AI policy template for UK small businesses: one page, plain English
An AI policy for a small UK business can fit on one page. It names the AI tools and accounts staff may use, and what must never go into them. It also covers checking every output, who to ask, how to report a slip and when you'll review it. Copy the template below.
I'm Managing Partner of a two-office law firm in East Sussex with around 30 people. Confidentiality comes first there, so the first question about any new tool is where the information goes, and who else can see it.
Sound familiar?
You didn't plan for AI at work. It arrived anyway, on phones and inside Outlook. Nobody has said what's allowed, and you're not sure what has already been pasted in.
- I know some of the team use ChatGPT. I don't know what they put into it.
- If a customer's details ended up in a free AI tool, would I even find out?
- What happens when an AI answer with a mistake in it goes out under our name?
- I want some rules, but I don't want a 20-page policy nobody will read.
Do I need an AI policy for a small business?
If anyone on your team uses AI for work, yes, a short one. UK GDPR applies whenever personal data goes into an AI tool, and the ICO lists data protection policies, where proportionate, as one way to show you comply. Acas recommends clear rules on AI at work. One page everyone has read beats a long document nobody opens.
Your staff are probably ahead of you. The ONS found that over half of employees (55%) say they use AI for work or education. Only around a third of businesses with 10 or more staff (35%) report using it. That gap is people using their own accounts, with their own habits, and nobody checking.
The government's Cyber security breaches survey 2025/26 tells a similar story. Of businesses using or considering AI, around a quarter (24%) had practices in place to manage the cyber risks from it. A short, agreed policy is a sensible first step towards being in that quarter.
Even the regulator writes one. The ICO's own internal AI use policy runs to 30 pages, but the rules for staff sit in one short section. Most of the rest covers buying, building and explaining AI systems, which a small business rarely needs.
What should an AI acceptable use policy include?
Eight things: why the policy exists, which tools and accounts are approved, what information can and can't go in, checking every output, being open with customers, who to ask, how to report mistakes, and when you'll review it. Everything else, such as training plans and supplier checks, can come later.
| Section | What it says | Where the rule comes from |
|---|---|---|
| 1. Purpose | Why you use AI and who the policy covers | Acas: have clear policies on AI at work |
| 2. Approved tools and accounts | Which tools, signed in with work accounts only | NCSC on shadow AI; the ICO's own policy allows approved tools only |
| 3. What can go in | What's fine, what needs agreement, what never goes in | UK GDPR; Acas on keeping personal data out of public tools |
| 4. Checking output | A person checks facts, figures and tone before anything is used | NCSC on AI getting things wrong; Acas on accuracy, tone and bias |
| 5. Telling customers | Be open where AI plays a big part, and in your privacy notice | ICO on the right to be informed; ASA on not misleading people |
| 6. Who to ask | One named person | Common sense |
| 7. Mistakes and breaches | Report it the same day so it can be fixed fast | ICO 72-hour rule; NCSC on reporting culture |
| 8. Review | A date in the diary | ICO: accountability is ongoing |
Want help agreeing rules your team will stick to? It's part of my AI training.
Book a free 30-minute callYour one-page AI usage policy template
Copy this into a document, replace the parts in square brackets, and delete anything that doesn't fit. It's written for a business of roughly 3 to 30 people, and it's general information to start from, not legal or HR advice.
AI use policy for [business name]
Version 1 · Agreed [date] · Policy owner: [name]
- Why we have this policy. We use AI tools to save time on drafting, summarising and admin. This policy explains how to do that without putting customers, colleagues or the business at risk. It applies to everyone who works for us, including contractors and temporary staff, on any device used for work.
- Approved tools and accounts. Only use the AI tools on this list: [for example, Microsoft Copilot through your work Microsoft 365 account]. Always sign in with your work account, never a personal one. Ask [name] before trying any other AI tool, app, browser extension or meeting note-taker.
- What can and can't go in. Fine: public information, general questions and our own drafts with no personal details. Only in an approved tool, and only for [agreed tasks]: customer and staff names and contact details. Never, in any tool: bank or card details, passwords, health information, anything told to us in confidence, or anything covered by a confidentiality agreement. If in doubt, leave it out and ask.
- Check everything. AI can be wrong while sounding certain. Check facts, figures, names, dates and tone before you send, publish or act on anything. You're responsible for your work, whether or not AI helped. AI never makes a final decision about a person, such as hiring, pay or a complaint: a person decides.
- Be open with customers. Don't present AI output as anyone's personal view or advice until a person has checked it. Tell customers when they're dealing with an AI tool rather than a person, and answer honestly if they ask. Our privacy notice explains how we use AI with personal data.
- Who to ask. Questions about AI go to [name]. If something feels wrong, stop and ask first.
- Mistakes and breaches. If something goes into an AI tool that shouldn't have, or AI output causes a problem, tell [name] the same day. Speed matters: some personal data breaches must be reported to the ICO within 72 hours. We would always rather hear about a slip early.
- Review. We'll review this policy every 6 months, and sooner if we add a new tool or the rules change. Next review: [date].
I've read this policy and will follow it: [name, signature, date]
Section 4 matters most. The NCSC warns that AI tools can get things wrong and present them as fact, a flaw known as hallucination. Acas makes the same point: check outputs for accuracy, tone and bias.
Which AI tools and accounts should staff use?
Business accounts, signed in with work logins, on tools you've chosen. Microsoft, OpenAI and Anthropic each say they don't use data from their business products to train their models by default. You can't see or control a member of staff's personal account. Pick one or two tools and ask everyone to use only those for work.
Microsoft's data and privacy page for Copilot says prompts and responses in its business Copilot aren't used to train its foundation models. It also says Copilot only shows people information they already have permission to see. So if your shared drive lets everyone open the payroll folder, Copilot can surface it too. Tidy up permissions before you switch it on.
OpenAI says the same about its business plans for ChatGPT, and Anthropic about its commercial Claude products. Check the vendor's own data page for the plan you're on, because names and settings change. Microsoft 365 Copilot, for example, is now called Microsoft Copilot.
Five questions before you approve an AI tool
- Can staff sign in with their work accounts, not personal ones?
- Does the vendor's own data page say business data isn't used to train its models?
- Can you see, export or delete chat history if you need to?
- What can the tool see inside your systems, and should everyone have that access?
- Can you switch it off quickly if something goes wrong?
Choosing between the two most common options? My guide to Copilot vs ChatGPT for a small business compares them side by side.
What information can staff put into AI tools?
Public information and your own non-confidential drafts are fine in any approved tool. Customer and staff personal details should only go into an approved business tool, for agreed tasks. Bank details, passwords, health information and anything shared in confidence shouldn't go into AI tools at all. The table below makes it quick to check.
| Information | Free or personal account | Approved business account |
|---|---|---|
| Public information, general questions, your own marketing drafts | Fine | Fine |
| Internal documents with no personal details (templates, procedures, product descriptions) | No | Fine |
| Customer or staff names, emails and phone numbers | No | Only for tasks your policy owner has agreed |
| Bank or card details, passwords and security codes | No | No |
| Health details and other sensitive personal information | No | No, unless you've taken advice first |
| Anything shared in confidence or under a confidentiality agreement | No | No, unless the agreement allows it |
Health data is one of the special categories of personal data that UK GDPR gives extra protection. Anything like that needs proper advice before it goes near a new tool. For the wider question, see my guide: is ChatGPT safe for business use?
How do you introduce an AI policy to your team?
Talk first, write second. Ask the team which AI tools they already use and what for, with no blame for honest answers. Then fill in the template, agree it at a short team meeting, and ask everyone to sign it. Acas recommends consulting staff when you bring in AI, and involving them in shaping the rules.
- Ask, don't accuse. A 10-minute chat or a quick anonymous form: which tools, which tasks, which accounts. The NCSC's advice on shadow AI is to understand why people use unapproved tools, because that tells you what they need.
- Choose the tools. One is often enough: whichever fits the software you already pay for.
- Fill in the template. Name a policy owner and set a review date.
- Agree it together. Half an hour with the team, walking through the traffic-light table with real examples from your business.
- Show people how. A rule without training quickly becomes a rule people work around.
If breaking the policy could lead to disciplinary action, it has to fit with your staff handbook and disciplinary rules. The Acas Code of Practice says disciplinary rules and procedures should be written down, specific and clear, with staff involved in developing them. How your AI policy links to discipline is a question for your HR adviser or an employment lawyer, not a template.
What if someone puts customer data into ChatGPT by mistake?
Deal with it quickly and calmly. Find out what went in, which tool and which account, and delete the chat if you can. If it included personal data, it may be a personal data breach. Notifiable breaches must be reported to the ICO within 72 hours of you becoming aware, so don't wait.
The ICO has a self-assessment tool to help you decide whether a data breach needs reporting. Whatever you decide, the ICO says to record every breach, including those you don't report. If the risk to the people affected is high, you must tell them directly too.
How you react matters as much as the rules. The NCSC warns that staff who are afraid for their jobs won't report mistakes. The whole point of the policy is that problems surface on the same day, while they're still small.
Please note: this is general information from official guidance, not legal or HR advice. My consultancy doesn't give legal advice. For a real breach, or anything touching contracts or discipline, speak to your data protection adviser, HR adviser or a solicitor.
In practice: what I see
In my own firm, AI helps draft web pages, guides and social posts, and automatic checks run before a person approves anything. That's section 4 of the template in real life: AI drafts, a person decides.
Our rules for that work are short. No client's name goes into anything we create or publish, and a tool scans for names automatically. Facts come only from official sources, and nothing goes out until I've approved it.
The question usually isn't whether your team uses AI. It's whether they're using personal accounts that nobody else can see. Rules agreed at the start are far easier to land than rules written after a slip.
Common pitfalls
- Copying a big company's policy. A 20-page document doesn't get read in a team of eight. Keep yours to a page.
- Banning AI outright. The NCSC says staff turn to unapproved tools when policies and approved options haven't kept pace. A ban with no approved alternative risks exactly that.
- Forgetting the hidden extras. AI now sits inside browsers, email and video calls. Your approved list should cover add-ons and meeting note-takers too.
- No named owner. If nobody owns the policy, nobody updates it or answers questions.
- Writing it once. The ICO says accountability is ongoing, and measures should be reviewed and updated. Tools and settings change often.
What to do next
How I can help
I run hands-on AI training for small teams, and agreeing a one-page policy like this is part of it. We use your own emails and documents, so people see what the rules mean in real work. Not sure which tools your team already relies on? The AI audit maps that first.
Questions people ask
Is an AI policy a legal requirement in the UK?
Official guidance doesn't say every business must have a document called an AI policy. But UK GDPR still applies the moment staff put personal data into an AI tool, and the ICO counts a proportionate data protection policy as one way to show you comply. Add Acas's advice to set clear rules on AI at work, and a one-page policy covers both.
Can I just ban ChatGPT at work?
You can, but a ban doesn't remove the need. The NCSC's blog on shadow AI cites research finding that 71% of employees had used AI tools their employer hadn't approved. One approved tool with clear rules gives people a safe way to do what they're already trying to do.
Should the AI policy be part of our employment contracts?
Not necessarily. The Acas Code says disciplinary rules should be written down, specific and clear, and that staff should know where to find them. Whether your AI policy should be contractual, and how it links to your disciplinary rules, is a question for your HR adviser or an employment lawyer.
How often should we review our AI policy?
Every 6 months suits most small businesses, and straight away if you add a tool or something goes wrong. The ICO says accountability measures need reviewing and updating over time. Its own internal AI policy was set for review a year after it came into use.
Do we have to tell customers we use AI?
Not every time. The ASA says there's no blanket legal requirement in the UK to disclose AI in ads, but nothing you publish can mislead. Your privacy notice must explain how you use personal data, including who receives it. And if a customer is chatting to an AI tool rather than a person, tell them.
Does this template work for Copilot, ChatGPT and Claude?
Yes. It doesn't depend on any one tool. List whichever tools you approve in section 2, then check each vendor's own data and privacy pages for the plan you're on.
Related guides
Is ChatGPT safe for business? A UK guide to customer data
Is ChatGPT safe for business? A plain UK guide to UK GDPR, personal vs business accounts, what staff should never paste in, and when you need a DPIA.
Read the guideAI training
Practical AI training for businesses in Sussex. Hands-on ChatGPT, Microsoft Copilot and Claude sessions on your own tasks, with simple rules for safe use.
AI training