Yunique AI
HomeTake the assessment
AI Policy Template

A policy is a starting point.
Not proof of governance.

Use this practical template to establish baseline expectations for AI use, ownership, risk, human oversight and escalation within your organisation.

A written policy sets expectations for what should happen. It does not, by itself, demonstrate that those expectations are being followed, that controls are operating, or that an organisation’s AI use is legally defensible.

What this template does — and doesn’t do

This template provides a practical starting structure for documenting how AI should be used and governed within an organisation. It can help establish expectations around approved use, accountability, risk, data protection, human oversight and incident reporting.

It does not independently demonstrate that governance controls are operating in practice. Operational governance also requires visibility into actual AI use, appropriate ownership and risk assessment, working controls, evidence and ongoing review.

How to use this template

This template provides a starting structure that should be adapted to your organisation, sector, risk profile and existing governance arrangements.

  • Replace bracketed placeholders with your organisation’s details.
  • Review prohibited and higher-risk uses against your organisation’s activities, regulatory environment and contractual obligations.
  • Align roles and responsibilities with your existing governance structure.
  • Adapt approval, escalation and review requirements to the risks associated with your AI use.
  • Use the CLEAR Assessment separately to establish a self-reported baseline of your wider AI governance position.

Relationship to CLEAR

This resource is informed by governance principles reflected within Yunique AI’s proprietary CLEAR methodology, including visibility, risk alignment, accountability, enablement and responsible execution. The methodology’s pillars are Clarity, Legal & Risk Alignment, Enablement, Accountability and Responsible Execution. Completing this template does not implement the CLEAR methodology.

AI Policy Template
[ORGANISATION NAME]
Artificial Intelligence (AI) Use Policy
Effective date: [DATE]
Version: 1.0
Approved by: [APPROVER NAME / BOARD]
1. PURPOSE AND SCOPE
This policy sets out how [ORGANISATION NAME] uses artificial intelligence (AI) tools and services in a way that is lawful, ethical, transparent, and aligned with our obligations to clients, employees, regulators, and other stakeholders.
This policy applies to all employees, contractors, directors, and third parties who use, approve, procure, or manage AI tools on behalf of [ORGANISATION NAME]. It covers AI used in any work context, including free and paid tools, browser extensions, generative AI services, and any software that makes or influences decisions.
2. PRINCIPLES
AI use at [ORGANISATION NAME] should be:
Transparent: AI use that affects people, clients, or decisions should be documented and capable of being explained.
Accountable: AI use should have clearly defined ownership and accountability appropriate to its nature and risk.
Lawful: AI use must comply with applicable data protection law, confidentiality obligations, consumer law, equality law, and sector-specific regulation.
Human-led: Meaningful human oversight should be established where appropriate to the use case, its impact on individuals, and any applicable legal or contractual obligations.
Risk-proportionate: Higher-risk uses warrant stronger controls, approval, and review.
Secure: AI tools should not introduce unacceptable confidentiality, security, or supply-chain risks.
3. ROLES AND RESPONSIBILITIES
Board / Senior Leadership: Sets risk appetite, approves high-risk AI use, and ensures governance is in place.
AI Owner: A named individual responsible for each AI tool or use case. The AI Owner maintains an entry in the AI inventory, assesses risk, and ensures compliance.
All Users: Use AI tools only for approved purposes, protect confidential information, and report incidents or concerns.
Legal / Compliance / Data Protection: Advises on high-risk use, reviews contracts, and supports incident response.
Procurement: Ensures AI tools are approved before purchase or trial and that vendor terms are reviewed.
4. APPROVED AI USE
AI tools may be used where:
The tool is listed in the approved AI inventory.
The AI Owner has completed a risk and compliance review.
The intended use is within the approved purpose.
Confidential, personal, or client information is only entered where permitted.
Outputs are verified before use in decisions, advice, or external communication.
Examples of typically lower-risk use may include drafting assistance, research, grammar checking, and internal brainstorming, provided the outputs are verified and confidential information is protected.
5. PROHIBITED OR HIGH-RISK AI USE
The following require explicit approval from [APPROVER / BOARD] and documented risk assessment before use:
AI that makes or materially influences decisions about individuals (e.g., recruitment, performance, credit, health, access to services).
AI that processes sensitive personal data, special category data, or confidential client information.
AI that creates content communicated to clients, regulators, or the public without human review.
AI that replaces professional judgment in regulated, legal, medical, financial, or safety-critical contexts.
The use of unapproved or unvetted AI tools, including personal accounts or free trials for work purposes.
Uploading proprietary, confidential, or personal data into public AI tools unless expressly permitted.
6. DATA PROTECTION AND CONFIDENTIALITY
Users must not input personal data, client data, trade secrets, or other confidential information into AI tools unless the tool is approved for that data and appropriate contractual and security safeguards are in place.
AI outputs must be checked for accuracy, bias, and confidentiality before use.
Any suspected data breach, prompt injection, or unintended disclosure must be reported immediately.
AI vendors must be assessed for data retention, training, subprocessing, and international data transfers.
7. HUMAN OVERSIGHT AND ACCOUNTABILITY
AI outputs should be reviewed by a competent person before they are relied upon, with the depth of review proportionate to the impact of the decision on clients, employees, third parties, or the organisation.
The AI Owner is accountable for ensuring the tool remains appropriate for its approved use and that this use is documented.
AI-generated content must be labelled or identified where required by applicable law, client contract, or internal procedure.
8. INCIDENT REPORTING
Any of the following must be reported to [CONTACT / DPO / LINE MANAGER] immediately:
Suspected disclosure of confidential or personal data to an AI tool.
Harmful, biased, inaccurate, or misleading AI output used in client work.
Security incident affecting an AI tool or integration.
Regulatory complaint, subject access request, or legal claim related to AI use.
9. TRAINING AND AWARENESS
All relevant staff must complete AI governance training that covers this policy, approved tools, confidentiality risks, and incident reporting. New joiners must receive guidance before using AI tools for work.
10. POLICY REVIEW
This policy is reviewed at least annually and whenever [ORGANISATION NAME] introduces a significant new AI use case, experiences a material incident, or relevant law or regulation changes.
11. GOVERNANCE INVENTORY
[ORGANISATION NAME] maintains an AI inventory that records each AI tool, its AI Owner, approved use, risk classification, and review date. The inventory is the primary source of truth for AI governance.
12. NON-COMPLIANCE
Failure to follow this policy may result in disciplinary action and may expose [ORGANISATION NAME] and the individual to legal, regulatory, or reputational risk. Questions about this policy should be directed to [CONTACT].
This template is provided for general guidance and does not constitute legal advice. It should be adapted to your organisation’s circumstances, applicable obligations and governance arrangements. Seek independent legal advice where appropriate.

Why start with a policy?

A policy creates a common set of expectations for how AI should be used, approved and escalated. It can help establish responsibilities and provide teams with a consistent starting point.

But documented expectations are only one part of governance. The next question is whether those expectations are reflected in how AI is actually being used — and whether the organisation can evidence what happened when a decision or control is challenged.

The next question

Is your governance operating in practice?

Once expectations are documented, the next step is understanding the wider governance environment around your AI use.

The CLEAR Assessment provides a self-reported baseline across the CLEAR methodology and helps identify areas that may require further attention. It does not independently verify that controls operate or establish that an organisation’s AI use is legally defensible.

Take the CLEAR AssessmentExplore AI governance resources