inventory.
- Transparency: Provide meaningful information about AI involvement to affected individuals when required.
- Human Oversight: Maintain appropriate human review based on risk tier.
- Fairness & Non-Discrimination: Conduct bias testing and mitigation for High-Risk AI.
- Security & Privacy: Protect Personal Data and sensitive business information throughout the AI lifecycle.
- Accountability: Assign clear ownership and escalation paths for issues.
6. Prohibited Uses
The following uses are prohibited unless expressly authorized and lawful:
- Real-time biometric identification in public spaces.
- Emotion recognition or inference from sensitive data without explicit approval.
- Automated decision-making that materially affects employment, credit, housing, or healthcare without documented assessments.
- Generation or dissemination of deceptive or misleading content (deepfakes) without disclosure.
- Training models on unlawfully obtained or non-compliant datasets.
7. AI Lifecycle Controls
7.1 Ideation & Intake. Submit AI projects through the intake process, including purpose, data sources, and expected outputs.
7.2 Risk Classification. Assign each AI System a risk tier (Minimal, Limited, High) with required controls per Appendix A.
7.3 Impact Assessments. Conduct internal AI impact assessments before deploying High-Risk AI and identify any separate assessment required by applicable law.
7.4 Testing & Validation. Perform pre-deployment testing, including accuracy, robustness, bias, and cybersecurity assessments.
7.5 Deployment & Monitoring. Monitor performance metrics, drift, and incident reports. Maintain logs for audit.
7.6 Change Management. Reassess risk when models are retrained, fine-tuned, or when data sources change.
7.7 Decommissioning. Document steps for retiring AI Systems, including data retention and access controls.
8. Data Management & Privacy
- Use Privacy Impact Assessments when processing Personal Data.
- Apply data minimization, anonymization, or pseudonymization where feasible.
- Respect consent, opt-out, and sensitive data requirements for applicable jurisdictions.
- Coordinate with the Data Protection Officer for cross-border transfers.
9. Vendor & Third-Party Management
- Perform due diligence on third-party AI vendors, including security reviews and contractual safeguards.
- Require vendors to provide documentation on model training data, testing, and compliance.
- Include audit and termination rights in vendor agreements.
10. Incident Response & Reporting
- Report AI incidents, such as model failures, bias findings, or security events, within [HOURS] hours to the AI Steering Committee and Security Team.
- Investigate incidents, implement corrective actions, and document lessons learned.
- Notify regulators or affected individuals if legally required.
11. Training & Awareness
- Provide annual training on responsible AI use to all relevant personnel.
- Offer specialized training for developers, product owners, and compliance reviewers.
- Maintain records of training completion.
12. Policy Violations
Violations of this Policy may result in disciplinary action up to and including termination of employment or contracts. Serious violations may be referred to regulatory authorities.
13. Review & Updates
The AI Steering Committee will review this Policy at least annually, or upon significant regulatory changes, technology updates, or incidents.
14. Regulatory Milestones Tracking
-
Maintain a regulatory register identifying each jurisdiction, sector,
effective date, system, owner, required control, evidence, and status. -
Do not copy a global AI-law milestone into this New York policy without
confirming that the organization, system, activity, and effective date are
in scope. -
Update this Policy before an applicable requirement takes effect and retain
the official source used for the update.
15. New York-Specific Requirements (If Applicable)
15.1 NYC Automated Employment Decision Tools
Complete this gate before using an AI or data tool in hiring or promotion:
| Applicability question | Finding and evidence |
|---|---|
| Employer or employment agency uses the tool “in the city” | [________________________________] |
| Tool uses covered computational techniques | [________________________________] |
| Tool substantially assists or replaces discretionary decision-making | [________________________________] |
| Tool screens a candidate for hire or employee for promotion | [________________________________] |
| Candidate/employee residency and job-location facts | [________________________________] |
If the tool is a covered AEDT:
☐ An independent bias audit was completed no more than one year before use.
☐ The public summary includes the audit date, data source and explanation,
unknown-category count, applicable group counts, selection or scoring rates,
and impact ratios.
☐ The public summary and the tool's distribution date were posted before use.
☐ Each covered New York City resident received notice of AEDT use and the job
qualifications or characteristics assessed at least 10 business days before
use.
☐ The notice includes instructions for requesting a reasonable accommodation.
☐ The type and source of data and the retention policy are on the website or a
process is ready to answer a written request within 30 days, subject to the
law's disclosure exceptions.
The employer or employment agency remains responsible for the use gate even
when a vendor arranged the audit. A bias audit does not by itself resolve
discrimination, accommodation, privacy, labor, or other applicable duties.
15.2 New York SHIELD Act Security Program
If the organization owns or licenses computerized data containing private
information of a New York resident, N.Y. Gen. Bus. Law § 899-bb requires a
reasonable security program. Record the program evidence:
| Safeguard area | Required record |
|---|---|
| Administrative: coordinator, risks, control assessment, training, provider contracts, change adjustment | [________________________________] |
| Technical: network/software, processing/transmission/storage, attack response, testing/monitoring | [________________________________] |
| Physical: storage/disposal risk, intrusion response, lifecycle access protection, secure disposal | [________________________________] |
| Small-business tailoring, if claimed | [________________________________] |
| Compliant-regulated-entity basis, if claimed | [________________________________] |
AI governance controls supplement rather than replace the security program.
15.3 Other New York and Sector Review
Legal/Compliance shall separately identify applicable anti-discrimination,
employment, labor, consumer-protection, financial-services, insurance,
education, health, biometric, surveillance, and public-sector requirements.
This Policy does not assume that every AI system is subject to the same New
York rule set.
Appendix A - Risk Tier Controls
| Risk tier | Minimum controls | Owner | Evidence |
|---|---|---|---|
| Minimal | Inventory, acceptable-use rules, security review | [____] | [____] |
| Limited | Minimal controls plus testing, notice review, monitoring | [____] | [____] |
| High | Independent validation, impact assessment, legal approval, human oversight, incident plan | [____] | [____] |
Appendix B - AI Inventory Template
| System | Owner | Purpose | Risk tier | Data sources | Jurisdictions | Status |
|---|---|---|---|---|---|---|
| [____] | [____] | [____] | [____] | [____] | [____] | [____] |
Appendix C - AI Impact Assessment Checklist
☐ Purpose, users, affected persons, and prohibited uses identified
☐ Data source, authority, quality, retention, and security reviewed
☐ Accuracy, robustness, bias, accessibility, and misuse risks tested
☐ Human oversight, appeal, accommodation, notice, and escalation designed
☐ Vendor evidence and contractual controls reviewed
☐ Monitoring thresholds, incident response, and decommissioning plan approved
| Sign-off | Name | Date |
|---|---|---|
| Product owner | [____] | [__/__/____] |
| Security/privacy | [____] | [__/__/____] |
| Legal/compliance | [____] | [__/__/____] |
About this template
- Last updated
- September 27, 2026
- Jurisdiction
- New York
- Category
- Compliance & Regulatory
Legal authority
- N.Y.C. Admin. Code §§ 20-870 to 20-871 (automated employment decision tool definitions and use requirements)
- N.Y. Gen. Bus. Law § 899-bb(2) (reasonable data-security safeguards)
Compliance documents are what regulated businesses use to prove they follow the rules that apply to their industry, whether that is privacy, anti-money-laundering, consumer protection, or sector-specific requirements. Regulators look for consistent policies, up-to-date records, and clear evidence of employee training. The cost of getting compliance paperwork right is almost always smaller than the cost of an enforcement action, fine, or public disclosure.
Not legal advice
This template is provided for informational purposes. We recommend having an attorney review any legal document before signing, especially for high-value or complex matters.
Checked against the law it cites
The statutes this template relies on are listed under Legal authority.
N.Y.C. Admin. Code § 20-871(a) (checked August 16, 2026): "In the city, it shall be unlawful for an employer or an employment agency to use an automated employment decision tool to screen a candidate or employee for an employment decision unless: 1. Such tool has been the subject of a bias audit conducted no more than one year prior to the use of such tool; and 2. A summary of the results of the most recent bias audit of such tool as well as the distribution date of the tool to which such audit applies has been made publicly available on the website of the employer or employment agency prior to the use of such tool."
N.Y.C. Admin. Code § 20-871(b) (checked August 16, 2026): "That an automated employment decision tool will be used in connection with the assessment or evaluation of such employee or candidate that resides in the city. Such notice shall be made no less than ten business days before such use and allow a candidate to request an alternative selection process or accommodation. The job qualifications and characteristics that such automated employment decision tool will use in the assessment of such candidate or employee. Such notice shall be made no less than 10 business days before such use."
N.Y.C. Admin. Code § 20-871(b)(3) (checked August 16, 2026): "If not disclosed on the employer or employment agency's website, information about the type of data collected for the automated employment decision tool, the source of such data and the employer or employment agency's data retention policy shall be available upon written request by a candidate or employee. Such information shall be provided within 30 days of the written request."
N.Y. Gen. Bus. Law § 899-bb(2)(a) (checked August 16, 2026): "Any person or business that owns or licenses computerized data which includes private information of a resident of New York shall develop, implement and maintain reasonable safeguards to protect the security, confidentiality and integrity of the private information including, but not limited to, disposal of data."
Draft your AI Acceptable Use & Governance Policy - New York in the editor
Answer a few questions, let the AI editor draft each section from your answers, review it, and download Word and PDF. $99 one time, or $249 per month for every document and every Ezel app.