The Oxford AI School crest
AI Learning Hub · Job Specific AI Training · Choosing AI Training · Guide 03 of 08

Bespoke AI Policy Training for Directors: Make Your AI Rules Work in Real Life

A policy nobody can remember is expensive wallpaper. Five steps to rules your directors and staff can actually use.

A policy nobody can remember is an expensive piece of wallpaper. Directors need to know what the rules mean at the moment somebody opens a chatbot, uploads a document or sends an AI-assisted answer to a customer. Bespoke AI policy training uses your organisation's own draft rules and your own work, so the board leaves with decisions rather than a reading list.

The short answer

Good AI policy training for directors takes the organisation's own draft rules and rehearses them against realistic work scenarios. Directors leave knowing who can approve a tool, what information is permitted, when a person must check the output, how staff raise a concern and when the policy will be reviewed.

Why directors need AI policy training, not just an AI policy

Many organisations now have an AI policy. Far fewer have directors who could explain, on the spot, what it means for a real situation. That gap matters, because staff take their lead from what managers do, not from what a PDF says.

Directors also carry the accountability. UK company directors already owe a duty to exercise reasonable care, skill and diligence under section 174 of the Companies Act 2006, and personal data used in AI tools remains subject to UK data protection law. AI does not create a new board; it adds a new set of everyday decisions the existing board is responsible for.

Bespoke training closes the gap by turning the policy into practised judgement. It also tends to expose the vague sentences that sounded fine in a draft and mean nothing in practice.

Your step-by-step guideAI policy training for directors in five steps
  1. 01
    Bring the real policyOr admit there isn't one.
  2. 02
    Use real scenariosOrdinary risks, named actions.
  3. 03
    Set the boundariesTools, data, review.
  4. 04
    Name the ownersApprove, review, escalate.
  5. 05
    Rehearse and reviewExplain it back, then revise.
Bring your current policy, approved-tool list and three situations that have actually happened.
Draft → Rehearse → Assign → Review

How should directors be trained on an AI policy?

1. Bring the policy people actually have

Use the existing policy, procurement rules, data guidance and approved-tool list. If nothing exists, say so plainly and start with an interim set of working questions. Do not pretend a glossy document has already been agreed.

Highlight the rules staff could act on tomorrow and mark every vague phrase that needs an owner. “Use AI responsibly” is a sentiment. “Do not paste client personal data into tools not on the approved list” is a rule.

Policy review prompt to try

Here is our draft AI policy. Identify every sentence a member of staff could not act on without asking someone, every rule with no named owner, and any gaps around personal data, client confidentiality, approved tools and human review. Present the findings as a table. Do not rewrite the policy.

Check your progress

Ready to move on? Every rule is marked as clear, vague or missing an owner, and the group has agreed which three to fix first.

2. Give each risk an ordinary example

Use realistic scenarios: a staff member pastes a client email into a public tool; a manager accepts an AI answer without checking; a team uses AI to summarise sensitive HR material; a salesperson sends an AI-written proposal with an invented statistic. Make the group decide what happens next.

For each scenario, name the first safe action, who owns the decision and what gets recorded. Disagreement among directors here is useful. It shows exactly where the policy needs clearer words.

Check your progress

Ready to move on? Directors have worked through at least four scenarios and agreed the first action and owner for each.

3. Set boundaries by task and information

Explain which tools are approved, what information must stay out, when anonymisation is useful and where human review is required. “Be sensible” is not an access control. Give people a route to ask before they guess.

A one-page traffic-light guide works well: green tasks anyone can do with approved tools, amber tasks that need anonymised data or a reviewer, and red tasks that stay human or need director sign-off. Build it from your own work and information categories, not someone else's template.

Check your progress

Ready to move on? A draft traffic-light guide exists, written in the language your staff actually use.

4. Assign decisions to named people

Decide who approves a new tool, who reviews high-impact use, who maintains the policy and who answers staff questions. Directors keep appropriate oversight; a policy should not make every routine draft wait for the board.

Add a name or role beside every approval, exception and escalation route. If two directors both think the other one owns it, nobody does.

Check your progress

Ready to move on? Every approval, exception and escalation route in the policy has a named role beside it.

5. Rehearse, revise and schedule a review

Run the scenarios again after explaining the rules. Listen for reasonable disagreements; they reveal where the language needs work. Set a review date and the triggers for revisiting the rules early, such as a new tool, a new type of data or an incident.

Ask a member of staff to explain the rules back using one example. If they cannot, improve the explanation before adding another page.

Staff explainer prompt to try

Using our final AI policy, write a one-page plain-English explainer for staff with no technical background. Include five short do and don't examples based on everyday office work, who to ask when unsure and how to report a mistake. Keep it under 400 words.

Check your progress

Ready to move on? A review date and early-review triggers are set, and a staff explainer has been tested on someone outside the board.

What should a director-level AI policy cover?

A practical map of the decisions directors usually need to make, and what bespoke training should rehearse for each.

What should a director-level AI policy cover?
Policy areaThe director's decisionWhat training should rehearse
Approved toolsWhich tools and accounts staff may use for workHow a new tool gets requested and approved
Information boundariesWhat data can and cannot go into each toolSpotting personal, confidential and client data
Human reviewWhere a person must check output before useWhat a proper check looks like, by task
AccountabilityWho owns approvals, exceptions and incidentsEscalation routes for real scenarios
TransparencyWhen customers or clients are told AI was usedPlain wording for disclosure
ReviewWhen and why the policy is revisitedTriggers for an early review

A practical summary, not legal advice. Take tailored professional advice where your organisation's regulatory position requires it.

Try the “would we be happy to explain this?” check

For every proposed AI use, ask: what is the task, what information goes in, what comes out, who checks it, who is accountable and how could a person challenge it? If a director cannot answer, pause the use and assign the missing decision.

Run this check on the three ways AI is already being used in your organisation, because it almost certainly is. Calm governance now is far more useful than panic after an incident.

Bespoke AI policy training for your board

Our AI Policy Workshop works through your own draft rules and scenarios with directors and managers. Before the session, read how to write an AI policy, our AI governance framework for UK businesses and the guide to AI usage policies for small businesses. You can also download our AI acceptable use policy template as a starting draft.

Based in Witney, Oxfordshire, we deliver in person across the UK and live online. Take the free two-minute AI skills assessment to see where your team stands.

Book bespoke policy training

Bespoke AI Policy Training for Directors: frequently asked questions

What is bespoke AI policy training for directors?

A practical session built on an organisation's own draft policy, work examples, tools and decision routes. Directors rehearse how the rules apply to real scenarios and identify gaps for the right owner to resolve.

Does AI policy training make a business compliant?

Training supports understanding and consistent practice, but it cannot by itself guarantee compliance or replace tailored legal or professional advice where an organisation needs it.

Who should attend AI policy training?

Directors or trustees, the person responsible for the policy, relevant operational leads and some of the staff who will use the tools. Include information governance or legal colleagues where appropriate.

How often should an AI policy be reviewed?

Set a planned review date and revisit the policy early when the organisation changes its tools, tasks, data use or approval arrangements, or after an incident. Name the person responsible for spotting those triggers.

Are directors personally responsible for how staff use AI?

Directors are responsible for the oversight of the company, including reasonable care, skill and diligence in how it operates. That includes setting sensible rules and checking they work. Take legal advice on your specific position.

Vivian Snowden writes practical AI training guides for The Oxford AI School, helping individuals and teams put AI to practical use. About the school.

Templates and scenarios in this guide are illustrative exercises, not client case studies. This guide is practical information, not legal or financial advice.

Sources and further reading

Sources and programme links checked on 6 October 2026.