AI policy template

There is no shortage of AI policy templates. The trouble is that most describe nobody in particular, and yours has to describe you and the UK rules you work under.

Two free routes for a UK organisation. Take the blank sixteen-section skeleton and write it yourself, or answer six questions and get a draft built round them, with the decisions only you can make left marked in the text.

AI policy

Most organisations are writing one now. The CIPD on generative AI at work found 31% of employers had worked on a generative AI policy in the past year, up from 16%. Below is what goes in it, what you have to change if you are in the UK, and where a downloaded document quietly lets you down.

If what brought you here is a supplier questionnaire, a tender or an insurance renewal that asks for your AI policy, the skeleton gives you a document to attach today, and the generator gives you one written round your own decisions.

What the template covers

Sixteen sections, and every one of them is a decision rather than a blank to fill. The generator marks the ones only you can answer, so you can see at a glance what is still yours to settle.

The frame

What the policy is for and who it binds.

  • 01Purpose and scope
  • 02Who it applies to

Using the tools

What people may use, and the checks around it.

  • 03Approved tools
  • 04How a new tool gets approved
  • 05Acceptable use
  • 06Uses that are not allowed
  • 07Human review before work goes out

Information and people

What can leave the building, and who has to be told.

  • 08What must never be put into an external tool
  • 09Personal data
  • 10Confidentiality and client work
  • 11Transparency to people affected

The working organisation

The skills, records and routes that keep it running.

  • 12AI literacy
  • 13Record keeping
  • 14Reporting a problem

Ownership

Who answers for it, and when it is looked at again.

  • 15Who owns this policy
  • 16Review date

Two ways to get it

They suit different starting points. Neither one is the paid version, because there is not a paid version.

What a UK organisation has to change

The headings travel. The obligations behind them do not, and this is where a template written for a general audience stops being enough.

Personal data is the constant. UK GDPR applies to it however the AI is used, so the personal data and confidentiality sections carry the weight, and the ICO guidance on AI and data protection is the reference to write them against rather than anything generic.

The EU AI Act is the variable. It reaches plenty of UK organisations, usually through outputs used in the EU rather than through having an office there, which is the point most summaries skip. If it does reach you, the AI literacy duty (Article 4) is already in force, while the high-risk obligations were deferred to 2 December 2027 and 2 August 2028. Whether any of it applies to you is a question to settle before you write the policy, not after, and the EU AI Act check answers it in ten questions.

One line is worth writing in plainly whatever your sector: what may never be put into an external tool. NCSC on the risk of public large language models is blunt that sensitive information should not go into public large language models, and that providers can retain and access what is submitted.

Where a downloaded template falls down

It does not know which rules reach you
A template cannot tell whether the EU AI Act applies to your organisation, and most UK organisations that are in scope are caught through outputs used in the EU rather than through having an office there. That question comes first, and a document cannot answer it.
It is written for nobody in particular
A clinic holding patient records, a firm giving regulated advice and a school teaching minors carry duties a generic document cannot know about. The personal data and confidentiality sections are where that gap shows up first.
It goes stale quietly
Staff adopt a tool without telling anyone and the policy stops describing what actually happens. Nothing announces this. It is why a named owner and a review date matter more than the wording, and the shadow AI guide covers what to do about it.
Filling it in is not the same as deciding
A policy is a record of decisions the organisation has actually made. Text in the boxes that nobody agreed to is worse than an empty document, because it looks settled.

None of this makes a template useless. It makes it a starting point rather than a finished job.

What to do once you have it

Settle the marked decisions first, because they are the ones that make the document yours. Then name an owner, usually whoever already owns risk, security or operations, and get sign-off from leadership so the record shows who agreed to what and when.

Give it a review date and keep the approved-tools list easy to update, since that is the part that drifts first. A policy nobody owns goes stale by default, and a stale policy is the one that gets quoted back at you.

Common questions

Is there a free AI policy template?
Yes, and there are two of them. The skeleton is a Word document of sixteen headings with nothing filled in, which suits an organisation that already knows what it has decided. The generator needs six answers to write a policy round them, and offers eight more that make it specific to your organisation. Either way it leaves the decisions only you can make marked in the text.
What should a UK AI policy template cover?
The same structure as anywhere else: approved tools and how a new one gets approved, acceptable and prohibited use, human review before AI-assisted work goes out, what may never be put into an external tool, personal data and confidentiality, transparency, AI literacy, record keeping, an owner and a review date. What changes for a UK organisation is the obligations behind those headings, because UK GDPR applies to the personal data throughout and the EU AI Act reaches some UK organisations through outputs used in the EU.
Can I use an AI policy template as it is?
Not safely. A template cannot tell you whether the EU AI Act applies to your organisation, it does not know your sector duties, and text nobody has agreed to looks settled without being settled. Treat it as a starting point: decide the marked questions, give it an owner, and put a review date on it.