Write an AI policy your team will actually follow
A short, practical AI policy beats a long one nobody reads. What to cover, from approved tools and data rules to accountability, and how to keep it current.
In 30 seconds
- Keep it short: approved tools, data rules, human review, and who to ask.
- A traffic-light scheme, with examples from your own work, makes data rules easy to follow.
- Involve your data protection lead, consider a Jargon busterDPIA: Data protection impact assessment: a documented check of the risks a project poses to people’s personal data, and how you’ll reduce them. UK GDPR requires one for high-risk uses. for high-risk uses, and review it regularly.
Your team may well be using AI already, policy or not. A good policy doesn’t ban it or bury it in legal language. It tells people which tools to use, what they can put into them, and who to ask when they’re not sure. Two pages that people read beat twenty that they don’t.
Start with purpose and tools
Open with a line on purpose, such as helping people use AI well while protecting customers, colleagues and the business. Then say who it covers: staff, contractors and anyone else working on your behalf.
Name the approved tools, and the plan for each. Business plans usually come with contract terms on how your data is handled, admin controls and a promise not to train on your data by default. Say how to ask for a new tool, so people don’t just sign up for one. That’s how Jargon busterShadow AI: AI tools that staff use for work without their organisation’s approval, or without it knowing. starts.
Data rules: a traffic light
Data rules are where policies succeed or fail. A traffic-light scheme is easy to remember, as long as every colour comes with examples from your own work.
An example scheme
- Green: any approved toolPublic or harmless information, such as published reports, general questions and drafts with nothing confidential in them.
- Amber: business plans onlyInternal documents and customer or staff details, only in approved business tools, with names removed wherever the task allows.
- Red: neverPasswords and security keys, health and HR case details, and anything a contract or the law says must stay confidential.
If someone isn’t sure which colour applies, the rule is simple: treat it as red, and ask.
Keep people accountable
Say that a named person checks anything AI helped produce before it leaves the team, and answers for it. Decisions about people, such as hiring, pay or performance, are made by people. If a decision about someone is made by AI alone and significantly affects them, Jargon busterUK GDPR: The UK law on personal data. It sets how organisations must collect, use and protect information about people. gives them rights, including to have a person review it.
Then say when you tell people AI was used: for example, when customers are chatting to a bot, when AI wrote most of a document, or when it helped make a decision about someone. For meetings, require everyone’s agreement before anything is recorded, and keep sensitive meetings off the record. AI for meetings has more.
Copyright, confidentiality and security
Don’t upload material you don’t have the rights to use, or that a client contract says stays private. Check what each tool’s terms say about who owns what it produces. AI and copyright explains more.
Assistants connected to email, files or calendars can act on what they read, and hidden instructions in a document or web page, called Jargon busterPrompt injection: Hidden instructions in a web page or document that try to trick an AI into doing something you didn’t ask., can trick them. The UK’s National Cyber Security Centre warns this may never be fully fixed. So limit what connected tools can reach, and require a person to approve actions such as sending, sharing or deleting.
Make it stick
Involve your data protection lead or legal adviser before you publish it. If AI will process personal data, you may need a Jargon busterDPIA: Data protection impact assessment: a documented check of the risks a project poses to people’s personal data, and how you’ll reduce them. UK GDPR requires one for high-risk uses.. The ICO’s guidance says most uses of AI involving personal data are likely to be high risk, which makes one a legal requirement.
Launch it with a short session using real examples from your team’s work, and name one person to ask. Acas, the workplace advice service, recommends talking to staff about AI early, so ask what they already use it for. Review the policy every six months, or whenever you adopt a new tool.
| Do | Don’t |
|---|---|
| Name the approved tools and plans | Say “use AI responsibly” and stop there |
| Give examples for each colour | List rules nobody can apply |
| Name one person to ask | Leave people to guess |
| Ask staff what they use it for | Write it without the people it affects |
| Set a review date | Write it once and forget it |
Draft a two-page AI policy for [type and size of organisation]. Approved tools: [tools and plans]. Cover: purpose and who it applies to; approved tools and how to request new ones; a traffic-light scheme for data, with examples from our work, such as [examples]; human review and accountability; when we tell customers and colleagues AI was used; recording meetings; copyright and confidentiality; connected apps and security; training; who to ask; and a review date. Use plain English. Flag anything our data protection lead or a lawyer should check.
Check yourself
3 quick questions nothing is savedSources (9)
- What are the accountability and governance implications of AI?Information Commissioner’s Office
- When do we need to do a DPIA?Information Commissioner’s Office
- Rights related to automated decision making including profilingInformation Commissioner’s Office
- Prompt injection is not SQL injection (it may be worse)National Cyber Security Centre, December 2025
- One third of employers think AI will increase productivityAcas, May 2025
- Enterprise privacy at OpenAIOpenAI
- Does Anthropic act as a data processor or controller?Anthropic
- Generative AI Security, Compliance and PrivacyGoogle Workspace
- Data, Privacy, and Security for Microsoft CopilotMicrosoft
Spotted a mistake? Tell us and an editor will check it.