Skip to main content
    NixInfinity-AI
    AI Policy

    GenAI Policy Template for UK Businesses: What Staff Can and Cannot Do

    Published 24 July 2026

    The two-page template

    1. Purpose

    This policy explains how staff at [Company] may and may not use generative AI tools to carry out their work. It applies to all employees, contractors and trustees.

    2. Approved tools

    • Microsoft 365 Copilot (Business or Enterprise licence)
    • ChatGPT Enterprise (org tenant only)
    • GitHub Copilot Business
    • Other tools listed at [internal link to register]

    Any tool not on the list must be approved by the AI owner before use. Public, consumer versions of AI tools may not be used for any work-related task.

    3. Permitted data

    Data classPublic AIEnterprise AI (Copilot etc.)
    Public informationAllowedAllowed
    Internal documentsNot allowedAllowed
    Personal dataNot allowedAllowed with DPIA
    Client confidentialNot allowedAllowed if contract permits
    Trade secrets / IPNot allowedAllowed with AI owner sign-off
    Regulated data (e.g. health, financial)Not allowedAllowed only via approved sector solution

    4. Output ownership and IP

    • Output generated using approved tools is the property of [Company]
    • Output must be reviewed for accuracy and bias before customer-facing use
    • Do not paste third-party copyrighted material as a prompt
    • Cite AI assistance where required by the client contract

    5. Fact-checking requirements

    • All numbers, dates, legal references and quotations must be independently verified
    • Customer-facing content must be reviewed by a named human reviewer before sending
    • Decisions about people (hiring, pricing, eligibility) must have human sign-off

    6. Prompt examples

    Acceptable: "Summarise the attached internal report into 5 bullets for the board pack." (Enterprise Copilot, internal docs)

    Not acceptable: "Here is our client's draft contract. Suggest improvements." (Public ChatGPT, client confidential)

    7. Escalation

    Report suspected misuse, data leakage or a tool malfunction to [AI owner] within 24 hours. Material incidents may need to be reported to the ICO and, under the CSR Bill, to the designated regulator within 24/72 hours.

    8. Consequences

    Breach of this policy may result in disciplinary action up to and including dismissal, contract termination for contractors, and personal liability where IP or personal data obligations are breached.

    Embedding the policy

    • Include in the staff handbook and contractor onboarding
    • Review annually and after any material vendor or regulatory change
    • Pair with the AI governance framework and the AI tool register
    • Train staff with concrete examples, not abstract principles

    Adapting the template for your sector

    Healthcare, financial services, legal and education each layer extra controls (e.g. regulator-specific guidance from FCA, SRA, MHRA). The template above is the floor, not the ceiling – adapt the permitted-data table to your regulator's wording.

    Need a hand getting certified?

    Speak to an IASME-licensed assessor. Pre-check, plain-English support, certificates issued £320 + VAT.

    Frequently Asked Questions