How do I create simple AI rules for a team that is already using ChatGPT without asking?

7 September 2026

How do I create simple AI rules for a team that is already using ChatGPT without asking?

If your team is already using ChatGPT without asking, do not start with a ban. Start with a short, practical AI use policy that brings the behaviour into the open. The safest first version should cover approved tools, banned data, allowed uses, human checking, client disclosure, manager approval for automations, and a simple AI register.

Start by accepting what is already happening

The direct answer is this: assume some people are already using AI and design rules around real behaviour, not around an ideal version of the business. ChatGPT, Copilot and Gemini are easy to access, useful within minutes and often already sitting in staff browsers. If the first message from management is a blanket ban, the risk is not that usage stops. The risk is that it becomes harder to see.

The UK evidence backs this up. The Office for National Statistics reported in July 2026 that AI use among UK businesses with 10 or more employees had risen from around 12% in late 2023 to around 35% in June 2026. It also found that over half of employees reported using AI for work or education, compared with around a third of businesses reporting AI use. That gap matters because it points to informal, employee-led adoption. In plain English, the tools are already in the workplace before many businesses have decided what the rules are.

Your first job is therefore not to write a 20-page policy. It is to bring usage into the open without embarrassing people. Ask managers to collect examples of where staff are using AI now: drafting emails, summarising documents, writing formulas, preparing meeting notes, researching suppliers, turning rough notes into records or checking tone. Separate useful low-risk habits from dangerous ones. A staff member asking ChatGPT to tidy a generic email is not the same risk as someone pasting a client contract, payroll file or complaint history into a free tool.

The tone matters. Say, "We know AI tools are useful. We are putting simple rules in place so people can use them safely." That is much more likely to work than, "Nobody should have used this without approval." Your goal is controlled use, not a witch hunt.

Write seven rules people can remember

A simple first policy should be short enough to read in five minutes. For most SMEs, seven rules are enough for the first version.

These rules are deliberately practical. They tell people what to do on Monday morning. A full policy can come later, but the first version should stop the obvious harms: leaking data, relying on unchecked answers, connecting tools without permission and hiding repeatable workflows from the business.

The Department for Science, Innovation and Technology found in the UK Business Data Survey 2026 that only 17% of AI-using businesses had any policy or guidelines on AI use or development. Just 5% had a formal written policy. That means most businesses using AI are still light on governance. You do not need to be perfect to be ahead of the market. You need to be clear.

Decide what staff can and cannot put into AI

The most important part of your rule set is the data rule. Staff need a simple test they can apply without asking a lawyer every time. A useful version is: if you would not email it to an unknown supplier, do not paste it into an AI tool unless the business has approved that tool for that data.

Create three categories. Green data is allowed: public information, generic examples, anonymised notes, public web pages, internal templates with no sensitive details and rough wording that does not identify clients or staff. Amber data needs manager approval: client context, internal performance figures, supplier details, commercial plans, draft proposals, customer emails and anything that could embarrass the business if exposed. Red data is banned unless there is a specific approved system and process: passwords, bank details, payroll, health information, disciplinary records, personal data about children, confidential contracts, legal advice files, regulated client data and customer lists.

This is where UK GDPR comes in. The ICO guidance on AI and data protection is clear that when personal data is processed in AI development or deployment, the organisation must identify a purpose and an appropriate lawful basis. The ICO also says the lawful basis should be documented and included in privacy information where required. For a small business, that does not mean every employee needs to understand every article of UK GDPR. It means staff need rules that stop them accidentally creating data processing the business has not assessed.

There is also a supplier question. A free personal AI account may use different settings, retention rules and admin controls from an approved business workspace. Before staff use AI with anything more than public or anonymised information, someone should check the vendor terms, training settings, data retention, account ownership, audit options and deletion controls. Microsoft, Google, OpenAI, Anthropic and specialist tools all have business products, but they are not identical. The rule should be narrow until you know what the tool does with the data.

Create an approval route that does not slow everything down

Simple AI rules fail when every useful action needs senior approval. Staff then either stop using AI or keep using it quietly. The better approach is a lightweight approval route with three lanes.

Lane one is everyday permitted use. Staff can use approved tools for low-risk drafting, summarising, brainstorming, formatting, translation, spreadsheet help, meeting preparation and internal notes, provided no restricted data is included and a person checks the output. Lane two is manager-approved use. This covers client work, recurring prompts, internal reports, proposals, customer-facing wording, performance analysis and workflows that use business information. Lane three is formal review. This covers system integrations, automated decisions, access to CRM or finance data, personal data at scale, HR use, legal or regulated work, and anything that could materially affect a customer, employee or supplier.

The approval process can be simple. Use a short form or shared document with six questions: what tool, what task, what data, who checks the output, what could go wrong and who owns it. For repeatable uses, add a review date. The answer may take five minutes for a low-risk workflow and longer for anything sensitive. That is fine. The aim is not bureaucracy. The aim is to make sure nobody accidentally turns a helpful prompt into an unmanaged business process.

Costs are usually modest at this stage. A basic policy workshop and staff briefing might cost £750 to £2,500 from a small consultancy, or less if handled internally. A more detailed AI governance setup with supplier checks, data mapping, staff training and an AI register might cost £3,000 to £8,000 for a small business. The expensive mistake is doing nothing until there is a data leak, client complaint or inaccurate output sent under the company name.

When this does not apply

A simple rule set is not enough when AI is making or influencing important decisions about people. If staff use AI to shortlist job applicants, assess performance, decide credit risk, prioritise vulnerable customers, produce legal advice, process health information or make regulated recommendations, you are beyond basic workplace guidance. You need a proper risk assessment, data protection input and clear human accountability.

The ICO guidance on lawfulness in AI says organisations must separate distinct processing operations, identify the purpose and lawful basis for each one, and document the decision. It also warns that special category data needs more protection. In practice, that means a manager cannot simply say, "Use AI carefully" and leave staff to work out the rest. If the AI use touches sensitive personal data or affects rights and opportunities, informal permission is not good enough.

The same applies to automations that quietly act on live business systems. A staff member using ChatGPT to improve an internal checklist is low risk. A staff member connecting an AI agent to the shared inbox, CRM and accounting package so it can reply, update records or trigger follow-ups is a different proposition. That needs access controls, logs, testing, rollback, ownership and monitoring.

If you are unsure which side of the line a use case sits on, start with one question: what happens if the AI is wrong? If the answer is mild inconvenience, keep the rule simple. If the answer is customer harm, legal exposure, financial loss, reputational damage, discrimination risk or a breach of confidentiality, slow down and review it properly.

How to roll the rules out without making staff defensive

Roll this out as a reset, not a reprimand. Start with a short team note: "AI tools are now common in everyday work. We want people to get the benefit safely, so these are the rules from today." Then run a 30-minute session with examples from your actual business. Show an allowed prompt, an amber prompt that needs approval and a red prompt that should never be used.

Make the first version temporary. Say it will be reviewed after 30 days once the business has seen how people use it. That lowers resistance because staff do not feel trapped by clumsy rules forever. It also gives you permission to improve the policy as you learn. Ask each manager to collect the top three useful AI uses and the top three concerns. That turns the policy into a living operating rule rather than a document nobody reads.

Keep the language plain. "Do not paste client personal data into free AI tools" is better than "Users must not process protected information through unauthorised large language model services." People follow rules they understand. They ignore policy language that feels written for a tribunal bundle.

Finally, give staff somewhere to ask. A named manager, operations lead or external adviser should own the policy. The sentence "ask if unsure" is useless unless people know who to ask and believe they will not be punished for asking. The most mature businesses are not the ones where nobody makes mistakes. They are the ones where uncertain use is surfaced early, checked quickly and turned into better rules.

Is This Right For You?

This approach is right for you if staff are already using ChatGPT, Copilot, Gemini or similar tools for everyday work and you need control without shutting down useful experimentation. It works especially well for UK SMEs with no full-time IT department, where the owner, operations manager or office manager needs a plain rule set people can follow this week.

It is not enough if you are using AI for regulated decisions, high-risk HR decisions, legal advice, medical advice, financial approvals, automated customer decisions or large-scale profiling. In those cases, you need a fuller governance process, a data protection assessment, supplier checks and professional advice. A one-page rule set is a starting point, not a substitute for legal or security review.

If you want to explore what a sensible AI usage policy should look like for your business, book a free call. No pitch, no pressure, just a practical look at where the risk sits and what rules your team actually needs.

Frequently Asked Questions

Should I ban ChatGPT at work until we have a full policy?

Usually, no. A temporary ban can be sensible for sensitive data, regulated work or unapproved system integrations, but a blanket ban often pushes usage underground. A short interim rule set is usually better: approved tools, banned data, human review and manager approval for anything repeatable or customer-facing.

Can staff use free ChatGPT accounts for work?

Only for low-risk work using public, generic or anonymised information. Staff should not use free personal accounts for client data, personal data, contracts, financial records, HR matters or confidential business information unless the business has assessed and approved that use.

Who should own AI rules in a small business?

Give ownership to a named person with enough authority to say yes or no, often the owner, operations manager, office manager or data protection lead. They do not need to be an AI expert, but they do need to keep a register, approve higher-risk uses and know when to get external help.

What should go in a simple AI register?

Record the tool, owner, purpose, data used, whether outputs affect customers or staff, who checks the result, monthly cost, approval date and review date. Keep it lightweight. The point is visibility, not paperwork for its own sake.

Do I need to tell clients if staff use AI?

Sometimes. If AI is only helping with internal drafting and a person checks the final work, disclosure may not be necessary. If AI materially shapes advice, decisions, customer service responses or processing of client data, disclosure may be sensible or required depending on the context and contract.

How often should we review the rules?

Review the first version after 30 days, then every three to six months. Also review it whenever you approve a new AI tool, connect AI to a business system, handle an incident, or start using AI in a higher-risk area such as HR, finance, legal or customer service.

What is the biggest mistake when introducing AI rules?

The biggest mistake is making the policy either too vague or too heavy. "Use AI responsibly" is not enough, but a long legal document will not be read. Give staff clear examples of allowed, approval-needed and banned use.