This is not legal advice. JNET.support is an AI implementation consultancy and not a law firm. No solicitor has reviewed the template below. It quotes published guidance from the ICO and the European Commission so you can check every claim yourself, and the points where a business needs its own advice are marked. Adopting this document guarantees nothing about your compliance position.
The direct answer
There is no UK statute requiring a business to have an AI policy. If you have been told otherwise, ask which Act.
What binds you is the law you were already under. UK GDPR and the Data Protection Act 2018 apply to personal data whoever or whatever processes it, and the ICO’s position on AI is blunt:
“In the vast majority of cases, the use of AI will involve a type of processing likely to result in a high risk to individuals’ rights and freedoms, and will therefore trigger the legal requirement for you to undertake a DPIA.”
The EU AI Act’s AI literacy duty in Article 4 has applied since 2 February 2025, and it reaches UK businesses only through EU-facing use. It does not bind every UK company by default.
So an AI policy does two jobs at once, and most templates blur them. Some clauses exist because a regulator can ask you about them. The rest exist because somebody will otherwise decide the question at speed, alone, with a customer waiting. Both belong in the document, only one carries a legal consequence, and your staff deserve to know which is which. Every clause below is labelled.
The full policy is on this page. There is no form.
What UK law requires, and what it does not
Data protection law applies whether or not AI is involved
Paste a customer’s email into a chat tool and you have processed personal data. The rules are the ones that applied before the tool existed. A lawful basis, a purpose you told people about, security appropriate to the risk, and a written contract with anyone processing that data on your behalf under Article 28.
The ICO’s Guidance on AI and data protection was last updated on 15 March 2023 and now carries a notice that it is under review because of the Data (Use and Access) Act. Two obligations in the ICO’s guidance are firm enough to build a policy on. The wording quoted below comes from its DPIA and personal-data-breach pages.
The DPIA trigger. ICO guidance on when a DPIA is needed treats AI as innovative technology, and requires a DPIA where that combines with another high-risk criterion such as evaluation or scoring, large-scale processing, or special category data. Where you conclude a use is not high risk, the ICO’s AI accountability chapter says “you still need to document how you have made this assessment.” That documenting is the step most often missed.
Breach reporting. Notifiable personal data breaches go to the ICO “without undue delay, but not later than 72 hours after becoming aware” of them, and you must “keep a record of any personal data breaches, regardless of whether you are required to notify.” An employee pasting a client list into a consumer AI account is a candidate for that assessment, and 72 hours is not long to decide.
Neither obligation mentions AI policies. They are what one is for.
The EU AI Act reaches you through EU-facing use
Article 4 requires providers and deployers to ensure a sufficient level of AI literacy among staff and others operating AI systems on their behalf. The European Commission’s AI Literacy Q&A confirms the timing. “Article 4 of the AI Act entered into application on 2 February 2025, therefore the obligation to take measures to ensure AI literacy of their staff already applies,” with supervision by national market surveillance authorities from August 2026.
Scope is the part that gets misreported. The Commission states that the Act applies to actors outside the EU “as long as the AI system is placed on the Union market, used in the Union or its use has an impact on people located in the EU. This is also valid for Article 4 of the AI Act.” A UK business whose AI use is internal and entirely UK-facing sits outside that. The extraterritoriality test is in the piece on whether the EU AI Act applies to UK businesses.
Worth knowing when somebody tries to sell you a certification. The Commission says there is “no need for a certificate,” and that organisations “can keep an internal record of trainings and/or other guiding initiatives.”
The Digital Omnibus on AI would change how Article 4 is framed, moving the duty to promote AI literacy onto Member States and the Commission. It was signed on 8 July 2026 and its status is “procedure completed, awaiting publication in the Official Journal”, so it is not yet law and the AI Act’s own record carries no amendment. It mainly defers parts of the high-risk regime, and it does not delay the Article 50 transparency obligations. The Article 50 article sets out what it does and does not move. Plan against the current text until it is published.
There is no UK AI Act, and nothing close to one
The UK framework is still the 2023 white paper, A pro-innovation approach to AI regulation, published 29 March 2023 and last updated 3 August 2023. Cross-sectoral principles applied by existing regulators inside their existing remits, with no statutory duty attached.
The AI-specific bills that have been introduced are private members’ bills. The Artificial Intelligence (Regulation) Bill [HL], sponsored by Lord Holmes of Richmond, received a first reading on 4 March 2025. Parliament’s bill record still shows first reading as its current stage and records it as not an Act.
The live activity is earlier-stage than legislation. DSIT opened a call for evidence, Data regulation in the age of AI and other data-intensive technologies, on 15 July 2026, closing 9 September 2026. It asks whether “further guidance, targeted changes or more fundamental reform is needed.” A call for evidence creates no obligation on anyone. Read it as a signal that the data protection rules around AI may move, and as a reason to keep your review date real. Anyone selling you a policy on the strength of an imminent UK AI law is describing something that does not exist.
How to use the template
Everything in the ruled blocks below is policy text. Everything outside them is commentary and stays
out of your document. Fill in anything in [SQUARE BRACKETS].
Delete any clause you will not enforce. A rule nobody checks teaches people to read the whole document as decoration, which costs more than the clause was worth.
Two failure modes are worth naming first. Banning AI outright moves the usage onto personal phones where you cannot see it. Rules so broad that nobody can tell whether their own task is covered get the same result more slowly.
The policy
1. Scope and ownership
AI use at [COMPANY NAME]
This policy applies to everyone working for [COMPANY NAME], including employees, contractors, freelancers and anyone using our systems or acting on our behalf.
It covers general-purpose AI tools (chat assistants, writing and coding assistants, meeting transcribers, image generators) and AI features built into software we already use.
The owner of this policy is [NAME, ROLE]. Questions about it go to them. It is reviewed on [DATE, at least every six months] and after any incident involving an AI tool.
House rule. No law requires it, and it keeps every other clause alive. A policy with no named owner goes stale within a quarter, because the tools change weekly and nobody is responsible for saying so.
Cost to enforce. One named person and two diary entries a year, roughly an hour each.
Keep contractors and freelancers in scope. They are the people most likely to be using their own tools on your work, and the Commission’s Article 4 guidance treats them as covered where the Act applies to you.
2. Approved tools
Approved tools
The AI tools approved for work at [COMPANY NAME] are:
- [TOOL NAME], on the [PLAN NAME] plan, accessed through your [COMPANY NAME] account
- [TOOL NAME], on the [PLAN NAME] plan, accessed through your [COMPANY NAME] account
Use these on your work account. Do not use a personal AI account for company work, and do not use a company account for anything you would not want logged.
To get a new tool approved, send [OWNER NAME] the tool, the task, and what data it will see. You will get an answer within [FIVE] working days. Until then, keep company data out of it. Trialling a tool with no company data in it is fine.
House rule with a legal core. The list is yours to write. What sits underneath it is not. Where a tool processes personal data on your behalf you need a contract with that provider, and the ICO states one limb of it plainly: where “you use a processor, the requirements on breach reporting should be detailed in the contract between you and your processor, as required under Article 28.”
Business and enterprise plans are normally offered with a data processing agreement, admin controls, and stated terms on whether inputs are used for training. Consumer plans generally are not. That difference is contractual and invisible on screen, which is why the plan name belongs in the policy and staff need access to the right one.
Cost to enforce. The five-day promise is the expensive part and decides whether the clause works. Miss the deadline twice and people stop asking. Budget twenty minutes per request, clustered in the first month.
3. What never goes into a general-purpose AI tool
What must not be pasted into an AI tool
Before you paste, ask yourself: would I be comfortable if this exact text appeared in a screenshot on a stranger’s blog with our company name visible? If the answer is no, or you have to stop and think, it does not go in.
These never go into a general-purpose AI tool, on any account:
- Personal data about a customer, employee or applicant. Names, addresses, phone numbers, dates of birth, NI or ID numbers, health details, financial or family circumstances. This includes the free-text box where somebody explained their situation.
- Details that identify one person without naming them. Order numbers, account references, ticket IDs, or a combination of small details that fits only one customer.
- Credentials. Passwords, API keys, tokens, connection strings,
.envcontents.- Unpublished commercial terms. Draft pricing, discount floors, margin, tender responses before submission.
- Anything covered by an NDA, and anything a client gave us that we could not forward to a third party.
If you need AI help with something in these categories, remove the identifying detail first, or ask [OWNER NAME] which approved tool is cleared for it.
Mixed, and the mix is the point. The personal data limb tracks a legal obligation. Credentials and commercial terms are house rules, and the NDA limb is a contractual duty you already signed.
Write it as one list anyway. Nobody consults a taxonomy with a finger over Ctrl+V. The three-second question at the top is what people remember.
Cost to enforce. Nothing to write, and real to teach. This clause fails silently, and you find out it was ignored once something has already gone out. Fifteen minutes of live redaction practice does more than rereading the list.
On credentials, a key pasted into a chat window has been disclosed. Rotating it is the fix, and deleting the conversation is not.
4. Personal data
Personal data and AI
Our obligations under UK data protection law apply in full when an AI tool is involved. Using AI creates no new lawful basis and removes no existing duty.
Before using AI on a new task that involves personal data, tell [OWNER NAME / DPO]. They decide whether a data protection impact assessment is needed and record the decision either way.
Where AI output contributes to a decision about a person that has a legal or similarly significant effect on them, such as [RECRUITMENT SHORTLISTING / CREDIT / DISCIPLINARY DECISIONS], a named person makes the decision. The AI output is an input to it.
Legal obligation. This is the clause a regulator would ask about. The DPIA duty comes from Article 35 UK GDPR, and the ICO’s view is that most AI use triggers it. Where you decide it does not, record why.
The last paragraph is deliberately conservative. The rules on solely automated decision-making changed when section 80 of the Data (Use and Access) Act 2025 replaced Article 22 UK GDPR, and the ICO’s headline AI guidance still reflects the older framing. A named human in the decision works under either reading.
Cost to enforce. The DPIA is real work, hours rather than minutes, and needs somebody who understands both the processing and the tool. The notification step costs a message, and it holds because it makes one person aware before the workflow is built and expensive to unpick.
Worth taking advice on. If AI touches recruitment, credit, insurance, safeguarding or anything affecting someone’s employment or access to a service, have a data protection specialist look at it before launch. An article cannot responsibly tell you where the line falls in your sector.
5. Checking output before it reaches a customer
Checking AI-assisted output
Anything drafted with AI that leaves the company is read by a named person before it goes. That person is responsible for what it says.
Check in this order:
- Identify the claims that cause a problem if they are wrong. Prices, dates, promises, capabilities, legal or safety statements.
- Verify those against the source. Another AI answer is not a source.
- Trace every number back to where it came from. A figure that is not in the source was invented.
- Open every link.
- Read for what is missing.
- Only then read for tone.
If the output contains a fact you did not already know and you cannot find its source in two minutes, delete the sentence.
These tasks are never sent without a named human check: [QUOTES AND PRICING / CONTRACT WORDING / ANYTHING TO A REGULATOR / TECHNICAL SPECIFICATIONS].
House rule, with two places where it turns legal. The first is the automated decision-making position in clause 4. The second applies where the EU AI Act reaches you, because Article 50(4)‘s disclosure duty for AI-generated text published on matters of public interest falls away where the content has undergone human review and a person holds editorial responsibility. Naming a reviewer is what engages that exemption, and the detail is here.
Cost to enforce. This is the most expensive clause in the policy and the one most often written then abandoned. Checking a page of AI-drafted output properly takes ten to twenty minutes. Multiply that by how often it happens. If the real answer is that nobody has that time, shorten the list of tasks requiring a check rather than pretending the check happens.
The failure it targets is specific. Fluent prose passes a skim that a clumsy but accurate draft would fail, so errors survive review precisely because the writing is good.
6. Telling people when AI was involved
Disclosure
Tell the customer when:
- A contract, tender or client policy requires it. Check before you assume it does not.
- A professional body you are registered with requires it.
- They are talking to an AI assistant rather than a person.
- AI-generated images or audio depict real people, places or events.
Internally, say so when you hand over AI-assisted work that someone else will rely on, so the reviewer knows what they are checking.
[COMPANY NAME] does not label ordinary AI-assisted drafting that a person has reviewed and taken responsibility for.
House rule in the UK. There is no general UK legal duty to tell a customer that content was AI-assisted. Say that clearly inside your company. The alternative is staff over-disclosing or hiding it by instinct, and neither is a decision anyone made.
The duties that do exist are narrow. Client contracts and tender terms are the most common source for a small business. Where the EU AI Act applies, Article 50 adds duties around chatbots and deepfakes.
Cost to enforce. Almost nothing, once the exceptions are written down. The cost sits in somebody reading the AI clause in your client contracts before you sign.
7. What gets recorded
Records
[OWNER NAME] keeps a single list of AI tools in use, with the owner, plan, purpose, what data it sees, and whether any of its output reaches people in the EU.
We also keep:
- The DPIA decision for each AI use involving personal data, including decisions that no DPIA was needed and why.
- A record of AI training delivered, covering who, when and what.
- Any incident involving an AI tool, and what was done about it.
A spreadsheet is sufficient. It is reviewed on the same cycle as this policy.
Mixed. The DPIA records and the breach record are legal obligations. The tool inventory is a house rule that makes them possible, because you cannot assess processing you do not know about. Training records are the Article 4 evidence where the EU AI Act reaches you.
Cost to enforce. A spreadsheet with dates and named owners does more here than any compliance platform, because a platform nobody updates records nothing. Expect the first inventory to take an afternoon and to surface a tool or two bought on a corporate card by one team.
8. When something goes wrong
Incidents
Tell [OWNER NAME] the same day if:
- Personal data, credentials or confidential material went into an AI tool it should not have.
- AI-generated content with a significant error reached a customer.
- An AI tool behaved in a way that could harm someone.
Reporting a mistake promptly will not be held against you. Concealing one will.
[OWNER NAME] assesses within 24 hours whether the incident is a personal data breach. If it is notifiable, it goes to the ICO within 72 hours of us becoming aware. All incidents are recorded whether or not they are notifiable.
Legal obligation, with a house rule wrapped around it. The 72-hour clock and the duty to record every breach come from UK GDPR. The internal same-day rule is yours, and it exists because the 72 hours runs from when the organisation becomes aware. A report sitting in an inbox for two days has spent most of your window.
The no-blame line is load-bearing. A policy that punishes disclosure buys silence, and silence turns a contained mistake into a late notification.
Cost to enforce. The assessment is the cost, and it needs somebody competent or with access to somebody who is. Write down now who that is.
9. Training and review
Training
Everyone using AI tools for work gets practical training covering the tools we use, this policy, and the failure modes for their role. New starters are covered within [30] days.
This policy is reviewed by [OWNER NAME] on [DATE] and after any incident.
House rule in the UK, and an obligation where the EU AI Act reaches you. The Commission’s Q&A takes the small-business case directly. Asked whether a company whose employees use ChatGPT for advertising text or translation needs to comply with Article 4, the answer is “Yes, they should be informed about the specific risks, for example hallucination.” It adds that relying on the tool’s instructions for use “might be ineffective and insufficient.”
Outside that scope the argument is operational. Every other clause assumes people can tell when output is wrong, and that judgement is taught.
Cost to enforce. Half a day per group, plus time to build examples from your own work. Generic exercises produce generic habits, which is why role-specific training beats a company-wide webinar.
What this policy leaves out on purpose
A definition of artificial intelligence. It changes nothing about what anyone does on Monday, and every attempt either excludes a tool you use or includes your spellchecker.
Sanctions for breach. Consequences belong in your existing disciplinary process and your HR advisers’ hands. Reference that process instead of inventing a parallel one.
Sector rules. Financial services, healthcare, legal practice and education carry obligations a general template has no business interpreting. This policy is a floor, and your regulator’s requirements sit on top.
Intellectual property positions. Ownership of AI-generated output and the training-data questions around it are unsettled and moving. A confident paragraph would be a guess.
Questions worth taking to an adviser
- Does our current AI use require a DPIA, and does our existing DPIA cover it?
- Do our contracts with AI vendors meet the Article 28 processor requirements for the personal data they see?
- Does any of our AI use produce output used in the EU, which would engage the EU AI Act?
- Where AI contributes to decisions about people, are we inside or outside the automated decision-making rules as amended by the Data (Use and Access) Act 2025?
- Do our client contracts contain AI disclosure or restriction clauses we are already in breach of?
The practical next step
Adopting this takes an afternoon. Fill in the brackets, delete what you will not enforce, name the owner, and send it round with the training booked rather than promised. A policy that arrives without a session attached gets read once.
Before you write the tool list in clause 2, find out what is already in use. That answer usually runs longer than management expects, and it is the same inventory an AI readiness assessment produces, because you cannot decide what to automate without knowing what is already running and who owns it.
Then book the training. Clauses 3 and 5 carry the real risk, and both depend on judgement rather than on people having read a document.