An editable AI acceptable use policy for UK businesses: which tools staff may use, what they must never paste in, and who checks the output. Download it in Word and make it yours.

If your team uses ChatGPT, Copilot or any other AI tool at work, they need to know the rules.

This template sets them out on a few pages: which tools are approved, what must never be pasted in, who checks AI output and what to do after a mistake. It follows the same principles as the guide is it safe to use ChatGPT with customer data? Read it below, then download the Word version and replace the details in square brackets.

Download the Word template

Replace everything in [square brackets] with your own details, delete anything that does not apply, and have it checked against your own obligations before you adopt it. This template is a practical starting point, not legal advice.

[Company name] AI Acceptable Use Policy

01

Purpose

This policy explains how people at [Company name] may use artificial intelligence (AI) tools in their work. It is meant to let us benefit from AI while protecting our customers, our colleagues and our business.

It covers generative AI tools such as chatbots and writing assistants, AI features built into software we already use, and any AI tool connected to our systems.

02

Who this policy applies to

Everyone who works for or with [Company name]: employees, directors, contractors, temporary staff and anyone else using our systems or handling our information.

It applies whenever you use AI for work, on any device, including your own phone or computer.

03

Approved tools

Use only the AI tools listed below, on accounts provided by [Company name]. Do not use personal or free accounts for work.

Approved tools: [Tool name, plan and what it may be used for]. [Tool name, plan and what it may be used for].

To request a new tool, ask [Name or role]. We will check its terms, where it stores data, whether it uses our content for training, and whether the provider will act as our data processor under a written agreement before approving it.

04

Information you must never enter

Unless [Name or role] has approved a specific, reviewed use in writing, never enter the following into an AI tool:

  • Passwords, access codes, API keys or other credentials.
  • Bank details, card numbers or full financial records.
  • Health information, or information about a person’s ethnicity, religion, sexuality, political views, trade union membership, biometrics or criminal record.
  • Information about children.
  • Full customer, client or staff lists, or exports from our databases.
  • Documents covered by a confidentiality agreement, legal privilege or client instructions that forbid it.
  • Staff HR records, grievances or disciplinary notes.
  • [Any other information specific to your business or regulator].
05

Using personal and client information

Share only what the task needs. Remove names, addresses, account numbers and other identifying details wherever you can.

Our obligations under UK data protection law, including the UK GDPR, still apply when information is processed by an AI tool. If you are unsure whether a use is allowed, ask [Name or role] before you start.

06

Checking AI output

Treat everything an AI tool produces as a draft. AI can be confidently wrong, invent facts or sources, and reflect bias.

A person must review AI output before it is sent to a customer, published, or relied on for a decision about a person, money or compliance. The person who uses the output is responsible for it.

07

Being open about AI

Where AI helps produce something a customer receives, follow our guidance on when to say so: [your guidance].

Where we use AI tools with customer information, our privacy notice will explain it.

08

Connecting AI to our systems

No AI tool may be connected to our email, files, customer records or other systems without written approval from [Name or role].

Before approval we will agree which information it can read, what it can write, send or change, where a person must approve its actions, and where data is stored and for how long.

09

Intellectual property and confidentiality

Do not enter other people’s copyrighted material, or our own confidential material, unless the tool’s terms and this policy allow it.

Check that AI output does not copy protected work before you publish or sell it.

10

Reporting mistakes

If you enter something you should not have, or notice an AI tool behaving unexpectedly, tell [Name or role] straight away. Early reporting matters more than blame, and prompt reporting of an honest mistake will always count in your favour.

Personal data incidents are handled under our data breach procedure: [link or reference].

11

Training and review

Everyone covered by this policy will receive a short introduction to it, with examples from our own work.

[Name or role] owns this policy and will review it at least every [six] months, and whenever we approve a new tool, because the tools and their terms change quickly.

Approved by: [Name, role]. Date: [date]. Next review: [date].

Template version 1.0, September 2026.

Five questions for anyone about to use an AI tool at work.

  1. Am I using an approved tool on a work account?
  2. Have I removed names and other identifying details?
  3. Is there anything here from the never-enter list?
  4. Would the customer or colleague be comfortable seeing how I used their information?
  5. Will a person check the output before anyone relies on it?
Policy questions

Want help choosing tools or training your team? See AI training for teams or AI for financial services.

Book a free 30-minute AI consultation
Do small businesses need an AI policy?

If anyone in the business uses AI tools for work, a short written policy helps. It tells people which tools they can use and what they must never paste in, and it shows customers and regulators that you have thought about the risks. The ICO’s guidance on AI and data protection explains the legal background.

Is this template legal advice?

No. It is a practical starting point based on common good practice. Your obligations depend on your sector, your contracts and the data you hold, so have the finished policy checked by someone who knows your business, particularly if you are regulated by the FCA or a professional body.

Can I edit it and use it in my business?

Yes. Download it, replace the details in square brackets, remove anything that does not apply and add anything your business needs. You do not need to credit 3rd Eye AI, although a link back is always appreciated.

What should I do after adopting it?

Walk your team through it with real examples from your own work, list the approved tools and who to ask, and put a review date in the diary. A policy that people understand does more than a long one nobody reads.