Build an AI policy starting draft

Six questions and you'll leave with a draft policy that marks every decision still waiting on you. Eight more are offered if you want it written closer to your organisation.

A starting draft for internal review, with every open decision marked.

Your staff need one place to check what's allowed

An AI use policy is where you write down which tools people may use and who signs off a new one, and what has to happen before anything an AI helped write goes to a customer. Staff get somewhere to look instead of asking, and you get a record of what was actually agreed.

You don't need every decision made before you start. The draft is written from the decisions you have made, and the ones you haven't, like the owner, the approver and the tools you allow, stay marked in the text so you can see what still needs settling before you issue it.

The draft comes in sixteen sections

The standing sections every serious policy carries, such as definitions and prohibited uses, arrive already written. Your answers write the rest, and everything they can't write is marked in the text as a decision that stays yours. The draft never invents an owner, an approver or a rule you haven't made.

Three sections link out to the guide behind the duty they cover, so you can read what the duty asks before you settle the wording.

What comes out is a starting draft for internal review, not a finished policy. The decisions it cannot make for you stay marked in the text.

AI use policy

[Organisation name] AI use policy

  1. Document control
  2. Purpose
  3. Scopeguide
  4. Definitions
  5. Roles and responsibilities
  6. Approved tools and new-tool approval
  7. How AI may be used
  8. Prohibited uses
  9. Human review of AI-assisted output
  10. Personal data and confidential information
  11. Transparency to people affectedguide
  12. Training and awarenessguide
  13. Incidents and reporting
  14. Monitoring, compliance and exceptions
  15. Related documents and references
  16. Review and version history

How the draft gets written

  1. Answer six questions, or fourteen

    The organisation's name, what it does with AI, which functions may use it, and who signs things off. Six optional ones follow, covering your sector, the tools already approved, what must never go into an external tool, where a problem gets reported, and how often the policy is reviewed. Skip anything unsettled and the draft records it as a decision still open.

  2. Watch the draft assemble

    Each answer writes its sections while you work, so you can see the policy take shape and where the open decisions sit. Your answers stay in this browser, and you can leave and pick the draft back up.

  3. Take away the Word document

    Download the draft as a Word document to edit and circulate, with every open decision marked in the text and ready to settle.

AI Governance CheckExit

Some of the policy only you can write

The draft won't invent an owner or an approver

It leaves the review date open too. You'll still need to name your approved tools and the uses that are off limits, and add the route staff use to report a problem.

Read it against what you've actually decided

Before you approve it or issue it to staff, have the policy owner and whoever is responsible for the systems and functions in scope check every statement against the decisions your organisation has really made, and settle each marked placeholder.

What the generator asks

The draft is written round your answers to these. Six are needed, eight are optional.

  1. What is the organisation called?

    Use the name the policy will be issued under.

  2. What brought you here?

    It changes what the purpose section says. Skip it if none fit.

    Answers offered

    • A client or supplier questionnaire asked about our AI use
    • An insurer or a renewal form asked about it
    • The board or a manager asked for a position
    • Something happened with an AI tool
    • Getting something in place before anyone asks
  3. What sector is the organisation in?

    The scope section names it.

    Answers offered

    • Professional services
    • Recruitment and staffing
    • Health and social care
    • Financial services
    • Legal
    • Education
    • Manufacturing and engineering
    • Technology
    • Retail and hospitality
    • Charity or public sector
    • Something else
  4. What does your organisation do with AI?

    Pick the closest fit.

    Answers offered

    • Uses AI tools supplied by other organisations
    • Builds or adapts AI systems
    • Does both
  5. Which parts of the business may use AI?

    Tick every function that belongs in scope today.

    Answers offered

    • Customer service
    • People and recruitment
    • Marketing and communications
    • Finance
    • Legal and compliance
    • Operations
    • Product and service delivery
    • Technology
    • Research
  6. Which AI tools are already approved for use?

    Name them as staff would, separated by commas. Include any you know people use unofficially.

  7. Can AI-assisted output be published or customer-facing?

    Think about anything a customer or the public would see.

    Answers offered

    • Yes, but a person must review it before release
    • No, AI-assisted output is for internal use only
    • This has not been decided
  8. What must never be put into an external AI tool?

    Tick everything that is off limits. This writes the prohibited-uses section.

    Answers offered

    • Client or customer data
    • Personal data about staff or customers
    • Health or other special-category data
    • Financial or commercially sensitive information
    • Anything covered by an NDA or a confidentiality clause
    • Source code or proprietary technical material
    • Passwords, keys or access credentials
  9. What should the draft say about personal data?

    Pick the closest current position.

    Answers offered

    • Personal data is not used with AI and must not be entered into AI tools
    • Personal data may be involved only where its use has been approved
    • Personal data is involved, but the handling rule still needs to be decided
    • The organisation does not yet know
  10. Who must approve a new AI tool?

    A role or a name. Leave it blank if nobody has been assigned yet.

  11. Where should someone report a problem with an AI tool?

    A person, a role or an inbox. Leave it blank if that route does not exist yet.

  12. What AI training have staff had?

    Record where you are now.

    Answers offered

    • All staff who use AI have had training
    • Some staff who use AI have had training
    • Staff who use AI have not yet had training
    • The organisation does not yet know
  13. How often should this policy be reviewed?

    The review section records it.

    Answers offered

    • Every six months
    • Once a year
    • Whenever something material changes
    • Not decided yet
  14. Who owns this policy?

    A role or a name. Leave it blank if that is still open.

Read the duty before settling the wording

Each guide sets out what one duty asks of an organisation. The draft doesn't reach a legal conclusion for you, so the wording stays yours to settle.