Resources

AI acceptable use policy

A starter policy for small businesses. Fill in the details, and the policy below updates as you type.

By Jason Kelly, Certified ISO/IEC 27001 Lead Implementer. Last reviewed October 2026.

General guidance, not legal advice. This is a starting point for a small business. Adapt it to the tools you use, the data you hold, and any sector or contractual requirements that apply to you.

1. Your details

Approved AI tools

List the tools staff may use, with business accounts, and what each is approved for.

Saved in this browser only. Nothing is sent to us.

2. Your policy

: AI acceptable use policy

Owner: · Effective: · Next review:

1. Purpose and scope

AI tools can save time, but they can also expose confidential information and produce confident mistakes. This policy explains how everyone at may use them. It applies to all staff, contractors and volunteers, and to any AI tool used for work. That includes chatbots, AI assistants built into software you already use, image and audio generators, meeting transcription, and browser extensions.

2. Approved tools only

  • Only use the AI tools listed below, for the purposes listed.
  • Always sign in with your work account, never a personal one. Free and personal accounts may use what you type to train their models.
  • Ask the policy owner before using any new tool, including AI browser extensions and plugins.
Approved toolApproved for
[Add approved tools above]

3. What you can and can’t put into AI tools

Never

  • Passwords, keys or access codes
  • Health, financial or other sensitive information about people
  • Client or customer information marked confidential, or covered by a contract
  • Anything you would not be comfortable seeing published

Only in approved tools, with work accounts

  • Other personal data, such as names and contact details
  • Internal documents, plans and pricing
  • Code and technical configurations

Fine

  • Public information
  • General questions and research
  • Drafting that contains no confidential details

If you’re not sure which category something falls into, treat it as “Never” and ask.

4. You are responsible for the output

  • Check facts, figures, names, quotes and references before you rely on or share AI output. AI tools regularly get these wrong.
  • Review anything going to a customer or the public as carefully as if you had written it yourself.
  • Watch for bias or unfair assumptions, especially in anything about people.

5. Decisions about people

AI must not be the sole basis for decisions that significantly affect someone, such as recruitment, performance, pay, disciplinary matters or a customer’s eligibility for a service. A person must make, or meaningfully review, those decisions.

6. Being open about AI use

  • Be honest if someone asks whether AI was used.
  • Don’t use AI to impersonate a real person, or to create misleading images, audio or video.
  • Tell people when they are interacting with an AI system rather than a person.

7. AI-enabled scams

Criminals use AI to write convincing emails and to clone voices and faces. If you receive an unusual or urgent request to pay money, change bank details or share information, even from someone you know, verify it by calling them back on a number you already have.

8. If something goes wrong

If you put information into an AI tool that you shouldn’t have, or notice an AI tool behaving unexpectedly, tell straight away. Mistakes reported quickly can usually be contained. If personal data is involved, it may need to be reported to the ICO within 72 hours, so don’t wait.

9. Review

This policy will be reviewed at least once a year, and whenever a significant new AI tool is introduced. Breaching it may lead to disciplinary action.

I have read and understood this policy.

NameSignatureDate

Copy the text into Word or Google Docs if you want to edit the wording.

Important

This starter template is provided free as general information for UK organisations. It is not legal or professional advice and it is not a substitute for advice on your circumstances. It does not cover every AI risk or legal requirement that may apply to you, such as sector rules, contractual obligations, employment law, or the EU AI Act if you operate in the EU. To the extent permitted by law, Cyber Ascent Consultancy Limited accepts no liability for any loss arising from use of this template. See our terms of use.