AI Policy Template for UK Businesses: What Belongs In It, and Why
A workable AI use policy for UK organisations, with the legal position as it actually stands in 2026, the clauses that matter, and the ones that quietly cause trouble.
Most AI policies fail for the same reason. They are written to protect the organisation from its staff, so staff route around them, and within three months the company has more shadow AI use than it started with and less visibility into it.
A policy that works does the opposite. It tells people clearly what they may do, so they stop guessing and stop hiding.
This piece sets out what a UK AI use policy needs to contain, why each part is there, and where the current UK legal position actually sits, which is more specific in 2026 than most templates you will find online reflect.
Where UK law actually stands in 2026
Worth clearing this up first, because a lot of policy templates in circulation are either written for the EU or written from a 2023 view of the world.
There is no UK AI Act. The 2023 white paper set out a pro-innovation framework built on existing law and existing regulators rather than a single statute, and that remains the position. A UK AI Bill has been signalled but, as of May 2026, none sits before Parliament.
Existing regulators do the regulating. The ICO covers personal data and automated decision-making. Ofcom covers online services and, since its April 2026 open letter, treats frontier AI cyber risk as sitting inside the Telecoms Security Act 2021 perimeter. The FCA covers financial services. DSIT coordinates policy across government but does not enforce.
The law that changed things is a data law, not an AI law. The Data (Use and Access) Act 2025 came into force from 5 February 2026. It replaced UK GDPR Article 22 with new Articles 22A to 22D, which permit solely automated decisions subject to safeguards: disclosure of the logic involved, a right to human review, and a right to contest the outcome.
A statutory ICO code is coming. From 12 May 2026 the ICO has a statutory duty to produce a single Code of Practice on AI and automated decision-making. Draft guidance on Articles 22A to 22D went out to consultation, which closed on 29 May 2026. Final guidance is expected during summer 2026 and the Code itself is more likely in 2027.
- Data protectionUK GDPR and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025. This is where most real AI risk lands for most organisations.
- Automated decisionsArticles 22A to 22D, in force since February 2026. If AI makes or substantially shapes a decision about a person, safeguards apply.
- Sector rulesFCA for financial services, MHRA for medical devices, Ofcom for online safety and network security. Your sector regulator's existing rules already apply to your AI use.
- Employment and equalityThe Equality Act 2010 does not care that a decision came from a model. Discriminatory outcomes are discriminatory outcomes.
- Contract and IPClient confidentiality clauses, NDAs and licence terms almost always predate AI tools and almost never contemplate them. This is where the quiet breaches happen.
Position as at June 2026. This is general information, not legal advice. Take your own advice on anything sector-specific.
There is also the EU AI Act, which reaches UK businesses that put AI systems on the EU market or whose outputs are used in the EU. If that describes you, it needs its own section in the policy.
The nine things a working policy contains
1. Scope, stated plainly
Who this applies to and what counts as AI. Be broad on the second one. If you define AI narrowly as “generative AI tools”, you have excluded the recruitment screening software, the fraud scoring, and the forecasting model your finance team built in a spreadsheet.
A workable definition: any system that produces outputs, recommendations, content or decisions using machine learning or statistical inference, whether bought, subscribed to, or built internally.
2. A tool list with a traffic light on it
This is the clause that determines whether the policy is used or ignored. People do not want principles, they want to know whether they can use the thing that is open on their screen.
The route to request review matters as much as the list. Without it, the answer to any new tool is a permanent no, and people simply stop asking.
3. Data rules, written as examples
Abstract data classifications do not survive contact with a Tuesday afternoon. Write the rules as things people actually do.
- Client documents, contracts and anything covered by an NDA do not go into a tool unless that tool is on the approved list and the client contract permits it.
- Personal data, including CVs, customer records and anything identifying a colleague, follows the same rule as any other processing. If you would not email it to an unknown third party, do not paste it into one.
- Commercially sensitive material such as pricing models, unreleased strategy and financial forecasts stays inside approved tools only.
- Anything already public is fine.
Then add the sentence that makes it stick: if you are not sure which category something falls into, treat it as confidential and ask.
4. The human accountability clause
The most important paragraph in the document, and the shortest.
The person who uses an AI output is accountable for it. Delegating the work does not delegate the responsibility. Nobody may attribute an error to a tool.
Everything else in the policy is administration. This is the part that changes behaviour.
5. Automated decisions about people
This is where UK law is now specific, so the policy should be too.
If an AI system makes, or substantially shapes, a decision that has legal or similarly significant effects on an individual, Articles 22A to 22D apply. In practice that means recruitment screening, credit and eligibility decisions, performance management, pricing that varies by individual, and anything that determines access to a service.
The policy should require, for any such use: a documented lawful basis, a data protection impact assessment, meaningful human review that is genuine rather than a rubber stamp, a way for the individual to contest the outcome, and a plain-English explanation of the logic involved.
And it should say clearly that these uses require sign-off before they go live, not after.
6. Disclosure
Decide your position and write it down, because otherwise every person decides individually.
A workable default: AI assistance in drafting, research or analysis does not require disclosure, because the human is accountable for the output either way. Anything published as a first-person account, anything presented as original research, and anything a client has specifically asked to be human-produced does require it. Client contracts that restrict AI use override the default.
7. Intellectual property
Two directions, both worth a paragraph.
Outward: check what the tool’s terms say about ownership of outputs, and be aware that purely machine-generated material may not attract copyright protection in the way your team assumes.
Inward: inputs may be retained or used for training depending on the plan and the contract, which is precisely why the approved list exists. Code assistants deserve a specific mention, because suggested code can carry licence obligations that nobody reads.
8. Reporting when it goes wrong
People will paste the wrong thing into the wrong tool. What determines the damage is whether they tell you within an hour or you find out in three months.
Say explicitly: report it, here is who to, and reporting a genuine mistake promptly will not be treated as a disciplinary matter. Then hold to that, because the first time you do not, the policy is finished.
9. Review date
AI tooling changes faster than policy cycles. Six months, named owner, in the diary. A policy with no review date is a policy that will be quietly wrong within a year, and everybody will know it.
Three clauses that cause more trouble than they prevent
A blanket ban. It does not stop usage, it stops visibility. Staff use their personal accounts on their phones and you lose every control you had. If the honest answer today is no, say “not yet, here is the review date and here is what we are working through” instead.
“Always verify AI output.” Nobody can act on this, so nobody does. Verify against what, to what standard, evidenced how? Replace it with a specific requirement: any factual claim, figure or citation that reaches a client or the public must be checked against a named primary source, and the person who checked it is on the record.
A policy written entirely in legal language. If it takes twenty minutes to read and three attempts to understand, it will not be read at all. Two pages that people follow beat fourteen pages that live in a folder.
Getting it adopted
The document is maybe a third of the job.
Write it with the people who will use it. Twenty minutes each with someone from marketing, sales, finance and delivery will surface the actual use cases and the actual worries. It also means the policy arrives with allies rather than as an edict.
Train on it once, properly. Thirty minutes, with real examples from your own business, including the awkward ones. Not a slide deck circulated by email.
Make the approved route the easy route. If the sanctioned tool is slower, worse or requires three approvals, people will use the unsanctioned one. This is the single largest determinant of whether a policy holds.
Review the tool list monthly, the policy every six months. The list changes far faster than the principles.
An honest word on templates
You can download an AI policy template, including from us, and it will get you to a reasonable first draft in an afternoon. What a template cannot do is tell you which of your processes already make automated decisions about people, what your client contracts actually say about third-party processing, or where your team is already using tools you have not approved.
That mapping is the work. The document is the write-up of the work.
If you would rather have that mapping done properly, with the tool inventory, the decision points and the gaps identified before the policy is drafted, that is the first half of an AI readiness audit. Our pricing page sets out what that costs, so you can decide whether it is worth it before you speak to anyone.
This article is general information about UK regulatory context and is not legal advice. Take your own advice before relying on any of it, particularly in a regulated sector.
Jon Goodey
Founder & CEO
Jon is the founder of Indexify, helping UK businesses leverage AI and data-driven strategies for marketing success. With expertise in SEO, digital PR, and AI automation, he's passionate about sharing insights that drive real results.
Related Resources
Continue Reading
- More Articles - Latest marketing insights
- Learning Hub - Free educational tracks
- Case Studies - Real client results
Our Services
- Digital PR - Earn quality backlinks
- Technical SEO - Site optimisation
- Marketing Analytics - Data-driven insights
- SEO Training - Private courses
Ready to Put These Insights Into Action?
Explore our services or get in touch to discuss your marketing goals.