AI at work series20 July 2026

What a sensible AI usage policy actually needs to say

Your staff are very likely already using AI tools at work, with or without your blessing. Here is what a policy needs to cover, in plain English.

Assume it is already happening

Across the UK, 61% of organisations now allow staff to use generative AI for work tasks, but only 31% have put together a formal policy on it in the past year (CIPD, Labour Market Outlook, autumn 2025). That gap is the real risk. It is not that AI is being used. It is that it is being used without anyone having said what is and is not allowed.

Left ungoverned, this settles into habit fast. Someone pastes a client contract into a chatbot to summarise it. Someone else drafts a reference using a tool that keeps what it is fed. None of that is malicious. It happens because nobody ever told them not to, and a policy is the cheapest way to have told them.

Two different things hiding under one label

Before you write a word of policy, it helps to separate what you are actually governing. Some of the tools your business runs on are automation: a payroll system that calculates the same figure the same way every time, a workflow that routes a holiday request to the right approver. Nobody needs a usage policy for that, beyond ordinary IT security.

Generative AI is the other thing, and it is what a usage policy is really for: tools that produce a written-sounding answer from patterns in data, where the same question can get a different answer twice. Your policy should say, in one place, which of your tools are which, so staff are not left guessing which kind of answer they are getting.

This is not a pedantic distinction to include for its own sake. A policy that treats every piece of software as "AI" ends up either banning things that were never risky, your rota system, your payslip portal, or waving through things that genuinely are, a public chatbot with no data controls. Naming the difference is what lets the rest of the policy be short.

The line that matters most

The single most important sentence in any AI usage policy is the one that says what must never be typed into a public AI tool: client data, a colleague's personal information, anything commercially sensitive, and anything from an employee's own HR record. Typing someone's pay or health details into a public chatbot is a data protection problem in its own right, not just a judgement call.

Be specific rather than general here. "Use AI responsibly" tells a busy member of staff nothing. "Do not paste a client's name and figures into ChatGPT to summarise an email" tells them exactly what not to do next time they are tempted.

Say when AI-assisted work needs to be flagged

Decide, and write down, when someone needs to say they used AI to help produce something: a job application, a piece of client-facing writing, a report going to a board. This is not about banning the practice. It is about making sure nobody downstream mistakes an AI-drafted first pass for a fully checked, human-verified piece of work.

A small firm putting this into practice

Take a fifteen-person accountancy practice. Junior staff had started drafting client emails with a general AI assistant, mostly harmlessly, until one draft included a client's turnover figure pasted in for context. One paragraph of policy fixed it: name the approved tools, say plainly that client figures never go into them, and say who to ask if a task feels like a grey area. That took an afternoon, not a project.

The same firm also found, once it started asking, that two members of staff were already using a different tool nobody in management knew about, because it was free and nobody had said otherwise. That is the ordinary shape of the problem: not a dramatic breach, just tools arriving quietly because no policy existed to arrive first.

A policy nobody can find is not a policy. It is a document.

What people get wrong

The most common mistake is not writing too little, it is writing a blanket ban and assuming that settles it. Staff who are told "no AI tools" with no practical alternative tend to keep using them anyway, quietly, on personal devices, which is worse than a governed policy because now nobody can see it happening at all. A policy that names what is approved works better than one that only names what is forbidden.

What a policy does not need

It does not need to be forty pages, and it should not try to anticipate every tool that will exist in a year's time. Keep it short enough that someone can read the whole thing in five minutes, review it every few months as the tools your business actually uses change, and treat it as a living document rather than something written once and filed.

Keeping it somewhere people actually find it

A policy nobody can find when they need it might as well not exist. Jamie HR holds policies and documents in one place, with a clear record of who has acknowledged them, so a new starter can see the AI policy on day one instead of hunting through an inbox for it.

Jamie HR
Policies people can actually find.
Jamie HR keeps your policies, documents and staff acknowledgements in one place, so a new one does not just join a pile nobody reads.
Start your 14-day free trial