An AI policy should help people make good decisions at work. It should not be a long document that nobody reads.
The strongest policies answer practical questions: which tools may staff use, what information may they enter, when must a person check the output and who owns each AI workflow?
The template below is a starting point, not legal advice. Adapt it to your business, contracts, sector duties and the types of information you handle. Where AI use affects people, regulated work or important decisions, obtain appropriate legal, data protection or professional advice.
This policy explains how [Business name] may use artificial intelligence at work. Its purpose is to support useful, responsible and secure use while protecting customers, staff, confidential information and the quality of our work.
This policy applies to employees, contractors and any other person using AI for work on behalf of [Business name]. It covers standalone AI services, AI features inside existing software and automated workflows that use AI.
Staff may use only the AI tools and account types approved by [Owner or role]. The current approved list is stored at [Location].
Requests for a new tool must explain:
Installing a browser extension or connecting an AI service to company data counts as using a new tool and requires approval.
Do not enter the following information into an AI service unless the specific workflow and tool have been approved for it:
Where a task can be completed with anonymised, redacted or fictional information, use that safer option.
AI output is a draft or recommendation unless an approved workflow states otherwise. The person using it remains responsible for checking accuracy, relevance, tone, confidentiality, copyright concerns and potential unfairness.
AI output must not be used as the sole basis for a legal, financial, employment, safety or other high-impact decision without an approved process and appropriate human oversight.
Customer messages, advice, quotations, decisions and published content created with AI must be reviewed by an authorised person before use unless a separately approved workflow defines equivalent controls.
Where customers interact directly with an AI system, [Business name] will consider whether clear disclosure, an alternative contact route and escalation to a person are needed.
An AI workflow must not send messages, change customer records, approve payments, issue refunds or make another material change unless the action has been explicitly approved, tested and logged.
High-impact actions require a human approval step unless [Named owner] has accepted a documented alternative control.
Every approved AI workflow must have a named business owner. The owner records its purpose, supplier, data, permissions, reviewers, known limitations, incidents and review date.
Use company-managed accounts where available. Do not share logins. Multi-factor authentication must be enabled where supported. Access must be removed when it is no longer required.
Connected tools receive only the permissions needed for the approved task.
Report accidental disclosure, incorrect actions, suspected security issues or harmful outputs immediately to [Contact or role]. Do not delete relevant records unless instructed to do so as part of the response.
Staff using AI for work receive training appropriate to their role. Training covers approved tools, restricted information, output checking, escalation and examples of safe use.
This policy is reviewed by [Owner] every [Period] and whenever a material tool, supplier, workflow or legal requirement changes.
Policy owner: [Name or role]
Approved on: [Date]
Next review: [Date]
A policy becomes useful when people can recognise their own work in it.
Examples might include:
Use examples that match your real workflows. Avoid promising that a tool is safe for every task simply because the business has approved it for one task.
Keep a short AI register beside the policy. For each use, record:
This turns the policy from a statement of intent into an operating control.
Do not copy a template and stop. The most common weaknesses are vague tool approval, no owner, no process for new requests, no rules for automated actions and no practical training.
A total ban can also push useful activity out of sight. Our guide to shadow AI in small businesses explains how to find unapproved use and replace it with safer routes.
Blue Canvas helps businesses turn policy decisions into approved tools, controlled workflows and role-based training. We can map current use, improve governance and implement practical systems through our AI consultancy.


It’s time to paint your business’s future with Blue Canvas. Don’t get left behind in the AI revolution. Unlock efficiency, elevate your sales, and drive new revenue with our help.
Book your free 15-minute consultation and discover how a top AI consultancy UK businesses trust can deliver game-changing results for you.