CONTACT

Do You Need an AI Acceptable Use Policy?

ai acceptable use policy

Your staff are already using AI. Not in a pilot, not after a business case, but today, in whatever tool they opened in a browser. The question is no longer whether to allow it. It is whether anyone has written down what is and is not acceptable.

An AI acceptable use policy is the document that tells staff which AI tools they may use, what they may put into them, and what has to be checked before the output is used. Most UK businesses need one, and the reason is practical rather than legal: without it, nobody can say whether a given use was allowed.

A policy nobody has read is only slightly better than no policy. A policy that bans everything is worse, because it pushes the use you were worried about somewhere you cannot see it.

What Is an AI Acceptable Use Policy?

A short internal document setting the boundaries for AI at work. It names the approved tools, states what data may and may not go into them, and explains who checks the output before it is relied on. It sits alongside your existing acceptable use policy rather than replacing it.

It is not an AI strategy and it is not a technical control. It is the written answer to a question your staff are currently guessing at, which is why the shortest useful version beats the longest thorough one.

Do UK Businesses Actually Need One?

Most do, and the trigger is usually not regulation. It is that AI use has already started without anyone deciding it should. Someone drafts client emails in a chatbot, someone else pastes a contract in to summarise it, and a third person builds a spreadsheet macro from generated code nobody reviewed.

That pattern has a name. We covered it in our post on shadow AI, and an AI acceptable use policy is the cheapest thing that brings it back into view. Transputec sees the same across AI consulting work: the tools arrive long before the rules do.

Putting AI Into Production?

Transputec builds AI with ISO 27001 applied from sprint zero rather than as a tick-box at the end, and every system ships with audit-grade decision logs, prompt-injection defences and data-handling controls, reviewed by an in-house security team before any production deployment. Those are the controls a policy has to name once a tool stops being an experiment. Talk to our team about the security work behind your AI rollout.

Get a Strategic Consultation

What Should an AI Acceptable Use Policy Include?

Six sections, and it can genuinely fit on two pages. The temptation is to write something exhaustive that covers every future scenario. Resist it. A policy staff can read in five minutes and recall in a meeting will prevent more incidents than one that reads like a contract.

SectionWhat it has to answer
Approved toolsWhich AI tools are allowed, and how someone asks for a new one to be added
What you may enterThe data that must never be pasted in: personal data, client confidential material, credentials, anything under NDA
Checking the outputWho is responsible for verifying AI output before it reaches a client, a decision or the public
DisclosureWhen AI involvement has to be declared, internally and to clients
Accounts and accessWhether personal accounts are allowed, and what happens when someone leaves
What to do when it goes wrongHow to report a mistake without anyone being punished for owning up

That last row does more work than it looks. People conceal AI mistakes because admitting one implies they were not doing the job themselves. A policy that makes reporting safe finds problems while they are still small.

What Does the Law Actually Require?

Less about AI specifically than most people expect, and more about the personal data going through it. The ICO’s guidance on AI and data protection applies existing UK GDPR duties to AI rather than creating a separate regime, and it covers the whole lifecycle from problem formulation to decommissioning.

Four obligations shape what your policy has to say. You need a lawful basis for processing personal data through an AI tool. You may need a Data Protection Impact Assessment before you start. Transparency applies, so people should be able to understand how a decision involving them was reached. And where a decision is made solely by automated means with a significant effect, Article 22 safeguards including human review come into play.

The practical translation is short. If personal data goes into a tool, someone has to have thought about it first. An AI acceptable use policy is where you record that thinking so it can be shown to an auditor, a client or the ICO.

How Do You Stop Staff Pasting Company Data into ChatGPT?

By making the approved route easier than the unapproved one. Enforcement alone fails here. If the sanctioned tool is slower, harder to reach or worse at the job, people will use the other one on their phone and you will never know it happened.

Three things work together, and the policy is only the first.

  • Say precisely what cannot go in. Vague warnings about confidentiality get ignored. A named list of data types does not.
  • Provide a tool that does the job. A business account with data protection terms removes most of the temptation, because the answer to “can I use AI for this” becomes yes rather than no.
  • Back it with a technical control. Data loss prevention and browser controls catch what policy alone cannot. Our guide to protecting confidential data in ChatGPT covers the specifics.

The order matters. Controls without an AI acceptable use policy feel arbitrary, and a policy without controls relies entirely on everyone reading it.

What Happens If You Do Not Have One?

Nothing, for a while. That is the problem. The absence of an AI acceptable use policy is invisible right up to the moment it is not, and the moment tends to arrive as a client question, an audit finding or a piece of work that turns out to be wrong in a way nobody caught.

  • You cannot answer the tender question. Client security questionnaires now ask how you govern AI use. No policy means no answer.
  • You cannot tell whether an incident was a breach. If nobody defined what was allowed, you cannot say whether a rule was broken.
  • Output goes out unchecked. Without a named reviewer, everyone assumes someone else looked at it.
  • Good use gets discouraged too. Cautious staff avoid AI entirely while confident staff use whatever they like, which is the worst of both.

None of that requires a dramatic failure. It is the slow accumulation of decisions nobody recorded.

How Do You Write One That People Follow?

Keep it short, name a person, and review it on a date you have already put in the diary. Policies fail for predictable reasons: they are too long to read, nobody owns them, and they describe a set of tools that changed six months ago.

A workable approach is to draft the two-page version first, circulate it to the people who actually use AI daily, and fix the parts they say are unworkable before publishing. A policy written without them will be wrong about how the work is really done, and they will know it. Transputec drafts these with clients rather than for them, for exactly that reason.

On the security side, the NCSC’s guidelines for secure AI system development are the right reference if you are building with AI rather than only using it. That is a different exercise from an acceptable use policy, and it is worth being clear internally about which one you are doing.

Your AI Acceptable Use Policy Checklist

Work through these before you publish anything.

  • List the tools already in use, including the ones nobody has approved. You cannot write rules for an estate you have not surveyed.
  • Name the data that must never be entered, in plain terms rather than by reference to another document.
  • Name one owner for the policy, with the authority to approve a new tool.
  • Decide the review date now, and treat six months as the maximum.
  • Give people an approved tool that is good enough to use, or the policy is a ban in disguise.
  • Write the reporting route, and make clear that owning up early carries no penalty.

If personal data is involved anywhere in that list, the security and compliance side needs to be part of the conversation rather than a later review.

Conclusion

An AI acceptable use policy is not a compliance exercise for its own sake. It is the document that lets a business say, honestly, that it knows how AI is being used inside it. Without one you are relying on the judgement of every individual, applied to tools that change monthly.

The version that works is short, names an owner, lists the tools, states the data that must never go in, and makes it safe to report a mistake. Where the tools on that list are ones Transputec builds or runs as part of AI consulting work, the decision logs, data-handling controls and pre-deployment security review behind them are what the policy should point at. Talk to us about the security work behind your AI rollout.

FAQs

Six things: the approved tools and how to request a new one, the data that must never be entered, who checks output before it is relied on, when AI involvement must be disclosed, rules on personal accounts and leavers, and a route for reporting mistakes without penalty. Two pages is enough.

There is no UK law requiring an AI policy specifically. But if personal data goes through an AI tool, UK GDPR duties apply, and the ICO expects a lawful basis, possibly a DPIA, transparency, and human review for significant automated decisions. The policy is where you record that thinking.

Name the data types that cannot go in, provide a business account that does the job properly, and back both with data loss prevention and browser controls. Enforcement alone pushes the behaviour onto personal devices where you cannot see it at all.

No, though it sits alongside one. A general acceptable use policy covers company systems and internet use. An AI use policy deals with what may be entered into AI tools, who verifies the output, and when its use must be declared. Most businesses add a section rather than write a separate document.

Every six months at most, and sooner if your tooling changes. The AI market moves faster than most policy cycles, so a document written a year ago will list tools nobody uses and miss the ones everyone does. Transputec puts the review date in the diary at publication, because otherwise it does not happen.

This article was drafted with AI assistance and reviewed by the Transputec team. Featured image: AI-generated.

Ready to experience the Transputec difference?

Turn IT headaches into operational strength. Book a free consultation and see exactly what we can streamline inside your business. 

Get a Strategic Consultation

Sonny Sehgal

CEO & Co-Founder

Since co-founding Transputec, Sonny has guided hundreds of enterprises through every major shift in technology- from the birth of the PC to the rise of Global Cloud and now Generative AI. Known for his "straight-talking" approach to cyber security and IT strategy, he provides the bridge between complex technical infrastructure and boardroom-level business outcomes.

Share Blog »

← Blogs

Contact

Get in Touch