AI Policy & Governance

How to write an AI policy

A plain-English guide to writing an AI policy for a UK small business. The fifteen questions we actually get asked, answered in full, plus a free AI policy template you can download as a Word document and complete this afternoon.

Your team is already using AI. The only real question is whether they are following your rules or making up their own. Writing an AI policy is how you take that decision on purpose. This page answers the fifteen questions we hear most, then hands you a template to build your own.

The quick answer

An AI policy is a short written document that sets out which AI tools your staff may use, what for, and what must never go into a public AI tool. No single UK law requires a document with that name, but UK GDPR, the Data Protection Act 2018, ICO guidance and the Data (Use and Access) Act 2025 all apply the moment your team uses AI, so the policy is the practical evidence that you take those duties seriously.

Write it in seven sections: purpose and scope, approved tools, what AI is for, the data red line, rules by department, gatekeepers, and review and sign-off. One page of plain English beats twenty pages nobody reads. The free Word template below gives you all seven as fill-in boxes.

What is an AI policy? An AI policy, sometimes called an AI acceptable use policy or an AI usage policy, is a short written document that sets out which AI tools your staff can use, what they can use them for, and what must never go into a public AI tool. For a UK business it sits alongside your data protection duties and works as your everyday AI governance policy: the rules that let your team use AI safely without exposing the business. This guide is written for AI policy for small business and SME use, in plain English, and it doubles as a walk-through of the free AI policy template below.

Free download · no sign-up

The AI Acceptable Use Policy template

A Word document with all seven sections flagged for you to fill in, plus guidance on each. Built for UK small businesses and UK GDPR.

  • Seven fill-in sections with guidance prompts
  • A ready-made rules-by-department table
  • A data red line for UK GDPR
  • Staff acknowledgement built in
Word · .docx
7
sections to complete
Download the template

Provided as guidance only, not legal advice. It gives you a sound starting structure, but a policy that genuinely protects your business needs tailoring to your tools, your workflows and your obligations under UK GDPR. The full note is at the foot of this page.

Fifteen questions about AI policy, answered

These are the questions we get asked in the room, week after week, by owners, directors and founders who know they need something written down and are not sure where to start. Every answer is here in full.

Do I need an AI policy?

If anyone in your business uses AI, and they do whether you know it or not, then yes. An AI policy is not bureaucracy for its own sake. It is the one page that tells your team which tools they can use, what for, and what must never go near a chatbot. Without it, every member of staff invents their own rules, one risky prompt at a time. With it, you keep all the speed of AI and lose the exposure. So the honest answer is that you need it the moment a single person on your team opens ChatGPT, which has almost certainly already happened.

Does every business need an AI policy?

Effectively, yes, and size makes no difference. A twelve-person practice carries the same duties under UK GDPR as a large firm. If your staff handle personal data and use AI, the risk is identical in kind, just smaller in scale. The Information Commissioner’s Office does not give small businesses a pass. What changes with size is the length of the policy, not the need for one. A sole trader might have half a page. A fifty-person company might have two. Nobody who uses AI at work needs zero.

Is an AI policy legally required?

No single UK law says you must have a document called an AI policy, and there is no UK AI Act in the way the EU has one, so people assume they are off the hook. That answer misleads, because the laws you already follow apply in full the moment your team uses AI. UK GDPR and the Data Protection Act 2018 govern any personal data your staff put into a tool, and the ICO publishes detailed guidance on AI and data protection that applies to businesses of every size. The Data (Use and Access) Act 2025 tightens the expectations around AI-assisted decisions about people. Employment and equality law still apply if AI touches hiring. So an AI policy is not the legal duty itself. It is the practical evidence, the thing you point an insurer, a client or the ICO to, that shows you take those existing duties seriously. As AI compliance UK expectations firm up through 2026, that written evidence matters more, not less.

How do I write an AI policy?

Work through seven sections and you have one. Start with purpose and scope, then your approved tools, then what AI is and is not for, then the data red line that keeps you GDPR-safe, then rules by department, then your gatekeepers, then review and sign-off. Keep it to one page of plain English a new starter can read in five minutes. The single biggest mistake is writing it alone in a back office and emailing it round, because that version gets skimmed and forgotten. The version that gets followed is the one your team helped write. You can start from the free fill-in template above, or have the whole thing built with your team in a day at our AI Policy Workshop.

What should an AI policy include?

Seven things. The tools you approve and the ones you ban. What AI may and may not be used for. A data red line listing exactly what must never go into a public AI tool under UK GDPR. Rules that differ by department, because marketing and finance carry very different risk. Named gatekeepers who approve new tools and answer the awkward questions. A training approach so new starters actually learn the rules. And a review date, because the tools change constantly. Underneath all of it sits one golden rule worth writing down in bold: AI drafts, a person decides, and nothing leaves the business on the machine’s say-so alone.

How do I manage employees using ChatGPT?

Not by banning it. Bans push usage underground, where you cannot see it or govern it. Manage it instead with three moves, which together make up a simple ChatGPT policy for business. Give people an approved tool on the right tier, so they are not reaching for a free public account with client data. Set clear rules on what AI is for and what data must never go into it, the heart of any generative AI policy. And train the team so everyone knows the rules rather than guessing. That is the whole of managing AI use: approved tools, clear rules, trained people. Get those three right and ChatGPT goes from a liability you worry about to a tool that saves your team a day a week.

Can employees use AI at work?

Yes, and trying to stop them rarely works. Surveys keep finding that most employees already use AI at work, a large share without telling anyone. The sensible position is not to fight that but to shape it. Let staff use approved tools, on the approved tier, for the jobs AI is genuinely good at, and set firm limits on the rest, especially anything involving personal or confidential data. Used within clear guidelines, AI at work is one of the biggest productivity gains a small business can get. Used without them, it is a data breach waiting for a quiet Tuesday.

How do I stop staff entering confidential information into AI?

You cannot rely on judgement in the moment. The person drafting a reply at five o’clock is not going to weigh up data protection law. They need a rule they already know. So write a clear data red line into your policy: a plain list of what must never go into a public AI tool, covering customer, staff and candidate personal data, financial details, health information, login credentials and anything confidential. Then give them a safe alternative, which is usually an approved business-tier tool with proper data terms, or anonymising the data first. Then train the team on it and get them to acknowledge it. Rule, alternative, training, acknowledgement. That combination is what actually stops it, not a stern email.

What are the risks of ChatGPT in business?

Four worth naming. Data exposure, where staff paste personal or confidential information into a free public account and you lose control of it, which under UK GDPR is your liability, not the tool’s. Wrong output, where AI states something confidently and incorrectly and a human sends it on without checking. Reputation, where AI-written content goes out unchecked or an AI image is passed off as real. And over-reliance, where the machine quietly starts making decisions a person should own. None of these are reasons to avoid ChatGPT. They are reasons to use it within rules. Each risk has a simple control, and those controls are exactly what an AI policy writes down.

What AI rules should employers have?

A short set that everyone can remember, which is the backbone of any AI workplace policy. Use only approved tools on the approved tier. Never put personal, financial or confidential data into a public AI tool. Always have a human check AI output before it goes to a client or customer. Ask the gatekeeper before trying a new tool. Flag AI-assisted work where it matters to the reader. And keep the sensitive stuff for the tools you control. Six rules, in plain English, that a new starter can absorb in a single read. The detail, including your AI risk policy and the odd edge case, lives in the full document, but the rules staff carry in their heads should be this short. If they cannot remember them, they will not follow them.

How do SMEs govern AI?

Lightly, and on purpose. AI governance for SMEs sounds like something only a big company needs a committee for, but a workable AI governance framework for a small business comes down to four things. An acceptable use policy that sets the rules. A named person who owns AI decisions. A simple approval route for new tools. And team training so the rules are understood rather than filed. That is genuine AI governance UK small businesses can actually run, sized for a small team, without turning a twelve-person firm into a bureaucracy factory. The aim is not to slow people down. It is to let them move fast without walking into a wall. Our AI Policy Workshop stands all four up in a single day.

What is responsible AI?

Responsible AI is using these tools in a way that is safe, fair and accountable. In a business, that means three practical things. Keeping people’s data protected, so you are not leaking personal information into public tools. Keeping a human accountable for outcomes, so the machine assists but does not decide anything that matters on its own. And being honest about where AI is used, so nobody is misled. It is less a lofty principle than a set of habits, and those habits are exactly what an AI policy turns into rules your team can follow. If you want the fuller version of this, trustworthy AI means lawful, ethical and robust. Responsible AI is not about slowing down. It is about not doing something daft at speed.

What is AI governance?

AI governance is the framework a business uses to control how AI is chosen, used and overseen. Put plainly, it is a written agreement on what AI your business will use, what it must never do, who signs off on new uses, and how a human stays accountable for the result. It is the umbrella. Your AI policy is the main document under it. For a small business the two are close enough to be almost the same thing, and neither needs to be heavy. Good governance for an SME is a short, clear framework that people actually follow, not a long one that nobody reads.

What is the difference between an AI policy and a data protection policy?

They overlap but do different jobs. A data protection policy covers how your business handles personal data across everything you do, in line with UK GDPR. An AI policy is narrower and more practical: it covers how your team uses AI tools specifically, including which ones are approved, what AI is for, and, crucially, what data must never go into a public AI tool. The two connect at the data red line. Your AI policy is where UK GDPR meets the chatbot. You can run them as two documents that reference each other, or fold the AI rules into your existing policies. Either works, as long as the AI-specific rules exist somewhere and do not contradict your data protection stance.

What AI training do employees need?

Two things, and most training only delivers the first. One is the skill of using AI well: prompting, drafting, summarising, and getting real work done faster. The other is the discipline of using it safely: what data to keep out, when to check output, and how to follow the rules. Training on the skill without the discipline creates confident staff doing risky things quickly. You need both, ideally in the same session, delivered in plain English and on the actual work your team does. That is precisely how we run training at The Oxford AI School, and our AI Policy Workshop pairs the training with a written policy so your team leaves knowing the rules and how to work within them.

The seven sections, in one place

Every answer above points back to the same structure. Here it is as a single checklist you can lift straight into your own document, or download as the fill-in template.

Your AI policy in seven sections
  • Purpose and scope: what it is for and who it covers
  • Approved tools: what you allow and ban, and the tier required
  • What AI is for: the jobs it does and the jobs it never does alone
  • The data red line: what must never go into a public AI tool under UK GDPR
  • Rules by department: because marketing and finance carry different risk
  • Gatekeepers and approval: who says yes to new tools
  • Review, training and sign-off: how it stays alive and gets followed

The template gives you all seven as fill-in boxes. But a document you complete alone is the slow way, and the version that tends to get ignored. The one your team follows is the one they helped write, because people follow rules they had a hand in making. That is the whole idea behind the workshop.

Your AI compliance checklist for UK businesses in 2026

A policy is the document. Compliance is the practice around it. If you want a short AI compliance checklist to work through as you roll AI out, this is the one we use with clients. It turns a responsible AI policy from words on a page into something that actually holds.

AI compliance checklist (UK, 2026)
  • Do a quick AI risk assessment: list where AI touches personal data and where it feeds decisions about people. An AI risk assessment UK businesses can do in an afternoon beats a perfect one you never start
  • Write the acceptable use policy: the seven sections above, agreed with your team
  • Check your tools and tiers: business tier with a data processing agreement for anything sensitive, never a free public account
  • Keep a human in the loop: for any AI-assisted decision that affects a person, in line with the Data (Use and Access) Act 2025
  • Line up your policies: make sure the AI rules do not contradict your data protection policy or your ICO obligations
  • Train the team: safe AI adoption for UK businesses depends on people knowing the rules, not just the policy existing
  • Set a review date: treat your AI implementation policy as living, and revisit it as ICO guidance and the tools move

Work through that and you have covered the ground most UK small businesses miss: not just how to use AI, but how to adopt it responsibly and prove you did. If you would rather not do it from a standing start, the workshop below builds the policy, the checklist and the team training in one day. For the evidence side of it, there is a longer piece on AI compliance, auditing and explainability that covers what to record and how to audit it twice a year.

Where the template stops and a real policy starts

I want to be straight about what a downloadable template can and cannot do, because plenty of sites hand one over and imply the job is finished.

A template gives you the structure, and structure is the part most businesses get wrong. What it cannot give you is the content: your tool list, your tiers, your red line, your departments, your gatekeepers, your risk appetite. Those are decisions, and decisions have to be made by the people who will live with them. That is why every prompt in the document is a bracketed box rather than a suggested answer we have guessed on your behalf.

It also cannot give you the thing that makes a policy stick, which is that your team was in the room when it was agreed. A policy handed down gets skimmed. A policy your staff argued over gets followed, because they know why each rule is there. If you fill the template in alone, at least walk the team through it and let them push back before you sign it off.

AI policy workshops and training near you

We run the AI Policy Workshop as a full day for up to ten people, virtually anywhere in the UK or in person. There are pages for each of the cities we work in most, with the local business districts we cover and the sectors we see most often in each:

The Oxford AI School is the best place to learn AI skills to optimise your business through AI in the UK. If your city is not on that list, the workshop still runs, either online or in person with travel quoted up front.

Harry Lang, director and trainer at The Oxford AI School

Harry Lang is the founder of The Oxford AI School. We teach UK business owners, directors and teams to use AI well, and to write down the rules that keep it safe, in plain English and without the compliance theatre.

Read next

This guide and the downloadable template are practical general information to help you build your own AI policy, protocols and guidelines. They are not legal advice, and the rules around AI, UK GDPR and copyright are moving quickly. The template will get you started, but a comprehensive AI policy that genuinely protects your business must be tailored to your tools, your workflows and your obligations under UK GDPR, and kept under review as the rules change. For decisions that carry real risk, take proper professional advice, and treat any policy as a living document you review at least every six months.

The Oxford AI School · AI Policy Workshop

Build your AI policy in a day, with your team in the room.

Our one-day AI Policy Workshop trains your team to use AI safely and builds this exact policy with everyone present. You leave with the finished document, your AI protocols and guidelines agreed, and staff who know how to use AI safely. One day, up to 10 people, £2,499 +VAT virtual or £2,599 +VAT in person.

See the workshop