Most of your staff are already using AI tools like ChatGPT, Microsoft Copilot and Gemini at work. Some are doing it openly. Many are doing it quietly. Very few are doing it with any formal guidance. If your business does not yet have an ai policy in place, this page will fix that.
An ai policy (sometimes called an ai usage policy or ai acceptable use policy) is simply a written set of rules that explains how your business allows or restricts the use of ai systems and ai tools at work. It covers which tools are approved, what data staff can and cannot put into them, and what to do if something goes wrong. An effective ai policy acts as a governance framework for artificial intelligence use across your organisation.
This guide is written for owners and office managers of small and medium businesses in Bristol, Bath, Cheltenham, Swindon, Gloucester and across the wider South West who know they need a policy but are not sure where to start. We Do Your IT Support is a managed IT support provider that helps local businesses put sensible, short, readable ai acceptable use policy documents in place. Not 40-page legal essays.
By the end of this page you will know the five things every ai policy must cover, understand the difference between Microsoft 365 Copilot and public ai tools, and be able to download a free ai policy template for UK SMBs. An ai policy safeguards businesses from data leaks and compliance risks, and yours can be ready this week.
Picture this: it is mid-2026. Your sales team has been using ChatGPT for over a year to rewrite proposals. HR has been pasting interview notes into Gemini. Finance found a free invoice analyser online. Marketing uses image generators with your brand name in the prompts. None of this was approved. None of it is logged. Nobody in leadership knows the full picture.
The decision to “not have an ai policy yet” is itself an ai governance decision, and a risky one. Under UK GDPR, businesses must demonstrate “appropriate organisational measures” to protect personal data. Having no documented ai usage policy means you have no evidence you considered the risks of new ai technology at all. Lack of an ai policy can lead to data breaches, and regulators like the ICO expect you to show you thought about this before something went wrong, not after.
Policies minimise operational, legal, and reputational risks associated with AI. Without guidelines, employees may misuse ai tools unknowingly. AI misuse can expose organisations to legal and reputational risks, and delaying a policy only widens the gap between what staff are doing and what the business can defend.
Here are three visible business impacts of continuing without a policy:
Different people using different tools with different assumptions about what is acceptable.
Customer data, HR records and financial details pasted into uncontrolled public tools.
If the ICO or a client asks what controls you have, you have nothing to show.
Shadow AI means any use of ai tools and ai systems by staff that the business has not approved, cannot see and cannot control. It is not malicious. Most of the time, staff are just trying to work faster. But the risk is real and growing.
These generative ai tools often send data to servers outside the UK. They may use your inputs as training data for their ai models. They sit outside your Microsoft 365 tenant, your backups and your security controls. Research from Microsoft in 2024 found that more than 75 per cent of knowledge workers are already using some form of ai tool at work, many without telling their employer. Globally, 80% of organisations use AI in at least one business function.
The ai ethics risk is just as serious. Staff can unintentionally generate biased, offensive or incorrect content that ends up on a document with your company logo. Inconsistent AI practices can result in discriminatory outcomes. And if shadow ai use involves personal data such as customer contact details, CVs or health information, it may qualify as a data breach under UK GDPR because there is no control over where that data goes. This is exactly why an ai acceptable use policy matters.
This is the practical core and backbone of the downloadable AI policy template. Aim for a simple three to five-page document staff will actually read. AI policies must include guidelines for acceptable and prohibited use, ethical use, and compliance.
Clearly list permitted and banned AI tools (e.g., Microsoft 365 Copilot approved; personal ChatGPT accounts banned). Access should be via business-managed accounts with single sign-on, multi-factor authentication, and logging.
Define public, internal, and confidential/personal data. Staff must not input customer names, emails, bank details, payroll, health or HR records into consumer AI tools. Enterprise AI like Copilot may allow some data if properly configured. This ensures GDPR compliance.
AI is a starting point, not final. Staff must fact-check, apply human judgement, and never copy raw AI content into contracts, HR letters, or legal docs without review. Human oversight is essential. Transparency and disclosure are required for external content.
Set a clear process for reporting issues (line manager, then IT) and timescales. Early reporting aids GDPR breach notifications. Documented steps simplify investigation and reduce legal risks.
Assign a senior owner (e.g., Managing Director) responsible for oversight. IT handles enforcement. Review the policy at least every six months to keep pace with fast-moving AI and evolving regulations. Regular audits ensure compliance and ethical use.
Effective AI policies define ethical use, mitigate unfair bias, and include mandatory human oversight to prevent discrimination and data misuse.
Many policies sit in a shared folder and are never read. An ai policy only works if staff understand it, remember the key rules and see it as relevant to their daily work. AI policies provide a framework for employees to use ai tools safely and effectively, but only if they are written for real people.
Implementing an AI policy requires clear employee training and governance structures. Training and awareness directions are crucial components of AI policies. Clear AI policies build trust within organisations because people know what is expected of them.
Make the ai usage policy part of new starter onboarding and annual refresher training. We Do Your IT Support delivers staff training through the Let’s Copilot programme, turning the ai policy into practical training sessions on real Copilot usage. Schedule a formal review every six months with IT and leadership. Regularly review AI policies to keep pace with technological changes. Engage diverse stakeholders in AI policy development for effectiveness, including hr professionals, your legal team and operations staff.
Fisher Phillips offers a GenAI usage policy for tools like ChatGPT as a reference point, but your policy should reflect your own business operations and risk profile.
Microsoft 365 Copilot is a specific ai system that runs inside your Microsoft 365 tenant. It uses data from your Outlook, Teams, SharePoint and OneDrive. It is protected by enterprise data protection, data residency settings and your existing permissions. It is an approved enterprise ai solution when procured and configured properly.
Consumer ai tools like free ChatGPT, Gemini and public image generators operate outside your tenant, often outside UK jurisdiction, and usually without the legal and technical safeguards your business needs. A general ai policy or ai acceptable use policy sets the high-level rules for all ai technologies. A dedicated Copilot policy adds detail on how staff should use Copilot in Word, Excel, Outlook and Teams, and what to be careful of.
Copilot inherits Microsoft 365 permissions, so staff can only access what they already have rights to. But misconfigured permissions can still expose too much data. The policy must make the distinction between approved enterprise ai and unapproved consumer ai tools crystal clear.
We Do Your IT Support’s AI Security Pack includes help drafting a Copilot-specific policy, configuring security baselines, and blocking unapproved ai tools with ThreatLocker Web Control. You cannot just say “Copilot is allowed” without any further detail in your organization’s ai policy.
Under UK GDPR, any time staff paste personal data into a public ai tool, there is a real chance this counts as an unauthorised disclosure of personal data. AI policies must comply with local and regional laws, including UK GDPR and the Data Protection Act 2018. AI policies must address data privacy and security considerations as a legal requirement, not just a best practice.
Many consumer ai systems may store prompts, may use them for machine learning model training, and may process them in data centres outside the UK and EU. This raises international transfer questions under applicable laws.
If such an incident occurs, the business might need to investigate, notify affected individuals and in some cases report to the ICO. Having a documented ai usage policy in place is the evidence that appropriate technical and organisational measures were taken. AI policies help mitigate risks related to data privacy. AI policies ensure compliance with evolving legal standards and relevant policies around data protection.
HR copying part of a disciplinary letter with employee names into ChatGPT.
Finance uploading a spreadsheet of customer invoices to a free AI website.
A manager pasting staff performance notes and health details into a public ai tool to “improve the wording”.
AI policies require data handling standards for compliance with GDPR. Data privacy and security considerations are essential in AI policies. We Do Your IT Support’s AI Security Pack uses ThreatLocker Web Control to block risky ai tools in the browser, supporting legal compliance with technical enforcement and reducing the significant risks of ungoverned ai use. AI policies protect data privacy and foster innovation when they are done right. Data security and regulatory compliance go hand in hand with a well-enforced policy.
We have written a free ai policy template specifically for UK small and medium businesses. It covers ai tools, ai systems, ai acceptable use policy rules and GDPR basics in plain English. The sample policy is designed as a starting point you can edit, not a finished legal document.
The template is in Word format so you can add your company name, roles and any sector-specific requirements for healthcare, legal, education or any other business function. The main sections inside the policy template include: purpose and scope, definitions of ai tools and ai technologies, approved and prohibited tools, data handling rules, ai ethics principles, ethical guidelines, ethical standards, ethical practices and the ethical and responsible use of artificial intelligence ai, human oversight, incident reporting, intellectual property considerations, fair use guidance, and a review schedule.
We Do Your IT Support can walk through the template with you, tailor it to your environment and deploy it alongside technical controls and staff training.
We Do Your IT Support is a managed IT support provider for businesses across Bristol, Bath, Cheltenham, Swindon, Gloucester and the wider South West. We help businesses streamline processes around ai integration and put practical ai governance in place without overcomplicating things.
Our AI Security Pack brings together ai governance, data security and training for Microsoft 365 and other business ai systems. The service includes reviewing relevant policies already in place (acceptable use, information security, data protection) and making sure the new ai policy fits alongside them. We also help configure Microsoft 365 Copilot securely, including permissions, data classification and logging, so the ai system respects privacy laws, legal and regulatory standards, and your company policies.
Benefits include reduced GDPR risk, clearer staff guidance, legally compliant ai use, and safer adoption of ai solutions across your business.
Using the ai policy template, customised to your business, aligned with existing policies like IT acceptable use and data protection, and reflecting your company’s commitment to safe ai use and organizational values.
Safe ai usage and Copilot training through the Let’s Copilot programme, including training sessions on how ai works, what is and is not acceptable, and how to apply human oversight in decision making.
ThreatLocker Web Control to block unapproved ai tools, supporting risk management and ensuring the policy applies in practice, not just on paper.
With 80% of UK organisations already using AI, a written policy sets clear rules to protect your business, staff and customers. It reduces risks like data breaches, safeguards trust, and shows regulators you have controls in place. AI policies should cover ethical use and data protection. Download our free AI policy template to start.
The essentials are: approved AI tools, data rules, AI-generated content handling, incident reporting, and policy ownership. Also include scope, ethics, guidance, and review frequency. Keep it short, clear, and aligned with existing policies like IT use and data protection. Download our AI policy template for a full example.
Shadow AI is staff using AI tools without IT approval. Risks include uncontrolled data sharing, biased or inaccurate outputs, and no audit trail. Microsoft found over 75% of knowledge workers use AI at work. Combining an AI policy with technical controls like web filtering is the best way to manage this risk.
Microsoft 365 Copilot runs inside your tenant with enterprise data protection and GDPR safeguards. A Copilot policy guides safe use in Outlook, Word, Excel and Teams. A general AI policy covers public tools like ChatGPT and Gemini that lack these protections. Your policy must approve enterprise AI like Copilot and restrict personal AI tools with company data.
ChatGPT use isn’t automatically illegal but becomes a GDPR risk if staff input personal or confidential data without controls. Examples include pasting customer lists or medical details into personal accounts. The safest approach is to ban sensitive data in public AI tools and use secured enterprise tools like Copilot. A clear AI policy is essential. We Do Your IT Support can help you draft and enforce it.
Your staff are already using ai tools. The only question is whether they are doing it safely. Putting a simple ai usage policy and basic ai governance in place is now essential, not optional. The goal is safe, productive use of ai, not banning artificial intelligence altogether.
Download the free AI Policy Template for UK SMEs and spend 30 to 45 minutes tailoring it to your business with your leadership team. It covers everything from approved tools to ethical use to incident response and regular audits.
Then contact We Do Your IT Support to book a Copilot security review. We will assess your current ai usage, Copilot readiness, GDPR risks and technical controls including ThreatLocker Web Control, and help you put a policy in place that staff will actually follow.
Call us on 0117 911 8808 or visit our website to schedule a consultation. No pressure, no strings attached. Just clear, practical guidance on getting ai governance right for your business.
This website uses cookies to improve your experience. Choose what you're happy with.
Required for the site to function and can't be switched off.
Help us improve the website. Turn on if you agree.
Used for ads and personalisation. Turn on if you agree.