Key Takeaways
- Approve specific uses and data categories, not a tool for every possible task.
- Keep a named person accountable for AI-assisted work.
- Separate permission to draft from permission to publish, send or change records.
- This operational template needs adaptation and appropriate professional review; it is not legal advice.
A business AI policy should help a member of staff answer a practical question: may I use this tool for this task with this information, and who checks the result? A broad statement that AI is encouraged or prohibited rarely answers all of that. The policy needs to connect real workflows, data and responsibility.
The template below is an operational starting point for a UK business. It is not legal advice, a certification or a guarantee of compliance. Adapt it to your actual systems, contracts, sector and risk profile, and obtain appropriate professional review where needed. Do not publish it internally with unresolved placeholders.
Before you write the policy
Inventory the tools already being used, including personal accounts and AI features embedded in ordinary software. Ask staff what tasks they are trying to improve. A useful policy should address the real workflow rather than assume that buying one business subscription removes all risks.
List the information involved: public marketing material, confidential business documents, customer records, staff information or other sensitive data. Identify who can approve each use. Keep the policy aligned with existing security, confidentiality, privacy and records-management arrangements.
Use the ICO's AI and data protection guidance as an official reference. The ICO notes that this guidance is under review following legislative changes, so check its current status. The NCSC's secure AI guidance provides a complementary security perspective.
Template: purpose and scope
“This policy explains how [business name] permits AI-assisted work while protecting customers, staff, confidential information and business operations. It applies to [staff, contractors and other relevant users] when using AI for business tasks, including features embedded in third-party software.
The policy owner is [role and contact]. The current version is [version], approved on [date], with a scheduled review on [date]. Existing confidentiality, security and professional obligations continue to apply. Where another rule is stricter, users must follow it or seek clarification before proceeding.”
Define the scope in language people can recognise. Include contractors where relevant, and check how the policy is communicated to them. Do not assume that a supplier's own policy automatically covers the data or authority you give it.
Template: approved tools and uses
“Users may use only the tools and use cases listed in the approved register. Approval identifies the account or workspace, permitted task, permitted data, responsible owner and review requirements. A tool approved for public-copy drafting is not automatically approved for customer records, financial decisions or external actions.
Requests for a new use must describe the intended benefit, data, integrations, outputs and risks. [Approval role] records the decision before use begins. Users must not connect additional services, browser access or action tools without the relevant approval.”
Keep the register short enough to maintain. Useful columns include tool, workspace owner, task, data category, allowed actions, reviewer and review date. If the intended use changes materially, revisit the approval rather than stretching the original description until it covers everything.
Template: information handling
“Users must minimise the information supplied to an AI system. Public information may be used only where rights and the approved purpose allow it. Confidential or personal information requires the specific approval and controls recorded for that workflow. Credentials, secret keys and authentication material must not be entered into prompts or general shared documents.
Before using external services, the responsible owner checks the relevant terms, retention, access arrangements and contractual requirements. Users must not assume that a paid plan, a training opt-out or a familiar brand makes every upload appropriate.”
Add organisation-specific examples. For a marketing team, an approved public product description may be acceptable while an unredacted customer complaint is not. For a professional-services team, even a document without a name may reveal confidential context. Get appropriate advice rather than treating redaction as automatic anonymisation.
Template: human review and accountability
“The person responsible for the work remains accountable for its accuracy, suitability and permitted use. AI output must be reviewed before it is relied on, published or sent, according to the workflow's risk. Review includes factual claims, calculations, sources, confidentiality, tone, rights and any commitments made on behalf of the business.
Users must not present invented citations, testimonials, client examples or results as genuine. Where an output cannot be verified, it must be corrected, clearly qualified or not used. AI assistance does not replace any professional judgement or authorisation required by the business.”
Specify what review means for each task. A marketing draft may need a source and brand check; a system connected to customer records needs permissions and operational tests as well. A box marked human reviewed is not useful if nobody knows what the reviewer was expected to inspect.
Template: actions and integrations
“Permission to draft does not imply permission to send, publish, spend, delete or change records. Each automated action must be explicitly allowed in the workflow register, with appropriate limits and approval controls. High-impact or sensitive actions remain subject to the designated decision-maker.
Systems must use the minimum necessary access. Information contained in an email, document or web page must not be treated as authority to bypass the approved workflow. Users must report unexpected tool behaviour and must not expand permissions simply to make a failed task complete.”
The agentic AI guide explains this distinction. Enforce important boundaries in the application and account permissions, not only in a prompt. Keep a record of the approved destination and action where the workflow can affect external systems.
Template: prohibited or restricted uses
“The following uses are prohibited unless separately authorised through the relevant specialist process: [organisation-specific list]. This may include sensitive employment decisions, financial commitments, regulated advice, identity or access decisions, unrestricted customer-data exports and destructive record changes.
Users must not impersonate a customer or colleague, manufacture reviews, conceal an unauthorised disclosure or use AI to evade the business's controls. When a task falls outside an approved use, the user must stop and ask [contact] rather than infer permission.”
Do not copy a generic prohibited list without considering the actual business. Some tasks may be inappropriate altogether; others may be possible only with specialist review and controls. The policy should identify the route for deciding, not suggest that ordinary manager approval resolves every legal or professional obligation.
Template: incidents, mistakes and escalation
“Users must promptly report suspected inappropriate disclosure, unauthorised action, misleading output relied on by the business or unexpected access through [internal route]. They should stop the affected workflow where safe, preserve relevant evidence and avoid further sharing of sensitive material.
[Incident owner] coordinates investigation, access revocation, recovery and any required professional or regulatory assessment. Users must not attempt to conceal the incident or assume that deleting a chat removes information already processed by a provider.”
Connect this section to the existing incident procedure. Provide an accessible contact and a backup, including what staff should do outside ordinary hours. Do not turn the policy into a separate reporting system that nobody monitors.
Template: records, training and review
“The business keeps proportionate records of approved uses, material changes, evaluations and incidents. Logs must help explain the workflow without retaining unnecessary sensitive content. Access and retention follow the applicable records arrangements.
Users receive training relevant to their role and must know how to find the current approved register. The policy and each significant workflow are reviewed after material provider, integration, data or business changes, and at the scheduled review date.”
Use practical exercises: spotting an invented source, recognising a confidential input and distinguishing a draft from an authorised send. Ask staff to explain what they would do when uncertain. That is more useful than collecting acknowledgements of a document they cannot apply.
Roll out the policy with one controlled workflow
Choose a low-risk, bounded pilot and apply the policy to it. Record the task, data, permissions, reviewer, evaluation examples and stop condition. Use the first-automation guide to select a sensible starting point.
Check whether the written controls match the real tool settings. Can an unapproved user access the workspace? Can the integration perform an action the policy prohibits? Can the owner pause it and return to a manual process? Fix those gaps before treating the policy as implemented.
Review feedback from the people doing the work. Clarify ambiguous wording and update examples when necessary. The objective is informed, accountable use, not a document that creates a false sense of safety while tools operate differently.
MattDarm can support AI strategy consulting, AI training and workshops and AI automation setup. Contact us to discuss the operational scope; legal and regulated decisions should be reviewed by the appropriate qualified advisers.
Frequently Asked Questions
Can we use this template without changes?
No. Replace the placeholders and adapt it to your tools, data, contracts, sector and approval structure. It is an operational starting point, not legal advice or a guarantee of compliance.
Does a paid AI account make customer data safe to upload?
Not by itself. Check the intended use, provider terms, retention, access controls and your obligations. Approval should cover the specific data and workflow, not merely the subscription tier.
Who should approve AI-generated work?
Assign a person with the knowledge and authority appropriate to the task. Define what they must check, including facts, confidentiality and commitments. Sensitive or regulated uses may need specialist review.
Should the policy cover tools embedded in other software?
Yes, where they are used for business tasks. AI features inside familiar products can still process information or take actions, so they should be included in the inventory and approval process.
What happens if someone uses an unapproved tool?
Follow a clear internal reporting and assessment process. Stop further risky use, preserve relevant evidence and let the responsible owner assess exposure and recovery. Do not assume deleting the conversation resolves the incident.




