Loading...
Governance · Free template
A free AI policy template that outlines a UK AI acceptable use policy, section by section. Use it as a starting point, then tailor it to your firm, your clients and your regulator.
In focus →
Where the line sits
Your staff are probably already using AI tools, with or without permission.
An AI policy for employees turns that into something you can see, manage and defend.
The government’s SME Digital Adoption Taskforce found that SMEs with clear internal policies permitting AI use are more likely to adopt AI tools.
A good policy is short, specific and built around one idea: a person stays responsible for anything the AI produces.
The AI policy template below sets out nine sections, and it is a starting point rather than legal advice.

What staff can use AI for
What always needs a person
The template, part one
Here is the AI policy template we recommend for a UK acceptable use policy.
Keep each section to a few plain sentences, so people actually read it.
The first five sections set the rules for everyday use.
The most important is data: the NCSC recommends not including sensitive information in queries to public AI tools.
The next most important is human review, because AI output can be confidently wrong.
Name the reviewer by role, not just “a manager”, so it is clear who signs off.
Illustrative batch with a typical confidence spread. Your real split comes from a pilot on your own work. Some decisions go to a person whatever the score.
The template, part two
The last four sections of the AI policy template make it stick.
An accountability owner gives staff one person to ask, and gives the board one person to hold to account.
Training matters because a policy nobody understands will be ignored.
Our AI literacy training is designed to sit alongside a policy like this.
Incident reporting should be blame-free, so people report mistakes early.
Link it to your data breach process, because an AI leak may also be a personal data breach.
UK sources
You do not need to write this from scratch.
The ICO’s guidance on AI and data protection explains how UK GDPR applies when AI uses personal data.
The NCSC also covers the security risks of AI tools, including prompt injection and leaked queries.
The government’s AI Playbook sets out 10 principles for civil servants, including meaningful human control.
Those principles translate well to private firms, especially the idea that people stay accountable for AI-assisted work.
If your policy touches decisions about people, check the ICO’s rules on automated decision-making too.
You do not need to write this from scratch.
Tailoring
This AI policy template is general guidance and not legal advice.
Regulated firms will need to add their regulator’s rules, for example on confidentiality or record keeping.
We help you tailor it: naming the tools, setting the data rules and designing the human review step.
If you want evidence that the policy works in practice, our AI assurance review tests it.
Get in touch and we will turn the outline into a policy your team can use.
This AI policy template is general guidance and not legal advice.
How it works
Each system ships with a named person accountable for what it does.
01
List the AI tools people already use, including free ones on personal accounts.
02
Agree approved tools, banned data and who reviews output, with leadership signing off.
03
Fill in the nine sections in plain English, with examples from your own work.
04
Brief every team, log incidents and review the policy at least once a year.
Questions
Further reading
Keep reading
Next step
A 30-minute call. We map one workflow, what the AI could take, and where a person must stay in the loop.