Decode & Grow

How to Write an AI Usage Policy for a Small Team

Short answer: An AI usage policy needs to cover which tools are approved, what data may and may not be entered, when AI output must be reviewed, when AI use must be disclosed, and who to ask when unsure. Keep it to two pages, make it specific to the tools your team actually uses, and pair it with recorded training — documented training is itself a legal obligation under the EU AI Act for businesses in scope.

Why this isn't optional any more

Two reasons. The regulatory one: AI literacy obligations under Article 4 of the EU AI Act have applied since February 2025 to organisations in scope, and they require that people dealing with AI systems have appropriate training. A policy plus a training record is the practical evidence.

The commercial one is more immediate. If an employee pastes client data into a consumer AI tool and it surfaces somewhere, the absence of a documented policy makes that considerably harder to defend — to the client, to your insurer, and to a regulator.

What the policy must cover

1. Approved tools. Name them. "Use AI responsibly" gives no guidance. "Approved: ChatGPT Team, Claude, Copilot in our Microsoft tenancy. Anything else requires approval from [name]" does. Include why the distinction matters — enterprise plans typically exclude your data from training; consumer plans may not.

2. Data rules. The section people actually read. Be concrete:

  • Never enter: client personal data, health or other special category data, credentials, unpublished financials, anything under NDA.
  • Enter with care: internal documents, anonymised examples, draft client-facing material.
  • Fine: public information, generic questions, your own draft writing.

3. Review requirements. Define where a human must check output before it goes anywhere. As a default: anything client-facing, anything published, anything used in a decision affecting a person, and any factual claim, figure or citation. Name the reviewer where it matters.

4. Disclosure. When AI use must be told to a client or the public. Article 50 transparency obligations require disclosure where people interact with an AI system and labelling of certain synthetic content. Beyond the legal minimum, decide your own line — many businesses commit to disclosing AI involvement in client deliverables as a trust measure.

5. Accountability. The person who sends the output owns it. This sentence prevents a great deal of ambiguity.

6. Who to ask. A named person, not a mailbox.

How to make it usable

  • Two pages maximum. Longer policies are not read, and an unread policy is not evidence of anything useful.
  • Write in examples. "Don't paste a client's contract into a consumer chatbot to summarise it — use the approved enterprise tool" beats an abstract prohibition.
  • Make the safe path easy. If the approved tool is harder to access than the unapproved one, people will use the unapproved one. Shadow AI is usually a friction problem, not a discipline problem.
  • Date it and review it. Six-monthly. Both the tools and the rules are moving.

The training record

The policy alone isn't enough. Keep a simple record: who was trained, when, on what content, and their confirmation of having read the policy. A spreadsheet is fine. Include new starters in onboarding. This record is what an obligation to ensure AI literacy actually looks like in practice.

Frequently asked questions

Does this apply to a UK business?

The EU AI Act applies extraterritorially where output is used in the EU, so many UK businesses are in scope. Separately, UK GDPR obligations around personal data in AI tools apply regardless.

What if we've banned AI entirely?

Then your policy says that, and you should verify it's true. Most organisations that believe they've banned AI have unmonitored use happening anyway.

Can we use a template?

As a starting structure, yes. It has to be edited to name your actual tools and your actual data categories, or it's decorative.

We build AI usage policies and training records as part of our compliance work. See what's covered.

AI Implementation
Made on
Tilda