Resources · 13 July 2026

How to write an AI acceptable use policy: a step-by-step guide (UK)

By the Operating Bench Team · Last reviewed 13 July 2026

Most guides tell you what an AI policy should contain. This one is about the harder part: actually writing it and getting your team to follow it. Here is a straightforward, seven-step process you can work through in an afternoon.

If you first want the full contents checklist, see what to include in an AI acceptable use policy. If you are not yet sure you need one, start with the five-minute self-check.

Step 1: Find out how AI is already being used

Do not start with the document. Start with reality. Ask around, honestly and without blame: which AI tools are people already using, and what for? You will almost always find more than you expected, often on personal accounts. This is shadow AI, and a policy written without knowing about it will miss the point. Fifteen minutes of asking tells you what your policy actually needs to address.

Step 2: Set the scope

Decide, in one sentence, who and what the policy covers. The answer is usually broader than “employees”: include contractors, temporary staff and volunteers who act on your behalf, on any device. AI use on a personal laptop is still your risk. A policy that only reaches permanent staff leaves half the exposure uncovered.

Step 3: Name your approved tools

This is the step that makes a policy real. List the specific AI tools people are allowed to use, and for what kind of data. “Use approved tools” means nothing without a list; naming Copilot, a paid ChatGPT Team plan or a particular vendor turns it into a rule. Anything not on the list needs a quick check before it is used. This single list is what stops people quietly reaching for a random free tool.

Step 4: Draw the hard line on data

Write the one rule that removes most of the risk:

Personal data, client or customer data, and anything confidential must never go into an unapproved AI tool.

Then make it concrete for your organisation with a short list of examples of what counts as confidential. If people can tell in five seconds whether something is safe to paste in, your policy is working. This is also the line that keeps you the right side of UK GDPR.

Step 5: Decide who checks AI output, and who is accountable

AI is confidently wrong sometimes. Your policy needs to say that a competent person reviews AI output before it is sent or relied on, and that the person, not the tool, is accountable for the result. Keep it proportionate: a quick sense-check for low-stakes drafting, a proper review for anything that affects a client, a decision or a published document.

Step 6: Add disclosure, reporting and the rules that apply to you

Three short sections finish the substance:

Step 7: Give it an owner and a review date

An unowned policy goes stale, and AI rules are moving quickly. Name a single owner and set a review date, three to six months out to begin with. Then do the most important thing: put it in front of people. Circulate a one-page summary, talk through it once, and make it easy to find. A policy nobody has read is not a policy.

Keep it short

Resist the urge to pad it out. A clear one or two pages that people read and follow beats a twenty-page document that lives in a folder. Add depth only where your sector or your risk genuinely calls for it. Some sectors, such as schools, healthcare practices and charities, carry duties a generic policy will miss, and are worth a sector-specific version.

A faster route

You can write all of this from scratch using the steps above. If you would rather not start from a blank page, the free AI Starter Kit gives you a one-page set of ground rules to adapt today. The full AI Safe-Use Pack provides an editable acceptable use policy alongside the approved-tools matrix, risk register, DPIA starter and disclosure clauses that Steps 3 to 6 call for, so the structure is already built and you are filling in the blanks. You can look inside it first.

Whichever route you choose, start today. A short policy in use beats a perfect one you never finish.


This article is general information, not legal advice. For advice on your specific circumstances, consult a suitably qualified professional.

Frequently asked questions

How do you write an AI acceptable use policy?
Start by finding out how AI is already being used in your organisation, then work through seven steps: set the scope, name your approved tools, draw the hard line on data, decide who checks AI output, set disclosure and reporting rules, note the regulations that apply to you, and give it an owner and a review date. Keep it to one or two pages people will actually read, then circulate and revisit it.
How long does it take to write an AI policy?
A usable first version takes an afternoon if you start from a good structure rather than a blank page. The slower part is agreeing your approved-tools list and getting sign-off, which is worth doing properly. Many organisations reach a sensible baseline in about 30 minutes using a ready-made pack and then refine it.
Who should write the AI policy?
One owner should draft it, usually someone in operations, IT, compliance or the senior team, with input from the people who actually use AI day to day. Writing it in isolation produces a document nobody follows. A short policy shaped by real use lands far better than a long one written in a vacuum.

Sources & further reading

External links are provided for reference and open in a new tab. This article is general information, not legal advice.

Share this LinkedIn X

One email when it matters

A short note when the rules change or we publish something genuinely useful for UK organisations. No spam, unsubscribe in one click.