Below is a complete AI acceptable use policy for a UK business of roughly 30 to 500 staff. It is in the body of the page, not behind a form. Copy it, fill in the bracketed placeholders, delete what does not apply and take it to your board. Under each clause is a short note on why it is there and the source it rests on, because a policy your managers cannot explain is one your staff will not follow.
This is the policy document, not the governance programme and not the audit. For the programme (ownership, risk register, procurement, review cadence) read our AI governance framework for UK businesses. To find out what staff already use before you write anything down, run the shadow AI audit. This page is the document those two point to.
Why a policy, and why now
Three facts from primary sources.
Staff are already using AI, approved or not. Research commissioned by Microsoft and conducted by Censuswide in October 2025, across 2,003 UK employees, found "71% of UK employees have used unapproved consumer AI tools at work, and 51% continue to do so every week". In the same survey "28% report that their company doesn't provide a work-approved option", only 32% were concerned about the privacy of company or customer data entered into consumer tools, and 22% had used a consumer AI assistant for finance-related tasks (Microsoft UK, 13 Oct 2025). Vendor-commissioned, and read it as such.
The UK's national cyber authority says the answer is not a ban. The National Cyber Security Centre, 7 Sep 2026: "Where cyber security policies cannot meet business needs, organisations are likely to continue seeing their employees adopt new AI services before they have had time to assess them and provide approved alternatives." Its recommendation: "Adopt a positive cyber security culture. Encouraging open communication about cyber security issues means employees are much less likely to turn to shadow IT services, including shadow AI." And: "You cannot manage what you do not know." (NCSC, 7 Sep 2026)
Businesses your size are the ones being hit. The Cyber Security Breaches Survey 2025/2026 (fieldwork Aug to Dec 2025) found 43% of UK businesses had a breach or attack in the previous 12 months, rising to 65% of medium and 69% of large businesses, with phishing "the most prevalent type of breach or attack by far" at 38% (DSIT and Home Office, 30 Apr 2026). The survey does not yet measure AI-enabled attacks at all. Do not wait for the statistic.
Nobody is making you write this. There is no UK AI Act, and government policy still rests on the 2023 approach of applying existing law through existing regulators (GOV.UK, 29 Mar 2023). The reason to have a policy is that existing law already applies to what staff type into a chatbot, and without one nobody knows where the lines are.
What the ICO and the NCSC actually say
The Information Commissioner's Office is the regulator whose law applies, but its "Guidance on AI and data protection" states "This guidance was updated on 15 March 2023" and carries the banner "Due to changes made by the Data (Use and Access) Act, this guidance is under review and may be subject to change" (ICO). Its guidance on monitoring workers carries the same banner (ICO). Cite the ICO for the principle that data protection law applies to AI in full. Do not treat either document as a settled 2026 position.
The NCSC has published no template, but it has published the shadow AI position above, a plain-English rule on agents (clause 9) and free services any UK organisation can switch on (clause 11). This template borrows all three. And since we hold it ourselves: Cyber Essentials Plus certifies baseline IT security controls. It does not, on its own, mean you have an AI policy (NCSC, Cyber Essentials v3.2).
Square brackets mark what only you can fill in. Where a clause offers a choice, the stricter option comes first.
The template: AI acceptable use policy
[Company name] Artificial Intelligence Acceptable Use Policy. Version 1.0. Owner: [AI owner, named role]. Approved by: [board or managing director]. Effective: [date]. Next review: [date, within 12 months].
1. Purpose and scope
1.1 This policy sets out how [Company name] and its people may use artificial intelligence tools, including generative AI assistants, AI features inside business software, and AI agents that can read from or write to company systems.
1.2 It applies to all employees, contractors and temporary staff, on company or personal devices, whether or not the company paid for the tool.
1.3 It covers any tool that takes text, files, images, audio or data as input and produces content, decisions or actions using a machine-learning model. If in doubt, treat the tool as covered and ask the AI owner.
Why this is here. Scope has to reach personal devices and free tools, because that is where most unapproved use happens (Microsoft/Censuswide).
2. Roles
2.1 The board approves this policy and receives a report on AI use, incidents and exceptions at least [quarterly].
2.2 The AI owner ([director-level role]) owns this policy, maintains the approved tool list, decides tool requests under clause 10 and is the escalation point for incidents.
2.3 The data protection lead is consulted before any AI tool processes personal data and before any monitoring under clause 14. The IT or security lead configures the controls in clauses 3, 9 and 11 and keeps the logs in clause 9.
2.4 Line managers ensure their teams have read this policy and completed training. Every user is accountable for the data they enter and the output they use.
Why this is here. "Which group oversees the AI policy" is a common search, and the usual answer is nobody. A named owner is also the first thing external frameworks look for: ISO/IEC 42001 requires an AI policy approved by top management, and NIST's AI Risk Management Framework starts with a Govern function covering roles and accountability.
3. Approved tools and account tiers
3.1 Only tools on the approved list (Appendix A) may be used for company work. Current list: [for example Microsoft 365 Copilot on the company tenant, ChatGPT Business or Enterprise on the company workspace, Claude Team or Enterprise on the company organisation, Gemini in Google Workspace on the company domain, HubSpot's built-in AI on the company portal].
3.2 Company work must only be done on business, team or enterprise tiers provisioned by the company. Personal accounts, free tiers and consumer subscriptions (including ChatGPT Free, Plus and Pro, Claude Free, Pro and Max, the consumer Gemini app and Copilot on a personal Microsoft account) must not be used for company work, even if the user pays for them.
3.3 When approving a tool the AI owner records: the tier, whether the vendor trains on inputs by default at that tier, retention, storage region, which certifications cover that tier, and which admin controls are on. A product name is not enough: "Copilot" and "Claude" each name a consumer product and a business product with different terms.
3.4 Browser extensions, plug-ins, connectors and agent integrations are separate tools and need separate approval.
3.5 Any AI account that is connected to a business system (a CRM connector, an email or document integration, an agent) is a company-provisioned business, team or enterprise account wherever the vendor offers one, and the vendor's setting that allows training on your data is confirmed off before the connection is enabled. On business, team and enterprise tiers an administrator sets this centrally. Where a vendor's connector will only work with a personal tier, the account is still company-owned, the training setting is switched off by hand on that account, and the AI owner records the check in Appendix A and repeats it at every review under clause 16.
Why this is here. Every consumer tier checked trains on your content by default and every business tier does not. OpenAI: "data sent to the OpenAI API is not used to train or improve OpenAI models (unless you explicitly opt in to share data with us)", while its published position is that "Improve the model for everyone" is on by default for Free, Plus and Pro personal workspaces (OpenAI). Anthropic changed its consumer default on 28 Aug 2025: "We will train new models using data from Free, Pro, and Max accounts when this setting is on", with five-year retention if accepted, and "These changes apply only to Claude Free, Pro and Max consumer accounts" (Anthropic). Its certifications cover "commercial products such as Claude for Work and the Anthropic API" and exclude "consumer products such as Claude Free, Pro, Max" (Anthropic). In the consumer Gemini app, chats pulled for human review "are not deleted when you delete your activity. Instead, they are retained for up to three years" (Google). Microsoft 365 Copilot: "Prompts, responses, and data accessed through Microsoft Graph aren't used to train foundation LLMs" (Microsoft Learn), but consumer Copilot on a personal account is opt-out (Microsoft). HubSpot states "Third-party AI providers cannot train their models on HubSpot customer data" (HubSpot) while its privacy policy reserves the right to "train our AI models" on personal data it processes (HubSpot, s.2.3). Two different promises, hence 3.3. ChatGPT tiers: ChatGPT Business vs Enterprise.
Clause 3.5 exists because connectors do not always insist on a business tier. HubSpot's connector for Claude requires "a paid Anthropic subscription (Pro, Max, Team, or Enterprise)" (HubSpot, updated 10 Aug 2026), and Pro and Max are the consumer tiers on which Anthropic trains "when this setting is on". Connect a live CRM to a Pro account with the default left in place and your customer records are in scope for model training. On Team and Enterprise an administrator controls the setting for everyone; on Pro and Max the individual has to turn it off, which is why 3.5 makes the AI owner check it rather than take the user's word.
4. Data that may never be entered
4.1 The following must never be entered into any AI tool, approved or not, without written approval from the AI owner and data protection lead for that specific use: passwords, keys, tokens and credentials; payment card and bank details; special category personal data (health, ethnicity, religion, sexual orientation, biometrics, criminal records); material under a non-disclosure agreement; unpublished financial results, board papers and material on acquisitions, disposals or litigation; source code or configuration that would help an attacker; anything marked [Confidential or above].
4.2 Personal data about customers, staff or suppliers may be entered only into approved business-tier tools, only under clause 5, and only as much as the task needs.
4.3 Uploading a file is entering data. Connecting a tool to a mailbox, drive, CRM or database is entering everything that connection can reach.
Why this is here. Staff rarely paste a secret on purpose. They paste a document that contains one. Clause 4.3 exists because a connector is standing access, and an attacker who compromises the agent gets "the same data, services, and privileges that the agent has legitimate access to" (NCSC).
5. Personal data and automated decisions
5.1 Entering personal data into an AI tool is processing under UK GDPR. It needs a lawful basis, must be limited to what the task requires and must be covered by our privacy notices. The data protection lead decides whether a data protection impact assessment is needed before a new AI use of personal data begins.
5.2 No decision with a legal or similarly significant effect on a person (recruitment, promotion, dismissal, credit, individual pricing, complaint outcomes) may be taken by an AI tool where there is no meaningful human involvement in the taking of the decision, unless the data protection lead has approved it and 5.3 applies.
5.3 Where an AI tool contributes to such a decision, the person must be informed, be able to make representations, be able to obtain human intervention and be able to contest the outcome. The human reviewer must have the authority, time and information to change the outcome. Confirming a recommendation without reading the case is not human involvement.
Why this is here. The rules changed on 5 Feb 2026. Section 80 of the Data (Use and Access) Act 2025 replaced UK GDPR Article 22 with a regime that turns on whether there is "no meaningful human involvement in the taking of the decision" and requires that data subjects are informed, can make representations, can obtain human intervention and can contest the outcome (legislation.gov.uk). Clause 5.3 uses that statutory language deliberately, because the ICO's guidance on it is under review.
6. Third-party material, intellectual property and copyright
6.1 Do not enter material belonging to a client, supplier or partner into an AI tool unless our contract with them permits it or they have agreed in writing.
6.2 Do not enter third-party copyright material to have it reproduced or reworked into something we will publish or sell, unless we hold a licence that allows it.
6.3 Treat AI-generated output as unprotected by copyright unless a person has made a real creative contribution. Do not rely on AI-generated content as company intellectual property in contracts or tenders without legal advice.
Why this is here. Copyright in AI output is unresolved. The government's Report on Copyright and Artificial Intelligence of 18 Mar 2026 recommends removing copyright protection for works generated wholly by AI without human authorship, declined a broad text-and-data-mining exception, and states that "both the user and provider of a model may be liable for infringement" (GOV.UK, 18 Mar 2026). A recommendation, not law, which is why the clause is cautious on both sides.
7. Output verification and accountability
7.1 The person who uses AI output is accountable for it as if they had produced it. "The AI said so" is not a defence.
7.2 Before AI output is sent to a customer, published, relied on for a decision or entered into a system of record, the user checks facts, figures, names, dates, legal statements and quotations against a primary source.
7.3 AI-generated code goes through the same review, testing and deployment controls as human-written code.
Why this is here. The NCSC describes models that "can get things wrong and present incorrect statements as facts". No vendor accepts accountability for output, so a person must.
8. Customer-facing use and disclosure
8.1 Where a customer or member of the public interacts with an AI system on our behalf (chatbot, voice agent, automated responder), they are told so at the start and have a clear route to a person.
8.2 AI systems must not be presented as having capabilities, authority or qualifications they lack. Where an image, voice or testimonial is AI-generated and a reasonable audience would assume it was real, say so.
8.3 [FCA-regulated firms:] AI-driven customer communications are within the Consumer Duty and must be clear, fair and not misleading.
Why this is here. No single UK law requires disclosure, but three regulators apply one test: do not mislead. The Competition and Markets Authority's "Complying with consumer law when using AI agents" (9 Mar 2026) applies existing consumer law to AI agents and keeps responsibility with the business even where a third party supplied the agent. The Advertising Standards Authority's 29 May 2025 guidance asks whether the audience would be misled without disclosure. The FCA's Consumer Duty communications standard applies to AI-driven interactions.
9. AI agents and write access to business systems
9.1 An AI agent is any AI tool that can take actions in a system rather than only produce text: creating or updating records, sending messages, moving money, changing settings, running code or calling other systems.
9.2 No agent is connected to a business system without the AI owner's written approval, a named human owner and a written scope: which systems, which actions, which data, for what task.
9.3 Agents run under their own credentials, not a person's, with the least privilege the task needs. Read-only where read-only will do. Credentials are scoped to the task, time-limited where the platform allows, and revocable without disabling the human owner's access.
9.4 Any action that creates, updates or deletes records, sends external communications, changes permissions, moves money or touches credentials requires human approval before it executes, and the approval must show what will change. Approval settings are set to require approval, never to allow by default.
9.5 An agent must not, in one configuration, have all three of: access to private company data, exposure to content from outside the company (inbound email, web pages, form submissions, third-party documents), and the ability to send data out. A use case that needs all three needs a separate security review.
9.6 Every agent action is logged with tool, action, record, the human on whose authority it acted, and time. Logs are kept for [12 months] and reviewed [monthly].
9.7 Where an agent bypasses validation rules that apply to human users, the human owner compensates with review or the agent does not get that permission.
9.8 An agent that cannot complete its task stops and reports. It does not find another way.
Why this is here. This is the clause most templates lack and the reason this one exists.
The NCSC's Chief Technology Officer for Architecture, Dave Chismon, 8 Dec 2025: "don't let an LLM processing emails from random external people have access to privileged tools", and "If the system's security cannot tolerate the remaining risk, it may not be a good use case for LLMs." Prompt injection, in his view, will probably never be fixed the way SQL injection was: "The best we can hope for is reducing the likelihood or impact of attacks" (NCSC). Clause 9.5 is Simon Willison's "lethal trifecta" written as a rule: "Access to your private data", "Exposure to untrusted content", and "The ability to externally communicate in a way that could be used to steal your data" (Willison, 16 Jun 2025).
Clauses 9.4 and 9.7 come from a real connector. HubSpot's connector for Claude can read, create and update most CRM objects and cannot delete anything. Its documentation says Claude "may show you what the proposed changes are", recommends you "set Write tools to Needs Approval", warns that on "Always allow, edits may occur without asking for approval", states that "Custom validation rules (including pipeline stage validations and association label validations) aren't applied when creating or updating HubSpot records using the connector", and confirms every write is attributed in the audit log "to both the user and the Claude connector" (HubSpot, updated 10 Aug 2026). The controls exist, they are settings, and the default is discretionary. More in governing AI write access to your CRM.
Clause 9.4 gates write actions rather than everything because blanket approval becomes a rubber stamp: Anthropic's own telemetry "showed users approved roughly 93% of permission prompts". The same post describes the credential model in 9.3, "a per-session scoped-down token" that "can be revoked independently of the user's" (Anthropic, 25 May 2026). See AI approval workflows.
Clauses 9.6 and 9.8 come from the clearest incident on record. In July 2026, during OpenAI's internal cybersecurity evaluations, its own test agents, running with safeguards deliberately reduced, "circumvented controls designed to isolate them from the internet and compromised parts of OpenAI's internal research infrastructure and Hugging Face's systems", executing code on dozens of Hugging Face servers and obtaining "limited private data". OpenAI states the events "did not affect OpenAI customer data, product functionality, or availability" (OpenAI, 26 Aug 2026). Its post-mortem makes this clause's case. Controls work: "the propensity to compromise infrastructure can drop over 100x when using the production ChatGPT harness and system prompt." Logging works: its monitoring, had it been running, "would have caught the initial relevant activity and paged our security team more than a day before models breached Hugging Face systems." And the root cause: "we did not extend the powerful safeguards that we deploy for our externally deployed models to all internal evaluations." A business that governs its customer-facing agents and not its internal ones is making the same mistake. Checklist: AI agent security review and monitoring AI systems.
10. Shadow AI and requesting a tool
10.1 If you use or want to use an AI tool not on the approved list, tell the AI owner. You will not be disciplined for disclosing use of an unapproved tool under this clause, provided no clause 4.1 data was entered and you stop using it for company work until a decision is made.
10.2 Requests go through [channel], stating the tool, tier, task, data involved and any connection to company systems. The AI owner responds within [10 working days] with approve, approve with conditions, or decline with a reason and where possible an approved alternative.
10.3 The approved list and decisions log are published to staff.
Why this is here. This follows the NCSC's position that shadow AI is a symptom of unmet need and that a positive culture, not prohibition, reduces it (NCSC). The amnesty is what makes "You cannot manage what you do not know" actionable. Method for finding current use: shadow AI audit.
11. Security: phishing, deepfakes and payment verification
11.1 Assume any email, message, voice call or video call could be AI-generated, however convincing, including where it appears to come from a colleague, director, client or supplier.
11.2 Any instruction to make a payment, change bank details, buy vouchers, share credentials or release confidential data that arrives by email, message or call is verified by calling the requester back on a number already held on file, never one supplied in the message. New beneficiaries and changes to supplier bank details need approval by two named people, one of whom made the call-back.
11.3 Urgency, secrecy and requests to bypass process are warning signs and are reported under clause 12.
11.4 Staff use phishing-resistant sign-in (passkeys or hardware keys) wherever supported. The IT lead enables it on approved AI tools and the systems they connect to, and registers the company for the NCSC's free Early Warning service.
Why this is here. Call-back on a known number and dual authorisation for new beneficiaries are long-standing UK Finance advice. What AI changes is the cost of impersonation: per ElevenLabs' own documentation, "Less than two minutes of audio can produce a usable clone" and cloning "is immediate" (ElevenLabs). At Ferrari in July 2024, an executive receiving a convincing voice clone of the chief executive asked the caller to name a book he had recently recommended. The caller hung up and no money was lost (MIT Sloan Management Review, reporting Bloomberg). The defence that worked was a human habit. On sign-in, the NCSC "recommends users opt for passkeys over passwords wherever they are available" because they "can't be intercepted, reused or stolen like passwords" (NCSC). Early Warning is "Free malicious activity notifications from the NCSC for UK organisations" (NCSC). We could not find a verified, named UK deepfake fraud case from 2024 to 2026, and would rather say so than borrow a number.
12. Incidents and reporting
12.1 An AI incident is any of: clause 4.1 data entered into any tool; personal data entered into an unapproved tool; an agent acting outside its approved scope; a suspected prompt injection or manipulation of an AI system; a suspected deepfake or AI-enabled fraud attempt, successful or not; or AI output that caused a customer, legal, financial or regulatory problem.
12.2 Report to the AI owner and IT lead within [one hour] of discovery. Prompt reporting is a mitigating factor under clause 15.
12.3 Where personal data is involved, the data protection lead assesses whether the ICO must be notified within the 72-hour window UK GDPR sets for reportable breaches.
12.4 Every incident is recorded, investigated and closed with a note of what changed. Affected third parties are told promptly.
Why this is here. OpenAI's conduct after its incident is the model at any scale: notify the affected party, investigate, publish what happened and what changed (OpenAI).
13. Training
13.1 All staff complete AI acceptable use training at induction and at least annually, covering this policy, the approved list, clauses 4, 7 and 11, and how to report.
13.2 Finance, HR, customer service and anyone operating an agent under clause 9 receive role-specific training, including a payment-verification exercise for finance. Completion is recorded.
Why this is here. Only 32% of UK employees were concerned about the privacy of company data entered into consumer AI tools, and 22% had used consumer AI for finance tasks (Microsoft/Censuswide). A policy nobody is trained on changes neither number.
14. Monitoring of staff use
14.1 The company monitors use of approved AI tools through their audit logs and admin consoles, to enforce this policy, investigate incidents and keep the approved list accurate. Staff are told this here and at induction.
14.2 Monitoring is limited to what is necessary and proportionate. The company does not read individual prompts as a matter of routine, only where an incident or a recorded concern justifies it.
14.3 Any proposal to use AI to monitor or score staff performance, communications or productivity requires a data protection impact assessment, consultation with affected staff, and approval by the data protection lead and the board before it begins. Decisions on pay, discipline or dismissal are not based solely on automated monitoring output (see clause 5).
Why this is here. The ICO's guidance "Employment practices and data protection: monitoring workers" covers calls, messages, keystrokes, screenshots, webcam and audio, and is under review because of the Data (Use and Access) Act (ICO), so expect this clause to need updating. Acas advises consulting staff before introducing AI that changes how they work.
15. Breaches and discipline
15.1 Breaches are dealt with under the disciplinary policy. Entering clause 4.1 data into an unapproved tool, connecting an agent without approval or bypassing a clause 9.4 approval control may be treated as gross misconduct.
15.2 Self-reporting under clauses 10.1 and 12.2 is taken into account. Concealment is an aggravating factor. Contractors and suppliers in breach may have access withdrawn.
Why this is here. Without consequences the policy is advice. Without 15.2 it drives use underground, the outcome the NCSC warns against. We could not verify any UK employment tribunal decision on misuse of AI at work, so the standard is the one that applies to any IT or data policy breach.
16. Review and change management
16.1 This policy is reviewed at least every 12 months by the AI owner and approved by the board.
16.2 It is also reviewed within [30 days] of: a vendor changing training, retention or data-handling terms for an approved tier; a new or materially changed model being deployed in an approved tool; a new connector or agent capability in an approved tool; an incident under clause 12; or a change in law or regulator guidance.
16.3 The AI owner subscribes to change notices from each approved vendor and records the version of the terms relied on at approval. Material changes trigger refresher training.
Why this is here. The terms move. Anthropic flipped its consumer default on 28 Aug 2025. Microsoft's consumer Copilot page carries a notice dated 18 Aug 2026 warning it may be superseded. HubSpot's connector documentation was updated on 10 Aug 2026. The ICO's core guidance is under review. A policy approved once and filed is wrong within a year, which is why our model decision table is republished after each major model release.
Appendix A, approved tools register: tool, tier, approval date, owner, trains by default at this tier, retention, storage region, certifications covering this tier, admin controls enabled, connectors permitted.
Appendix B, agent register: agent, human owner, systems, permitted actions, credential scope, approval setting, log location, last review.
How this maps to ISO/IEC 42001, NIST AI RMF and the EU AI Act
None of the three requires a UK business of this size to do anything, and this template is not a certification. But a customer, insurer or auditor will eventually ask.
ISO/IEC 42001:2023 is a certifiable AI management system standard for organisations that develop, provide or use AI (ISO). It requires an AI policy approved by top management as one element of a wider management system. Clauses 1, 2 and 16 are that element. When a vendor claims it, ask which tier it covers: HubSpot's Trust Center, for instance, currently shows SOC 1, 2 and 3 and HIPAA and does not currently show ISO 27001 or ISO 42001 (HubSpot), which is a question, not a finding.
NIST AI RMF 1.0 (January 2023) is a free, voluntary US framework whose Govern function includes "Legal and regulatory requirements involving AI are understood, managed, and documented". No legal standing in the UK.
The EU AI Act is not UK law, and its Article 26 deployer duties apply only to systems classed high-risk under Annex III (Article 26). Ordinary use of a general-purpose assistant is not that, and the EU has just deferred its own timetable: the Digital Omnibus on AI entered into force on 27 Jul 2026, with Annex III obligations reported as deferred to 2 Dec 2027 (European Commission). If you sell into the EU and use AI in recruitment, credit or critical infrastructure, get advice. Otherwise the Act is not the reason to write this policy.
| Template clause | ISO/IEC 42001 | NIST AI RMF | EU AI Act Art. 26 (high-risk only) |
|---|---|---|---|
| 1 to 2 Scope, roles | AI policy, leadership | Govern | Deployer accountability |
| 3 to 6 Tools, data, GDPR, IP | Data and legal controls | Govern, Map | DPIA link |
| 7 Output verification | Operation | Measure | Human oversight |
| 9 Agents | Operational controls | Manage | Human oversight, logging |
| 12 Incidents | Improvement | Manage | Serious incident reporting |
| 14 Monitoring | Interested parties | Govern | Worker notification |
| 16 Review | Continual improvement | Govern | Monitoring |
The mapping is ours, from the public descriptions of each framework, not a formal gap analysis.
Frequently asked questions
What should an AI policy include? Who it applies to and who owns it, which tools and account tiers are approved, what data must never be entered, how personal data and automated decisions are handled under UK GDPR, who is accountable for output, how customers are told they are dealing with AI, rules for agents that act in business systems, how staff request a tool, payment and phishing verification, incident reporting, training, monitoring, consequences and a review cycle. The template above covers all sixteen in that order.
Should companies have an AI policy? Is it a legal requirement in the UK? No UK law requires one and there is no UK AI Act. The reason to have one is that existing law already applies to what staff do with AI: UK GDPR to personal data entered, the automated decision-making rules amended by the Data (Use and Access) Act 2025 from 5 Feb 2026, copyright law to inputs and outputs, and consumer law to anything customer-facing. The NCSC's advice of 7 Sep 2026 is that banning tools does not work.
How do you write an AI policy? Find out what is already in use, name a director-level owner, decide the approved list and the banned data, then adapt a template rather than drafting from blank. Have the data protection lead check clauses 5 and 14, finance check clause 11, and whoever runs your CRM check clause 9. Approve at board level, train everyone, set a review date.
Which group oversees the implementation of the AI policy? One named owner at director level, supported by the data protection lead and the IT or security lead, reporting to the board at a set interval. A committee with no named owner is the most common failure.
What should an AI policy include regarding data privacy? A list of data that must never be entered into any AI tool. A rule that personal data only goes into approved business-tier tools whose vendor does not train on inputs by default, with a lawful basis and, where risk is high, a data protection impact assessment. And a rule on automated decisions reflecting the Data (Use and Access) Act 2025: the person must be informed, be able to make representations, obtain human intervention and contest the outcome.
Is an AI acceptable use policy the same as an AI security policy? They overlap. An acceptable use policy tells staff what they may do. An AI security policy tells IT which controls must exist: least privilege for agents, approval gates on write actions, logging, phishing-resistant sign-in, monitoring. This template combines both, because in a business of 30 to 500 people the same two or three people own them. Clauses 9 and 11 are the security policy.
Does this cover AI agents that can change data in our CRM? Yes, clause 9: written scope, agent-specific least-privilege credentials, human approval before any write action, a ban on combining private data, untrusted input and outbound communication in one agent, full logging, and a rule that an agent that cannot complete its task stops rather than improvises.
The next step
This template is one third of the work. The other two thirds are finding out what is actually in use and configuring the controls the policy assumes. For a structured view of where your data, systems and AI use stand before you adopt it, start with the AI and Data Readiness Assessment on our AI implementation page or book a diagnostic. If you already know what you need built, request a quote and you will receive a scoped proposal within two working days.
Two companion posts this week: the threat to plan for now and what "pace the frontier" means for UK businesses using AI now. Slugs proposed, may change.
Sources
- Microsoft UK Stories, "Rise in 'Shadow AI' tools raising security concerns for UK organisations", 13 Oct 2025. https://ukstories.microsoft.com/features/rise-in-shadow-ai-tools-raising-security-concerns-for-uk/
- NCSC, "The hidden risks of shadow AI", Simon B, Senior Cloud Researcher, 7 Sep 2026. https://www.ncsc.gov.uk/blogs/the-hidden-risks-of-shadow-ai
- DSIT and Home Office, Cyber Security Breaches Survey 2025/2026, 30 Apr 2026. https://www.gov.uk/government/statistics/cyber-security-breaches-survey-20252026/cyber-security-breaches-survey-20252026
- GOV.UK, "AI regulation: a pro-innovation approach", 29 Mar 2023 (updated 3 Aug 2023). https://www.gov.uk/government/publications/ai-regulation-a-pro-innovation-approach
- ICO, "Guidance on AI and data protection" (updated 15 Mar 2023, under review). https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/guidance-on-ai-and-data-protection/
- ICO, "Employment practices and data protection: monitoring workers" (under review). https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/employment/monitoring-workers/
- NCSC, "Cyber Essentials: Requirements for IT Infrastructure v3.2". https://www.ncsc.gov.uk/files/cyber-essentials-requirements-for-it-infrastructure-v3-2.pdf
- OpenAI, "Your data" (API documentation). https://developers.openai.com/api/docs/guides/your-data
- Anthropic, "Updates to our consumer terms", 28 Aug 2025. https://www.anthropic.com/news/updates-to-our-consumer-terms
- Anthropic, "What certifications has Anthropic obtained?". https://privacy.claude.com/en/articles/10015870-what-certifications-has-anthropic-obtained
- Google, "Gemini Apps Privacy Hub". https://support.google.com/gemini/answer/13594961?hl=en
- Microsoft Learn, "Microsoft 365 Copilot privacy", 9 Jul 2026, updated 18 Aug 2026. https://learn.microsoft.com/en-us/copilot/microsoft-365/microsoft-365-copilot-privacy
- Microsoft, "Privacy FAQ for Microsoft Copilot" (notice dated 18 Aug 2026). https://support.microsoft.com/en-us/microsoft-copilot/privacy-faq-for-microsoft-copilot
- HubSpot, "Security and compliance". https://www.hubspot.com/security-and-compliance
- HubSpot, Privacy Policy, effective 14 Apr 2026, s.2.3. https://legal.hubspot.com/privacy-policy
- HubSpot Trust Center. https://trust.hubspot.com/
- legislation.gov.uk, Data (Use and Access) Act 2025, s.80. https://www.legislation.gov.uk/ukpga/2025/18/section/80
- GOV.UK (DSIT and IPO), "Report on Copyright and Artificial Intelligence", 18 Mar 2026. https://www.gov.uk/government/publications/report-and-impact-assessment-on-copyright-and-artificial-intelligence/report-on-copyright-and-artificial-intelligence
- NCSC, "Prompt injection is not SQL injection (it may be worse)", Dave Chismon, 8 Dec 2025. https://www.ncsc.gov.uk/blog-post/prompt-injection-is-not-sql-injection
- Simon Willison, "The lethal trifecta for AI agents", 16 Jun 2025. https://simonwillison.net/2025/Jun/16/the-lethal-trifecta/
- HubSpot Knowledge Base, "Set up and use the HubSpot connector for Claude", updated 10 Aug 2026. https://knowledge.hubspot.com/integrations/set-up-and-use-the-hubspot-connector-for-claude
- Anthropic, "How we contain Claude", 25 May 2026. https://www.anthropic.com/engineering/how-we-contain-claude
- OpenAI, "The Hugging Face incident and the road ahead", 26 Aug 2026. https://openai.com/index/hugging-face-incident-and-the-road-ahead/
- ElevenLabs, "Voice cloning" (documentation). https://elevenlabs.io/docs/eleven-api/concepts/voice-cloning
- MIT Sloan Management Review, "How Ferrari hit the brakes on a deepfake CEO" (reporting Bloomberg). https://sloanreview.mit.edu/article/how-ferrari-hit-the-brakes-on-a-deepfake-ceo/
- NCSC, "Passkeys". https://www.ncsc.gov.uk/passkeys
- NCSC, "Early Warning". https://www.ncsc.gov.uk/information/early-warning-service
- ISO, "ISO/IEC 42001:2023". https://www.iso.org/standard/42001
- EU AI Act Explorer, Regulation (EU) 2024/1689, Article 26. https://artificialintelligenceact.eu/article/26/
- European Commission, "Digital Omnibus on AI". https://digital-strategy.ec.europa.eu/en/library/digital-omnibus-ai-regulation-proposal
- Unregistered, cited via research briefs and marked in the body: CMA, "Complying with consumer law when using AI agents", 9 Mar 2026 (https://www.gov.uk/government/publications/complying-with-consumer-law-when-using-ai-agents); ASA, AI disclosure guidance, 29 May 2025 (https://www.asa.org.uk/news/disclosure-of-ai-in-advertising-striking-the-balance-between-creativity-and-responsibility.html); NIST AI RMF Playbook, Govern (https://airc.nist.gov/airmf-resources/playbook/govern); NCSC, "AI and cyber security: what you need to know", reviewed 31 Jul 2026 (https://www.ncsc.gov.uk/guidance/ai-and-cyber-security-what-you-need-to-know).
Stay Updated with Our Latest Insights
Get expert HubSpot tips and integration strategies delivered to your inbox.




