Free company AI policy template

AI Usage Policy Template for UK Businesses

A company AI usage policy gives employees clear rules for using ChatGPT, Microsoft Copilot, generative AI and AI-enabled business tools without exposing confidential information, personal data or the organisation to avoidable risk.

Quick answer

What is this policy and why does it matter?

An AI usage policy tells staff which AI tools are approved, what information may be entered, when human review is required and who remains responsible for the result. It helps a business adopt AI consistently while managing data protection, cyber security, accuracy, intellectual-property and supplier risks.

Business case

Why does a company need this policy?

A policy is not a substitute for technical controls, but it gives employees, managers and IT teams one written standard to work from.

✓

Control shadow AI

Staff can start using new AI services in minutes. A written policy makes the approved route clear and reduces uncontrolled use of consumer accounts, browser extensions and unreviewed tools.

✓

Protect confidential and personal data

Employees need a simple rule for customer information, employee data, contracts, credentials, commercially sensitive material and other information that must not be pasted into an unapproved AI service.

✓

Keep humans accountable

AI can produce inaccurate, invented or inappropriate output. The policy defines where review is mandatory and confirms that the employee and business process remain responsible for the final decision or content.

✓

Set rules before AI agents arrive

Copilots, connectors and AI agents can reach email, files, CRM systems and other data. A policy creates a governance baseline before permissions and automation become difficult to control.

Inside the template

What should the policy cover?

The downloadable template is designed to be edited around your organisation, technology and employment practices rather than published unchanged.

Approved AI tools and business accounts
ChatGPT, Microsoft Copilot and generative AI use
Personal data, UK GDPR and data minimisation
Confidential, privileged and commercially sensitive information
Human review and responsibility for AI output
Hallucinations, fact checking and quality control
AI use in HR, recruitment and people decisions
Copyright, licensing and third-party material
AI-generated code, scripts and technical output
AI agents, connectors, permissions and automation
Prompt injection and untrusted content
Incident reporting, staff training and policy review
Who should use it?

Designed for practical UK business use.

  • Businesses already using ChatGPT, Copilot or other generative AI
  • Employers whose staff are experimenting with AI without formal rules
  • Organisations handling customer, employee or confidential information
  • SMEs introducing AI assistants, meeting tools, coding tools or automated agents

Important: This is a practical template and should be adapted to your organisation. It is not legal or employment-law advice.

Implementation

How to put the policy into practice.

  1. 1

    Identify the AI services and features staff currently use, including personal accounts and browser extensions.

  2. 2

    Create an approved AI register that records the permitted purpose and permitted information for each service.

  3. 3

    Classify the information staff must never enter into an unapproved AI service.

  4. 4

    Set mandatory human-review points for customer content, technical output, employment decisions and other important work.

  5. 5

    Brief staff, record acceptance where appropriate and make the policy easy to find.

  6. 6

    Review the policy when new AI tools, connectors, agents, suppliers or business processes are introduced.

Free 39Security download

Get the Company AI usage policy.

Editable AI Usage Policy Template and branded PDF copy.

  • Branded 39Security template
  • Editable Word document
  • Secure email link - no attachment
  • © 2026 Matthew Southgate. All rights reserved.

Email me the download link

By requesting the resource you agree that the transactional delivery email can use a unique open pixel and secure link so 39Security can record delivery-email opens, link clicks and downloads. These measurements can be affected by mail-security scanners and privacy proxies. You will not be added to marketing by this form.

See the privacy notice.

Policy implementation support

Need help making the policy real?

39Security supports small and medium businesses across Essex, Kent, Hertfordshire and London with AI governance, Microsoft 365 security, staff cyber-security training and practical policy implementation. Remote support is also available more widely across the UK.

Talk to 39Security
Frequently asked questions

30 practical answers.

Use these answers alongside your own risk assessment, technical controls and employment or legal advice where needed.

Does a company need an AI usage policy?

If staff use generative AI, copilots, transcription tools, coding assistants or AI agents for work, a written policy helps define approved tools, permitted data, human review, accountability and incident reporting. The policy should reflect the organisation’s actual AI use rather than simply banning or allowing everything.

Can employees use ChatGPT or other public AI tools for work?

Only if the organisation has approved the service for the intended purpose and information type. A public consumer account may have different data-handling, retention, administrative and contractual controls from an enterprise service.

Does UK GDPR apply when staff use AI?

Yes when personal data is processed. The organisation still needs an appropriate lawful basis, transparency, data minimisation, security, accountability and support for applicable individual rights. Using an AI supplier does not remove the organisation’s responsibilities.

Can staff paste customer information into an AI chatbot?

Not by default. Customer information should only be entered where the AI service and use case have been approved for that data, the processing is lawful and necessary, and supplier/security arrangements are understood. Minimise or anonymise information where possible.

Can staff upload employee or HR information to AI?

HR data can be sensitive and may affect people significantly. It should not be uploaded to an AI service unless the use has been formally assessed, the selected service is approved, appropriate data-protection controls are in place and meaningful human review is maintained.

What information should never be entered into AI?

Passwords, MFA codes, private keys, API secrets and authentication tokens should never be entered. Highly confidential, legally privileged, security-sensitive, special-category or restricted information should also be prohibited unless a specifically approved environment and use case permits it.

What is shadow AI?

Shadow AI is the use of AI tools, accounts, browser extensions or features that the organisation has not approved or may not even know are being used. It can create uncontrolled data sharing, retention, security and compliance risks.

Should we keep a list of approved AI tools?

Yes. An approved-services register can record the service, permitted purpose, permitted data classification, owner and review date. Approval should include specific features and connectors rather than treating an entire vendor ecosystem as automatically approved.

What should we check before approving an AI supplier?

Review how prompts, uploads and outputs are stored; whether data is used for model training; retention and deletion; subprocessors; data location where relevant; authentication; audit logs; incident notification; contractual terms; connectors; and whether external models receive the data.

Do we need a DPIA for AI?

A DPIA must be considered where AI processing is likely to result in a high risk to people’s rights and freedoms. High-impact uses, sensitive data, extensive profiling, workplace monitoring or new forms of automated decision-making are examples that deserve particular attention.

Can AI make recruitment or HR decisions?

AI may support some HR processes, but high-impact decisions require careful assessment of lawfulness, fairness, bias, transparency and human involvement. Staff should not use an AI output as the sole basis for a significant employment decision without an approved process and the required safeguards.

What does human review mean in an AI policy?

A suitably competent person should check important AI output before it is relied upon, sent to a customer, published, used in a decision or deployed to a production system. The reviewer must be able to challenge or reject the AI output rather than merely rubber-stamp it.

What are AI hallucinations?

AI systems can confidently produce incorrect facts, citations, calculations, legal statements, code or technical instructions. Important claims should be verified against reliable sources and not presented as fact solely because an AI system produced them.

Who is responsible when an employee uses AI?

The person and business process using the AI remain accountable for the outcome. A policy should assign clear ownership to the business function, data-protection/security roles and the person approving the final decision or output.

Can we use AI to write customer emails and reports?

Yes where the tool and source information are approved, but the output should be reviewed for accuracy, confidentiality, tone, legal risk and fabricated content before it is sent externally.

Can we use AI to summarise meetings?

Potentially, but AI meeting assistants can capture personal data, confidential information and sensitive discussions. The organisation should approve the service, provide appropriate notice, control who can access transcripts and set retention rules.

Can staff use AI to generate computer code?

Yes in an approved development environment, but generated code must be treated as untrusted until reviewed, tested and scanned. Staff should check dependencies, licences and security implications and must not paste production secrets into coding assistants.

Can an AI tool have access to Microsoft 365, Google Workspace or our CRM?

Only after assessing the permissions and business need. Connectors can expose large volumes of email, files and customer information. Apply least privilege, restrict scopes, use approved accounts and make sure access can be revoked quickly.

What is prompt injection?

Prompt injection is an attack or manipulation that tries to make an AI system ignore its intended instructions or reveal or act on information in an unsafe way. It is particularly important when AI systems process untrusted web pages, emails, documents or tool outputs.

Should AI agents be allowed to take actions automatically?

High-impact actions should not be fully autonomous by default. Payments, bank-detail changes, account creation, deletion, privilege changes and other material actions should normally require human approval and appropriate logging.

Can AI output be copyrighted?

Intellectual-property treatment can be complex and depends on the material, jurisdiction, service terms and human contribution. Businesses should not assume AI output is automatically safe to publish or free from third-party copyright or licence issues.

Can we paste copyrighted documents into AI?

Only if the organisation is entitled to use the material in that way and the AI service is approved. Contracts, licences and confidentiality restrictions may limit what can be uploaded even where the organisation lawfully possesses a copy.

Do we need to tell customers that we use AI?

Sometimes. Where AI processes personal data or materially affects people, transparency obligations may require meaningful information about the processing. Even outside a strict legal requirement, disclosure can be appropriate where it is important to trust or customer expectations.

Should we let staff use personal AI accounts?

Prefer organisationally managed accounts for business use where available. Personal accounts reduce the organisation’s ability to control access, enforce settings, manage retention, remove users, investigate incidents and demonstrate contractual protections.

Should AI access use MFA?

Yes where supported. Approved AI services should use organisational identity, MFA and least-privilege access, particularly when the service can see internal files, email, code or customer data.

How should we handle an accidental confidential-data upload to AI?

Report it immediately through the security/data-protection incident process. Record what was uploaded, the service used, account, time and whether the content can be deleted or support contacted. Do not hide the mistake; rapid reporting improves containment and regulatory assessment.

Should staff receive AI security training?

Yes. Training should cover approved tools, data classification, confidential and personal data, hallucinations, prompt injection, phishing, intellectual property, human review, AI agents and how to report incidents.

Can we monitor how staff use workplace AI tools?

Monitoring must have a defined purpose and be necessary, proportionate and transparent. Workers should receive appropriate privacy information and a DPIA should be considered where monitoring creates a high risk to rights and freedoms.

How often should an AI policy be reviewed?

At least annually is a useful baseline, but review sooner after major supplier changes, new AI features, changes to law or ICO guidance, significant incidents, new automated use cases or changes to the categories of data being processed.

Can I download a company AI policy template?

Yes. 39Security provides an editable UK-focused Company AI Usage Policy Template. Enter your email address on this page and we will send a secure download link rather than attaching the document to the email.

Related guidance

Keep improving the control set.