How to Write an AI Usage Policy: A Template for UK Small Businesses

How to Write an AI Usage Policy: A Template for UK Small Businesses

A practical template for writing an AI usage policy: the six sections every policy should cover, a ready-to-adapt structure, and common first-draft mistakes.

An AI usage policy is a short, written document that tells staff what they can and cannot do with AI tools at work. It does not need to be long. It needs to be clear enough that a new employee reads it once and understands the rules. Most UK small businesses that lack one are not avoiding AI. Their staff are already using it informally, without any guidance. This guide gives a practical, ready-to-adapt structure for writing one.

Why a Short Policy Beats No Policy

Staff at most UK businesses already use AI tools daily, even without official approval. They draft emails with ChatGPT. They summarise documents with Claude. They generate first drafts of reports. This happens whether or not a policy exists. The risk is not AI use itself. The risk is AI use with no guardrails around data handling, accuracy checking, or accountability. A short policy closes that gap quickly, without needing a lengthy governance framework.

The Six Sections Every Policy Should Cover

SectionWhat to Include
Approved toolsName the specific AI tools staff can use, and note which need manager approval first
Data handling rulesList what must never go into an external AI tool: customer data, financial figures, unreleased plans
Human review requirementState which outputs need a person to check them before use, such as client emails or financial reports
Accuracy expectationsRemind staff that AI tools can produce confident but wrong answers, and must be verified for factual claims
AccountabilityName who owns the policy and who staff should ask when unsure
Review scheduleSet a date to revisit the policy, since tools and risks change quickly

A Simple Template You Can Adapt

Below is a starting structure. Adjust the specific tools and thresholds to fit your business.

  1. Approved tools: Staff may use [tool names] for [permitted tasks]. Any other AI tool needs approval from [named role] first.
  2. Never enter this data: Customer names, contact details, financial figures, unpublished plans, or anything covered by a confidentiality agreement must never be typed into an external AI tool.
  3. Always check before sending: Any AI-drafted content going to a client, customer, or external party must be reviewed by a person before it is sent.
  4. Verify facts: Do not treat AI-generated statistics, quotes, or citations as accurate without checking the original source.
  5. Questions go to: [Named person or role], who owns this policy and reviews it every [six months / year].

Common Mistakes When Writing a First Policy

  • Making it too long. A ten-page policy gets skimmed once and ignored. A one-page policy gets followed.
  • Banning AI outright. This usually just pushes use underground, since staff keep using it on personal devices instead.
  • Skipping the data handling section. This is the single highest-risk gap, and the easiest one to fix with one clear list.
  • Never revisiting it. AI tools change fast. A policy written a year ago may already be outdated.

Expert Insight

Consultants working with UK SMEs consistently find that the businesses at greatest risk are not the ones avoiding AI. They are the ones with no policy at all, where staff have already adopted tools informally. A simple, one-page policy addressing data handling and human review closes most of the practical risk immediately, well before more detailed governance work is needed.

Frequently Asked Questions

Does a small business really need a written AI policy?

Yes. Even a one-page policy meaningfully reduces risk, since staff are very likely already using AI tools without guidance.

How long should an AI usage policy be?

One page is usually enough for a small business. A short, clear document gets read and followed. A long one gets ignored.

Should the policy name specific AI tools?

Yes. Naming approved tools directly removes ambiguity and gives staff a clear, simple rule to follow.

How often should the policy be reviewed?

Every six months to a year is reasonable, since new tools and risks emerge quickly in this space.

Final Thoughts

A short, clear AI usage policy closes most of the practical risk a small business faces from informal AI adoption. Start with the six sections above, adapt the template to your business, and revisit it regularly. For a deeper look at AI governance beyond the basics, see our guide to AI consulting and governance. For our full AI coverage, see the AI hub.