What is an AI policy?
An AI policy is a short set of rules for how your people use AI tools such as ChatGPT or Microsoft 365 Copilot: which tools are allowed, what must never go in, and who checks the results. Some call it an AI acceptable use policy.
Does a business need an AI policy?
If anyone uses ChatGPT, Copilot or a similar tool for work, yes. Without one, each person decides what to paste in, customer details and confidential documents included. A short signed policy settles that and shows you've thought about the risks.
What should an AI policy include?
A useful AI policy is short enough to read. It covers which tools are approved, what must never go in, what may go in with care, who checks AI work, when a new use needs a data protection impact assessment (DPIA), how to report a mistake and when the policy is reviewed.
The template has a section for each and a sign-off table. The list of what must never go in matters most, so use your own examples.
Is an AI policy the same as an acceptable use policy?
Mostly. The acceptable use part tells staff what they may and may not do with AI tools, and that's most of this template. A fuller policy adds who owns AI decisions, how new uses are approved and how often the rules are reviewed.
The AI policy template
Fill in the parts in square brackets, and add the tools you approve to the table in section 3.
AI policy
Fill in the parts in square brackets, talk it through with your team, then ask everyone who uses AI at work to read and sign it. Review it at least every six months. It isn't legal advice.
- Business
- [Your business]
- Policy owner
- [Name, role]
- Approved by
- [Name, role]
- Date
- [DD/MM/YYYY]
- Next review
- [DD/MM/YYYY]
1Why we have this policy
AI tools can save us time on drafting, summarising and finding information. They can also get things wrong, and anything we type into them leaves our hands. This policy sets out which tools we use, what never goes into them, and who checks the results.
2Who it applies to
Everyone who works for or with [Your business] and uses an AI tool for our work, on any device, including contractors and temporary staff.
3The tools you may use
Use only the tools in this table, through the business account we set up. Don't use personal accounts for work. If you'd like to use another tool, ask [policy owner] first.
Tool [For example, Microsoft 365 Copilot] [Tool] [Tool] What it may be used for, Account, Approved by: filled in for each row in the Word file.
4What must never go into an AI tool
- Personal data about customers, staff or anyone else, unless the tool is approved for it in the table above and [data protection lead] has agreed.
- Health, financial hardship or other sensitive personal data.
- Client-confidential material, or anything covered by a confidentiality agreement.
- Passwords, access codes, bank details or card numbers.
- [Anything else specific to your business, such as prices or bids]
5What may go in, with care
- Your own drafts and notes with names and identifying details taken out.
- Public information, such as published guidance or your own website.
- Internal documents, in an approved tool that keeps each person to the files they can already open.
6Checking AI work
- A person checks every piece of AI work before it's used, sent or published.
- Check facts, figures, names, dates and quotes against the source. AI tools can state wrong things confidently.
- AI never makes decisions about people, such as hiring, pay or discipline. A person decides.
- If you can't check it, don't use it.
7New uses of AI
Before we start using AI for a new job that involves personal data, [data protection lead] decides whether we need a data protection impact assessment (DPIA). The ICO says most uses of AI with personal data need one.
8Being open about AI
Tell clients when AI has helped with work they'd expect to come from a person, such as advice or a report. Never present AI work as checked when it hasn't been.
9Mistakes and questions
If something goes into an AI tool that shouldn't have, or AI work goes out with a mistake, tell [contact] the same day. Ask [policy owner] if you're unsure about anything in this policy.
10Review
[Policy owner] reviews this policy every six months, or sooner if our tools or the law change.
11Agreement
I've read this policy and will follow it.
Name Role, Signed, Date: filled in for each row in the Word file.
Free to use and change.
How do you write an AI policy?
In six steps, starting with who already uses AI.
- Ask who uses AI now. A short, no-blame question to the team: which tools, for what, on which accounts.
- Choose the tools you'll approve. Set up business accounts for them, so work stays out of personal accounts.
- Fill in the template. Add your own examples of what must never go in, and name who checks AI work.
- Talk it through. Go through it at a team meeting and answer the questions people raise.
- Ask everyone to sign it. Keep the signed copies with your other policies.
- Review it in six months. Sooner if you add a tool or start using AI for a new kind of job.
How often should you review an AI policy?
At least every six months, and straight away if you add a tool, change supplier or use AI for a new kind of job, because AI tools change their features and terms often.
When a new use involves personal data, check first whether you need a DPIA.