Free download
Four pages, plain language, no legal jargon. It sorts everything your team might hand to an AI tool into four levels, names the rule at each one, and includes a one-page Microsoft Copilot explainer built from Microsoft's own documentation.
What is inside
Public, Internal, Confidential, Restricted. Two questions sort any piece of information, and the rule changes at each level. Your staff can apply it in ten seconds.
The distinction almost nobody has explained to their team: a company AI account carries a contract that stops the vendor training on your data. A personal free account does not.
A fill-in table that turns the policy from a document into a decision: which tools, up to which level, on which account, and who to ask for access.
Six bright lines that apply regardless of tool or level — the section a lawyer will ask about first.
One page on what Microsoft promises and what it does not, sourced from Microsoft's own documentation, so the decision about Copilot gets made on facts.
Follows the U.S. government's AI Risk Management Framework — the reference an auditor or insurer will recognize — without the framework jargon.
Questions
Yes. Download the PDF directly, no email required. If you want the editable Word version, tell us where to send it and we will email it over.
Small and mid-size businesses — the version most templates skip. It is four pages, in plain language, with a fill-in approved-tools table and a one-page explainer on Microsoft Copilot sourced from Microsoft's own documentation.
Public, Internal, Confidential, and Restricted. Two questions sort any piece of information into a level, and the rule about where it may go changes at each one.
That is the point. The template uses [Company] placeholders throughout. Swap in your name, fill in the approved-tools table, and it is your policy.
It follows the U.S. government's NIST AI Risk Management Framework — the reference an auditor or insurer will recognize — without burying your staff in framework language.
When the policy is not enough
A policy tells your team what not to paste into public AI. It does not give the sensitive work anywhere to go. That is what SterlingPRIVATE.ai is for — a dedicated private AI environment, managed by the same Portland team. See how it works →
Next step
Thirty minutes, on your schedule. We will run a real analysis in front of you — on a sample of your own data if you are comfortable, or on ours if you would rather — and show you exactly where that data goes at each step. Nothing to prepare on your side.