New module · AI Policy & Compliance

The AI Policy Workshop: decide how your team uses AI before they decide for you.

Someone in your business pasted a client email into a chatbot last week. Nobody signed anything, nobody agreed it was allowed. The AI Policy Workshop is a one-day session for UK small businesses that trains your people to use AI safely and sends you home with your own written AI acceptable use policy. Not a plan to write one. The actual document.

Owners & directors SMEs Sole traders HR & ops Finance Marketing
The workshop

Why every UK business needs an AI policy, and why one page is enough.

An AI acceptable use policy is one plain-English page that tells your staff which AI tools they can use, what they can use them for, and what must never go anywhere near a chatbot. It is the difference between AI helping your business and AI quietly leaking it.

Most small businesses learn how to use AI and never stop to decide how their team should use it. So people improvise. One person drops a customer list into ChatGPT to tidy it up. Another sends a client a quote the AI wrote and nobody checked. It works fine, right up until the day it doesn't.

This is a practical day on implementing AI in a small business without the compliance headache. We look at the tools worth using, the jobs AI should and shouldn't do, and the lines your team must not cross under UK GDPR. Then we write the policy with everyone in the room, so it fits how you actually work rather than sitting in a drawer.

It is built for owners, directors and the people who do the work, from sales and marketing to finance, HR and operations. You leave with your tools agreed, your rules by department set, your gatekeepers named, and a finished AI acceptable use policy your staff can follow on Monday morning.

If your team already knows the tools and wants to go deeper on one discipline, look at AI for Marketing Teams or Intro to GEO. This day is the one that sets the ground rules underneath all of them.

Half a day of admin now, or a very bad afternoon later. Your choice.

The short version

AI training teaches your team to use AI. An AI policy tells them how far to go.

Most training covers the first. Almost nobody covers the second. This workshop does both, because the risk lives in the gap between them.

Using AI

The skill everyone's chasing

Prompting, drafting, summarising, getting real work done faster. Useful, and most of your team is already having a go, with or without you.

Governing AI

The bit that keeps you safe

Deciding the tools, the rules and the red lines, so all that speed doesn't come with a data leak, a GDPR breach or a client email the AI wrote and nobody read.

On the day

How to write an AI policy in a day: the workshop schedule.

One focused day, four sessions and a proper lunch. You walk out at the end with the policy written, not promised.

01

Where you are now, and what could go wrong

Theory Morning

An honest look at what's already happening, and the risks nobody has priced in yet.

  • A frank audit of which AI tools your team already uses, sanctioned or not
  • The real risks in plain terms: data leaks, poor output, reputation, legal exposure
  • Where UK GDPR and the Data (Use and Access) Act 2025 actually touch your day-to-day AI use
  • The single most expensive mistake SMEs make with public AI tools, and how to sidestep it
02

Tools, processes and the approved list

Practical Late morning

Agreeing what you allow, what you don't, and exactly which jobs AI does here.

  • Pick the AI tools your business allows, and the ones it doesn't, with reasons that hold up
  • Choose the best AI tools for your UK small business: Claude, ChatGPT, Copilot and where each earns its place
  • Decide the exact jobs AI does, from drafting to summarising to checking
  • Set the golden rule: AI drafts, a person decides, and nothing leaves the building on the machine's say-so
Lunch
03

Rules by department, and the lines nobody crosses

Theory Early afternoon

Marketing's freedom is finance's nightmare, so each team sets its own limits.

  • Each team defines its own good use and its own red line, from sales to finance to HR
  • Set the firm protocols everyone follows, every time, whatever their role
  • Draw the data red line for UK GDPR: exactly what never goes into a public AI tool
  • Work through the awkward cases: client data, candidate data, financial data, AI-generated content
04

Gatekeepers, policy and sign-off

Practical Afternoon

The part where it stops being a conversation and becomes a document.

  • Name your gatekeepers: the people who approve new tools and answer the hard questions
  • Draft the one-page AI acceptable use policy together, in plain English
  • Build the habits that keep the policy alive past day one
  • Agree it, set a review date, and decide who rolls it out to the rest of the team
Take it away

The AI policy checklist: your AI acceptable use policy template.

Seven sections, and you have an AI policy for your UK business. This is the exact structure we build with you on the day, and it doubles as an AI policy template for a UK small business.

1

Purpose & scope

  • Two lines on what the policy is for
  • Who it covers: staff, contractors, freelancers
  • When it applies: work devices, personal devices, client work
2

Approved tools

  • The AI tools your business allows
  • The ones that are banned, with a short reason
  • Which tier is required: free, business or enterprise
  • Nothing off-list without a gatekeeper's yes
3

What AI is for

  • The jobs AI does here: drafting, summarising, research
  • The jobs it never does alone: final decisions, sign-off
  • A human checks the output before it goes anywhere
4

The data red line (UK GDPR)

  • What must never be entered into a public AI tool
  • Customer, staff and candidate personal data
  • Financial, health and contract data
  • How to anonymise data before any AI use
5

Rules by department

  • Each team gets its own fair-game and off-limits list
  • Match the freedom to the risk: marketing differs from finance
  • A named point of contact for each department
6

Gatekeepers & approval

  • The AI lead who approves new tools
  • The data owner who guards the red line
  • How staff ask "can I use this?" and get an answer
7

Review, training & sign-off

  • A review date, because the tools keep moving
  • How new starters are trained on the policy
  • Who signed it off, and when it takes effect

You leave with it done

  • All seven sections finished on the day
  • Tailored to your business, not a blank template
  • Ready to circulate to your team on Monday

Golden rule running through every section: AI drafts, a person decides. Nothing leaves the building on the machine's say-so alone.

One size fits nobody

AI policy rules, department by department.

Give the whole business one blanket rule and you either strangle marketing or expose finance. On the day, each team agrees its own green light and its own red line. Here's the starting point.

AI policy rules by department: what is fair game and what is off limits
DepartmentFair gameOff limits
SalesDrafting outreach, summarising calls, prepping for meetingsReal customer data in public tools. Auto-sent quotes
MarketingContent drafts, campaign ideas, image mockups, editingPublishing unchecked. Passing off AI images as real photos
FinanceExplaining reports, drafting policies, spotting anomaliesLive financial or bank data. Final numbers without a human
HRJob specs, policy drafts, interview question setsCandidate or staff personal data. Hiring or firing calls
OperationsProcess notes, supplier emails, rota first draftsAnything with names, health or contract data attached

Swipe the table sideways to see the off-limits column.

The approved shortlist

Best AI tools for UK small businesses, and the tier each one needs.

Fewer tools, used well, beats a drawer full of half-learned apps. We help you pick the shortlist and set the tier each one needs to stay on the right side of GDPR.

Claude

The thinking tool

Writing, analysis, drafting, summarising and planning, with Anthropic's AI.

ChatGPT

The all-rounder

General tasks and quick answers. Use the business tiers for anything sensitive.

Microsoft Copilot

The Microsoft one

AI inside Word, Excel, Outlook and Teams, with enterprise-grade security for Microsoft 365.

Google Gemini

The Workspace one

Plugged into Gmail, Docs and Workspace for teams already living in Google.

Canva AI

The design tool

Graphics, social posts and simple brand work, no designer required.

Your approved list

Decided together

Whatever fits your business. On the day, we write it down and set the rules.

Who should be in the room

Who the AI Policy Workshop is for.

A policy written by one person in a back office gets ignored. A policy the team helped write gets followed. Bring the people who actually use the tools. Small enough to decide things, broad enough that nobody feels done to.

The owner or MD One person per department Whoever handles IT & data Your resident AI sceptic HR Finance
What you leave with

Three things your business did not have this morning.

01

A written policy

Your own AI acceptable use policy, finished on the day, in plain English a new starter can follow in five minutes.

02

A team that gets it

Staff who know which tools to use, what AI is for, and the data that must never go near a chatbot.

03

A clear conscience

The rules agreed, the gatekeepers named and a review date set, so AI is something you run rather than something that runs off with your data.

Questions

AI policy, UK GDPR and compliance, answered.

The questions UK small businesses ask us most about AI policy, GDPR and training staff to use it safely.

What should an AI policy include for a UK business?
Seven things: the tools you approve and ban; what AI is and isn't for; a data red line listing what must never go into a public AI tool under UK GDPR; named gatekeepers who approve new tools; rules that differ by department; a training approach for new starters; and a review date. For most SMEs, one page of plain English does the job. Our workshop builds all seven with you and you leave with the finished document.
How do I write an AI acceptable use policy for employees?
Start by finding out what tools your staff already use. Then agree an approved list, decide what AI is and isn't for, set a clear data red line for UK GDPR, name your gatekeepers and set rules by department. Keep it to one page a new starter can read in five minutes. You can follow the seven-part checklist on this page, or join the workshop and leave the same day with it written for your specific business.
Can my staff use ChatGPT for client data under UK GDPR?
Not safely in the public version. Drop identifiable client or personal data into a public AI tool and you lose control of where it goes and how it's processed, which can put you in breach of UK GDPR. The safer routes are a business or enterprise tier with a data processing agreement in place, anonymising the data first, or keeping personal data out of public tools entirely. Your policy should make that a firm, written rule everyone understands.
What is the Data (Use and Access) Act 2025 impact on AI?
The Data (Use and Access) Act 2025 got Royal Assent on 18 June 2025, with most of it rolling out through 2026. It amends UK GDPR rather than replacing it. The change most relevant to AI relaxes the rules on solely automated decision-making, allowing a wider range of lawful bases as long as you build in meaningful human review and safeguards. It does not change UK copyright law, but it sets a roadmap for future reform. In short: if AI helps make decisions about people, keep a human in the loop and write it down. This is general information, not legal advice.
Who owns the copyright of AI-generated content in the UK?
It's genuinely unsettled. Under current UK law a purely computer-generated work with no human author can be protected for 50 years, credited to the person who made the arrangements for creating it. Where a human adds little original input, protection is uncertain and may not apply at all. For business use, treat AI output as a draft you review and adapt, keep a record of your own contribution, and check the terms of the tool you use, because some grant you rights to the output and some don't.
How can I train my small business team to use AI safely?
Pair practical training with a written policy. Training alone leaves people guessing at the rules, and a policy alone gets ignored if nobody knows how to follow it. Show staff the approved tools, the exact jobs AI should and shouldn't do, and the data that must never go near a public tool. The AI Policy Workshop does both in a single day, so people leave knowing the rules and how to work within them.
What is an AI policy template and how do I make one?
An AI policy template is a reusable structure for your acceptable use policy: purpose, approved tools, what AI is for, the data red line, rules by department, gatekeepers and a review date. You make one by working through each section with the people who actually use AI in your business, so the rules fit how you really work. The checklist on this page is a ready-made template. The workshop goes further and delivers your own completed AI policy document, tailored to your business, rather than a blank form you still have to fill in.
How much does the AI Policy Workshop cost and how long is it?
It's a full day for up to 10 people. £2,499 +VAT delivered virtually, or £2,599 +VAT in person across Oxfordshire and the UK. Your finished AI policy document, the takeaway checklist and 30 days of follow-up are all included. Bigger group or more than one site? Get in touch and we'll price it properly.
Decide it on purpose

Book your team's day on AI policy.

A 10-minute intro call first. Tell us how your team is using AI and where you're nervous, and we'll tailor the day to your business, your tools and your risks.