Guides

An AI acceptable-use policy a UK business can adopt this week.

By Zain M · 25 September 2026 · 13 min read

An AI acceptable-use policy for a UK business needs eight things: the tools staff may use and on which plan, what may be put into them and what may not, a duty to check outputs before they are relied on, a rule on personal data that matches your UK GDPR obligations, a rule on client confidentiality, when AI use must be disclosed, what the firm monitors and why, and what happens when the policy is broken. CIPD reported in 2025 that most UK employers allow generative AI at work but fewer than a third had a written policy, which is the gap this template closes. The policy below is written to be adopted as it stands, on one page, then adjusted for the sectors and tools you actually use.

LengthOne page, eight clauses
Pair withA business plan, not personal accounts
ReviewEvery six months, and when tools change

Why a one-page policy beats a twenty-page one

Staff are already using AI at work. CIPD’s 2025 research found that a majority of UK organisations allowed generative AI for work tasks while fewer than a third had developed a formal policy in the previous year, and fewer still had provided training. The ICO expects organisations of any size that process personal data through AI tools to be able to show how they govern that use, and the practical evidence is a written policy staff have read. A policy nobody reads provides no evidence at all, which is why this one is a page.

Two principles run through it. The policy names tools and plans, because the data position differs between a personal ChatGPT or Claude account and a Business or Team workspace, and a policy that says “use AI responsibly” without saying which AI is not a policy. And every rule has an example, because “do not paste confidential information” is ignored and “do not paste a client’s bank details, a candidate’s CV or an unsigned contract” is followed.

The policy

Replace the bracketed items. Everything else can stand.

011. Approved tools. Staff may use [Claude Team] and [ChatGPT Business] through the firm’s workspace, and [Microsoft 365 Copilot] where licensed. Personal AI accounts, free or paid, may not be used for any work task. If you need a tool that is not listed, ask [name]; do not start using it.
022. What may go in. Anything the firm already holds and that you are permitted to see, provided the rules below on personal data, client confidentiality and third-party material are met. Examples: a draft you are writing, a public document, an internal process, a spreadsheet of the firm’s own figures, an anonymised summary of a client situation.
033. What may not go in. Personal data about identifiable people beyond what the task needs (see 5). Anything a client has marked confidential or that is subject to a non-disclosure agreement, unless the client has agreed in writing to AI processing. Passwords, keys, card or bank details. Material the firm does not have the right to use, such as a competitor’s paywalled report. Anything you would not be comfortable seeing quoted back in a dispute.
044. Check before you rely. AI output is a draft. Before it is sent to a client, filed, published or acted on, a named person must check facts, figures, citations, names and legal or regulatory statements, and is responsible for the result as if they had written it. AI may not be used to make a decision about a person (hiring, discipline, credit, pricing to an individual) without a human deciding.
055. Personal data. Use the minimum. Where a task needs personal data, use the firm’s workspace tool, not a personal account; do not enter special-category data (health, ethnicity, religion, sexual orientation, trade-union membership, biometrics, criminal records) unless [name] has confirmed a lawful basis and a DPIA covers the use. Delete conversations containing personal data when the task is done, in line with the retention setting.
066. Disclosure. Tell clients when AI has materially produced work they are paying for, in the way the engagement letter describes. Do not present AI output as a person’s expert opinion where it is not. Where a regulator or a client contract requires disclosure or restricts AI use, that requirement overrides this policy.
077. Monitoring. The firm can see workspace usage and, on [Enterprise] plans, conversation logs. The firm will review them only to investigate a suspected breach of this policy, a security incident or a subject access request, and will tell you if a review concerns you. The firm does not read your conversations as a matter of routine.
088. Consequences and questions. Breaches are handled under the disciplinary policy in proportion to the harm. Mistakes reported promptly are treated more leniently than mistakes discovered. Questions go to [name]. This policy is reviewed every six months and whenever an approved tool or plan changes. Last reviewed [date]; signed [owner].

The reasoning behind each clause

Clause 1 exists because the data position turns on the plan. ChatGPT Business, Claude Team and Enterprise workspaces are not used for training and are covered by a data processing addendum; the consumer plans on both sides use conversations for training unless each person changes a setting. A policy that permits “ChatGPT” without saying which is permitting both.

Clauses 2 and 3 do the work most policies skip: they give examples. The list of what may not go in is drawn from the incidents firms actually have, which are almost never about state secrets and almost always about a CV, an invoice or a contract pasted in for a quick summary.

Clause 4 is the ICO’s accuracy principle and the employment-law point CIPD makes about automated decisions in one sentence: a human is accountable for the output, and a human decides anything that affects an individual. It also protects the firm commercially; the fee earner who signs the advice owns it.

Clause 5 is UK GDPR in the form staff can follow: minimisation, the right plan, special-category data gated behind a lawful basis and a DPIA, and deletion. The DPIA point matters more than it looks. The ICO’s screening criteria catch profiling and special-category data at scale, and a firm that has a policy but no DPIA for its candidate-screening or patient-triage use is exposed on exactly the process most likely to be complained about.

Clause 6 covers professional obligations, which vary by sector: the SRA, FCA, ICAEW and NHS each have positions on AI use and client transparency, and the engagement letter is where the firm’s own promise is recorded.

Clause 7 is the monitoring rule. Employees must be told what is monitored and why before it happens, and monitoring must be necessary and proportionate. Saying that conversations are not read routinely, and only reviewed for stated reasons, is both the lawful position and the one that keeps staff using the sanctioned tool instead of a personal one.

Clause 8 makes the policy enforceable and keeps it alive. CIPD recommends updating employment contracts and pairing the policy with training; the six-month review is what stops the policy naming a plan that no longer exists.

What to do alongside the policy

A policy on its own changes little. Four things make it work. Put the firm on business plans and cancel the expensed personal accounts the same week, so clause 1 is true. Build two or three shared projects or custom GPTs on the firm’s own templates, so the sanctioned tool is the easier one to use. Run a ninety-minute session per team on the two tasks that team does most, and walk through clauses 2 to 5 with real examples from that team’s work. And add Anthropic or OpenAI to the record of processing activities with the DPA reference, so the policy and the paperwork agree.

Sector add-ons are short. A law firm adds a line on privilege and the SRA’s expectations; an accountancy practice adds the ICAEW position and HMRC data; a clinic adds the NHS and CQC position on patient data and a blanket ban on identifiable patient information outside an approved system; a recruitment agency adds a rule that AI screening output is advisory and a recruiter decides.

Common questions

Does a UK business need an AI policy?

There is no statute that requires one, but the ICO expects any organisation processing personal data through AI to be able to show how it governs that use, and CIPD advises a written policy paired with training and contract updates. A one-page policy is the cheapest evidence you can hold.

What should an AI acceptable-use policy include?

Approved tools and plans, what may and may not be entered, a duty to check outputs, a personal-data rule, a confidentiality rule, when AI use is disclosed, what the firm monitors, and consequences. The template above covers all eight in a page.

Can staff use their personal ChatGPT or Claude account for work?

The policy says no, because consumer plans on both sides use conversations for training unless the individual changes a setting, and the firm cannot see or control it. Business plans cost a few pounds a seat and fix this.

Can we monitor what staff put into AI tools?

Yes, if it is necessary, proportionate and staff are told in advance what is monitored and why. Routine reading of conversations is hard to justify; review for a stated reason, such as a suspected breach, is not.

Do we need a DPIA?

For high-risk processing under the ICO’s screening criteria, yes: systematic profiling, special-category data at scale, or automated decisions about individuals. Everyday drafting does not usually need one; candidate screening or patient triage usually does.

Should we tell clients we use AI?

Where AI has materially produced work they are paying for, yes, in the way your engagement letter describes, and always where a regulator or contract requires it. Do not present AI output as a person’s expert opinion.

How often should the policy be reviewed?

Every six months and whenever an approved tool or plan changes. Tools rename plans and change data terms often enough that an annual review leaves the policy wrong for months.

Is this template legal advice?

No. It is a working policy drawn from the ICO’s guidance and CIPD’s recommendations, written to be adopted and then checked against your sector’s rules and, where the firm is regulated, by your adviser.

Want the policy adopted, not just downloaded?

We adapt the policy to your sector and tools, put the firm on the right plans, add the processor records and run the session per team, at a fixed price.

Start a conversation →