Skip to main content
Home > Insights > An Acceptable Use Policy for your AI system – Why Bother?

An Acceptable Use Policy for your AI system – Why Bother?

July 31st, 2025September 30th, 2025Chris KempNo CommentsReading duration: 4 min

An Acceptable Use Policy or “AUP” is a set of rules established by the owner or operator of a technology system to specify permitted and prohibited use by users. In the era of regulated AI AUPs are becoming more important.

AUPs and providers of GPAI models

Article 53 of the EU AI Act[1] requires providers of general-purpose AI (“GPAI”) models to draw up a range of technical and transparency information for regulatory authorities and downstream integrators of GPAI models. This information must include a description of the AUPs applicable (see Annexes XI and XII).

The recently published Code of Practice for GPAI Models – which gives adherents a way of demonstrating compliance with the Act’s rules for GPAI models – sheds light on this. The Code’s Model Documentation Form (see end Chapter 2[2]) includes a box for AUPs. Providers are invited to provide a link to the AUP, attach a copy to the Form, or indicate that no AUP exists. There are also boxes for “intended uses” of the GPAI model and the types of AI system into which it “can be integrated”.

The GPAI model rules at Chapter V of the AI Act kick in in August this year. Providers of GPAI models are subject to a specific penalties regime for infringements of relevant provisions of the Act: fines of up to 3% turnover or EUR 15m (whichever is higher).

AUPs and prohibited AI practices

The AI Act also sets out a nuanced approach to regulating the various actors in the AI “value chain”, including concepts of “intended purpose” and “reasonably foreseeable misuse” (see definitions).

The Commission’s guidelines on prohibited AI practices gives some clarification on these points, and suggest a role for AUPs.[3]

The guidelines indicate that responsibility for compliance with the prohibited AI practices rules can be balanced between providers and deployers. At para. 39: “The provisions apply to any AI system, whether with an ‘intended purpose’ or ‘general purpose’… Accordingly, each operator should take measures for which they are best placed based on their role and control over the system in the value chain to ensure a responsible and safe provision and use of AI systems.”

The guidelines continue: “While the harm often arises from the way AI systems are used in practice, providers also have a responsibility not to place on the market or put into service AI systems… that are reasonably likely to behave or be directly used in a [prohibited] manner.” In their “contractual relationships with deployers” providers are “expected to exclude use of their AI system for prohibited practices” (para. 40).

In this way, AUPs start to look like one way providers of AI systems can demonstrate the steps they have taken to ensure compliance with the Article 5 prohibitions, given their position in the value chain.

The prohibited AI practices regime took effect in February this year. Non-compliance is subject to the higher fines threshold (the higher of EUR 35m and 7% turnover).

AUPs and contracts

Outside this new regulatory context, AUPs have a more traditional role as part of the binding contractual arrangements between buyers and sellers of AI systems.

Here, the party imposing the AUP may be able to take a range of actions if the accepting party breaches its terms. E.g. terminating a licence, suspending a service or bringing an action for breach of contract.

In practice, the role of contractual AUPs in promoting generally ‘good behaviour’ can be quite limited. A decision to enforce an AUP or not will be subject to the private objectives of the contract parties. And taking formal legal action may be prohibitively expensive and time consuming.

A point to remember is that AUPs now have a regulatory angle too.

Key takeaways

Does the AI Act require you to put an AUP in place? Would it be advantageous to do so anyway?

Have you checked your AUP is consistent with the requirements of the AI Act? In particular, the rules on prohibited AI practices and high-risk AI systems.

How will you balance the new regulatory context for AUPs with your commercial objectives?


[1] See here for the Act: https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng.

[2] See here for the GPAI Code of Practice: https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai.

[3] See here for the prohibited AI practices guidelines: https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-prohibited-artificial-intelligence-ai-practices-defined-ai-act.

About the author

Chris is recognised as “one of the UK’s leading software and data lawyers” (LexisNexis). He has extensive experience advising buyers and sellers of software, data and technology products, including specific “expertise in AI projects” (Legal 500, 2025).

Subscribe