How do I write an AI usage policy my team will actually follow?
13 August 2026
How do I write an AI usage policy my team will actually follow?
The AI usage policy your team will follow is the one that removes uncertainty from daily work. It should be plain English, specific to your tools, and built around real decisions: what staff can use AI for, what data is banned, when outputs must be checked, and who owns approval. A long legal document that nobody remembers will not control risk.
What should the policy actually say?
The best AI usage policy starts with five decisions, not legal language. First, list the approved tools. That might be Microsoft 365 Copilot for documents, ChatGPT Team for general drafting, Claude Team for analysis, or Gemini for Google Workspace users. Second, define banned data. Staff should not put client personal data, contracts, passwords, payroll records, medical information, unpublished financials or confidential strategy into free consumer tools. Third, set review rules. AI can draft, summarise and suggest, but a person must approve anything that affects customers, money, employment, legal advice or regulated decisions. Fourth, explain ownership. The employee remains responsible for checking accuracy, bias, tone and confidentiality. Fifth, name the escalation route when someone is unsure.
For a UK SME, that can usually fit into 2 to 4 pages. The mistake is trying to write a policy that covers every possible future AI use. It becomes so abstract that nobody uses it. Start with the tools and workflows your team already touches. The Office for National Statistics reported in July 2026 that AI use among UK businesses with 10 or more employees had risen from around 12% in late 2023 to around 35% by June 2026, so many teams are already experimenting whether owners have approved it or not. Your policy should bring that behaviour into the open.
Link the policy to real examples: drafting a proposal, summarising a meeting transcript, rewriting a customer email, analysing anonymised survey comments, or checking a spreadsheet for anomalies. Staff follow rules faster when they can recognise their own work in them.
Source: Office for National Statistics, Artificial intelligence in UK businesses.
What data should staff never put into AI tools?
The clearest section should be the data rule. Do not phrase it as a vague instruction to be careful with sensitive information. Give staff a simple traffic light system. Green data is safe: public website copy, anonymised examples, internal templates with no names, generic process notes and publicly available research. Amber data needs approval: client context with identifiers removed, internal sales figures, supplier information, board papers, draft contracts and customer complaints. Red data is banned unless a specific approved business tool and process exists: personal data, special category data, payroll, passwords, access keys, legal advice, confidential client documents, HR records, merger plans, credit decisions and anything covered by a non-disclosure agreement.
The ICO says its AI guidance is suitable for businesses in the public, private and third sectors, and its AI and data protection resources explain how UK GDPR applies to information used in AI systems. That matters because the legal issue is not whether the tool feels clever. It is whether the business has a lawful basis, transparency, minimisation, security and accountability for the personal data being processed.
Free consumer AI accounts are the highest-risk place for unclear behaviour. Some business plans offer stronger contractual protection, admin controls and data training commitments, but that does not remove the need for rules. A staff member can still upload the wrong file into the right tool. The policy should say exactly what must be removed before using AI: names, emails, phone numbers, addresses, account numbers, customer IDs, employee records and any detail that would let a person be identified.
Make the rule easy to remember: if you would not paste it into a public forum or send it to an external contractor without permission, do not put it into an unapproved AI tool.
Source: ICO artificial intelligence guidance.
How do you make the rules practical enough to stick?
Write the policy as a working guide, not a compliance monument. A useful structure is one page of principles, one page of approved and banned uses, one page of examples, and one page of escalation and review. Staff should be able to answer a real question in under 60 seconds: Can I use AI for this task, which tool should I use, what must I remove, who checks the result, and who do I ask if I am unsure?
Use examples by role. Sales may use AI to summarise a prospect call, draft a follow-up email and research public company information, but not to invent pricing promises or upload signed contracts. Operations may use AI to turn meeting notes into actions, compare supplier responses and draft process documents, but not to approve refunds or change stock orders without human review. Finance may use AI to explain spreadsheet patterns or draft a board narrative, but not to make payment decisions, payroll judgements or tax advice without qualified review.
Include an approval ladder. Low-risk drafting can be self-approved after checking. Customer-facing copy needs line manager review until the team is trained. Legal, HR, finance, personal data and contractual use needs named approval. Automation that connects AI to a CRM, accounts package or project management system should need a written purpose, permission review, test plan, rollback route and named owner.
The policy should also say what good use looks like. Encourage staff to use AI for first drafts, summaries, options, checklists and questions they should consider. Discourage blind copy-paste, fake citations, unreviewed customer answers and using AI to hide weak thinking. The tone matters. If the document only says no, people will work around it. If it shows safer ways to get the benefit, they are more likely to comply.
What security risks should the policy cover?
The NCSC is clear that managers and senior leaders do not need to be technical experts, but they do need to understand enough AI risk to discuss it with key staff. Your policy should cover the practical risks staff can control: data leakage, hallucinations, bias, prompt injection, fake tools, browser extensions, weak account ownership and over-permissioned integrations.
Prompt injection is worth explaining in plain English. If an AI tool reads a web page, email, document or ticket, that content may contain instructions designed to manipulate the AI. Staff should not connect AI tools to inboxes, CRM records, file stores or websites without approval, because the risk changes when AI can read untrusted content and then take action. This is especially important for agentic AI tools, which can plan tasks, make decisions and act on a user's behalf. The NCSC's frontier AI guidance says organisations will need clear oversight of how agentic AI tools are used and what access they have to systems and data.
The policy should require named accounts, not shared logins. It should ban unofficial AI browser extensions unless approved. It should require multi-factor authentication on business AI tools. It should say that staff must report suspicious AI links, unexpected file-sharing prompts, tool impersonation and outputs that appear to reveal confidential information. It should also define who can approve new AI tools, because the easiest way for shadow AI to grow is for every department to sign up for a different trial.
A sensible SME approval process does not need a committee. The owner, operations lead, data protection contact and external IT support can review purpose, data, permissions, cost and risk in 20 minutes for most low-risk tools.
Source: NCSC, AI and cyber security and NCSC frontier AI guidance.
What should implementation cost and involve?
If you write it yourself, a first AI usage policy usually takes 3 to 6 focused hours: one hour to list current tools and use cases, one to agree data rules, one to write the policy, one to build examples, and one or two hours to brief managers and answer questions. If you use an external adviser, expect roughly £1,500 to £5,000 for a practical SME policy, depending on whether they also review tools, data protection risk, contracts and staff training. A more formal governance package with DPIA support, supplier review, approved tool register and training can run from £5,000 to £15,000+.
The first rollout should be simple. Send the policy, then run a short live session where staff test it against real scenarios. Ask: Can I upload this customer email? Can I use AI to write a reply? Can I ask Copilot to summarise this board paper? Can I use a free AI image tool for a client campaign? Can I connect an AI note-taker to meetings? The answers should be in the policy. If they are not, improve the policy rather than blaming staff.
Review it every quarter. AI tools change quickly, but the core rules do not: approved tools, permitted data, human review, accountability, approval for integrations and incident reporting. Keep a one-page change log so staff know what has changed.
Finally, make managers model the behaviour. If leaders paste confidential information into random AI tools while telling staff to follow the policy, the policy is finished. Teams follow what leaders do when time is short.
When this is NOT right for you
A lightweight AI usage policy is not enough if your business is using AI to make or recommend decisions about employment, credit, eligibility, health, legal matters, insurance, housing, education or vulnerable customers. Those uses need deeper governance, legal review, data protection assessment, testing, audit trails and human accountability. A 4 page staff policy cannot carry that risk by itself.
It is also not enough if you are connecting AI agents to live business systems with write access. Once AI can update CRM records, send emails, approve transactions, change stock levels or trigger customer communications, you need system design, permission control, monitoring, rollback and incident response. The policy can say who may request that work, but it cannot replace technical controls.
Do not write a policy as theatre. If the business will not enforce tool approvals, will not pay for safer business accounts where needed, and will not give staff time to learn, the document will sit unread. In that case, start smaller: ban high-risk uses, approve one safe tool, train one team, and build from there.
Is This Right For You?
This applies if staff are already using ChatGPT, Microsoft Copilot, Gemini, Claude or AI features inside business software, but the rules are informal or unclear. It is especially relevant if your team handles client data, financial records, HR information, contracts, customer messages or commercially sensitive plans.
It may not be the right first project if nobody in the business is allowed to use AI at all, or if you are buying a high-risk AI system that makes automated decisions about people. In those cases, you need wider governance, supplier due diligence and probably a data protection impact assessment before a lightweight staff policy is enough.
Frequently Asked Questions
How long should an AI usage policy be?
For most UK SMEs, 2 to 4 pages is enough for the first version. If it is longer than 8 pages, create a one-page quick guide as well, because staff need rules they can use during real work.
Who should own the AI usage policy?
The owner or senior leadership team should own it, with input from operations, IT, HR and whoever handles data protection. Do not leave it only with IT, because many AI risks are about behaviour, judgement and customer impact.
Should we ban free AI tools completely?
Not always, but free tools should be limited to public or anonymised information unless you have checked the terms, privacy settings and data handling. Anything confidential or personal should use an approved business tool and process.
Do we need a data protection impact assessment for staff AI use?
You may need a DPIA if AI use is likely to create high risk for individuals, especially where personal data, monitoring, profiling or automated decision making is involved. For low-risk drafting using non-personal data, a DPIA may not be necessary.
How often should we update the policy?
Review it every quarter for the first year, then at least twice a year after that. Update it sooner if you approve a new AI tool, connect AI to business systems, or discover staff are using tools outside the policy.
What should we do if someone breaks the policy?
Treat accidental mistakes as a learning and containment issue first. Preserve evidence, stop further sharing, assess whether personal or confidential data was exposed, take advice if needed, and update training or controls. Deliberate misuse may need HR action.
Should the policy include examples?
Yes. Examples are what make the policy usable. Include approved, restricted and banned examples for sales, operations, finance, customer service and management so people can recognise their own work.