Mon–Sat 10:00–18:00 London · UK
Remote & on-site ☎ 0207 096 0936
← Guides
Security

Writing an AI Use Policy for Your Business

Your staff are already using AI tools. A one-page policy that people actually read beats a ban you cannot enforce — here is what to put in it.

Your staff are already using AI. Not “might be” — are. Someone in your business pasted a client email into a free chatbot last week and asked it to write a polite reply. Someone else fed it a spreadsheet and asked what the numbers meant. Nobody mentioned it, because nobody thought it needed mentioning.

That is the situation a policy has to deal with. Not a hypothetical future where you decide whether to adopt AI, but a present where the decision has already been made for you, one member of staff at a time. A ban you cannot enforce does not reverse that. It simply moves the activity onto personal phones, where you will never see it and cannot correct it.

A short, honest policy works better. Here is what belongs in it.

What actually goes wrong

Be specific about the risks, because vague warnings get ignored. Five things cause real damage:

  • Confidential material leaves the business. Client data, personal data, staff records, commercially sensitive figures — pasted into a tool the business has no agreement with. Under UK data protection law this can amount to an unauthorised transfer, and it is your business that has to explain it. The basics of GDPR for small businesses apply to a chatbot exactly as they apply to email.
  • Free consumer tiers may use your inputs for training. Business and enterprise tiers usually promise they do not. Free tiers frequently reserve the right to, and the setting that opts you out is often buried. This is the single clearest reason to pay for a proper tier.
  • Hallucinated facts go out under your letterhead. These tools invent case citations, statistics, product specifications and references with total confidence. When that reaches a client, the error is yours.
  • Nobody checks the generated code or contract clause. AI-written code can carry real vulnerabilities. AI-written terms can quietly contradict what you have signed elsewhere.
  • Something under NDA gets disclosed. Often by accident, in a prompt, when someone is just trying to summarise a document quickly.

The three-bucket rule

Most policies fail because they try to anticipate every scenario. A simpler structure survives contact with real work. Sort uses into three buckets and give examples of each.

Always fine. Anything with no client, personal or confidential content. Rewording a job advert. Drafting a blog post. Explaining a spreadsheet formula. Brainstorming names. Summarising a public document. Nobody needs to ask permission for these.

Fine with care. Work touching business information that is not especially sensitive, using an approved tool, with a named human checking the output before it goes anywhere. Internal process notes, first drafts of client-facing copy, help with a report structure.

Never. Client-confidential material, personal data about staff or customers, anything under NDA, credentials, financial records, health or legal information about identifiable people, and source code from a client’s system. Not into a free tool, not into an approved one without a specific decision behind it.

The value of three buckets is that people can hold them in their heads. A twelve-page policy full of conditional clauses cannot be held in anyone’s head, which is why it is not followed.

Approved tools, and why paying is cheaper

Name the tools your business permits and say who to ask if someone wants another added. Then actually pay for the business tier of the ones you approve. Business and enterprise plans typically come with contractual commitments that your inputs are not used for model training, with administrative control, and with a record of who is using what.

Set against the cost of one confidentiality breach involving a client’s data — the notification, the awkward conversations, the possible reportable incident — a handful of paid licences is not an expensive control. It is one of the cheaper ones you will buy this year, and it sits naturally alongside the rest of your cyber security spend.

The alternative is shadow tools: staff signing up to whatever they find with a work email address, on personal cards, with no oversight at all. That is where the genuinely bad outcomes come from.

One rule that matters more than the rest

Nothing generated by AI leaves the building without a person reading it properly first. Not skimming — reading, and taking responsibility for it. Facts checked, figures verified, tone corrected, and anything that sounds authoritative confirmed against a real source.

State plainly that the member of staff who sends the work owns the work. AI is not a defence. That single line does more for quality control than any amount of tool configuration, and it is the sentence to lead with when you brief the team. Building it into how staff think about their work is exactly what security awareness training is for.

Clients and regulators are starting to ask

Two pressures are converging. Clients increasingly ask suppliers, in tenders and in contract reviews, whether AI is used on their data and under what controls. And professional bodies have issued their own guidance — solicitors, accountants and healthcare practices in particular should check what their regulator expects before writing anything.

Having a policy you can send when the question arrives is a small commercial advantage. Not having one, and having to invent an answer, is not.

Keep it to one page

Write it as plain statements, not legal drafting. Something like: here are the tools we allow; here is what you may never put into them; here is what needs a second pair of eyes; here is who to ask; here is what to do if you think something has gone in that should not have. That last point deserves its own line — you want people telling you about a mistake on the day, not three months later.

Then take ten minutes at a team meeting to walk through it. A policy nobody has heard of protects nobody.

This is general guidance rather than legal advice, and your sector may impose more. If you would like a hand shaping something practical for your team, our IT consultancy work often starts exactly here — with a page of sensible rules people will actually follow.

Frequently asked questions

Should we just ban AI tools at work instead?

You can, but understand what you are buying. A ban you cannot technically enforce does not stop the behaviour — it moves it to personal phones and personal accounts, where you have no visibility and no record. Most businesses get a better result from a short list of approved tools plus clear rules about what may never be pasted into them.

Do we have to tell clients we use AI?

It depends on your contracts and your sector. A growing number of client agreements, tender questionnaires and professional bodies now ask directly, and some prohibit AI processing of their data without written consent. Check your existing contracts and any NDAs before you assume silence is fine, and be ready to answer the question in writing.

How often should an AI policy be reviewed?

Every six months is sensible, and immediately whenever you adopt a new tool or a supplier changes its terms. This field moves quickly — a tool that had no business tier last year may have one now, and a free product's data-handling terms can change without much fanfare. A short policy is easy to revisit, which is another argument for keeping it to a page.

Related services

Free · no obligation

Want a hand with any of this?

Tell us what you're trying to sort out and we'll come back with a clear, no-obligation plan and price.