AI User Guidelines and Policy
Effective Date: July 23, 2026
Version: 2.0
This document governs the use of Acquia's AI Features by all users. It supplements Acquia's Subscription and Services Agreement and applicable Product and Services Guides.
Introduction and Scope
This AI User Guidelines and Policy ("Policy") governs the use of Acquia's artificial intelligence features, tools, and capabilities ("AI Features") embedded in or made available through Acquia's products and services. AI Features are available across a range of Acquia products, including (without limitation):
- Acquia DAM — AI-powered asset tagging, metadata generation, content recognition, duplicate detection, and smart search
- Acquia Source CMS — AI-assisted content creation, site building, and editorial tools
- Acquia Web Governance — AI-driven accessibility detection and remediation suggestions
- Acquia Content Optimization — AI-powered SEO recommendations and performance insights
- Acquia Conversion Optimization — AI-driven A/B testing and behavioral targeting
- Other AI Features as described in the applicable Product and Services Guide at docs.acquia.com
This Policy applies to all users who access or interact with AI Features, whether as employees, contractors, or authorized representatives of a subscribing organization ("Customer"), or as individual users of Acquia's platforms. Acquia Customers are responsible for communicating this Policy to their end users, such as by incorporating it into their acceptable use policy and/or privacy policy.
Your use of AI Features is also governed by:
- Acquia's Subscription and Services Agreement (or the applicable agreement between your organization and Acquia)
- The product-specific terms within each relevant Product and Services Guide at docs.acquia.com/guide
- Acquia's Privacy Policy at acquia.com/about-us/legal/privacy-policy
By using AI Features, you agree to this Policy. If you do not agree, you must not use AI Features. Contact your Acquia account team if you have questions about applicability or scope.
1. User Responsibilities
a. Respectful and Authorized Use
AI Features must only be used for lawful, authorized purposes consistent with your subscription and your organization's policies. Users are expected to interact with AI Features responsibly and professionally. The following uses are strictly prohibited:
- Harmful or offensive content: Generating content promotes any activity that is illegal or that violates the rights of others, is harmful to others, or is harmful to our operations or reputation, including (i) disseminating, promoting or facilitating child pornography, (ii) offering or disseminating fraudulent goods, services, schemes, or promotions, (iii) make-money-fast schemes, ponzi and pyramid schemes, (iv) phishing, or pharming, or (v) threatening, inciting, promoting, or encouraging hate speech, harassment, discrimination, or violence based on race, ethnicity, nationality, religion, gender, sexual orientation, disability, or any other protected characteristic.
- Offensive use: Creating content that is defamatory, obscene, abusive, invasive or privacy, or otherwise objectionable, including content that constitutes child pornography.
- Deceptive or fraudulent use: Creating or distributing disinformation, deepfakes intended to deceive, fake reviews, impersonation of real people or organizations, or AI-generated content designed to mislead customers or the public.
- Privacy violations: Using AI Features to surveil, profile, or monitor individuals without appropriate authorization, or processing data in ways that are inconsistent with your organization's data governance policies and applicable legal obligations.
- Intellectual property infringement: Reproducing, republishing, or creating derivative works from third-party copyrighted or trademarked content without authorization.
- Security attacks and system abuse: Generating malware, viruses, Trojan horses, worms, time bombs, cancelbots, exploit code, or phishing content; attempting to reverse-engineer, jailbreak, or circumvent Acquia's AI safety controls; or conducting prompt injection attacks.
- Violation of Acquia's terms: Any use that violates Acquia's Subscription and Services Agreement, applicable Product and Services Guides, or other Acquia policies.
b. Human Oversight and Accountability
AI Features are designed to assist human judgment — not replace it. You are responsible for all content, decisions, and actions that result from your use of AI Features, regardless of whether AI assisted in producing them. Before relying on AI-generated outputs, you should apply meaningful human review, particularly when:
- Publishing content to a public-facing website, product, or channel
- Sending customer-facing communications that were substantially AI-generated
- Making significant business decisions informed by AI analysis or recommendations
Important: AI outputs can be inaccurate, incomplete, or biased. Always verify factual claims, statistics, and citations before use. You are accountable for what you publish or decide. Acquia has no liability for any output generated.
c. Transparency
Users are expected to be transparent about the use of AI Features, especially when using AI-generated outputs in a public or high-stakes context. You should not present AI-generated content as human-created without meaningful human contribution and review. Depending on your jurisdiction, industry, and context, you may have obligations to disclose AI involvement in certain content — you are responsible for understanding what those requirements are for your organization.
d. Compliance with Laws
Users must comply with all applicable laws and regulations when using AI Features. Acquia does not provide legal or regulatory compliance advice. The regulatory landscape for AI is evolving and varies by jurisdiction and sector. You are solely responsible for assessing and meeting your own compliance requirements. Consult your organization's legal counsel for guidance specific to your situation.
e. Third-Party Rights
Be respectful of others' rights. Do not use AI Features to plagiarize third-party content, infringe intellectual property rights, or create content that misappropriates another party's work. AI-generated content may inadvertently resemble existing works; review outputs for potential similarity issues before commercial use or publication. You, and not Acquia, are responsible for any potential violation of third-party property rights.
2. Transparency, Accountability, and Limitations of AI
a. Transparency
Users are expected to be transparent about the use of AI Features, especially in public, customer-facing, or formal contexts. Acquia encourages responsible disclosure when AI has materially shaped a deliverable or communication.
b. Accountability
Users are ultimately responsible for their use of AI Features and for any outputs produced. This includes content published, decisions made, and any resulting harm, regardless of whether AI assisted in the process.
c. Good Judgment, No Professional Advice, and the Limitations of AI
Important: AI is rapidly advancing, but is limited by its design, training data, and infrastructure. Users should understand these limitations and exercise good judgment.
AI-generated outputs may contain errors, hallucinations, outdated information, or reflect biases present in training data. Always verify critical information from authoritative independent sources before relying on it.
3. Data Collection and Use
a. Data Logging
User interactions with AI Features may be logged to enhance system performance and accuracy, support quality assurance, and for safety monitoring purposes, as described in the applicable Product and Services Guide and Acquia's Privacy Policy.
b. Data Input Principles
Before inputting any data into AI Features, consider its sensitivity and whether its use is appropriate given the context. Aside from the baseline data security rules found in 3(c) below, Acquia does not prescribe what data you may or may not process — that determination is governed by your own organization's data governance policies, your applicable legal obligations, and the terms of your agreement with Acquia.
If your organization has an internal AI acceptable use policy or data classification framework, you should follow it when deciding what to submit to Acquia AI Features. If you are unsure whether a particular use is appropriate, consult your organization's legal, privacy, or compliance team before proceeding.
Your organization's AI policies apply. What data you input and how you use the outputs are decisions governed by your own organization's acceptable use policies, internal AI guidelines, and legal obligations. Acquia is not in a position to provide legal advice about those obligations and cannot be held responsible if an input or use violates your company’s internal AI guidelines or relevant law
c. Data Handling Principles
- Use AI Features in a manner consistent with your organization's internal AI and data governance policies
- Be thoughtful about the sensitivity of information you input — consider whether it is appropriate to submit given the context and purpose
- Use enterprise accounts with your organizational credentials to ensure data is covered by Acquia's contractual and security controls
- Promptly report any suspected data leakage, unintended output of sensitive information, or privacy incidents involving AI Features to [email protected]
d. Data Masking and Obfuscation
Acquia makes efforts to protect user data through appropriate technical and organizational measures. Details are set out in the applicable Product and Services Guide and Acquia's DPA.
e. Data Retention
Data is retained for a limited period and processed in accordance with Acquia's Data Processing Agreement (DPA). Acquia does not use your inputs to train third-party foundation models for use by other customers. However, Acquia may use your inputs in aggregated, anonymized format to train other AI features, solutions, and tools, such as Acquia’s support system.
4. Security
a. Account Security
Users must access AI Features using their enterprise or organizational account credentials. Do not use personal or consumer-grade accounts for business-related use of AI Features. Ensure your account is protected with strong, unique credentials and enable multi-factor authentication where available.
b. Prohibited Security-Related Activities
- Do not attempt to extract, reconstruct, or reverse-engineer training data or model weights through adversarial prompting techniques
- Do not use AI Features in ways designed to circumvent Acquia's content moderation, safety filters, or access controls
- Do not generate malware, exploit code, phishing content, or other malicious artifacts using AI Features
c. Reporting Security Concerns
Report any security vulnerabilities, unexpected behaviors, or suspected prompt injection attacks to [email protected]. For urgent security incidents, contact Acquia Support at acquia.my.site.com and mark the ticket as high priority.
5. Intellectual Property
a. Ownership of AI-Generated Outputs
As between Acquia and Customer, outputs generated through your use of AI Features in connection with your subscription ("AI Outputs") are owned by Customer, subject to the underlying subscription terms, any third-party rights in content you input, and applicable law.
Note on copyright: AI-generated text, images, and code may not be independently copyrightable under current law in many jurisdictions. For content requiring strong IP protection, ensure meaningful human authorship and creative contribution is documented. Acquia does not provide legal advice on IP matters — consult your own counsel.
b. Third-Party Intellectual Property
- Do not input third-party copyrighted content in ways that would infringe copyright (e.g., submitting full-text articles or licensed media for wholesale reproduction)
- Do not use AI Features to create content that infringes trademarks, trade dress, or other IP rights of third parties
- Be aware that AI-generated content may inadvertently resemble existing copyrighted works; review outputs before publication or commercial use
c. Open Source
If you use AI Features to assist with software development involving open-source licensed materials, you are responsible for reviewing and complying with applicable open source licenses. Acquia does not warrant that AI-generated code is free of open source license obligations.
6. Agentic AI and Automated Workflows
Certain Acquia AI Features include agentic capabilities — meaning they can take sequences of actions autonomously, such as publishing content, modifying assets, triggering workflows, or interacting with external systems. These capabilities require heightened care.
a. Requirements for Agentic Use
- Every agentic workflow should have a named human owner accountable for its behavior and outputs
- Configure agentic features that can take irreversible actions (e.g., publishing content, deleting assets, sending communications) with appropriate human approval checkpoints
- Before enabling agentic features in production, test thoroughly in a non-production environment and review the permissions granted
- Apply the principle of least privilege: grant agentic AI only the permissions necessary for the specific workflow
- Monitor agentic workflows regularly and establish alerting for unexpected behavior
b. Prohibited Agentic Uses
- Do not configure agentic AI to take fully autonomous actions that could cause significant harm if they malfunction — including mass publishing to live sites, bulk deletion of assets, or customer communication at scale without human review
- Do not grant agentic AI access to systems or data beyond what the specific workflow requires
7. Monitoring and Compliance
a. Monitoring
Acquia reserves the right to monitor the usage of AI Features to ensure compliance with this Policy, address security concerns, and investigate suspected violations, consistent with applicable law, privacy obligations, and the terms of the applicable subscription agreement.
b. Auditing
Periodic reviews may be conducted to assess compliance with this Policy and identify areas for improvement in privacy, security, and data handling practices related to AI Features.
c. Enforcement
Violations of this Policy may result in suspension or revocation of access to AI Features, restriction or termination of subscription to affected products, and, where violations result in data breaches, IP infringement, or other harm, legal action and reporting to applicable regulatory authorities.
8. Reporting Concerns
If you encounter harmful AI outputs, a suspected privacy incident, a security concern, or a suspected violation of this Policy, please report it promptly:
- Privacy matters: [email protected]
- Security matters: [email protected]
- General AI policy concerns: via your Acquia account manager or the support portal at acquia.my.site.com
9. Regulatory Context
Informational only — not legal advice. The regulatory landscape for AI is evolving rapidly and varies by jurisdiction and industry. The information below is provided for general awareness only. Acquia does not represent that compliance with this Policy satisfies any specific legal or regulatory obligation. You are solely responsible for assessing and meeting your own compliance requirements, and should consult your legal counsel for guidance specific to your organization.
Your use of Acquia AI Features may be subject to a range of laws and frameworks depending on your location, industry, and use case. These may include, without limitation:
|
Regulatory Area
|
Why it may be relevant
|
|---|---|
|
EU AI Act |
Regulation of AI systems by risk classification; may impose obligations depending on use case and risk tier for organizations deploying AI in the EU |
|
GDPR / CCPA / CPRA and other privacy laws |
Data protection obligations when AI Features process personal data; specific requirements vary by jurisdiction |
|
FTC Act and guidance |
US rules on deceptive and unfair practices; may apply to AI-generated content and consumer-facing communications |
|
Sector-specific regulation |
Financial services, healthcare, education, and government organizations may face additional AI-specific obligations from their regulators |
|
NIST AI RMF / ISO 42001 |
Voluntary frameworks for AI risk management widely referenced in enterprise governance programs |
|
Why it may be relevant
|
|---|
|
EU AI Act |
Regulation of AI systems by risk classification; may impose obligations depending on use case and risk tier for organizations deploying AI in the EU |
|
GDPR / CCPA / CPRA and other privacy laws |
Data protection obligations when AI Features process personal data; specific requirements vary by jurisdiction |
|
FTC Act and guidance |
US rules on deceptive and unfair practices; may apply to AI-generated content and consumer-facing communications |
|
Sector-specific regulation |
Financial services, healthcare, education, and government organizations may face additional AI-specific obligations from their regulators |
|
NIST AI RMF / ISO 42001 |
Voluntary frameworks for AI risk management widely referenced in enterprise governance programs |
This list is illustrative, not exhaustive.
10. Limitations of AI Features
a. Accuracy
While Acquia strives for quality, AI Features may occasionally produce incorrect, incomplete, or outdated information. AI-generated outputs may contain factual errors, reflect biases in training data, or misinterpret context. Users should verify critical information from reliable, authoritative sources before relying on AI outputs.
b. Scope of Knowledge
AI models have knowledge cutoff dates and may not reflect recent events, regulatory changes, or market developments. Product-specific information about model versions and knowledge currency is available in the applicable Product and Services Guide at docs.acquia.com.
c. No Professional Advice
AI Features are not intended to provide medical, legal, financial, or any other professional advice and should not be used for that purpose. Information entered into AI Features is not protected by professional privilege or confidentiality protections.
11. Changes to Policy
Acquia reserves the right to change this Policy and other product documentation based on prevailing market practices and the evolution of our products. Material changes will be communicated via notice on the Acquia legal page at acquia.com/about-us/legal and, where appropriate, through direct communication to your account team. Continued use of AI Features following notice of an update constitutes acceptance of the revised Policy.
12. Contact
For questions about this Policy or Acquia's AI Features, contact your Acquia account manager or visit the support portal at acquia.my.site.com. For product documentation and Product and Services Guides, visit docs.acquia.com.