The policy
AI can help team members research, explore, draft, analyse and deliver better work. This policy creates room to use that capability with confidence, while making the boundaries and responsibilities clear.
1. Purpose
[Organisation] encourages the thoughtful use of approved AI tools where they help team members do better work or serve others more effectively. This policy sets the minimum rules that make that use possible while protecting customers, colleagues, partners, information, intellectual property and the organisation itself.
Routine, low-risk use does not require case-by-case permission when the tool, information and purpose are permitted by this policy. If you are unsure, ask early: uncertainty is a reason for a conversation, not a reason to abandon a useful idea.
The organisation remains responsible for work produced with AI. Using a tool does not transfer accountability to the tool or its provider.
2. Who and what it applies to
This policy applies to employees, contractors, agency partners and anyone else using AI for work on behalf of [Organisation]. It covers public, licensed, built-in and internally developed AI systems, including generative AI, automated summaries, recommendations, classifications and decision support. In this policy, “team members” means everyone covered by this policy.
It applies whether AI is used to create a final output or only to support an intermediate step.
3. Policy principles
Use it where it helps
Team members are encouraged to use approved tools for a clear purpose where they can improve the work or experience.
Team members remain accountable
A named team member owns the purpose, input, review, decision and outcome.
Use must be proportionate
The greater the possible impact, the stronger the approval, testing and human review required.
Protect information
Only information permitted for the approved tool and purpose may be entered or connected.
Check before relying
Important facts, sources, calculations, claims and implications are independently checked.
Be open when it matters
Routine assistance with spelling, structure, layout or clarity does not automatically require an AI declaration. Disclosure is expected where AI materially creates or alters content in a way that could affect trust, consent or a decision, and whenever law, contract or platform rules require it.
Learn visibly
Useful patterns, limitations and higher-risk decisions are recorded so that practice improves.
4. Required rules
Use approved tools
Team members must use AI tools approved for the type of work and information involved. A free account, personal account or feature included in other software is not automatically approved for organisational use.
When a tool, purpose and information type are approved, team members are encouraged to use it without seeking permission for every routine task. Managers should help teams identify useful opportunities rather than waiting for individuals to discover them alone.
Experiment inside the boundaries
Team members are encouraged to explore approved tools using permitted information, especially for early thinking, drafting, comparison and learning. Experiments should be easy to stop, review and improve before they affect customers, colleagues or material decisions.
Use approved organisational context
Where the organisation provides an approved prompt, Brand Kit, template, terminology list or knowledge source, use it as the starting point. These resources help the tool reflect the organisation without requiring every team member to recreate the rules. Do not paste full internal guidelines, confidential strategy or unpublished material into a tool unless that information and arrangement are approved.
Use permitted information
Do not enter personal data, confidential information, commercially sensitive material, credentials, unpublished research, customer content or third-party material unless the tool, purpose and handling arrangement are explicitly approved.
Is this tool approved for this task, this information and the people who may be affected?
Review outputs
AI-assisted work must receive review proportionate to its impact before it is published, sent, used in a decision or treated as evidence. The reviewer must be able to judge the subject matter and must have time and authority to change or reject the work.
Would the reviewer spot a confident but wrong answer, and do they have the authority to change or reject it?
Check rights and ownership
Team members must consider copyright, licence, attribution, confidentiality, contract and ownership before using AI inputs or outputs. AI-generated does not mean free to use.
Do not misrepresent
Do not use AI to impersonate a person, fabricate evidence, conceal a material conflict, create deceptive media or suggest that a qualified professional has reviewed work when they have not.
Respect people
AI must not be used to discriminate unlawfully, manipulate vulnerable people, infer sensitive traits without an approved and legitimate purpose, or remove a person’s fair opportunity to question a consequential decision.
5. Higher-risk uses
Approval from [named role or group] is required before AI is used for decisions or outputs that could materially affect a person’s rights, access, employment, safety, finances, health, legal position or reputation.
Higher-risk uses include:
- recruitment, performance, promotion or disciplinary decisions;
- eligibility, pricing, credit, insurance or access to essential services;
- medical, legal, financial or safety-critical guidance;
- profiling, surveillance or decisions based on sensitive information;
- external claims that could create significant legal, financial or reputational exposure;
- automated action without a meaningful opportunity for human intervention.
If the output were wrong, biased, disclosed or misunderstood, who could be harmed and how difficult would it be to put right?
6. Problems and incidents
Stop or contain the use and report it to [contact or reporting route] if AI:
- reveals or may have received information it should not have;
- produces harmful, discriminatory, deceptive or materially incorrect content;
- is used outside its approval or intended purpose;
- causes, or could cause, a significant adverse decision or outcome;
- creates uncertainty about rights, ownership, security or legal duties.
Reporting a question, limitation or near miss is encouraged. Good-faith reporting helps the organisation improve tools, instructions, controls and training before someone is harmed, and should be treated as a contribution to better practice.
7. Responsibilities
Team members using AI
Look for useful applications, including repetitive drafting, summarising and reporting that can be reduced or redesigned. Use the time saved for judgement, creativity, relationships and other work that benefits from human attention. Share successful experiments, prompts and lessons through [team channel or forum] so useful innovation becomes visible and repeatable. Follow this policy, use approved tools, protect information, carry out the required review and raise questions early.
Managers and commissioners
Encourage thoughtful experimentation, share relevant examples, set a clear purpose, confirm the risk level, allow time for review and ensure that a named team member remains accountable.
Tool and information owners
Assess providers, settings, contractual terms and provider policies. Define permitted uses and data, monitor material changes to models, features, terms, privacy and data use, alert affected team members, and maintain the approved-tool record.
Policy owner
Keep this policy usable and current, make approved routes easy to find, support learning and training, coordinate incidents and exceptions, and make changes visible.
If AI saves an hour, what more valuable human work should take its place?
8. Exceptions and review
Exceptions must be approved in writing by [role], be limited in scope and time, and record the reason, risks, controls and review date. This policy is reviewed on the schedule above and sooner after a material incident, legal change or significant change to approved systems.