AI policy
An AI policy is a practical document that explains how people in an organisation may use AI tools at work. It should cover approved tools, personal data, confidential information, human review, staff responsibilities and how to ask for help.
AI usage policy
An AI usage policy is another name for an AI policy focused on day-to-day use. It usually tells staff what is allowed, what is not allowed and what needs approval before AI is used.
AI governance
AI governance is the wider set of decisions and controls around AI use. It includes ownership, approved tools, risk review, training, monitoring, exceptions and how the organisation keeps AI use aligned with its responsibilities.
The AI policy vs AI governance guide explains how governance and staff-facing rules fit together.
Approved AI tools
Approved AI tools are tools the organisation has reviewed and allowed for defined work purposes. An approved tools list should explain the tool name, owner, permitted use, data restrictions and review date.
Public AI tools
Public AI tools are services that staff can usually access directly on the web, such as public chatbot or image-generation tools. They may be useful, but staff need clear rules about confidential information, personal data and approved use.
Human review
Human review means a person checks AI-assisted work before it is used, shared or relied upon. The review should consider accuracy, tone, context, confidentiality, fairness and whether the output is suitable for the audience.
AI readiness
AI readiness is an organisation's practical ability to adopt AI safely and usefully. It includes policy, training, approved tools, data rules, leadership support, security controls and a clear view of where AI could create value.
Read more about AI readiness and governance.
DPIA
A DPIA, or data protection impact assessment, is a structured review used to understand and reduce data protection risk. Higher-risk AI use involving personal data may need DPIA consideration before it is launched.
AI tool register
An AI tool register is a list of AI tools used or approved by the organisation. It can record the tool owner, purpose, users, data restrictions, supplier details, review date and whether the tool is approved, restricted or retired.
AI risk register
An AI risk register records AI-related risks, controls, owners and review dates. It can help organisations track issues such as data leakage, inaccurate outputs, bias, security exposure, supplier risk and unclear accountability.
AI acceptable use
AI acceptable use is the set of behaviours the organisation permits when staff use AI tools. It should be specific enough to guide real work, such as drafting, summarising, coding, analysis, customer communication or research.
Personal data and AI
Personal data is information that identifies, or could identify, a person. Staff should understand when prompts, uploaded documents, meeting notes, support tickets or spreadsheets include personal data before using AI tools.
The AI policy and UK GDPR guide covers this in more detail.