Policy template

AI usage policy template (UK)

A short, plain-English AI usage policy you can copy, adapt and publish this week. Written for UK businesses without a legal department, with a note under each clause explaining what it's actually for.

Last reviewed: August 2026

Before you copy it

A policy is only useful if it matches what your business actually does. Fill in every square-bracketed field, delete anything that doesn't apply to you, and name a real person as owner. A policy with "[named owner]" still in it is worse than no policy — it shows nobody read it.

  • Decide who owns AI in the business. One person, by name.
  • List the AI tools already in use before you write the approved list, not after.
  • Circulate it to staff and get a written acknowledgement — an email reply is fine.
  • Diarise the six-month review.

Why the order matters

Staff read the first two clauses and skim the rest. That's why "what you must never put into an AI tool" sits near the top rather than buried in an appendix.

The template

1. Purpose and scope

This policy sets out how staff at [Company name] may use artificial intelligence tools in their work. It applies to all employees, contractors and temporary staff, and covers any AI tool used for company purposes — whether provided by the company or signed up to individually.

Why it's here: Free personal accounts are where most uncontrolled AI use happens. Saying the policy covers them closes the biggest gap.

2. Approved tools

Only AI tools on the approved list maintained by [named owner] may be used for company work. To request a new tool, contact [named owner] before using it. The current approved list is available at [location].

Why it's here: You cannot assess a tool you don't know about. An approval route that takes a day is what stops staff from routing around the policy.

3. What must never be entered into an AI tool

Do not enter the following into any AI tool unless it is on the approved list and specifically cleared for that data type: customer personal data, employee personal data, health information, financial account details, login credentials, confidential client material, unpublished commercial information, or anything covered by a non-disclosure agreement.

Why it's here: This is the clause that prevents the most common real-world incident: pasting a client document into a public chatbot.

4. Human responsibility for output

AI output is a draft, never a final answer. The member of staff using the tool remains responsible for anything they send, publish or act on. Check facts, figures, names, legal points and calculations before use.

Why it's here: Accountability sits with your business, never the vendor. Staff need to hear that plainly.

5. Decisions about people

AI tools must not be used to make a final decision about an individual — including hiring, promotion, pay, discipline, pricing, credit or eligibility — without meaningful review by a person who has the authority and information to reach a different conclusion. Any such use must be approved in advance by [named owner] and recorded.

Why it's here: This maps directly to UK GDPR's rules on automated decisions and to the Equality Act. It is the clause a regulator will look for first.

6. Transparency with customers

Where AI is used in a way that affects customers, this must be reflected in our privacy notice and, where appropriate, disclosed to the customer. Do not present AI-generated content as the work of a named individual where that would mislead.

Why it's here: Transparency is an explicit ICO expectation and increasingly a contractual requirement in customer due diligence.

7. Reporting problems

If an AI tool produces a harmful, discriminatory or seriously inaccurate output, or if confidential data has been entered into a tool by mistake, report it to [named owner] immediately. Reporting a mistake promptly will not result in disciplinary action; concealing one may.

Why it's here: You need incidents to surface. The no-blame wording is what makes that happen in a small team.

8. Review

This policy is owned by [named owner] and will be reviewed at least every six months, or sooner if our AI use or the relevant regulations change. Version [1.0], dated [date].

Why it's here: An undated policy with no owner reads as decoration. A date and a name make it evidence.

What a policy does not do

A usage policy tells your staff what to do. It does not, on its own, satisfy UK GDPR. For that you also need a record of which tools you use, a lawful basis for each one that touches personal data, an updated privacy notice, and a written impact assessment for anything that influences a decision about a person.

If you'd rather not assemble that by hand, our free check produces a register and risk rating for each tool, and generates the policy and impact assessment already populated with your company details.

See where your own AI use actually stands

Register the AI tools your team uses and get a risk rating for each one, in plain English. Free, and it takes about ten minutes.

Not legal advice. This guide explains how the rules are generally understood and is here to help you get organised. It isn't a substitute for advice from a qualified solicitor or your own compliance team.