Control shadow AI
Staff can start using new AI services in minutes. A written policy makes the approved route clear and reduces uncontrolled use of consumer accounts, browser extensions and unreviewed tools.
A company AI usage policy gives employees clear rules for using ChatGPT, Microsoft Copilot, generative AI and AI-enabled business tools without exposing confidential information, personal data or the organisation to avoidable risk.
An AI usage policy tells staff which AI tools are approved, what information may be entered, when human review is required and who remains responsible for the result. It helps a business adopt AI consistently while managing data protection, cyber security, accuracy, intellectual-property and supplier risks.
A policy is not a substitute for technical controls, but it gives employees, managers and IT teams one written standard to work from.
Staff can start using new AI services in minutes. A written policy makes the approved route clear and reduces uncontrolled use of consumer accounts, browser extensions and unreviewed tools.
Employees need a simple rule for customer information, employee data, contracts, credentials, commercially sensitive material and other information that must not be pasted into an unapproved AI service.
AI can produce inaccurate, invented or inappropriate output. The policy defines where review is mandatory and confirms that the employee and business process remain responsible for the final decision or content.
Copilots, connectors and AI agents can reach email, files, CRM systems and other data. A policy creates a governance baseline before permissions and automation become difficult to control.
The downloadable template is designed to be edited around your organisation, technology and employment practices rather than published unchanged.
Important: This is a practical template and should be adapted to your organisation. It is not legal or employment-law advice.
Identify the AI services and features staff currently use, including personal accounts and browser extensions.
Create an approved AI register that records the permitted purpose and permitted information for each service.
Classify the information staff must never enter into an unapproved AI service.
Set mandatory human-review points for customer content, technical output, employment decisions and other important work.
Brief staff, record acceptance where appropriate and make the policy easy to find.
Review the policy when new AI tools, connectors, agents, suppliers or business processes are introduced.
Editable AI Usage Policy Template and branded PDF copy.
39Security supports small and medium businesses across Essex, Kent, Hertfordshire and London with AI governance, Microsoft 365 security, staff cyber-security training and practical policy implementation. Remote support is also available more widely across the UK.
Use these answers alongside your own risk assessment, technical controls and employment or legal advice where needed.
If staff use generative AI, copilots, transcription tools, coding assistants or AI agents for work, a written policy helps define approved tools, permitted data, human review, accountability and incident reporting. The policy should reflect the organisation’s actual AI use rather than simply banning or allowing everything.
Only if the organisation has approved the service for the intended purpose and information type. A public consumer account may have different data-handling, retention, administrative and contractual controls from an enterprise service.
Yes when personal data is processed. The organisation still needs an appropriate lawful basis, transparency, data minimisation, security, accountability and support for applicable individual rights. Using an AI supplier does not remove the organisation’s responsibilities.
Not by default. Customer information should only be entered where the AI service and use case have been approved for that data, the processing is lawful and necessary, and supplier/security arrangements are understood. Minimise or anonymise information where possible.
HR data can be sensitive and may affect people significantly. It should not be uploaded to an AI service unless the use has been formally assessed, the selected service is approved, appropriate data-protection controls are in place and meaningful human review is maintained.
Passwords, MFA codes, private keys, API secrets and authentication tokens should never be entered. Highly confidential, legally privileged, security-sensitive, special-category or restricted information should also be prohibited unless a specifically approved environment and use case permits it.
Shadow AI is the use of AI tools, accounts, browser extensions or features that the organisation has not approved or may not even know are being used. It can create uncontrolled data sharing, retention, security and compliance risks.
Yes. An approved-services register can record the service, permitted purpose, permitted data classification, owner and review date. Approval should include specific features and connectors rather than treating an entire vendor ecosystem as automatically approved.
Review how prompts, uploads and outputs are stored; whether data is used for model training; retention and deletion; subprocessors; data location where relevant; authentication; audit logs; incident notification; contractual terms; connectors; and whether external models receive the data.
A DPIA must be considered where AI processing is likely to result in a high risk to people’s rights and freedoms. High-impact uses, sensitive data, extensive profiling, workplace monitoring or new forms of automated decision-making are examples that deserve particular attention.
AI may support some HR processes, but high-impact decisions require careful assessment of lawfulness, fairness, bias, transparency and human involvement. Staff should not use an AI output as the sole basis for a significant employment decision without an approved process and the required safeguards.
A suitably competent person should check important AI output before it is relied upon, sent to a customer, published, used in a decision or deployed to a production system. The reviewer must be able to challenge or reject the AI output rather than merely rubber-stamp it.
AI systems can confidently produce incorrect facts, citations, calculations, legal statements, code or technical instructions. Important claims should be verified against reliable sources and not presented as fact solely because an AI system produced them.
The person and business process using the AI remain accountable for the outcome. A policy should assign clear ownership to the business function, data-protection/security roles and the person approving the final decision or output.
Yes where the tool and source information are approved, but the output should be reviewed for accuracy, confidentiality, tone, legal risk and fabricated content before it is sent externally.
Potentially, but AI meeting assistants can capture personal data, confidential information and sensitive discussions. The organisation should approve the service, provide appropriate notice, control who can access transcripts and set retention rules.
Yes in an approved development environment, but generated code must be treated as untrusted until reviewed, tested and scanned. Staff should check dependencies, licences and security implications and must not paste production secrets into coding assistants.
Only after assessing the permissions and business need. Connectors can expose large volumes of email, files and customer information. Apply least privilege, restrict scopes, use approved accounts and make sure access can be revoked quickly.
Prompt injection is an attack or manipulation that tries to make an AI system ignore its intended instructions or reveal or act on information in an unsafe way. It is particularly important when AI systems process untrusted web pages, emails, documents or tool outputs.
High-impact actions should not be fully autonomous by default. Payments, bank-detail changes, account creation, deletion, privilege changes and other material actions should normally require human approval and appropriate logging.
Intellectual-property treatment can be complex and depends on the material, jurisdiction, service terms and human contribution. Businesses should not assume AI output is automatically safe to publish or free from third-party copyright or licence issues.
Only if the organisation is entitled to use the material in that way and the AI service is approved. Contracts, licences and confidentiality restrictions may limit what can be uploaded even where the organisation lawfully possesses a copy.
Sometimes. Where AI processes personal data or materially affects people, transparency obligations may require meaningful information about the processing. Even outside a strict legal requirement, disclosure can be appropriate where it is important to trust or customer expectations.
Prefer organisationally managed accounts for business use where available. Personal accounts reduce the organisation’s ability to control access, enforce settings, manage retention, remove users, investigate incidents and demonstrate contractual protections.
Yes where supported. Approved AI services should use organisational identity, MFA and least-privilege access, particularly when the service can see internal files, email, code or customer data.
Report it immediately through the security/data-protection incident process. Record what was uploaded, the service used, account, time and whether the content can be deleted or support contacted. Do not hide the mistake; rapid reporting improves containment and regulatory assessment.
Yes. Training should cover approved tools, data classification, confidential and personal data, hallucinations, prompt injection, phishing, intellectual property, human review, AI agents and how to report incidents.
Monitoring must have a defined purpose and be necessary, proportionate and transparent. Workers should receive appropriate privacy information and a DPIA should be considered where monitoring creates a high risk to rights and freedoms.
At least annually is a useful baseline, but review sooner after major supplier changes, new AI features, changes to law or ICO guidance, significant incidents, new automated use cases or changes to the categories of data being processed.
Yes. 39Security provides an editable UK-focused Company AI Usage Policy Template. Enter your email address on this page and we will send a secure download link rather than attaching the document to the email.