Skip to main content
AI Policy

Clear rules your whole team can follow — written in plain English.

A bespoke, legally-grounded policy setting out which AI tools staff can use, which are prohibited, and what data can never be entered.

The problem

Without a policy, your staff are making it up as they go

63% of UK organisations have no AI acceptable use policy. Every day without one is another day your data is at risk.

Every person, a different approach

One team member uses ChatGPT for client emails, another pastes contracts into Claude. Without written rules, there's no right answer — just risk.

Personal data leaving the UK

AI tools often store and process data on US servers. If staff are entering client details, you may already be in breach of GDPR.

Contracts and NDAs at stake

Many client agreements prohibit sharing information with third parties. AI tools count — and most staff don't realise it.

Good intentions aren't enough

Your team isn't being careless. They just don't have rules to follow. No policy means no accountability when something goes wrong.

What we do

AI Acceptable Use Policy

Tailored to your business, not a template

We write every section specific to your sector, size, and the AI tools your team actually use. No generic templates.

Process

How it works

01

Discovery & requirements

Day 1–2

We learn about your business — sector, size, how your team works, what AI tools are in use, and what data you handle. This shapes every section of the policy.

02

Policy drafting

Day 3–5

We write your bespoke AI acceptable use policy from scratch. Approved tools, prohibited tools, data handling rules, breach procedures — all in plain English, branded to your business.

03

Review & sign-off

Day 6–7

You review the draft, we make any changes, and the final policy is ready to issue to staff — complete with acknowledgement forms for sign-off.

Deliverables

What you receive

Bespoke AI acceptable use policy

Fully tailored to your sector, size, and the specific AI tools your team uses. Not a template — written from scratch for your business.

Approved and prohibited tool lists

Clear lists staff can reference instantly. Which tools are allowed, which are banned, and a brief explanation of why for each.

Data handling rules

Explicit rules about what types of data can and cannot be entered into AI tools. No ambiguity — staff know exactly where the line is.

Breach procedure framework

What happens if someone breaks the rules. Escalation process, consequences, and remediation steps — proportionate and fair.

Staff acknowledgement form

Ready-to-issue sign-off document so every team member formally acknowledges they've read and understood the policy.

Ready to get started?

Book a free 30-minute AI Governance Discovery Call. We'll talk through your situation and show you exactly how we can help.

30 minutes · No obligation · Plain English