
A useful AI policy for a small business should help people make good everyday decisions. It should say which tools are approved, what information must stay out of them, when a person must check the output and who owns a problem. It does not need to read like a technology textbook.
The AI policy template below is deliberately short enough to implement and specific enough to guide real work. Replace the bracketed text, review it against your contracts, data and sector requirements, then brief the team. It is a starting point—not legal advice or a substitute for a risk assessment.
Among AI-using UK businesses surveyed in 2025–26.
Most governance was either informal or absent.
Among businesses whose policy or guidance already existed.
Those figures come from the UK Business Data Survey 2026. They matter because staff do not wait for a formal AI programme before trying readily available tools. A lightweight policy can replace uncertainty with clear boundaries while the organisation develops a more mature approach.
What should an AI policy do?
An AI policy sets the house rules for using AI-enabled tools. It should protect information, require meaningful review, name the approver and give staff a quick route to ask before trying a new tool or sensitive data set.
The Information Commissioner’s Office guidance on AI and data protection explains how UK GDPR principles apply when an AI system processes personal information. The ICO’s DPIA guidance says an assessment is required for processing likely to result in high risk and is good practice for major projects involving personal data. Its detailed AI guidance is currently being reviewed following changes made by the Data (Use and Access) Act 2025, so check the latest position for your use case.
You still need to assess the supplier, contract, settings, data flow and use. High-impact work may need legal, data-protection, employment, security or sector advice.
Four things to do before adopting the template
List AI features, meeting assistants, browser tools and personal accounts already used for work.
Identify personal, confidential, credential, contractual and commercially sensitive information.
Give one person authority to approve tools, obtain advice and stop unsuitable use.
Review regularly and after a material tool change or incident.
Do not begin by compiling a list of fashionable products. Begin with the work, the information involved and the consequence of a mistake. Futuro Digital Consultancy’s AI Opportunity Audit is designed to identify and rank those use cases before technology is selected.
AI policy template for a UK small business
The wording below is intentionally plain. Copy it into your own document, replace the bracketed sections and remove anything that does not fit. Have the final version reviewed by the appropriate professional where your activities are regulated, high risk or involve significant decisions about people.
1. Purpose and scope
This policy explains how directors, employees, contractors and temporary workers may use artificial intelligence tools for [Business name]. It covers standalone services and AI features embedded in other software. It applies whether a tool is accessed through a business or personal account.
We use AI to support people, improve appropriate processes and create better information—not to avoid professional responsibility. Everyone remains accountable for the work they submit, approve or send.
2. Approved tools and accounts
Only tools approved by [owner/role] may be used for business work. Approved tools and permitted uses are recorded in [register/location]. Business information must only be processed through the approved account, workspace and settings. Staff must not purchase, connect or enable an AI service for business use without approval.
Approval considers the intended purpose, supplier terms, security, data use and retention, access controls, integrations, cost, exit arrangements and the consequences of an incorrect output.
3. Permitted uses
Within an approved tool and the information rules below, AI may be used to:
- generate ideas, outlines, draft wording or alternative phrasing;
- summarise approved non-sensitive material;
- classify or route routine information within an approved workflow;
- assist with research where sources are checked independently; and
- support other documented uses approved by [owner/role].
4. Uses requiring prior approval
Written approval from [owner/role] is required before AI is used with personal or confidential information; connected to email, files, CRM, finance or operational systems; used to communicate externally without review; or used to support a decision that materially affects a person, client, worker or supplier.
AI must not be used as the sole decision-maker for recruitment, performance, eligibility, pricing, credit, legal rights, health and safety, or similarly significant matters unless the use has been specifically assessed and authorised with the necessary safeguards.
5. Data, privacy and confidentiality
Do not enter personal data, special-category data, client-confidential information, passwords, access keys, unpublished financial information, legal advice, protected intellectual property or sensitive business plans into an AI tool unless that precise use and environment have been approved.
Use the minimum information needed. Redact or anonymise material where appropriate. Follow our data-protection, retention, security, acceptable-use and client-confidentiality policies. Anonymisation means more than removing a name if a person could still be identified from the remaining detail.
6. Human review and accuracy
AI output is a draft or recommendation unless an approved automated process states otherwise. The person using or approving it must check facts, calculations, sources, tone, confidentiality, bias, intellectual-property concerns and suitability for the intended audience.
The depth of review must match the consequence of error. Client advice, contractual wording, financial figures, regulated work and public claims require review by a suitably competent person. Sources must be opened and verified; an AI-generated citation is not evidence that the source exists or supports the claim.
7. Fairness, transparency and decisions about people
AI must not be used in a way that unlawfully discriminates or creates unjustified disadvantage. Where AI materially influences a decision about a person, [owner/role] must approve the process, its data-protection assessment, the information given to affected people and the route for meaningful human review or challenge.
We will be transparent about AI use when withholding that information would mislead a client, worker or other person, or where disclosure is required by law, contract, professional rules or an approved process.
8. Intellectual property and external content
Do not assume AI output is accurate, original or safe to publish. Check for copied wording, third-party rights, licence restrictions and confidential material. Do not ask a tool to imitate a living creator or reproduce protected work for commercial use without appropriate permission and review.
9. Security and integrations
Use multi-factor authentication where available, follow access-control rules and never share credentials. AI integrations must use approved service accounts and the minimum permissions required. Outputs and logs must be protected according to the sensitivity of the information they contain.
Automated workflows must have an owner, test evidence, failure alerts, an exception route and a safe way to pause them. Material supplier, model or configuration changes must be reviewed before continued use.
10. Records, incidents and concerns
Record new tools and material use cases in [register/location]. Retain the prompts, outputs, approvals and test evidence required by the use-case assessment. Do not record sensitive prompts in an unsuitable log.
Report accidental disclosure, harmful or discriminatory output, suspected security issues, incorrect external communication or other material concerns immediately to [contact/role] using [incident route]. Do not conceal or quietly correct an incident that may need formal handling.
11. Training and responsibilities
[Business name] will provide proportionate training on approved tools, information handling, output checking and incident reporting. Managers are responsible for applying this policy in their teams. Users are responsible for following the policy and asking before proceeding when a use is unclear.
12. Review and non-compliance
[Owner/role] reviews this policy at least every [six/twelve] months and after a material tool change, new high-impact use or incident. Use outside this policy may result in access being removed and action under the relevant staff, contractor or security procedures.
For each approved tool or workflow, record its owner, supplier, purpose, users, information types, connected systems, approval date, risk assessment, human controls, retention settings, contract renewal and next review. A simple maintained register is more useful than a detailed policy nobody can apply.
A simple way to classify AI uses
| Level | Typical example | Minimum approach |
|---|---|---|
| Low | Ideas for a public-information article, with no confidential or personal input. | Use an approved tool; a person checks the result before use. |
| Moderate | Drafting a client email from approved CRM fields or summarising internal meeting notes. | Document the use; minimise data; confirm supplier settings; require named human approval. |
| High | Profiling people, handling sensitive data, or influencing recruitment, access or professional advice. | Pause for specialist review, a formal assessment and senior approval; do not deploy until safeguards are adequate. |
| Prohibited | Uploading confidential data to an unapproved public tool or allowing AI to send significant advice without review. | Do not proceed. Redesign the process or use an approved controlled environment. |
This classification is an internal triage tool, not a legal determination. The DSIT AI Risk Management Toolkit, published in September 2026, provides a fuller starting point for understanding, assessing and managing risks when designing, buying or operating AI products.
How to introduce the policy without creating shelfware
- Discuss real examples. Apply the rules to an email draft, meeting summary and connected workflow.
- Make approval quick. Give people one route for proposing a tool or data use.
- Configure the tools. Use business accounts, access controls, suitable retention and managed integrations.
- Test understanding. Practise spotting risky prompts and verifying outputs.
- Review the register. Remove unused access and check actual use against the approved purpose.
The NCSC Guidelines for Secure AI System Development cover supplier risk, AI assets, documentation, access, monitoring and incidents. Those questions remain useful when a small business buys rather than builds AI.
The best first policy is not the longest. It makes approved tools, prohibited information, human approvals, ownership and incident reporting unmistakable.
How the policy changes everyday work
A colleague may use an approved tool to suggest marketing headings from public information, but still verifies every claim. A meeting assistant requires a check of the account, participant notice, recording and retention. An approved CRM workflow may suggest an enquiry category while uncertain cases go to a person. A proposal to rank job applicants is paused for specialist assessment rather than tried informally.
If you want help turning these principles into controls across CRM, email and operations, see our AI automation and integration services. For continued ownership, supplier decisions and a governed improvement backlog, explore fractional AI consultancy.
AI policy template FAQs
Does a UK small business legally need an AI policy?
There is no universal rule requiring every small business to have a document with that name. Existing data-protection, confidentiality, employment, consumer and sector duties may still apply. A proportionate policy helps manage and evidence them; obtain advice for your circumstances.
Can employees use free AI tools for work?
Only if the business has assessed and approved the tool, account and use. Free or personal accounts may have unsuitable contractual, data-use, retention, administrative or security arrangements; versions of the same product may differ.
Can we put customer information into an AI tool?
Assess the purpose, lawful basis, necessity, supplier contract, security, retention, transfers, transparency and individual rights. Use the minimum information, complete a DPIA where required and seek advice if uncertain.
How often should an AI policy be reviewed?
Set a regular review—often every six or twelve months—and also review after a significant use, supplier or legal change, a new integration, an incident or evidence that practice differs from policy.
Should customers be told when AI is used?
It depends on the use, but people should not be misled. Data-protection, contractual or professional transparency duties may apply. Decide this during assessment rather than after launch.
Is this template suitable for a regulated business?
It is only a starting structure. Map it to sector rules, professional duties, client contracts and risk controls, with specialist review where appropriate.
Turn your AI policy into practical controls
Futuro Digital Consultancy can map current AI use, prioritise sensible opportunities and design controlled workflows around your people, CRM and business systems.
This article and template provide general operational information for UK businesses. They are not legal, regulatory, employment, cyber-security or sector-specific advice. Laws, regulatory guidance and supplier terms change; confirm the current requirements for your organisation and proposed use.