Company AI Usage Policy for UK Businesses
Businesses increasingly need a clear rule for what staff may put into AI, which services are approved, when human review is required and how personal or confidential data is protected. A useful AI policy enables safe adoption rather than treating every AI tool as either automatically safe or completely banned.
What the policy should cover
Approved AI services and accounts; personal and confidential data; GDPR and DPIAs; human review; accuracy and hallucinations; recruitment and HR use; copyright; AI-generated code; connectors and agents; incident reporting; monitoring and staff training.
Why this matters for GDPR and security
The ICO’s AI guidance expects organisations processing personal data with AI to address accountability, transparency, lawfulness, security, data minimisation, fairness and individual rights. The UK Government AI Cyber Security Code also stresses risk assessment, human responsibility, asset protection, secure infrastructure, supply-chain security, documented data/models/prompts, testing and monitoring.
Download the free policy template
Editable AI Usage Policy Template for UK organisations, with an approved-services register and AI use-case checklist.
Get the Company AI usage policy.
Editable AI Usage Policy Template and branded PDF copy.
- Branded 39Security template
- Editable Word document
- Secure email link - no attachment
- © 2026 Matthew Southgate. All rights reserved.
30 practical answers.
Does a company need an AI usage policy?
If staff use generative AI, copilots, transcription tools, coding assistants or AI agents for work, a written policy helps define approved tools, permitted data, human review, accountability and incident reporting. The policy should reflect the organisation’s actual AI use rather than simply banning or allowing everything.
Can employees use ChatGPT or other public AI tools for work?
Only if the organisation has approved the service for the intended purpose and information type. A public consumer account may have different data-handling, retention, administrative and contractual controls from an enterprise service.
Does UK GDPR apply when staff use AI?
Yes when personal data is processed. The organisation still needs an appropriate lawful basis, transparency, data minimisation, security, accountability and support for applicable individual rights. Using an AI supplier does not remove the organisation’s responsibilities.
Can staff paste customer information into an AI chatbot?
Not by default. Customer information should only be entered where the AI service and use case have been approved for that data, the processing is lawful and necessary, and supplier/security arrangements are understood. Minimise or anonymise information where possible.
Can staff upload employee or HR information to AI?
HR data can be sensitive and may affect people significantly. It should not be uploaded to an AI service unless the use has been formally assessed, the selected service is approved, appropriate data-protection controls are in place and meaningful human review is maintained.
What information should never be entered into AI?
Passwords, MFA codes, private keys, API secrets and authentication tokens should never be entered. Highly confidential, legally privileged, security-sensitive, special-category or restricted information should also be prohibited unless a specifically approved environment and use case permits it.
What is shadow AI?
Shadow AI is the use of AI tools, accounts, browser extensions or features that the organisation has not approved or may not even know are being used. It can create uncontrolled data sharing, retention, security and compliance risks.
Should we keep a list of approved AI tools?
Yes. An approved-services register can record the service, permitted purpose, permitted data classification, owner and review date. Approval should include specific features and connectors rather than treating an entire vendor ecosystem as automatically approved.
What should we check before approving an AI supplier?
Review how prompts, uploads and outputs are stored; whether data is used for model training; retention and deletion; subprocessors; data location where relevant; authentication; audit logs; incident notification; contractual terms; connectors; and whether external models receive the data.
Do we need a DPIA for AI?
A DPIA must be considered where AI processing is likely to result in a high risk to people’s rights and freedoms. High-impact uses, sensitive data, extensive profiling, workplace monitoring or new forms of automated decision-making are examples that deserve particular attention.
Can AI make recruitment or HR decisions?
AI may support some HR processes, but high-impact decisions require careful assessment of lawfulness, fairness, bias, transparency and human involvement. Staff should not use an AI output as the sole basis for a significant employment decision without an approved process and the required safeguards.
What does human review mean in an AI policy?
A suitably competent person should check important AI output before it is relied upon, sent to a customer, published, used in a decision or deployed to a production system. The reviewer must be able to challenge or reject the AI output rather than merely rubber-stamp it.
What are AI hallucinations?
AI systems can confidently produce incorrect facts, citations, calculations, legal statements, code or technical instructions. Important claims should be verified against reliable sources and not presented as fact solely because an AI system produced them.
Who is responsible when an employee uses AI?
The person and business process using the AI remain accountable for the outcome. A policy should assign clear ownership to the business function, data-protection/security roles and the person approving the final decision or output.
Can we use AI to write customer emails and reports?
Yes where the tool and source information are approved, but the output should be reviewed for accuracy, confidentiality, tone, legal risk and fabricated content before it is sent externally.
Can we use AI to summarise meetings?
Potentially, but AI meeting assistants can capture personal data, confidential information and sensitive discussions. The organisation should approve the service, provide appropriate notice, control who can access transcripts and set retention rules.
Can staff use AI to generate computer code?
Yes in an approved development environment, but generated code must be treated as untrusted until reviewed, tested and scanned. Staff should check dependencies, licences and security implications and must not paste production secrets into coding assistants.
Can an AI tool have access to Microsoft 365, Google Workspace or our CRM?
Only after assessing the permissions and business need. Connectors can expose large volumes of email, files and customer information. Apply least privilege, restrict scopes, use approved accounts and make sure access can be revoked quickly.
What is prompt injection?
Prompt injection is an attack or manipulation that tries to make an AI system ignore its intended instructions or reveal or act on information in an unsafe way. It is particularly important when AI systems process untrusted web pages, emails, documents or tool outputs.
Should AI agents be allowed to take actions automatically?
High-impact actions should not be fully autonomous by default. Payments, bank-detail changes, account creation, deletion, privilege changes and other material actions should normally require human approval and appropriate logging.
Can AI output be copyrighted?
Intellectual-property treatment can be complex and depends on the material, jurisdiction, service terms and human contribution. Businesses should not assume AI output is automatically safe to publish or free from third-party copyright or licence issues.
Can we paste copyrighted documents into AI?
Only if the organisation is entitled to use the material in that way and the AI service is approved. Contracts, licences and confidentiality restrictions may limit what can be uploaded even where the organisation lawfully possesses a copy.
Do we need to tell customers that we use AI?
Sometimes. Where AI processes personal data or materially affects people, transparency obligations may require meaningful information about the processing. Even outside a strict legal requirement, disclosure can be appropriate where it is important to trust or customer expectations.
Should we let staff use personal AI accounts?
Prefer organisationally managed accounts for business use where available. Personal accounts reduce the organisation’s ability to control access, enforce settings, manage retention, remove users, investigate incidents and demonstrate contractual protections.
Should AI access use MFA?
Yes where supported. Approved AI services should use organisational identity, MFA and least-privilege access, particularly when the service can see internal files, email, code or customer data.
How should we handle an accidental confidential-data upload to AI?
Report it immediately through the security/data-protection incident process. Record what was uploaded, the service used, account, time and whether the content can be deleted or support contacted. Do not hide the mistake; rapid reporting improves containment and regulatory assessment.
Should staff receive AI security training?
Yes. Training should cover approved tools, data classification, confidential and personal data, hallucinations, prompt injection, phishing, intellectual property, human review, AI agents and how to report incidents.
Can we monitor how staff use workplace AI tools?
Monitoring must have a defined purpose and be necessary, proportionate and transparent. Workers should receive appropriate privacy information and a DPIA should be considered where monitoring creates a high risk to rights and freedoms.
How often should an AI policy be reviewed?
At least annually is a useful baseline, but review sooner after major supplier changes, new AI features, changes to law or ICO guidance, significant incidents, new automated use cases or changes to the categories of data being processed.
Can I download a company AI policy template?
Yes. 39Security provides an editable UK-focused Company AI Usage Policy Template. Enter your email address on this page and we will send a secure download link rather than attaching the document to the email.