Subscribe free
AI at work3 min readAdvanced

Write an AI policy your team will actually follow

A short, practical AI policy beats a long one nobody reads. What to cover, from approved tools and data rules to accountability, and how to keep it current.

3 min read

In 30 seconds

  • Keep it short: approved tools, data rules, human review, and who to ask.
  • A traffic-light scheme, with examples from your own work, makes data rules easy to follow.
  • Involve your data protection lead, consider a for high-risk uses, and review it regularly.

Your team may well be using AI already, policy or not. A good policy doesn’t ban it or bury it in legal language. It tells people which tools to use, what they can put into them, and who to ask when they’re not sure. Two pages that people read beat twenty that they don’t.

Start with purpose and tools

Open with a line on purpose, such as helping people use AI well while protecting customers, colleagues and the business. Then say who it covers: staff, contractors and anyone else working on your behalf.

Name the approved tools, and the plan for each. Business plans usually come with contract terms on how your data is handled, admin controls and a promise not to train on your data by default. Say how to ask for a new tool, so people don’t just sign up for one. That’s how starts.

Data rules: a traffic light

Data rules are where policies succeed or fail. A traffic-light scheme is easy to remember, as long as every colour comes with examples from your own work.

An example scheme

  • Green: any approved toolPublic or harmless information, such as published reports, general questions and drafts with nothing confidential in them.
  • Amber: business plans onlyInternal documents and customer or staff details, only in approved business tools, with names removed wherever the task allows.
  • Red: neverPasswords and security keys, health and HR case details, and anything a contract or the law says must stay confidential.

If someone isn’t sure which colour applies, the rule is simple: treat it as red, and ask.

Keep people accountable

Say that a named person checks anything AI helped produce before it leaves the team, and answers for it. Decisions about people, such as hiring, pay or performance, are made by people. If a decision about someone is made by AI alone and significantly affects them, gives them rights, including to have a person review it.

Then say when you tell people AI was used: for example, when customers are chatting to a bot, when AI wrote most of a document, or when it helped make a decision about someone. For meetings, require everyone’s agreement before anything is recorded, and keep sensitive meetings off the record. AI for meetings has more.

Don’t upload material you don’t have the rights to use, or that a client contract says stays private. Check what each tool’s terms say about who owns what it produces. AI and copyright explains more.

Assistants connected to email, files or calendars can act on what they read, and hidden instructions in a document or web page, called , can trick them. The UK’s National Cyber Security Centre warns this may never be fully fixed. So limit what connected tools can reach, and require a person to approve actions such as sending, sharing or deleting.

Make it stick

Involve your data protection lead or legal adviser before you publish it. If AI will process personal data, you may need a . The ICO’s guidance says most uses of AI involving personal data are likely to be high risk, which makes one a legal requirement.

Launch it with a short session using real examples from your team’s work, and name one person to ask. Acas, the workplace advice service, recommends talking to staff about AI early, so ask what they already use it for. Review the policy every six months, or whenever you adopt a new tool.

DoDon’t
Name the approved tools and plansSay “use AI responsibly” and stop there
Give examples for each colourList rules nobody can apply
Name one person to askLeave people to guess
Ask staff what they use it forWrite it without the people it affects
Set a review dateWrite it once and forget it
Draft your first version

Draft a two-page AI policy for [type and size of organisation]. Approved tools: [tools and plans]. Cover: purpose and who it applies to; approved tools and how to request new ones; a traffic-light scheme for data, with examples from our work, such as [examples]; human review and accountability; when we tell customers and colleagues AI was used; recording meetings; copyright and confidentiality; connected apps and security; training; who to ask; and a review date. Use plain English. Flag anything our data protection lead or a lawyer should check.

Then ask a few colleagues to apply it to real cases. Where they disagree, the policy needs another example.

Check yourself

3 quick questions nothing is saved
1In a traffic-light scheme, where do passwords belong?

2When might you need a data protection impact assessment?

3Why limit what connected AI tools can reach and do?

Up next in AI at work

Beginner4 min read

Job hunting with AI: CVs, cover letters and interviews

AI can help you tailor your CV, draft a cover letter and practise for interviews. The rule that matters most: use only your real experience, and check every line.

More guides

Get AI explained at your level, every weekday

The five stories that matter, in plain English, plus a new guide each week. Free.