The short answer
Yes, almost certainly. If your staff use ChatGPT, Copilot or any AI tool for work, you need a short policy that says which tools are approved, what data must never go into them, and who to ask when unsure. It does not need to be long. One page in plain English beats a forty-page document nobody reads.
Here is the uncomfortable part. Your staff are probably using AI already, and most of them have not asked. McKinsey found the share of employees using AI at work jumped from 30 percent in 2023 to 76 percent in 2025. Meanwhile the CIPD found only 31 percent of UK employers have a formal AI policy. That gap, between what people are doing and what you have agreed they can do, is exactly where the risk lives.
An AI policy is not about slowing your team down. It is about giving them permission to use AI with confidence, and drawing a clear line around the few things that could genuinely hurt you.
Do you actually need one?
Ask yourself one question: could someone on my team paste a customer's details, a contract, or something commercially sensitive into a free AI tool this afternoon? If the answer is yes, and for almost every business it is, you need a policy. Not because your people are careless, but because nobody has told them where the line is.
This is often called shadow AI. Quiet, well-meaning use that nobody signed off and nobody can see. A policy turns it into something open and safe.
What happens without one?
The failures are predictable. Confidential client data ends up training a model you do not control. A confident, wrong answer goes out in an email over your letterhead. Two people use two different tools and produce work that contradicts itself. And when something does go wrong, there is no agreed standard to point to, which makes it far harder to deal with fairly.
What should an AI policy cover?
A good policy is short and specific. These are the points worth nailing down:-
The seven things a good AI policy settles
- Approved tools. Which AI tools are signed off, and on which accounts (a paid business plan behaves very differently from a free one).
- What must never go in. Client data, personal data, anything under NDA, anything you would not email to a stranger.
- The human check. A person is responsible for anything AI helps produce before it leaves the building.
- Transparency. When and how you tell clients or colleagues that AI was involved.
- Ownership and accuracy. Who owns AI-assisted work, and who is accountable if it is wrong.
- Who to ask. One named person for the grey-area questions.
- Review date. When you will look at it again, because the tools move fast.
Isn't the law enough?
No. UK data protection law, the pending rules around AI, and the EU AI Act where it reaches UK firms all set the legal floor. Your policy is the house rules on top of that. The UK has taken a lighter, pro-innovation line rather than a single AI statute, which means the responsibility to set sensible internal standards sits squarely with you. A policy is how you meet it.
How long should it be, and who writes it?
One page. Plain English. Written with a couple of the people who actually use the tools, not just handed down from on high, because a policy your team helped shape is a policy your team will follow. Review it every quarter. That is the whole job.
Do You Need an AI Policy? – frequently asked questions
Do we legally need an AI policy in the UK?
There is no single UK law that says you must have one. But data protection law, employment law and consumer law all still apply to AI use, and a policy is how you show you are managing those responsibilities sensibly. In practice, any business whose staff use AI needs one.
What should an AI policy include?
Approved tools, what data must never be entered, a requirement for a human to check output, rules on transparency, who owns AI-assisted work, one named person for questions, and a review date. Keep it to a page.
How long should an AI policy be?
One page is ideal. A short, clear policy that people read and follow beats a long legal document that sits unread in a shared drive. You can always link out to more detail where it is genuinely needed.
Who should own the AI policy?
Someone senior enough to make the call, usually an owner, operations lead or head of a function, with input from the people who actually use the tools. Name one person staff can go to with grey-area questions.
Do small businesses need an AI policy?
Yes. Small teams often have less oversight, not more, so a clear line on what is safe matters just as much. The good news is a small business policy can be genuinely short.
Does the EU AI Act apply to UK companies?
It can, if you offer AI-driven products or services to people in the EU, or your systems are used there. Most UK small businesses are more affected by UK data protection rules day to day, but the EU AI Act is worth checking if you trade into Europe.
Which Oxford AI School training fits this need?
Turn the answer into a policy your team will follow, then build the habits behind it. Available in Oxfordshire, London, across the UK and online.
Want a policy your team will actually use?
Our AI Policy Workshop helps UK teams agree a clear, one-page policy and the practical habits behind it, in a single half-day session. No jargon, no box-ticking.
Book the AI Policy Workshop Training for your team