Short answer: An AI usage policy needs to cover which tools are approved, what data may and may not be entered, when AI output must be reviewed, when AI use must be disclosed, and who to ask when unsure. Keep it to two pages, make it specific to the tools your team actually uses, and pair it with recorded training — documented training is itself a legal obligation under the EU AI Act for businesses in scope.
Two reasons. The regulatory one: AI literacy obligations under Article 4 of the EU AI Act have applied since February 2025 to organisations in scope, and they require that people dealing with AI systems have appropriate training. A policy plus a training record is the practical evidence.
The commercial one is more immediate. If an employee pastes client data into a consumer AI tool and it surfaces somewhere, the absence of a documented policy makes that considerably harder to defend — to the client, to your insurer, and to a regulator.
1. Approved tools. Name them. "Use AI responsibly" gives no guidance. "Approved: ChatGPT Team, Claude, Copilot in our Microsoft tenancy. Anything else requires approval from [name]" does. Include why the distinction matters — enterprise plans typically exclude your data from training; consumer plans may not.
2. Data rules. The section people actually read. Be concrete:
3. Review requirements. Define where a human must check output before it goes anywhere. As a default: anything client-facing, anything published, anything used in a decision affecting a person, and any factual claim, figure or citation. Name the reviewer where it matters.
4. Disclosure. When AI use must be told to a client or the public. Article 50 transparency obligations require disclosure where people interact with an AI system and labelling of certain synthetic content. Beyond the legal minimum, decide your own line — many businesses commit to disclosing AI involvement in client deliverables as a trust measure.
5. Accountability. The person who sends the output owns it. This sentence prevents a great deal of ambiguity.
6. Who to ask. A named person, not a mailbox.
The policy alone isn't enough. Keep a simple record: who was trained, when, on what content, and their confirmation of having read the policy. A spreadsheet is fine. Include new starters in onboarding. This record is what an obligation to ensure AI literacy actually looks like in practice.
The EU AI Act applies extraterritorially where output is used in the EU, so many UK businesses are in scope. Separately, UK GDPR obligations around personal data in AI tools apply regardless.
Then your policy says that, and you should verify it's true. Most organisations that believe they've banned AI have unmonitored use happening anyway.
As a starting structure, yes. It has to be edited to name your actual tools and your actual data categories, or it's decorative.
We build AI usage policies and training records as part of our compliance work. See what's covered.