A policy nobody can remember is an expensive piece of wallpaper. Directors need to know what the rules mean at the moment somebody opens a chatbot, uploads a document or sends an AI-assisted answer to a customer. Bespoke AI policy training uses your organisation's own draft rules and your own work, so the board leaves with decisions rather than a reading list.
Good AI policy training for directors takes the organisation's own draft rules and rehearses them against realistic work scenarios. Directors leave knowing who can approve a tool, what information is permitted, when a person must check the output, how staff raise a concern and when the policy will be reviewed.
Why directors need AI policy training, not just an AI policy
Many organisations now have an AI policy. Far fewer have directors who could explain, on the spot, what it means for a real situation. That gap matters, because staff take their lead from what managers do, not from what a PDF says.
Directors also carry the accountability. UK company directors already owe a duty to exercise reasonable care, skill and diligence under section 174 of the Companies Act 2006, and personal data used in AI tools remains subject to UK data protection law. AI does not create a new board; it adds a new set of everyday decisions the existing board is responsible for.
Bespoke training closes the gap by turning the policy into practised judgement. It also tends to expose the vague sentences that sounded fine in a draft and mean nothing in practice.
- 01Bring the real policyOr admit there isn't one.
- 02Use real scenariosOrdinary risks, named actions.
- 03Set the boundariesTools, data, review.
- 04Name the ownersApprove, review, escalate.
- 05Rehearse and reviewExplain it back, then revise.
How should directors be trained on an AI policy?
1. Bring the policy people actually have
Use the existing policy, procurement rules, data guidance and approved-tool list. If nothing exists, say so plainly and start with an interim set of working questions. Do not pretend a glossy document has already been agreed.
Highlight the rules staff could act on tomorrow and mark every vague phrase that needs an owner. “Use AI responsibly” is a sentiment. “Do not paste client personal data into tools not on the approved list” is a rule.
Policy review prompt to try
Here is our draft AI policy. Identify every sentence a member of staff could not act on without asking someone, every rule with no named owner, and any gaps around personal data, client confidentiality, approved tools and human review. Present the findings as a table. Do not rewrite the policy.
Check your progress
2. Give each risk an ordinary example
Use realistic scenarios: a staff member pastes a client email into a public tool; a manager accepts an AI answer without checking; a team uses AI to summarise sensitive HR material; a salesperson sends an AI-written proposal with an invented statistic. Make the group decide what happens next.
For each scenario, name the first safe action, who owns the decision and what gets recorded. Disagreement among directors here is useful. It shows exactly where the policy needs clearer words.
Check your progress
3. Set boundaries by task and information
Explain which tools are approved, what information must stay out, when anonymisation is useful and where human review is required. “Be sensible” is not an access control. Give people a route to ask before they guess.
A one-page traffic-light guide works well: green tasks anyone can do with approved tools, amber tasks that need anonymised data or a reviewer, and red tasks that stay human or need director sign-off. Build it from your own work and information categories, not someone else's template.
Check your progress
4. Assign decisions to named people
Decide who approves a new tool, who reviews high-impact use, who maintains the policy and who answers staff questions. Directors keep appropriate oversight; a policy should not make every routine draft wait for the board.
Add a name or role beside every approval, exception and escalation route. If two directors both think the other one owns it, nobody does.
Check your progress
5. Rehearse, revise and schedule a review
Run the scenarios again after explaining the rules. Listen for reasonable disagreements; they reveal where the language needs work. Set a review date and the triggers for revisiting the rules early, such as a new tool, a new type of data or an incident.
Ask a member of staff to explain the rules back using one example. If they cannot, improve the explanation before adding another page.
Staff explainer prompt to try
Using our final AI policy, write a one-page plain-English explainer for staff with no technical background. Include five short do and don't examples based on everyday office work, who to ask when unsure and how to report a mistake. Keep it under 400 words.
Check your progress
What should a director-level AI policy cover?
A practical map of the decisions directors usually need to make, and what bespoke training should rehearse for each.
| Policy area | The director's decision | What training should rehearse |
|---|---|---|
| Approved tools | Which tools and accounts staff may use for work | How a new tool gets requested and approved |
| Information boundaries | What data can and cannot go into each tool | Spotting personal, confidential and client data |
| Human review | Where a person must check output before use | What a proper check looks like, by task |
| Accountability | Who owns approvals, exceptions and incidents | Escalation routes for real scenarios |
| Transparency | When customers or clients are told AI was used | Plain wording for disclosure |
| Review | When and why the policy is revisited | Triggers for an early review |
A practical summary, not legal advice. Take tailored professional advice where your organisation's regulatory position requires it.
Try the “would we be happy to explain this?” check
For every proposed AI use, ask: what is the task, what information goes in, what comes out, who checks it, who is accountable and how could a person challenge it? If a director cannot answer, pause the use and assign the missing decision.
Run this check on the three ways AI is already being used in your organisation, because it almost certainly is. Calm governance now is far more useful than panic after an incident.
Bespoke AI policy training for your board
Our AI Policy Workshop works through your own draft rules and scenarios with directors and managers. Before the session, read how to write an AI policy, our AI governance framework for UK businesses and the guide to AI usage policies for small businesses. You can also download our AI acceptable use policy template as a starting draft.
Based in Witney, Oxfordshire, we deliver in person across the UK and live online. Take the free two-minute AI skills assessment to see where your team stands.
Book bespoke policy trainingBespoke AI Policy Training for Directors: frequently asked questions
What is bespoke AI policy training for directors?
A practical session built on an organisation's own draft policy, work examples, tools and decision routes. Directors rehearse how the rules apply to real scenarios and identify gaps for the right owner to resolve.
Does AI policy training make a business compliant?
Training supports understanding and consistent practice, but it cannot by itself guarantee compliance or replace tailored legal or professional advice where an organisation needs it.
Who should attend AI policy training?
Directors or trustees, the person responsible for the policy, relevant operational leads and some of the staff who will use the tools. Include information governance or legal colleagues where appropriate.
How often should an AI policy be reviewed?
Set a planned review date and revisit the policy early when the organisation changes its tools, tasks, data use or approval arrangements, or after an incident. Name the person responsible for spotting those triggers.
Are directors personally responsible for how staff use AI?
Directors are responsible for the oversight of the company, including reasonable care, skill and diligence in how it operates. That includes setting sensible rules and checking they work. Take legal advice on your specific position.
Sources and further reading
- legislation.gov.uk: Companies Act 2006, section 174, duty to exercise reasonable care, skill and diligence
- ICO: Artificial intelligence guidance for organisations
Sources and programme links checked on 6 October 2026.
