← All terms

Acceptable Use Policy (AUP)

An acceptable use policy defines how employees may use company systems, data, and accounts — the baseline document behind shadow IT, AI, and BYOD rules.

An acceptable use policy (AUP) is the document that defines how employees may use an organization's systems, networks, accounts, and data — and how they may not. It typically covers personal use of company devices, handling of confidential information, software installation, external services and AI tools, and the consequences of violations. Most employees meet it once, as a signature line in onboarding paperwork; whether it ever influences behavior again is what separates a control from a formality.

How it works

The AUP draws the official boundary that other security efforts depend on. Incident response needs it to establish that an action was unauthorized; HR and legal need it to act on violations; auditors ask for it under frameworks such as ISO 27001 and PCI DSS. In daily life, though, the policy competes with convenience. Where it is vague, outdated, or silent — on personal cloud drives, on unsanctioned apps, on pasting work data into personal AI accounts, on work from personal devices (BYOD) — employees fill the silence with whatever gets the job done. The gap between what the policy imagines and what people actually do is where unmanaged risk accumulates, usually invisibly until an incident surfaces it.

How to defend

Write the AUP for the reader, not the auditor: short, concrete, and current enough to name the tools employees actually reach for, including generative AI. Pair every prohibition with a sanctioned path — a policy that only says no to personal file sharing, without providing an approved equivalent, is a request to be ignored. Revisit it on a schedule, because a document that predates AI assistants cannot govern them. And close the loop with training: a rule read once at onboarding decays like any other memory, so the policies that matter should reappear in ongoing awareness training and in moment-of-risk reminders. Our guide to shadow AI at work shows what happens when policy and practice drift apart — and how to pull them back together.

Related terms

Shadow ITShadow IT is technology used without IT approval — unsanctioned apps, accounts, and AI tools that expand attack surface outside security's visibility.Shadow AIShadow AI is employees' use of AI tools without IT approval — chatbots, assistants, note-takers — creating invisible data leakage and compliance risk.BYOD (Bring Your Own Device)BYOD (bring your own device) lets employees use personal phones and laptops for work — expanding productivity and the attack surface at the same time.Security CultureSecurity culture is the shared attitudes, norms and habits that shape how people in an organization actually behave around security when nobody is checking.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo