CIPD research in 2025 found that around a third of UK employers had a formal AI policy, while staff use of AI had already become routine. That gap is where the risk lives, and writing a longer policy is not what closes it.
In short: An AI use policy works when it is short enough to remember and specific enough to act on. Name the tools that are approved rather than describing categories, draw one clear line about what must never be entered into an unapproved tool, state that a human owns every AI assisted output, and give people a named route to ask about anything not covered. Put the detail in an appendix if you need it, but keep the operative part to a single page. A policy nobody can recall under time pressure is not a control.
Why most AI policies fail
They fail for the same three reasons, and none of them is that people are careless.
- They ban a category rather than naming a tool. "Do not use generative AI with company data" sounds firm and means nothing to someone deciding whether a summarise button inside a tool you already pay for is allowed.
- They are written to satisfy an auditor rather than to be followed. Eleven pages of definitions is a document people acknowledge once and never open again.
- They have no route to yes. If the only answer available is no, and the work still needs doing, the policy simply moves the activity out of sight. That is the pattern we describe in finding shadow AI in your business.
The five things a working policy says
Everything else is optional. These five are what change behaviour.
- These tools are approved, and this is what each is for. Actual product names. Where AI sits inside a tool people already use, say so, because otherwise they will assume it is banned and go elsewhere.
- This is the line about data. One sentence. Ours is: never put customer data, personal data, credentials or anything commercially unpublished into a tool the company has not approved. If someone can only remember one thing from the document, it should be this.
- A person owns every output. AI can draft, summarise and suggest. It does not sign, send or decide. The named human is accountable for accuracy, and that expectation needs to be explicit, because "the AI wrote it" will otherwise be offered as an explanation eventually.
- Say where AI must not be used at all. Usually anything determining an outcome for a person: hiring, discipline, credit, access. That is not just prudence, it is where UK law now has specific safeguards, which we cover in automated decisions and the ICO.
- Here is who to ask. A name and a channel. Add that requests get an answer within a couple of days, and then meet that.
"If the policy cannot be recalled from memory at the moment someone is about to paste, it is not doing any work."

Say what happens when someone gets it wrong
The most useful paragraph in an AI policy is often the one about mistakes. If pasting a customer list into the wrong tool is treated as a disciplinary matter, nobody will report it, and you will find out from the customer instead.
Say plainly that self reporting a mistake promptly will not be treated as misconduct, and that the priority is containment. You want the person who has just realised what they did to tell you within the hour, because at that point you can still revoke a session, review what was shared and decide whether anything needs reporting.
Keep it alive
An AI policy has a shorter shelf life than almost any other. Tools change, features appear inside products you already own, and the regulatory picture moves.
- Review it quarterly, not annually. Put it on the same cycle as your quarterly tenant health check so it happens without a separate meeting.
- Version it visibly. People need to see it has been touched recently, or they will assume it predates whatever they are holding.
- Update the approved list first. Most reviews only need that one section changed, which makes the review a ten minute job rather than a project.
A note on tone
Policies written in the language of prohibition get read as distrust, and the people most likely to comply are the ones who were never the risk. The version that lands better says what the organisation is trying to protect and why, then gives clear boundaries inside that.
There is a commercial reason too. Clients have started asking whether their suppliers have an AI policy, and the answer increasingly appears in procurement questionnaires. Having one that is short, dated and genuinely followed is a better answer than a long one that was written once. We cover what those questions look like in the AI questions your clients are about to start asking.
If you want a hand drafting something that fits how your teams actually work, that sits inside our AI advisory and enablement work, and our compliance packs service covers the wider policy set it needs to sit alongside.



