Skip to content

Acceptable AI Use Policy

Ready

Purpose. The staff-facing rules for using AI at work: what is encouraged, what needs approval, and what is never allowed. This is the most-read document in the kit, and usually the one that prevents the most damage.

When to use it. As early as possible — staff are already using AI tools whether or not you have a policy. Review at least twice a year while the tool landscape moves.

How to use it. Write it for the whole workforce, not for specialists: one page, plain language, specific tool names. Pair it with a genuinely usable approved-tool list. A policy that only says "seek approval" without saying from whom, and how long it takes, produces shadow AI rather than compliance.

Closes assessment gaps

This template addresses Q09, Q10, Q19, Q20, Q21, Q25, Q27, Q39 in the readiness assessment.


The template

1. Purpose

This policy sets out how people at [Organisation] may and may not use AI tools. It applies to everyone — employees, contractors, and anyone acting on our behalf — and to all AI tools, whether we provide them or not.

2. The short version

If you read nothing else

You are accountable for anything you produce with AI, exactly as if you had written it yourself. Check it before it goes out. Never put Confidential or Restricted information into a tool that has not been approved for it. Tell people when they are dealing with AI output that affects them.

3. Approved tools

Tool Approved for Maximum data classification Owner
[Tool A] [General drafting, summarising] Internal [role]
[Tool B] [Coding assistance] Confidential [role]
[Tool C] [Customer-facing] [Restricted — with controls] [role]

Tools not on this list are not approved. To request one, contact [route] — expected turnaround Five working daysUnless: Ten days where the tool will process personal data and needs a DPIA..

4. Always prohibited

You must not use AI to:

  1. Perform any practice prohibited by the EU AI Act — social scoring, manipulative techniques, untargeted scraping of facial images, emotion inference in the workplace, or unlawful biometric categorisation.
  2. Make a final decision that materially affects a person — hiring, firing, promotion, credit, pricing, or access to a service — without meaningful human review.
  3. Enter Restricted data into any tool not explicitly approved for it.
  4. Generate content that impersonates a real person or organisation.
  5. Circumvent a control, or produce material you know to be misleading.

5. Requires approval before you proceed

Situation Approve with
New AI tool, or new use of an existing one [Governance / IT]
AI affecting customers or the public [Committee]
AI in HR, recruitment, or performance decisions [HR + Legal] — Annex III high-risk
AI processing special category personal data [DPO]
Building or fine-tuning a model [Governance] — see AI Development & Deployment Standard

6. Your responsibilities when using AI

  • Verify output. AI is confidently wrong. You own what you send.
  • Protect data. Check the classification before you paste — see Data Classification & Handling Policy.
  • Be transparent. Tell people when they are interacting with AI, and disclose AI-generated content where it could mislead.
  • Watch for bias. If output looks skewed against a group, stop and report it.
  • Report problems to [route] — they go in the Issue & Incident Log.

7. What we encourage

This policy exists to make safe AI use easy, not to discourage it. Drafting, summarising, research, code assistance, and analysis on Internal data using approved tools need no special permission. If in doubt, ask — asking is never the wrong answer.

8. Breaches

Handled under [the disciplinary process]. Self-reported mistakes are treated far more leniently than concealed ones — we would rather know.

9. Review

Version Date Owner Approved by
0.1 [date] [role] [committee]

Adaptation notes

  • Small organisations: Sections 2, 3, and 4 alone make a usable one-page policy. Publish that this week rather than a complete one next quarter.
  • Regulated sectors: Add record-keeping obligations for AI-assisted advice or communications, and align section 4 with your existing conduct rules.
  • Engineering-heavy organisations: Add explicit rules for code assistants: licence contamination from suggested code, secrets in prompts, and review requirements for AI-generated code paths.
  • Unions / works councils: Where AI touches workforce monitoring or employment decisions, consultation may be required before you publish. Involve them early rather than presenting a finished policy.

Not legal advice

These templates are a head start, not a substitute for professional judgement. Adapt them to your jurisdiction, sector, and risk appetite, and have qualified counsel review anything material before you rely on it.