[ORGANISATION NAME]
Artificial Intelligence (AI) Use Policy
Effective date: [DATE]
Version: 1.0
Approved by: [APPROVER NAME / BOARD]
1. PURPOSE AND SCOPE
This policy sets out how [ORGANISATION NAME] uses artificial intelligence (AI) tools and services in a way that is lawful, ethical, transparent, and aligned with our obligations to clients, employees, regulators, and other stakeholders.
This policy applies to all employees, contractors, directors, and third parties who use, approve, procure, or manage AI tools on behalf of [ORGANISATION NAME]. It covers AI used in any work context, including free and paid tools, browser extensions, generative AI services, and any software that makes or influences decisions.
2. PRINCIPLES
AI use at [ORGANISATION NAME] should be:
•Transparent: AI use that affects people, clients, or decisions should be documented and capable of being explained.
•Accountable: AI use should have clearly defined ownership and accountability appropriate to its nature and risk.
•Lawful: AI use must comply with applicable data protection law, confidentiality obligations, consumer law, equality law, and sector-specific regulation.
•Human-led: Meaningful human oversight should be established where appropriate to the use case, its impact on individuals, and any applicable legal or contractual obligations.
•Risk-proportionate: Higher-risk uses warrant stronger controls, approval, and review.
•Secure: AI tools should not introduce unacceptable confidentiality, security, or supply-chain risks.
3. ROLES AND RESPONSIBILITIES
•Board / Senior Leadership: Sets risk appetite, approves high-risk AI use, and ensures governance is in place.
•AI Owner: A named individual responsible for each AI tool or use case. The AI Owner maintains an entry in the AI inventory, assesses risk, and ensures compliance.
•All Users: Use AI tools only for approved purposes, protect confidential information, and report incidents or concerns.
•Legal / Compliance / Data Protection: Advises on high-risk use, reviews contracts, and supports incident response.
•Procurement: Ensures AI tools are approved before purchase or trial and that vendor terms are reviewed.
4. APPROVED AI USE
AI tools may be used where:
•The tool is listed in the approved AI inventory.
•The AI Owner has completed a risk and compliance review.
•The intended use is within the approved purpose.
•Confidential, personal, or client information is only entered where permitted.
•Outputs are verified before use in decisions, advice, or external communication.
Examples of typically lower-risk use may include drafting assistance, research, grammar checking, and internal brainstorming, provided the outputs are verified and confidential information is protected.
5. PROHIBITED OR HIGH-RISK AI USE
The following require explicit approval from [APPROVER / BOARD] and documented risk assessment before use:
•AI that makes or materially influences decisions about individuals (e.g., recruitment, performance, credit, health, access to services).
•AI that processes sensitive personal data, special category data, or confidential client information.
•AI that creates content communicated to clients, regulators, or the public without human review.
•AI that replaces professional judgment in regulated, legal, medical, financial, or safety-critical contexts.
•The use of unapproved or unvetted AI tools, including personal accounts or free trials for work purposes.
•Uploading proprietary, confidential, or personal data into public AI tools unless expressly permitted.
6. DATA PROTECTION AND CONFIDENTIALITY
•Users must not input personal data, client data, trade secrets, or other confidential information into AI tools unless the tool is approved for that data and appropriate contractual and security safeguards are in place.
•AI outputs must be checked for accuracy, bias, and confidentiality before use.
•Any suspected data breach, prompt injection, or unintended disclosure must be reported immediately.
•AI vendors must be assessed for data retention, training, subprocessing, and international data transfers.
7. HUMAN OVERSIGHT AND ACCOUNTABILITY
•AI outputs should be reviewed by a competent person before they are relied upon, with the depth of review proportionate to the impact of the decision on clients, employees, third parties, or the organisation.
•The AI Owner is accountable for ensuring the tool remains appropriate for its approved use and that this use is documented.
•AI-generated content must be labelled or identified where required by applicable law, client contract, or internal procedure.
8. INCIDENT REPORTING
Any of the following must be reported to [CONTACT / DPO / LINE MANAGER] immediately:
•Suspected disclosure of confidential or personal data to an AI tool.
•Harmful, biased, inaccurate, or misleading AI output used in client work.
•Security incident affecting an AI tool or integration.
•Regulatory complaint, subject access request, or legal claim related to AI use.
9. TRAINING AND AWARENESS
All relevant staff must complete AI governance training that covers this policy, approved tools, confidentiality risks, and incident reporting. New joiners must receive guidance before using AI tools for work.
10. POLICY REVIEW
This policy is reviewed at least annually and whenever [ORGANISATION NAME] introduces a significant new AI use case, experiences a material incident, or relevant law or regulation changes.
11. GOVERNANCE INVENTORY
[ORGANISATION NAME] maintains an AI inventory that records each AI tool, its AI Owner, approved use, risk classification, and review date. The inventory is the primary source of truth for AI governance.
12. NON-COMPLIANCE
Failure to follow this policy may result in disciplinary action and may expose [ORGANISATION NAME] and the individual to legal, regulatory, or reputational risk. Questions about this policy should be directed to [CONTACT].
This template is provided for general guidance and does not constitute legal advice. It should be adapted to your organisation’s circumstances, applicable obligations and governance arrangements. Seek independent legal advice where appropriate.