The good news is that a useful policy is short. The bad news is that most templates stop halfway.

What the templates cover

Search for an AI policy template and you’ll find the same sensible list:

  • which tools are approved;
  • what information must never go into them, such as customer personal data, financial details and anything confidential;
  • a rule that a person checks AI output before it’s used;
  • who to ask when you’re not sure.

Keep all of that. Personal data rules still apply when a tool is new, and the Information Commissioner’s Office publishes guidance on AI and data protection that’s worth a read.

But that list only governs people using AI. It says nothing about AI doing things: sending the email, updating the record, replying to the customer. That’s where most businesses are heading, and it’s where a policy earns its keep.

What they miss: who is allowed to do what

The question that stops most AI adoption isn’t “is it accurate?”. It’s “what did it do while I wasn’t looking?”. A policy should answer that before anything is switched on. Four rules do most of the work.

1. Nothing acts without a person approving it, at first. The AI proposes and a named person approves, edits or rejects. Approving sends the work on. Editing becomes a rule the system learns from. Rejecting needs a one-line reason. How an approval queue works →

2. Freedom is earned, and anyone can check the record. Each use starts with no authority of its own. It moves from reporting, to suggesting, to acting within limits, only after a run of clean approvals that anyone can inspect.

3. One bad call takes the freedom away. A single rejection sends it back to the start, not one step down, and the reason becomes a rule. Trust is lost quickly and regained slowly, on purpose. How autonomy is withdrawn →

4. Some work never goes to AI at all. Write down the line. In our own business, no AI moves money, makes a legal commitment or touches live customer data, however good its record. Yours will have its own version. What not to automate →

Add two practical controls and the policy is complete. First, spending limits: a hard monthly cap for each tool, so the bill can’t surprise you. Second, an audit trail: every action logged and attributable, so “what did it do?” always has an answer.

A one-page outline you can copy

[Business name] AI policy — version 1, [date]

1. Who owns this policy. [Name] keeps it current and reviews it every [three] months.

2. Approved tools. [List]. Ask [name] before using anything else, including AI features switched on in software we already use.

3. What stays out. Never put in customer or staff personal data, bank or card details, passwords, or anything marked confidential, unless the tool is approved for it in writing.

4. People check the work. Anything AI produces is checked by a person before it reaches a customer, a supplier or our accounts. The person who uses it is responsible for it.

5. When AI does things for us. Every automated task has a named owner. It starts by proposing and a person approves. It earns more freedom only after [twenty] clean approvals. One rejection returns it to proposing, and the reason is written down as a rule.

6. The line. No AI will ever: [move money / sign or agree contracts / delete records / contact [group] / …].

7. Limits and records. Each tool has a monthly spending cap of £[x]. Automated actions are logged, and anyone on the team can ask to see the log.

8. Speaking up. If something looks wrong, tell [name]. Nobody gets in trouble for stopping an AI task they weren’t sure about.

Making it stick

A policy that lives in a shared drive changes nothing. Three habits make it real:

  • Say what changes for whom. People worry less about AI when they can see the controls than when they’re given reassurance. Landing AI with a worried team →
  • Review it on a schedule. Tools and habits move fast. A short review every quarter keeps the approved list and the line honest.
  • Start with one task. Choose one repetitive, reversible job, run it through the policy, and adjust the policy from what you learn.

If you’d like help drawing your line, or deciding which of your processes are worth handing over at all, that’s the first thing we do in a Blueprint.

This guide is general guidance, not legal advice.