Resources · 13 July 2026
How to write an AI acceptable use policy: a step-by-step guide (UK)
By the Operating Bench Team · Last reviewed 13 July 2026
Most guides tell you what an AI policy should contain. This one is about the harder part: actually writing it and getting your team to follow it. Here is a straightforward, seven-step process you can work through in an afternoon.
If you first want the full contents checklist, see what to include in an AI acceptable use policy. If you are not yet sure you need one, start with the five-minute self-check.
Step 1: Find out how AI is already being used
Do not start with the document. Start with reality. Ask around, honestly and without blame: which AI tools are people already using, and what for? You will almost always find more than you expected, often on personal accounts. This is shadow AI, and a policy written without knowing about it will miss the point. Fifteen minutes of asking tells you what your policy actually needs to address.
Step 2: Set the scope
Decide, in one sentence, who and what the policy covers. The answer is usually broader than “employees”: include contractors, temporary staff and volunteers who act on your behalf, on any device. AI use on a personal laptop is still your risk. A policy that only reaches permanent staff leaves half the exposure uncovered.
Step 3: Name your approved tools
This is the step that makes a policy real. List the specific AI tools people are allowed to use, and for what kind of data. “Use approved tools” means nothing without a list; naming Copilot, a paid ChatGPT Team plan or a particular vendor turns it into a rule. Anything not on the list needs a quick check before it is used. This single list is what stops people quietly reaching for a random free tool.
Step 4: Draw the hard line on data
Write the one rule that removes most of the risk:
Personal data, client or customer data, and anything confidential must never go into an unapproved AI tool.
Then make it concrete for your organisation with a short list of examples of what counts as confidential. If people can tell in five seconds whether something is safe to paste in, your policy is working. This is also the line that keeps you the right side of UK GDPR.
Step 5: Decide who checks AI output, and who is accountable
AI is confidently wrong sometimes. Your policy needs to say that a competent person reviews AI output before it is sent or relied on, and that the person, not the tool, is accountable for the result. Keep it proportionate: a quick sense-check for low-stakes drafting, a proper review for anything that affects a client, a decision or a published document.
Step 6: Add disclosure, reporting and the rules that apply to you
Three short sections finish the substance:
- Disclosure. When and how you tell clients, customers or service users that AI was involved, and how that shows up in your privacy information.
- Reporting. A simple, supportive route for people to flag when something has gone wrong, so you hear about it early rather than after a complaint.
- The rules that apply to you. UK GDPR and the ICO for everyone, plus your sector regulator or professional body where relevant. If you serve people in the EU, the EU AI Act’s AI-literacy duty may apply too.
Step 7: Give it an owner and a review date
An unowned policy goes stale, and AI rules are moving quickly. Name a single owner and set a review date, three to six months out to begin with. Then do the most important thing: put it in front of people. Circulate a one-page summary, talk through it once, and make it easy to find. A policy nobody has read is not a policy.
Keep it short
Resist the urge to pad it out. A clear one or two pages that people read and follow beats a twenty-page document that lives in a folder. Add depth only where your sector or your risk genuinely calls for it. Some sectors, such as schools, healthcare practices and charities, carry duties a generic policy will miss, and are worth a sector-specific version.
A faster route
You can write all of this from scratch using the steps above. If you would rather not start from a blank page, the free AI Starter Kit gives you a one-page set of ground rules to adapt today. The full AI Safe-Use Pack provides an editable acceptable use policy alongside the approved-tools matrix, risk register, DPIA starter and disclosure clauses that Steps 3 to 6 call for, so the structure is already built and you are filling in the blanks. You can look inside it first.
Whichever route you choose, start today. A short policy in use beats a perfect one you never finish.
This article is general information, not legal advice. For advice on your specific circumstances, consult a suitably qualified professional.