What should an AI acceptable use policy include?
Approved tools, data rules, human review, client disclosure and a named contact for questions. Keep it short enough that staff actually read and follow it.
Short beats comprehensive
A two-page policy that staff read and remember does more than a twenty-page document filed and forgotten. There is no UK legal requirement to have a standalone AI policy. However, UK GDPR accountability duties require you to be able to show how you handle personal data, including in AI tools, and a short, clear policy is one of the simplest ways to do that.
Write it for the person at their desk deciding whether to paste a document into a chatbot. If they cannot find the answer in under a minute, the policy is too long.
The five sections that matter
Approved tools: List the specific tools and versions staff may use for work, and say which are off limits. Update the list as you approve new tools so it never goes stale.
Data rules: Set out what can and cannot go into each tool, using simple categories such as client personal data, confidential commercial information and public material. Tie this to your position on client data and UK GDPR.
Human review: State that a person checks AI output before it is used, sent or relied on, and that the person who sends it owns it. Be specific about higher-risk outputs such as advice, figures and anything contractual.
Disclosure to clients: Decide when you tell clients that AI helped produce work, and how. Some clients have their own rules, so check contracts and ask where it is unclear.
Who to ask: Name a person, not a department, for questions and new tool requests. A fast route to a yes reduces the temptation to work around the policy.
What else to include
Purpose and scope: One paragraph on why the policy exists and who it covers. Include contractors and freelancers if they use your systems or client data.
Reporting mistakes: Tell staff how to report a data slip or a bad output, and make clear that early reporting will not be punished.
Review date: AI tools change quickly, so set a fixed review date. Every six months is a sensible starting point for most SMEs.
Why policies fail
Most AI policies fail for one of three reasons.
No training: Staff skim the document once and never connect it to their daily work. Short, practical sessions using real examples from your business make the rules stick.
No owner: Without a named person accountable for keeping it current, the approved tools list falls out of date and staff stop trusting it.
Too restrictive: A policy that bans everything useful creates shadow AI, with staff quietly using personal accounts instead. Make the approved route easier than the workaround.
Before you publish it
Test the draft with the two or three people who use AI most in your business. Ask them what they would do in a few real scenarios, such as summarising a client email or drafting a proposal, and fix anything they find unclear. Then brief the whole team in person rather than relying on an email.
If you work in a regulated sector or handle sensitive client information, take advice on your own situation so the policy reflects your specific obligations.
More questions
