AI policy template
There is no shortage of AI policy templates. The trouble is that most describe nobody in particular, and yours has to describe you and the UK rules you work under.
Two free routes for a UK organisation. Take the blank sixteen-section skeleton and write it yourself, or answer six questions and get a draft built round them, with the decisions only you can make left marked in the text.
Most organisations are writing one now. The CIPD on generative AI at work found 31% of employers had worked on a generative AI policy in the past year, up from 16%. Below is what goes in it, what you have to change if you are in the UK, and where a downloaded document quietly lets you down.
If what brought you here is a supplier questionnaire, a tender or an insurance renewal that asks for your AI policy, the skeleton gives you a document to attach today, and the generator gives you one written round your own decisions.
What the template covers
Sixteen sections, and every one of them is a decision rather than a blank to fill. The generator marks the ones only you can answer, so you can see at a glance what is still yours to settle.
The frame
What the policy is for and who it binds.
- 01Purpose and scope
- 02Who it applies to
Using the tools
What people may use, and the checks around it.
- 03Approved tools
- 04How a new tool gets approved
- 05Acceptable use
- 06Uses that are not allowed
- 07Human review before work goes out
Information and people
What can leave the building, and who has to be told.
- 08What must never be put into an external tool
- 09Personal data
- 10Confidentiality and client work
- 11Transparency to people affected
The working organisation
The skills, records and routes that keep it running.
- 12AI literacy
- 13Record keeping
- 14Reporting a problem
Ownership
Who answers for it, and when it is looked at again.
- 15Who owns this policy
- 16Review date
Two ways to get it
They suit different starting points. Neither one is the paid version, because there is not a paid version.
The blank skeleton
Sixteen headings and nothing filled in. Take it away as a Word document and write it yourself. Best if you already know what your organisation has decided.
Download the skeletonA draft built round your answers
Six questions, eight more if you want it specific, then a policy drafted round the organisation that answered them, with the decisions only you can make marked in the text. Best if you are starting from nothing.
Build a starting draftWhat a UK organisation has to change
The headings travel. The obligations behind them do not, and this is where a template written for a general audience stops being enough.
Personal data is the constant. UK GDPR applies to it however the AI is used, so the personal data and confidentiality sections carry the weight, and the ICO guidance on AI and data protection is the reference to write them against rather than anything generic.
The EU AI Act is the variable. It reaches plenty of UK organisations, usually through outputs used in the EU rather than through having an office there, which is the point most summaries skip. If it does reach you, the AI literacy duty (Article 4) is already in force, while the high-risk obligations were deferred to 2 December 2027 and 2 August 2028. Whether any of it applies to you is a question to settle before you write the policy, not after, and the EU AI Act check answers it in ten questions.
One line is worth writing in plainly whatever your sector: what may never be put into an external tool. NCSC on the risk of public large language models is blunt that sensitive information should not go into public large language models, and that providers can retain and access what is submitted.
Where a downloaded template falls down
- It does not know which rules reach you
- A template cannot tell whether the EU AI Act applies to your organisation, and most UK organisations that are in scope are caught through outputs used in the EU rather than through having an office there. That question comes first, and a document cannot answer it.
- It is written for nobody in particular
- A clinic holding patient records, a firm giving regulated advice and a school teaching minors carry duties a generic document cannot know about. The personal data and confidentiality sections are where that gap shows up first.
- It goes stale quietly
- Staff adopt a tool without telling anyone and the policy stops describing what actually happens. Nothing announces this. It is why a named owner and a review date matter more than the wording, and the shadow AI guide covers what to do about it.
- Filling it in is not the same as deciding
- A policy is a record of decisions the organisation has actually made. Text in the boxes that nobody agreed to is worse than an empty document, because it looks settled.
None of this makes a template useless. It makes it a starting point rather than a finished job.
What to do once you have it
Settle the marked decisions first, because they are the ones that make the document yours. Then name an owner, usually whoever already owns risk, security or operations, and get sign-off from leadership so the record shows who agreed to what and when.
Give it a review date and keep the approved-tools list easy to update, since that is the part that drifts first. A policy nobody owns goes stale by default, and a stale policy is the one that gets quoted back at you.