Blog

AI acceptable use policy: what a business should include

Phil Patterson
calender
August 7, 2026

An AI acceptable use policy tells staff how they may use AI tools at work. It should make safe use easier, not bury people in abstract principles. The most useful policy answers common questions at the moment someone is about to enter information or rely on an output.

This guide offers a practical structure. Your final policy should reflect the organisation, its data, contracts, sector and legal advice.

State the purpose and scope

Explain why the policy exists and who it covers. Include permanent staff, contractors and anyone using company information or systems. Say whether it covers public AI tools, features built into existing software and custom workflows.

List approved and restricted tools

Provide an approved-tools list with the permitted account type and business purpose. Explain how staff can request another service. Avoid language that accidentally approves every feature from a supplier.

State clearly when a tool must not be used. Give people an alternative route for the task where possible.

Define what information may be entered

  • Public information
  • Internal information approved for the tool
  • Personal data
  • Customer and supplier confidential information
  • Commercially sensitive plans or financial records
  • Copyright material and licensed content

Do not rely on staff guessing the classification. Use examples from the organisation and link to the existing data and security policies.

Set rules for checking outputs

Require users to check facts, calculations, sources, tone and confidential content before using an output. Identify work that always needs specialist or management approval. AI should not be presented as the source of a decision when a person remains responsible.

Cover customer-facing use

State whether AI-prepared material may be sent to customers and what review is required. Explain when a person must take over. Avoid automatic use in complaints, legal commitments, pricing, safety or other high-impact situations unless a separately approved process exists.

Assign responsibilities

Name the owner of the policy, the approver for new tools and the contact for security or data concerns. Staff should know how to report a mistake without hiding it. Managers need to model the same behaviour expected from their teams.

Include training and review

Give staff practical examples before expecting compliance. Review the policy when tools, laws, contracts or business processes change. The AICC Responsible AI tools include a policy builder and governance resources. The ICO toolkit supports consideration of data protection risks.

Roll the policy out properly

Ask each team to work through realistic examples and identify any conflict with its normal process. Publish a short summary beside the full policy. Record acknowledgement, but do not treat a tick box as proof of understanding. Managers should revisit the rules during team meetings and when a new AI feature appears in existing software.

Keep the policy connected to real work

Use short supporting checklists, an accessible approved-tools register and a simple request process. A policy succeeds when staff can apply it during a busy day.

Develop practical AI rules for your team

Blue Canvas can combine policy work with practical AI training so the written rules become normal working practice.

Book a free 15-minute call

Read more

No items found.

Have a conversation with our specialists

It’s time to paint your business’s future with Blue Canvas. Don’t get left behind in the AI revolution. Unlock efficiency, elevate your sales, and drive new revenue with our help.

Book your free 15-minute consultation and discover how a top AI consultancy UK businesses trust can deliver game-changing results for you.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.