What is an AI policy?
An AI policy is a short set of rules for how people at your business use AI tools such as ChatGPT or Microsoft 365 Copilot. It names the tools they may use, the information that must never go into them, and who checks the results before they're used. Some businesses call it an AI acceptable use policy.
Does a business need an AI policy?
If anyone at your business uses ChatGPT, Copilot or a similar tool for work, it's worth having one. Without it, each person decides what to paste in, including customer details and confidential documents. A short policy that people have read and signed removes that guesswork and shows you've thought about the risks.
What should an AI policy include?
Keep it short enough that people read it. A useful AI policy covers which tools are approved, what must never go in, what may go in with care, who checks AI work, when a new use needs a data protection impact assessment (DPIA), how to report a mistake and when the policy is reviewed.
The template has a section for each, plus a sign-off table. The part that matters most is the list of what must never go in, so write it with your own examples.
Is an AI policy the same as an acceptable use policy?
Mostly, yes. An AI acceptable use policy is the part that tells staff what they may and may not do with AI tools, and that's most of this template. A fuller AI policy adds who owns AI decisions, how new uses are approved and how often the rules are reviewed.
The AI policy template
This is the same policy as the Word file. Fill in the parts in square brackets, and add the tools you approve to the table in section 3.
AI policy
Fill in the parts in square brackets, talk it through with your team, then ask everyone who uses AI at work to read and sign it. Review it at least every six months. It isn't legal advice.
- Business
- [Your business]
- Policy owner
- [Name, role]
- Approved by
- [Name, role]
- Date
- [DD/MM/YYYY]
- Next review
- [DD/MM/YYYY]
1Why we have this policy
AI tools can save us time on drafting, summarising and finding information. They can also get things wrong, and anything we type into them leaves our hands. This policy sets out which tools we use, what never goes into them, and who checks the results.
2Who it applies to
Everyone who works for or with [Your business] and uses an AI tool for our work, on any device, including contractors and temporary staff.
3The tools you may use
Use only the tools in this table, through the business account we set up. Don't use personal accounts for work. If you'd like to use another tool, ask [policy owner] first.
Tool [For example, Microsoft 365 Copilot] [Tool] [Tool] What it may be used for, Account, Approved by: filled in for each row in the Word file.
4What must never go into an AI tool
- Personal data about customers, staff or anyone else, unless the tool is approved for it in the table above and [data protection lead] has agreed.
- Health, financial hardship or other sensitive personal data.
- Client-confidential material, or anything covered by a confidentiality agreement.
- Passwords, access codes, bank details or card numbers.
- [Anything else specific to your business, such as prices or bids]
5What may go in, with care
- Your own drafts and notes with names and identifying details taken out.
- Public information, such as published guidance or your own website.
- Internal documents, in an approved tool that keeps each person to the files they can already open.
6Checking AI work
- A person checks every piece of AI work before it's used, sent or published.
- Check facts, figures, names, dates and quotes against the source. AI tools can state wrong things confidently.
- AI never makes decisions about people, such as hiring, pay or discipline. A person decides.
- If you can't check it, don't use it.
7New uses of AI
Before we start using AI for a new job that involves personal data, [data protection lead] decides whether we need a data protection impact assessment (DPIA). The ICO says most uses of AI with personal data need one.
8Being open about AI
Tell clients when AI has helped with work they'd expect to come from a person, such as advice or a report. Never present AI work as checked when it hasn't been.
9Mistakes and questions
If something goes into an AI tool that shouldn't have, or AI work goes out with a mistake, tell [contact] the same day. Ask [policy owner] if you're unsure about anything in this policy.
10Review
[Policy owner] reviews this policy every six months, or sooner if our tools or the law change.
11Agreement
I've read this policy and will follow it.
Name Role, Signed, Date: filled in for each row in the Word file.
Free to use and change, with no email needed.
How do you write an AI policy?
Start by finding out who already uses AI and for what. Choose the tools you'll approve, set up business accounts for them, and fill in the template with your own examples of what must never go in. Then agree who checks AI work and who people tell when something goes wrong.
- Ask who uses AI now. A short, no-blame question to the team: which tools, for what, on which accounts.
- Choose the tools you'll approve. Set up business accounts for them, so work stays out of personal accounts.
- Fill in the template. Add your own examples of what must never go in, and name who checks AI work.
- Talk it through. Go through it at a team meeting and answer the questions people raise.
- Ask everyone to sign it. Keep the signed copies with your other policies.
- Review it in six months. Sooner if you add a tool or start using AI for a new kind of job.
How often should you review an AI policy?
Review it at least every six months, and straight away if you add a tool, change supplier or start using AI for a new kind of job. AI tools change their features and terms often, so a policy written a year ago may not match the tools your team uses today.
When a new use involves personal data, check whether you need a DPIA first. The DPIA template for AI projects covers it.