Resources · 7 July 2026
AI acceptable use policy template (UK): what to include
By the Operating Bench Team · Last reviewed 13 July 2026
If you are looking for an AI acceptable use policy template, the useful question is not just “where do I download one?” but “what does a good one actually contain?” Get the contents right and you can adapt almost any starting point. This guide walks through a solid UK policy section by section, with an adaptable sample clause for each part and a quick checklist at the end.
If you are still deciding whether you need one at all, start with the five-minute self-check. If you would rather follow a process than a checklist, see how to write an AI acceptable use policy, step by step. And if you are weighing a free template against a paid pack, we compare them in free vs paid AI policy template.
The sample clauses below are a starting point to adapt, not finished legal wording. Replace every
{{placeholder}}, delete what does not apply, and check it against the rules for your sector.
What this guide covers
- What an acceptable use policy is for
- Who and what it covers
- Your approved tools
- The one data rule
- Human review and accountability
- Disclosing AI use
- The rules that apply to you
- Reporting problems
- Ownership and review
- The quick checklist
What an acceptable use policy is for
An AI acceptable use policy is the core document in your AI governance. It exists to answer, in plain words, how your people may use AI without putting data, clients or the organisation at risk. It is not a ban and it is not a lecture. It is a short set of clear lines everyone can follow. The sections below are what a good one covers, and rarely needs much more.
Who and what it covers
Set the scope in a sentence or two: who the policy applies to, and what counts as an “AI tool”. Make it broad. It should reach employees, and also contractors, temporary staff and volunteers who act on your behalf, on any device. A policy that only reaches permanent staff leaves half the exposure uncovered.
Sample clause. This policy applies to all employees, contractors, temporary staff and volunteers of {{Organisation Name}} (“we”, “us”), on any device used for our work. “AI tools” means any system that generates, analyses, classifies or transforms content using machine learning or large language models, however it is reached: a website, an app, a browser extension, a built-in assistant, or an API.
Your approved tools
This is the section that makes a policy real. Name the specific AI tools people are allowed to use, and for what kind of data. “Use approved tools” means nothing without a list. Naming your tools, and keeping the list somewhere people can find it, is what stops staff quietly reaching for a random free tool, which is how shadow AI takes hold.
Sample clause. You may use the AI tools on our approved list, held at {{location}}, for the data types each one is approved for. You must not use any other AI tool for our work without approval from {{role, e.g. the Operations Director}}. If you would like a new tool added, ask; do not simply start using it.
The one data rule
This is the single rule that removes most of the risk: personal data, client or customer data, and anything confidential must never go into an unapproved AI tool. Make it concrete with a short list of what counts as confidential for you. If people can tell in five seconds whether something is safe to paste in, your policy is working. If that line is fuzzy for your team, what data is safe to put into AI spells it out.
Sample clause. Do not enter personal data, client or customer information, or anything confidential into an AI tool that is not approved for that data. This includes {{examples, e.g. names, contact details, financial information, case notes}}. If you are not sure whether something is safe to enter, treat it as confidential and ask first.
Human review and accountability
AI is confidently wrong sometimes, so a competent person must check AI output before it is relied on or sent, and that person, not the tool, is accountable for the result. Keep it proportionate: a quick sense-check for low-stakes drafting, a proper review for anything that affects a client, a decision or a published document.
Sample clause. AI output is a draft, not a decision. A suitably competent person must review AI-assisted work before it is sent externally, relied on, or used to make a decision about a person. The named individual, not the AI tool, remains responsible for the accuracy and appropriateness of the final result.
Disclosing AI use
Decide when you tell clients, customers, pupils or service users that AI was used, and how that shows up in your privacy information. You do not need to label every draft email, but you should be transparent where it matters and where people would reasonably expect to know.
Sample clause. We are transparent about our use of AI. Where AI has materially contributed to advice, a decision or a deliverable for a client, we will say so on request, and our privacy information explains how we use AI in relation to personal data.
The rules that apply to you
Name the rules that bind you, so the policy is anchored in something real. UK GDPR and the ICO apply to everyone. Add your sector regulator or professional body where relevant. If you serve people in the EU, the EU AI Act’s AI-literacy duty may apply too.
Sample clause. Our use of AI must comply with UK GDPR and guidance from the Information Commissioner’s Office, {{sector regulator or professional body, if any}}, and any other legal or professional obligation that applies to our work. Where these set a higher bar than this policy, the higher bar applies.
Reporting problems
Give people a simple, supportive route to flag when something has gone wrong, so you hear about it early rather than after a complaint. The tone matters: people report mistakes when they will not be punished for honesty.
Sample clause. If you think AI has been misused, or that data may have been entered into a tool it should not have been, tell {{role/contact}} as soon as possible. Reporting a genuine mistake promptly will never itself lead to disciplinary action; hiding one may.
Ownership and review
An unowned policy goes stale, and AI rules are moving quickly. Name a single owner and a date to review it. Three to six months is a sensible first interval.
Sample clause. {{Name / role}} owns this policy. It will be reviewed by {{date}}, and sooner if the law, our tools, or our risks change materially.
How long should it be
Resist the urge to make it long. A clear one or two pages that people read and follow is worth far more than an exhaustive document that sits in a folder. The sample clauses above are deliberately short. Add depth only where your sector or your risk genuinely calls for it.
The quick checklist
A good AI acceptable use policy answers all of these. Copy it, and tick each one off:
- Scope — does it cover staff, contractors and volunteers, on any device?
- Approved tools — is there a named list, and a way to add to it?
- The data line — is it clear what must never go into an unapproved tool?
- Human review — must a person check AI output, and are they accountable?
- Disclosure — do you say when and how you disclose AI use?
- The rules — does it name UK GDPR, the ICO and your sector regulator?
- Reporting — is there a safe, simple way to flag problems?
- Ownership — is there a named owner and a review date?
If you can tick all eight, you have a defensible policy. For a printable one-page version of this checklist plus a ready-made set of ground rules, the free AI Starter Kit has both.
Where sector nuance matters
Some sectors carry duties that a generic template will miss. We have practical, sector-specific versions for accountants, training providers and recruitment agencies, and full sector guides for schools, charities and healthcare practices, each built around the rules and regulators that actually apply.
Getting yours in place
You can write this from the sections and clauses above, or start from ready-made documents. The free AI Starter Kit gives you a one-page set of ground rules to begin with. For the full set, the AI Safe-Use Pack provides an editable acceptable use policy, with every clause above already written and ready to adapt, alongside a risk register, an approved-tools matrix, a DPIA starter and disclosure clauses, with tailored editions by sector. You can look inside it before you decide.
Whichever route you take, start today. A clear one-page policy in use beats a perfect one you never finish.
This article is general information, not legal advice. For advice on your specific circumstances, consult a suitably qualified professional.