Yes. An acceptable-use policy gives staff clear rules: which tools are approved, what data they can enter, when a human has to check the output, and how to handle anything AI produces. Cyber insurers, customers running due diligence and ISO 27001 auditors increasingly expect to see one.