An AI policy for employees is a short written document that names the AI tools staff may use and on which accounts, lists the data they must never paste into them, says who checks AI-assisted work before it reaches a client, and gives people a route to request a new tool. You can build one in five minutes with our free AI policy generator. Then comes the part a policy can't do: getting anyone to actually use the tools.

The Tuesday your policy was written for

Somewhere in your company last Tuesday, someone in finance pasted the quarterly forecast into a free ChatGPT account. The board deck was due at four. A formula wouldn't behave. ChatGPT fixed it in twelve seconds. Nobody told IT, because nobody thought of it as a security event. It was just Tuesday.

That's the scene every AI policy is written for, and the numbers say it's the norm. Microsoft and LinkedIn's 2024 Work Trend Index surveyed 31,000 people in 31 countries: 75% of knowledge workers already used generative AI at work, and 78% of them brought their own tools rather than waiting for the company to provide one. Cyberhaven, which watches this from the data side, found that 73.8% of ChatGPT use at work ran through non-corporate accounts, and that 27.4% of the data employees put into AI tools was sensitive, up from 10.7% a year earlier.

The paperwork lags behind. ISACA's 2026 AI Pulse Poll of 3,400 digital trust professionals found 38% of organisations with a formal, comprehensive AI policy, up from 28% the year before. The trend is right. It still means most companies are running the finance scene above with nothing written down.

Does your company need an AI policy?

No UK law says "you must have an AI policy". Several laws make its absence expensive.

  • UK GDPR. Personal data your staff paste into a consumer AI tool is a disclosure you're accountable for. If it goes wrong, the 72-hour route to the ICO applies whether or not anyone knew the tool existed.
  • Confidentiality and contracts. Client confidentiality doesn't pause because a tool was convenient, and a growing number of client contracts restrict AI use outright.
  • Employment and equality law. A decision about a person stays your decision, however it was drafted.
  • The EU AI Act, if it reaches you. Article 4 has required deployers to take measures on staff AI literacy since 2 February 2025, with national supervision from 3 August 2026. A UK company with EU customers, staff or operations may be in scope. A UK-only company usually isn't. Here's how Article 4 plays out by department, and what the July 2026 Digital Omnibus changed.

The cautionary tale is still Samsung. In April 2023, engineers pasted proprietary source code and a transcribed internal meeting into ChatGPT on three occasions in twenty days. By May, Samsung had banned generative AI on company devices. A ban is a policy too. It's the most expensive one, because it also bans the upside.

What should an AI policy include?

Twelve sections, and most of them fit on one page. This is the outline our generator produces, with the question each section is there to settle and the place generic templates fall down.

SectionThe question it settlesWhere a generic template fails
1. Purpose and scopeWho this applies to, contractors includedTalks about "AI systems" in the abstract
2. Approved AI toolsWhich tools, by name, on which account tierNever names ChatGPT, Copilot, Gemini or Claude
3. Personal accountsWhether a personal ChatGPT login is allowed for workSilent, so everyone assumes yes
4. Prohibited dataWhat must never go in: customer data, employee data, special category data, unpublished financials, source code and credentialsSays "confidential information" and stops
5. Accuracy and human reviewWho checks AI-assisted work before it leaves the buildingOne line, no named reviewer
6. Client-facing work and disclosureWhether clients are told, proactively or on requestMissing
7. Intellectual propertyWho owns AI-generated work and what may go into itMissing
8. Requesting a new toolHow someone asks instead of signing up quietlyMissing, which is how shadow AI starts
9. Training and AI literacyWhat the company promises its people, and by whenA vague line with no date
10. Sector obligationsFCA, SRA, CQC, DfE or Charity Commission expectations where relevantAbsent
11. Incidents and reportingWho to tell, when, and the ICO 72-hour route"Report to your manager"
12. Ownership and reviewNamed owner, review date, acknowledgementNo owner, so it rots

Three of these do most of the work.

The account tier clause

This is the single most differentiating line in the document. Business and enterprise tiers of ChatGPT, Copilot, Gemini and Claude generally exclude your content from model training by default and give an administrator control over retention. Free consumer tiers often don't, unless someone finds the setting. A policy that approves "ChatGPT" without saying which ChatGPT has approved the leak. If you don't know which tiers are in use, the policy should say so and require an inventory within 30 days. The retention defaults per vendor are here.

The approval route

Shadow AI is what happens when the only answer to "can I use this?" is a shrug. One paragraph fixes it: the name of the person who approves, what they check, how long it takes. That converts a hidden habit into a visible request. More on why the shrug costs more than the tool.

The human review clause

Someone with a name reads AI-assisted work before it goes to a client. The weight of the clause should match the exposure. A firm that sends AI-drafted proposals every week needs a named reviewer. A firm that uses AI for internal notes needs an accuracy reminder. Answering "regularly", "occasionally" or "internal only" changes the wording, which is exactly what a template can't do.

How to write it in five minutes

Build your AI policy with the free generator. Fifteen questions, five minutes, one editable Word document with your organisation on the title page. UK GDPR and ICO framing throughout, your tools named, and the EU AI Act Article 4 clause included only when you have an EU nexus. Your answers never leave your browser: the document is built on your device and we never see them. Start the questions.

A few notes on using it well.

  • Answer for the company you have. If people already use personal accounts, say so. The generator writes a clause that manages the situation instead of one that pretends it doesn't exist.
  • Read it out loud to a manager. The policy is written in the second person ("You may... You must not...") so a team lead can read it in a stand-up. If a sentence makes them stumble, edit it. It's a Word file for a reason.
  • Get it checked. The generator gives you general information, not legal advice. Your DPO, compliance lead or counsel signs it off.
  • Set the review date. Six or twelve months, and the document computes it. AI vendors change their terms faster than that.

That gets you a policy by Thursday. Now the harder part.

A policy is a list of don'ts. Adoption runs on the do's

Read your new policy again and count the verbs. Must not. Never. Only with approval. That's correct, it's what a policy is for. It answers "what could get me fired". It says nothing about "what should I do with this on Monday morning".

The Monday question is the one your team is actually asking. Here's what the data says happens when only the first question gets answered.

People break the rule anyway. KPMG and the University of Melbourne surveyed 48,000 people in 47 countries: 48% of employees admitted using AI in ways that contravene company policy, including uploading company data to public tools. The policy existed. The work still needed doing.

They hide it. In the same study, 57% said they had concealed their AI use and presented AI-generated work as their own. Microsoft found 52% of AI users reluctant to admit using it for their most important tasks. A policy that only says no teaches people to go quiet, and quiet is where the Samsung incidents live.

Nobody showed them how. Only 47% of employees in the KPMG study had received any AI training. Microsoft's figure was 39%. So the average company has told its people what never to do and skipped the part where anyone showed them what to do.

The licence goes unused. The CBI's August 2026 Adoption Decade report found 49% of AI deployment leaders meeting their expected ROI against 15% of laggards, on the same tools. The gap is behaviour. I wrote about why it's a people problem. The short version: the tool was never the problem. Nobody taught them to drive.

"A policy is a seatbelt. I've never met anyone who learned to drive from one. Most companies I walk into have the seatbelt and a car park full of people who've never left second gear." Toni Dos Santos, co-founder of We Call Shotgun and author of Teach Them to Drive

There's a structural reason the policy can't do this. It's written by the people furthest from the work: legal, IT, compliance. They can tell a credit controller what never to paste. They can't tell her what to do with the forty invoice disputes in her inbox, because they've never seen her inbox. The do's are workflow-specific. They have to be written with the people doing the work, in the tools they've been given, on the tasks that eat their week.

What the do's look like

Here's what sits next to the policy in the companies where the licences get used. Same twelve-section document, plus:

  • A narrative from the top. One page from the CEO on why the company is doing this and what it means for people's jobs. Without it, the policy gets read as the first step towards headcount cuts, and people behave accordingly.
  • A green list per team. The five tasks each team is expected to do with AI, by name. Finance: first draft of the variance commentary. Sales: call notes into the CRM. HR: handbook questions answered from the handbook. Permission spelled out beats a general blessing.
  • The tool for the task. Copilot inside Excel for one team, Claude for the team that lives in long documents, a notetaker for the one that lives in meetings. The policy says which tools are allowed. The do's say which one to reach for.
  • A review rule per output. Internal draft: self-check. Client-facing: named reviewer. Anything about a person: a human decides.
  • A baseline and a measure. How long the task took before, how long it takes after twelve weeks. Cycle time, error rate, hours back. Adoption that isn't measured is a feeling.
  • Everyone shown how, on their own work. Their inbox, their spreadsheet, their Tuesday, with someone in the passenger seat.

Where We Call Shotgun comes in

The generator gives you the don'ts for free. We do the do's.

Our work is a 90-day adoption pilot, run with your teams on the licences you already pay for. It starts with the narrative and the strategy: what leadership actually wants AI to change, said in words a team can repeat. Then the permissions, team by team: the green list, the tools that fit each task, the review rules. Then everyone gets shown how on their own work, in their own tools, with a baseline measured before and cycle time measured after. It's the method in Teach Them to Drive, applied to your Tuesday. Tool-agnostic across ChatGPT Enterprise, Microsoft Copilot, Google Gemini and Claude, delivered in English, French and Portuguese, on site or remote.

If you've just generated your policy, bring it. In a free 20-minute call we'll read it with you and tell you which do's are missing for your teams. Book the review. If you'd rather see where you stand first, the free AI adoption scorecard takes eight minutes, and the enterprise adoption hub lays out how a pilot runs.

Frequently asked questions

Does a UK company legally need an AI policy?

No UK law requires a standalone AI policy. UK GDPR still makes you accountable for personal data staff paste into consumer AI tools, confidentiality duties to clients still apply, and employment and equality law still governs AI-assisted decisions about people. A short written policy covering approved tools, prohibited data, human review and an approval route is the cheapest control most organisations can put in place.

What should an AI policy for employees include?

At minimum: which AI tools are approved and on which account tiers; what data must never be entered into them; who reviews AI-assisted work before it leaves the organisation; whether AI use is disclosed to clients; how someone requests a new tool; what to do when something goes wrong, including the UK GDPR 72-hour breach route to the ICO; and who owns the policy and when it's reviewed. Intellectual property and training clauses are worth adding.

Is there a free AI policy template?

Yes. The We Call Shotgun AI policy generator asks 15 questions and produces a tailored AI acceptable use policy as an editable Word document, free and without an account. It names the tools your staff actually use and the account tiers they're on, which a static template can't do. The document is generated in your browser and your answers are never stored.

Can employees use ChatGPT at work?

Yes, subject to the same duties as any other tool: data protection, confidentiality, contractual terms and accuracy. The person sending AI-assisted work remains responsible for it. Account tier matters most: business and enterprise tiers generally exclude your content from model training, while free consumer tiers often don't by default.

Does the EU AI Act apply to a UK company's AI policy?

Sometimes. The Act reaches providers and deployers outside the EU where an AI system is used in the Union or its output is used there. A UK company with EU customers, staff or operations may be in scope of Article 4 on AI literacy, which has applied since 2 February 2025 with national supervision from 3 August 2026. A UK-only company usually isn't. The generator asks and includes the clause only when your answer supports it.

How often should an AI policy be reviewed?

Every six to twelve months, by a named owner. AI vendors change their terms, tiers and retention defaults faster than most internal documents get read, so a policy without a review date quietly goes out of date. The generator sets the next review date for you.

What is the difference between an AI policy and AI adoption?

A policy states what must never happen. Adoption is what should happen: the tasks each team does with AI, the tool for each task, the review rule for each output, and a measured change in how long the work takes. KPMG's 2025 study found 48% of employees breaking AI policy anyway, so the policy on its own governs very little. The do's, the permissions and people shown how on their own work are what change behaviour.

The don'ts are free. Let's do the do's

We're We Call Shotgun, a founder-led AI adoption practice working across the UK and France. We take the passenger seat: narrative, strategy, permissions, the right tool for each task, and everyone shown how on their own work, measured over 90 days. Tool-agnostic across ChatGPT Enterprise, Microsoft Copilot, Google Gemini and Claude. 1,500+ professionals, 50+ companies, 4.98/5 average rating.

Build your AI policy (free) Review your policy with us

Sources and further reading