# How to Write an AI Policy for Employees (+ Free Generator) | We Call Shotgun

> What an AI policy for employees must include (approved tools, account tiers, prohibited data, human review, an approval route), a free generator that builds one in 5 minutes, and why 48% of staff break the policy anyway.

Source: https://wecallshotgun.com/blog/how-to-write-an-ai-policy-for-employees
Language: en

---

AI Tools

# How to Write an AI Policy for Employees: What to Include, a Free Generator, and Why the Policy Alone Changes Nothing

By [Toni Dos Santos](https://wecallshotgun.com/about)
•
Sep 2, 2026
•
14 min read

SummaryAn AI policy for employees names the approved tools and account tiers, lists prohibited data, sets a human review rule, gives people a route to request a new tool and names an owner. Our free generator produces one as an editable Word document in five minutes, with UK GDPR framing and the EU AI Act clause only where it applies. The policy is a list of don'ts. KPMG found 48% of employees break it anyway and 57% hide their AI use, because nobody wrote the do's: the tasks per team, the tool for each, the review rule and a measured baseline. That's the adoption work, and it's where we come in.

An AI policy for employees is a short written document that names the AI tools staff may use and on which accounts, lists the data they must never paste into them, says who checks AI-assisted work before it reaches a client, and gives people a route to request a new tool. You can build one in five minutes with our [free AI policy generator](https://wecallshotgun.com/ai-policy-generator). Then comes the part a policy can't do: getting anyone to actually use the tools.

## The Tuesday your policy was written for

Somewhere in your company last Tuesday, someone in finance pasted the quarterly forecast into a free ChatGPT account. The board deck was due at four. A formula wouldn't behave. ChatGPT fixed it in twelve seconds. Nobody told IT, because nobody thought of it as a security event. It was just Tuesday.

That's the scene every AI policy is written for, and the numbers say it's the norm. Microsoft and LinkedIn's [2024 Work Trend Index](https://www.microsoft.com/en-us/worklab/work-trend-index/ai-at-work-is-here-now-comes-the-hard-part) surveyed 31,000 people in 31 countries: 75% of knowledge workers already used generative AI at work, and 78% of them brought their own tools rather than waiting for the company to provide one. Cyberhaven, which watches this from the data side, [found](https://www.cyberhaven.com/blog/shadow-ai-how-employees-are-leading-the-charge-in-ai-adoption-and-putting-company-data-at-risk) that 73.8% of ChatGPT use at work ran through non-corporate accounts, and that 27.4% of the data employees put into AI tools was sensitive, up from 10.7% a year earlier.

The paperwork lags behind. ISACA's [2026 AI Pulse Poll](https://www.isaca.org/about-us/newsroom/press-releases/2026/ai-use-accelerates-while-governance-and-roi-lag-says-new-isaca-research) of 3,400 digital trust professionals found 38% of organisations with a formal, comprehensive AI policy, up from 28% the year before. The trend is right. It still means most companies are running the finance scene above with nothing written down.

## Does your company need an AI policy?

No UK law says "you must have an AI policy". Several laws make its absence expensive.

- **UK GDPR.** Personal data your staff paste into a consumer AI tool is a disclosure you're accountable for. If it goes wrong, the [72-hour route to the ICO](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/personal-data-breaches/) applies whether or not anyone knew the tool existed.

- **Confidentiality and contracts.** Client confidentiality doesn't pause because a tool was convenient, and a growing number of client contracts restrict AI use outright.

- **Employment and equality law.** A decision about a person stays your decision, however it was drafted.

- **The EU AI Act, if it reaches you.** Article 4 has required deployers to take measures on staff AI literacy since 2 February 2025, with national supervision from 3 August 2026. A UK company with EU customers, staff or operations may be in scope. A UK-only company usually isn't. [Here's how Article 4 plays out by department](https://wecallshotgun.com/blog/eu-ai-act-ai-literacy-article-4-risks-action-plan), and [what the July 2026 Digital Omnibus changed](https://wecallshotgun.com/blog/digital-omnibus-ai-act-2026-what-changed).

The cautionary tale is still Samsung. In April 2023, engineers pasted proprietary source code and a transcribed internal meeting into ChatGPT on three occasions in twenty days. By May, [Samsung had banned generative AI on company devices](https://www.bloomberg.com/news/articles/2023-05-02/samsung-bans-chatgpt-and-other-generative-ai-use-by-staff-after-leak). A ban is a policy too. It's the most expensive one, because it also bans the upside.

## What should an AI policy include?

Twelve sections, and most of them fit on one page. This is the outline our generator produces, with the question each section is there to settle and the place generic templates fall down.

| Section | The question it settles | Where a generic template fails |

| **1. Purpose and scope** | Who this applies to, contractors included | Talks about "AI systems" in the abstract |

| **2. Approved AI tools** | Which tools, by name, on which account tier | Never names ChatGPT, Copilot, Gemini or Claude |

| **3. Personal accounts** | Whether a personal ChatGPT login is allowed for work | Silent, so everyone assumes yes |

| **4. Prohibited data** | What must never go in: customer data, employee data, special category data, unpublished financials, source code and credentials | Says "confidential information" and stops |

| **5. Accuracy and human review** | Who checks AI-assisted work before it leaves the building | One line, no named reviewer |

| **6. Client-facing work and disclosure** | Whether clients are told, proactively or on request | Missing |

| **7. Intellectual property** | Who owns AI-generated work and what may go into it | Missing |

| **8. Requesting a new tool** | How someone asks instead of signing up quietly | Missing, which is how shadow AI starts |

| **9. Training and AI literacy** | What the company promises its people, and by when | A vague line with no date |

| **10. Sector obligations** | FCA, SRA, CQC, DfE or Charity Commission expectations where relevant | Absent |

| **11. Incidents and reporting** | Who to tell, when, and the ICO 72-hour route | "Report to your manager" |

| **12. Ownership and review** | Named owner, review date, acknowledgement | No owner, so it rots |

Three of these do most of the work.

### The account tier clause

This is the single most differentiating line in the document. Business and enterprise tiers of ChatGPT, Copilot, Gemini and Claude generally exclude your content from model training by default and give an administrator control over retention. Free consumer tiers often don't, unless someone finds the setting. A policy that approves "ChatGPT" without saying which ChatGPT has approved the leak. If you don't know which tiers are in use, the policy should say so and require an inventory within 30 days. [The retention defaults per vendor are here](https://wecallshotgun.com/blog/zero-data-retention-ai-models-comparison).

### The approval route

Shadow AI is what happens when the only answer to "can I use this?" is a shrug. One paragraph fixes it: the name of the person who approves, what they check, how long it takes. That converts a hidden habit into a visible request. [More on why the shrug costs more than the tool](https://wecallshotgun.com/blog/shadow-ai-enterprise-governance-risk).

### The human review clause

Someone with a name reads AI-assisted work before it goes to a client. The weight of the clause should match the exposure. A firm that sends AI-drafted proposals every week needs a named reviewer. A firm that uses AI for internal notes needs an accuracy reminder. Answering "regularly", "occasionally" or "internal only" changes the wording, which is exactly what a template can't do.

## How to write it in five minutes

**Build your AI policy with the free generator.** Fifteen questions, five minutes, one editable Word document with your organisation on the title page. UK GDPR and ICO framing throughout, your tools named, and the EU AI Act Article 4 clause included only when you have an EU nexus. Your answers never leave your browser: the document is built on your device and we never see them. [Start the questions](https://wecallshotgun.com/ai-policy-generator).

A few notes on using it well.

- **Answer for the company you have.** If people already use personal accounts, say so. The generator writes a clause that manages the situation instead of one that pretends it doesn't exist.

- **Read it out loud to a manager.** The policy is written in the second person ("You may... You must not...") so a team lead can read it in a stand-up. If a sentence makes them stumble, edit it. It's a Word file for a reason.

- **Get it checked.** The generator gives you general information, not legal advice. Your DPO, compliance lead or counsel signs it off.

- **Set the review date.** Six or twelve months, and the document computes it. AI vendors change their terms faster than that.

That gets you a policy by Thursday. Now the harder part.

## A policy is a list of don'ts. Adoption runs on the do's

Read your new policy again and count the verbs. Must not. Never. Only with approval. That's correct, it's what a policy is for. It answers "what could get me fired". It says nothing about "what should I do with this on Monday morning".

The Monday question is the one your team is actually asking. Here's what the data says happens when only the first question gets answered.

**People break the rule anyway.** KPMG and the University of Melbourne [surveyed 48,000 people in 47 countries](https://kpmg.com/xx/en/our-insights/ai-and-technology/trust-attitudes-and-use-of-ai.html): 48% of employees admitted using AI in ways that contravene company policy, including uploading company data to public tools. The policy existed. The work still needed doing.

**They hide it.** In the same study, 57% said they had concealed their AI use and presented AI-generated work as their own. Microsoft found 52% of AI users reluctant to admit using it for their most important tasks. A policy that only says no teaches people to go quiet, and quiet is where the Samsung incidents live.

**Nobody showed them how.** Only 47% of employees in the KPMG study had received any AI training. Microsoft's figure was 39%. So the average company has told its people what never to do and skipped the part where anyone showed them what to do.

**The licence goes unused.** The CBI's August 2026 Adoption Decade report found 49% of AI deployment leaders meeting their expected ROI against 15% of laggards, on the same tools. The gap is behaviour. [I wrote about why it's a people problem](https://wecallshotgun.com/blog/cbi-adoption-decade-ai-execution-divide). The short version: the tool was never the problem. Nobody taught them to drive.

> "A policy is a seatbelt. I've never met anyone who learned to drive from one. Most companies I walk into have the seatbelt and a car park full of people who've never left second gear." Toni Dos Santos, co-founder of We Call Shotgun and author of Teach Them to Drive

There's a structural reason the policy can't do this. It's written by the people furthest from the work: legal, IT, compliance. They can tell a credit controller what never to paste. They can't tell her what to do with the forty invoice disputes in her inbox, because they've never seen her inbox. The do's are workflow-specific. They have to be written with the people doing the work, in the tools they've been given, on the tasks that eat their week.

## What the do's look like

Here's what sits next to the policy in the companies where the licences get used. Same twelve-section document, plus:

- **A narrative from the top.** One page from the CEO on why the company is doing this and what it means for people's jobs. Without it, the policy gets read as the first step towards headcount cuts, and people behave accordingly.

- **A green list per team.** The five tasks each team is expected to do with AI, by name. Finance: first draft of the variance commentary. Sales: call notes into the CRM. HR: handbook questions answered from the handbook. Permission spelled out beats a general blessing.

- **The tool for the task.** Copilot inside Excel for one team, Claude for the team that lives in long documents, a notetaker for the one that lives in meetings. The policy says which tools are allowed. The do's say which one to reach for.

- **A review rule per output.** Internal draft: self-check. Client-facing: named reviewer. Anything about a person: a human decides.

- **A baseline and a measure.** How long the task took before, how long it takes after twelve weeks. Cycle time, error rate, hours back. Adoption that isn't measured is a feeling.

- **Everyone shown how, on their own work.** Their inbox, their spreadsheet, their Tuesday, with someone in the passenger seat.

## Where We Call Shotgun comes in

The generator gives you the don'ts for free. We do the do's.

Our work is a 90-day adoption pilot, run with your teams on the licences you already pay for. It starts with the narrative and [the strategy](https://wecallshotgun.com/ai-strategy-consulting): what leadership actually wants AI to change, said in words a team can repeat. Then the permissions, team by team: the green list, the tools that fit each task, the review rules. Then everyone gets shown how on their own work, in their own tools, with a baseline measured before and cycle time measured after. It's the method in [Teach Them to Drive](https://wecallshotgun.com/teachthem), applied to your Tuesday. Tool-agnostic across ChatGPT Enterprise, Microsoft Copilot, Google Gemini and Claude, delivered in English, French and Portuguese, on site or remote.

If you've just generated your policy, bring it. In a free 20-minute call we'll read it with you and tell you which do's are missing for your teams. [Book the review](https://cal.com/wecallshotgun/ai-adoption). If you'd rather see where you stand first, [the free AI adoption scorecard](https://wecallshotgun.com/audit) takes eight minutes, and [the enterprise adoption hub](https://wecallshotgun.com/enterprise) lays out how a pilot runs.

## Frequently asked questions

### Does a UK company legally need an AI policy?

No UK law requires a standalone AI policy. UK GDPR still makes you accountable for personal data staff paste into consumer AI tools, confidentiality duties to clients still apply, and employment and equality law still governs AI-assisted decisions about people. A short written policy covering approved tools, prohibited data, human review and an approval route is the cheapest control most organisations can put in place.

### What should an AI policy for employees include?

At minimum: which AI tools are approved and on which account tiers; what data must never be entered into them; who reviews AI-assisted work before it leaves the organisation; whether AI use is disclosed to clients; how someone requests a new tool; what to do when something goes wrong, including the UK GDPR 72-hour breach route to the ICO; and who owns the policy and when it's reviewed. Intellectual property and training clauses are worth adding.

### Is there a free AI policy template?

Yes. The We Call Shotgun AI policy generator asks 15 questions and produces a tailored AI acceptable use policy as an editable Word document, free and without an account. It names the tools your staff actually use and the account tiers they're on, which a static template can't do. The document is generated in your browser and your answers are never stored.

### Can employees use ChatGPT at work?

Yes, subject to the same duties as any other tool: data protection, confidentiality, contractual terms and accuracy. The person sending AI-assisted work remains responsible for it. Account tier matters most: business and enterprise tiers generally exclude your content from model training, while free consumer tiers often don't by default.

### Does the EU AI Act apply to a UK company's AI policy?

Sometimes. The Act reaches providers and deployers outside the EU where an AI system is used in the Union or its output is used there. A UK company with EU customers, staff or operations may be in scope of Article 4 on AI literacy, which has applied since 2 February 2025 with national supervision from 3 August 2026. A UK-only company usually isn't. The generator asks and includes the clause only when your answer supports it.

### How often should an AI policy be reviewed?

Every six to twelve months, by a named owner. AI vendors change their terms, tiers and retention defaults faster than most internal documents get read, so a policy without a review date quietly goes out of date. The generator sets the next review date for you.

### What is the difference between an AI policy and AI adoption?

A policy states what must never happen. Adoption is what should happen: the tasks each team does with AI, the tool for each task, the review rule for each output, and a measured change in how long the work takes. KPMG's 2025 study found 48% of employees breaking AI policy anyway, so the policy on its own governs very little. The do's, the permissions and people shown how on their own work are what change behaviour.

## The don'ts are free. Let's do the do's

We're We Call Shotgun, a founder-led AI adoption practice working across the UK and France. We take the passenger seat: narrative, strategy, permissions, the right tool for each task, and everyone shown how on their own work, measured over 90 days. Tool-agnostic across ChatGPT Enterprise, Microsoft Copilot, Google Gemini and Claude. 1,500+ professionals, 50+ companies, 4.98/5 average rating.

[Build your AI policy (free)](https://wecallshotgun.com/ai-policy-generator) [Review your policy with us](https://cal.com/wecallshotgun/ai-adoption)

## Sources and further reading

- [Microsoft and LinkedIn, 2024 Work Trend Index: "AI at Work Is Here. Now Comes the Hard Part"](https://www.microsoft.com/en-us/worklab/work-trend-index/ai-at-work-is-here-now-comes-the-hard-part) (May 2024, 31,000 knowledge workers in 31 countries): the 75%, 78%, 52% and 39% figures

- [Cyberhaven Labs, AI Adoption and Risk Report, Q2 2024](https://www.cyberhaven.com/blog/shadow-ai-how-employees-are-leading-the-charge-in-ai-adoption-and-putting-company-data-at-risk): 73.8% of workplace ChatGPT use through non-corporate accounts, 27.4% of data entered into AI tools sensitive, up from 10.7%

- [KPMG and the University of Melbourne, "Trust, attitudes and use of artificial intelligence: A global study 2025"](https://kpmg.com/xx/en/our-insights/ai-and-technology/trust-attitudes-and-use-of-ai.html) (48,340 people, 47 countries, surveyed November 2024 to January 2025): the 48%, 57% and 47% figures

- [ISACA, 2026 AI Pulse Poll](https://www.isaca.org/about-us/newsroom/press-releases/2026/ai-use-accelerates-while-governance-and-roi-lag-says-new-isaca-research) (May 2026, 3,400 digital trust professionals): 38% with a formal, comprehensive AI policy, up from 28% in 2025

- [Bloomberg, "Samsung Bans ChatGPT, Google Bard, Other Generative AI Use by Staff After Leak"](https://www.bloomberg.com/news/articles/2023-05-02/samsung-bans-chatgpt-and-other-generative-ai-use-by-staff-after-leak), 2 May 2023

- [CBI and Oliver Wyman, "The Adoption Decade" (August 2026)](https://wecallshotgun.com/blog/cbi-adoption-decade-ai-execution-divide), via our analysis of the 49% versus 15% execution divide

- [Regulation (EU) 2024/1689, the EU AI Act](https://eur-lex.europa.eu/eli/reg/2024/1689/oj), Article 4 on AI literacy, as amended by the Digital Omnibus on AI

- [ICO, personal data breaches guidance](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/personal-data-breaches/): the 72-hour notification route under UK GDPR

## Keep Reading

[AI Tools Aug 29, 2026 ### Enterprise AI Agents in 2026: The Vendor-Neutral Benchmark for Companies The enterprise AI agent market has consolidated into four buying routes, and the honest benchmark is not the leaderboard, it is your own workflows. We compare OpenAI, Anthropic, Microsoft, Google, Salesforce and ServiceNow as of August 2026, price them, and cover the four risks and five limits that vendor demos skip. 16 min read Read →](https://wecallshotgun.com/blog/enterprise-ai-agents-benchmark-2026)

[AI Tools Aug 29, 2026 ### Zero data retention in AI models: what OpenAI, Claude, Gemini and Copilot actually offer Every major AI provider now offers some form of zero data retention, and not one of them turns it on by default. Anthropic's most capable models are excluded from it entirely. Here's what OpenAI, Claude, Gemini and Copilot each give you, what you give up in return, and the questions to put in your RFP. 17 min read Read →](https://wecallshotgun.com/blog/zero-data-retention-ai-models-comparison)

[AI Tools Aug 29, 2026 ### Vibe Coding vs Agentic Workflows: The 2026 Guide for UK Business Leaders Vibe coding asks "can we build this?"; agentic workflows ask "can we safely run, change and depend on this?". Same AI tools, different rules, and the dividing line is verification. With the AppDirect, Leatherman, Lucid and Thoughtworks cases, the 2026 security evidence, a 13-question decision framework and a role-by-role action list for UK SMB and mid-market leaders. 17 min read Read →](https://wecallshotgun.com/blog/vibe-coding-vs-agentic-workflows)

## Related AI Training Solutions

Programs tailored to your role, industry, or function.

[Financial Services](https://wecallshotgun.com/ai-training-financial-services)
[Healthcare](https://wecallshotgun.com/ai-training-healthcare)
[Legal Teams](https://wecallshotgun.com/ai-training-legal)
[Operations](https://wecallshotgun.com/ai-training-operations)
[Product Teams](https://wecallshotgun.com/ai-training-product)
[Marketing](https://wecallshotgun.com/ai-training-marketing)
[Sales Teams](https://wecallshotgun.com/ai-training-sales)
[Customer Support](https://wecallshotgun.com/ai-training-customer-support)
[HR Teams](https://wecallshotgun.com/ai-training-hr)
[Data & Analytics](https://wecallshotgun.com/ai-training-data-analytics)
[Executives](https://wecallshotgun.com/ai-training-executives)
[C-Level](https://wecallshotgun.com/ai-training-c-level)
[UK Hub](https://wecallshotgun.com/ai-training-uk)

## Need help with AI Adoption?

We take the passenger seat and lead your teams to adopt AI for real work.

[Book a Call](https://wecallshotgun.com/#contact)
