AI Policy Maker

AI policy guidance

What should an AI policy contain?

A useful AI policy gives staff clear, practical rules for using AI at work. It should explain what tools are allowed, what information must stay protected, when a person must check the output and who owns the policy.

Start with the purpose

The first section should explain why the policy exists. For most organisations, the purpose is simple: help people use AI productively while protecting confidential information, personal data, quality of work and organisational trust.

This is also where the policy can set the tone. It should make clear that AI is allowed where it is useful and controlled, but that staff remain responsible for what they create, share or rely on.

Approved AI tools

Staff need to know which AI tools they can use for work. The policy should distinguish between approved tools, restricted tools and tools that are not allowed for organisational information.

  • Tool name and owner
  • What the tool may be used for
  • What information can and cannot be entered
  • Whether approval is needed before use
  • When the tool and policy will be reviewed

This matters for public tools such as ChatGPT, Gemini and Claude, and for integrated platforms such as Microsoft Copilot. If your organisation is planning Copilot, the policy should sit alongside permission reviews, training and data protection checks.

Personal data and confidential information

The policy should be clear about personal data, client material, pupil records, patient information, donor data, staff records, financial information, source code, security information and anything commercially sensitive.

A plain rule often works best: do not enter personal, confidential or sensitive information into public or unapproved AI tools unless the tool and use case have been approved. The AI policy and UK GDPR guide goes deeper on this point.

Human review and accountability

AI can draft, summarise and suggest. It can also misunderstand, invent details or produce confident wording that is not right. A good AI policy should make human review unavoidable for important work.

Staff should be expected to check accuracy, tone, context, confidentiality, copyright, fairness and relevance before using or sharing AI-assisted work. If they cannot explain the output, they should not present it as finished work.

Acceptable and unacceptable use

Acceptable

Using an approved AI tool to improve the wording of a general internal announcement, then checking and editing the result before sending.

Needs care

Using AI to summarise meeting notes, analyse spreadsheets or draft external communications where personal or confidential information may be present.

Not acceptable

Pasting customer records, staff information, safeguarding notes, passwords, source code or confidential documents into an unapproved public AI tool.

Roles and responsibilities

The policy should say who is responsible for AI governance. In a small organisation, that may be a senior manager. In a larger organisation, responsibility may sit across leadership, IT, security, data protection, HR and operational teams.

If you are trying to separate day-to-day staff rules from wider oversight, the AI policy vs AI governance guide explains the difference in practical terms.

  • Staff follow the policy and review AI-assisted work
  • Managers help teams apply the rules in real situations
  • IT or security reviews approved tools and technical controls
  • Data protection leads advise on personal data and higher-risk use
  • Senior leadership reviews policy direction and risk appetite

Transparency, records and exceptions

Some AI use should be disclosed, especially where AI materially contributes to external work, important decisions, formal advice or public content. The policy should explain when staff need to be transparent and what records should be kept.

It should also give people a route for exceptions. Staff should know who to ask if they want to use a new AI tool, try a new use case, or report an accidental disclosure, unusual output or concern.

AI policy checklist

  • Purpose and scope
  • Approved AI tools and restrictions
  • Rules for personal, confidential and sensitive information
  • Human review and accountability expectations
  • Acceptable and unacceptable use examples
  • Roles for staff, managers, IT/security and leadership
  • Transparency, records and exception routes
  • Incident reporting and escalation
  • Training or awareness expectations
  • Review date and policy owner

FAQ

Common questions about AI policy content

How long should an AI policy be?

Long enough to answer practical staff questions, but short enough to be read and used. A concise policy with clear examples is usually more useful than a long document nobody opens.

Should the policy cover ChatGPT, Copilot, Gemini and Claude?

Yes. If staff may use those tools, the policy should explain what each tool can be used for, what information is restricted and when human review is required.

Should every organisation have the same AI policy?

No. A school, charity, MSP, law firm and manufacturer may need different examples, approved tools and escalation routes. The core principles may be similar, but the policy should fit real working practices.