Blog

AI policy template for UK businesses

Phil Patterson
calender
August 19, 2026

An AI policy should help people make good decisions at work. It should not be a long document that nobody reads.

The strongest policies answer practical questions: which tools may staff use, what information may they enter, when must a person check the output and who owns each AI workflow?

The template below is a starting point, not legal advice. Adapt it to your business, contracts, sector duties and the types of information you handle. Where AI use affects people, regulated work or important decisions, obtain appropriate legal, data protection or professional advice.

How to use this template

  1. Name one senior owner.
  2. List the AI tools currently used, including features inside existing software.
  3. Replace the bracketed wording with your own decisions.
  4. Test the rules against real tasks from different teams.
  5. Train staff using examples.
  6. Review the policy when tools, suppliers or workflows change.

Copyable AI policy template

1. Purpose

This policy explains how [Business name] may use artificial intelligence at work. Its purpose is to support useful, responsible and secure use while protecting customers, staff, confidential information and the quality of our work.

2. Scope

This policy applies to employees, contractors and any other person using AI for work on behalf of [Business name]. It covers standalone AI services, AI features inside existing software and automated workflows that use AI.

3. Approved tools

Staff may use only the AI tools and account types approved by [Owner or role]. The current approved list is stored at [Location].

Requests for a new tool must explain:

  • the business task
  • the information the tool will receive
  • the expected output or action
  • the supplier and account type
  • who will review the result

Installing a browser extension or connecting an AI service to company data counts as using a new tool and requires approval.

4. Restricted information

Do not enter the following information into an AI service unless the specific workflow and tool have been approved for it:

  • passwords, security keys or authentication codes
  • customer or employee personal data
  • health, financial or other sensitive personal information
  • confidential contracts, tenders or legal advice
  • unpublished financial or commercial information
  • material owned by another party where we lack permission

Where a task can be completed with anonymised, redacted or fictional information, use that safer option.

5. Checking outputs

AI output is a draft or recommendation unless an approved workflow states otherwise. The person using it remains responsible for checking accuracy, relevance, tone, confidentiality, copyright concerns and potential unfairness.

AI output must not be used as the sole basis for a legal, financial, employment, safety or other high-impact decision without an approved process and appropriate human oversight.

6. Customer-facing use

Customer messages, advice, quotations, decisions and published content created with AI must be reviewed by an authorised person before use unless a separately approved workflow defines equivalent controls.

Where customers interact directly with an AI system, [Business name] will consider whether clear disclosure, an alternative contact route and escalation to a person are needed.

7. Automated actions

An AI workflow must not send messages, change customer records, approve payments, issue refunds or make another material change unless the action has been explicitly approved, tested and logged.

High-impact actions require a human approval step unless [Named owner] has accepted a documented alternative control.

8. Ownership and records

Every approved AI workflow must have a named business owner. The owner records its purpose, supplier, data, permissions, reviewers, known limitations, incidents and review date.

9. Security and access

Use company-managed accounts where available. Do not share logins. Multi-factor authentication must be enabled where supported. Access must be removed when it is no longer required.

Connected tools receive only the permissions needed for the approved task.

10. Reporting problems

Report accidental disclosure, incorrect actions, suspected security issues or harmful outputs immediately to [Contact or role]. Do not delete relevant records unless instructed to do so as part of the response.

11. Training

Staff using AI for work receive training appropriate to their role. Training covers approved tools, restricted information, output checking, escalation and examples of safe use.

12. Review

This policy is reviewed by [Owner] every [Period] and whenever a material tool, supplier, workflow or legal requirement changes.

Policy owner: [Name or role]

Approved on: [Date]

Next review: [Date]

Add role-specific examples

A policy becomes useful when people can recognise their own work in it.

Examples might include:

  • Sales may use an approved tool to draft a follow-up from non-sensitive notes, but a person checks the final email.
  • Operations may classify incoming requests, but unusual or urgent items go to a person.
  • Finance may use AI to explain a spreadsheet formula, but it does not approve payments or final figures.
  • Managers may summarise an internal meeting, provided attendance, storage and confidential material are handled through the approved system.

Use examples that match your real workflows. Avoid promising that a tool is safe for every task simply because the business has approved it for one task.

Connect the policy to a register

Keep a short AI register beside the policy. For each use, record:

  • workflow name and owner
  • approved tool and account type
  • purpose
  • data used
  • connected systems
  • output and action
  • human review
  • supplier review date
  • incidents or changes

This turns the policy from a statement of intent into an operating control.

Avoid the usual policy mistakes

Do not copy a template and stop. The most common weaknesses are vague tool approval, no owner, no process for new requests, no rules for automated actions and no practical training.

A total ban can also push useful activity out of sight. Our guide to shadow AI in small businesses explains how to find unapproved use and replace it with safer routes.

Blue Canvas helps businesses turn policy decisions into approved tools, controlled workflows and role-based training. We can map current use, improve governance and implement practical systems through our AI consultancy.

Sources

Book a free 15-minute call

Read more

No items found.

Have a conversation with our specialists

It’s time to paint your business’s future with Blue Canvas. Don’t get left behind in the AI revolution. Unlock efficiency, elevate your sales, and drive new revenue with our help.

Book your free 15-minute consultation and discover how a top AI consultancy UK businesses trust can deliver game-changing results for you.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.