Resources · 30 June 2026

Do I need an AI policy? A five-minute self-check for UK organisations

By the Operating Bench Team · Last reviewed 30 June 2026

The honest answer is: probably, but not the kind you are picturing. Most people hear “AI policy” and imagine a twenty-page document that takes a working group three months and then sits in a folder. You do not need that. You need a short, clear set of rules that a new starter could read in five minutes.

Here is a five-minute check to work out whether you need one, and how far it needs to go. Prefer it interactive? Our AI Policy Health Check gives you a scored result and a tailored next step in about two minutes.

The five-minute check

Answer these honestly. If you are not sure, treat that as a yes.

  1. Do your staff use AI tools for work? Even free ones, even occasionally. ChatGPT, Copilot, an AI notetaker, a summariser, a writing aid. If you think the answer is no, it is worth reading what shadow AI looks like first, because it is usually happening whether or not anyone has said so.
  2. Does any of that work touch personal, client or confidential data? Customer details, staff records, financial information, anything you would not want to see forwarded outside the organisation.
  3. Does anyone rely on AI output without a person checking it? A drafted email that goes straight out, a summary that informs a decision, numbers that get reused.
  4. Would a client, funder, auditor or regulator expect you to have rules? In some sectors this is already a question on tenders and due-diligence forms.
  5. If someone misused an AI tool tomorrow, is it written down who is responsible and what to do?

Scoring is simple. If you answered yes, or “not sure”, to any of these, you need something written down. Most UK organisations answer yes to the first three without thinking hard about it.

What “enough” looks like

For a lot of small organisations, a good AI policy is one page. It needs to answer five questions:

If you can answer those five clearly, you have covered most of the risk. That is the whole point of starting small: get the basics written and used, then add depth where it matters.

When you need more than the minimum

Some organisations need to go further, and it is usually obvious which:

None of this means a bigger document for its own sake. It means the same five questions, answered with your sector’s specifics in mind.

How to get there this week

You do not have to start from a blank page.

Start with the one page. You can have the basics in place today, and that is worth far more than a perfect policy you never finish.


This article is general information, not legal advice. For advice on your specific circumstances, consult a suitably qualified professional.

Frequently asked questions

Does a small business really need an AI policy?
If your staff use AI at work and any of it touches personal, client or confidential data, then yes. It does not need to be long. A one-page set of clear rules is far more useful than a document nobody reads.
Is an AI policy a legal requirement in the UK?
There is no single law that says you must have an AI policy. But the rules that already apply to you, UK GDPR and your sector regulator or professional body, are much easier to meet if your AI use is written down. A policy is how you show you have thought about it.
What is the minimum an AI policy should cover?
Five things: which tools are approved, what data must never go in, who checks AI output before it is relied on, who is accountable, and what to do when something goes wrong.

Sources & further reading

External links are provided for reference and open in a new tab. This article is general information, not legal advice.

Share this LinkedIn X

One email when it matters

A short note when the rules change or we publish something genuinely useful for UK organisations. No spam, unsubscribe in one click.