Do we actually need an AI policy?

When an AI governance policy is worth writing, when it is premature, and what it is really for once your staff are already using AI at work.

Usually yes, and usually sooner than feels necessary. But the reason isn’t the one most people give, and it’s worth being clear about it before you spend anyone’s afternoon on a document.

An AI policy, sometimes called an AI governance policy or an AI use policy, isn’t a compliance artefact you produce to satisfy a rule. For most UK organisations there’s no law that says “thou shalt have an AI policy”. It’s a record of decisions, and the reason to write one is that your staff are making those decisions right now, individually, without telling you.

The test that actually settles it

Ask yourself one question: if someone put a client’s document into a public AI tool tomorrow, would they know whether that was allowed?

If the answer is no, you need a policy, and it doesn’t matter how small you are. If the answer is yes, and you can point at where that’s written down and who agreed it, you might already have what a policy would give you.

Everything else people worry about at this stage tends to be a version of that question. Can they use it for customer emails? Does anyone check the output before it goes out? What happens if it’s wrong? Those aren’t legal puzzles. They’re decisions somebody has to make and write down.

Why waiting usually costs more

The instinct is to wait until you’ve properly worked out your position on AI. It’s a reasonable instinct and it’s normally wrong, because adoption doesn’t wait for you.

People are already using these tools. Sometimes on work you’d rather they didn’t. The NCSC has been blunt that sensitive information shouldn’t go into public large language models, and that providers can retain and access what’s submitted. That is the sort of thing people do without meaning any harm, and the shadow AI guide covers what to do about it. Every week without a stated position is a week of individual judgement calls you can’t see, made by people who are trying to be helpful.

The policy doesn’t have to be finished to be useful, either. A short document naming the approved tools and the two or three things nobody may do is worth more than a thorough one that arrives in six months.

What it’s genuinely for

Three things, and none of them is protection from a regulator.

It tells staff what’s allowed, so they stop guessing. It gives you a record of what was agreed and by whom, which is what anyone asking about your governance actually wants to see. And it surfaces the questions nobody had answered, which is usually the most valuable part: writing down who approves a new tool tends to reveal that nobody does.

If the EU AI Act reaches your organisation, and it reaches more UK organisations than people expect through outputs used in the EU, then some of this stops being optional. The AI literacy duty in Article 4 is already in force. But that’s a reason the policy has to be accurate, not the reason to have one.

When it genuinely is premature

If nobody in your organisation uses AI for anything, and you’d know if they did, then writing a policy about it is theatre. Spend the time finding out whether that first half is true, because it usually isn’t.

The other case is where a policy would substitute for a decision nobody has made. A document saying “AI use must be appropriate” is worse than nothing. It looks settled without settling anything, and it gives everyone cover to carry on exactly as they were.

Where to start

If you want the document, the AI policy template has both routes: a blank sixteen-section skeleton to fill in yourself, or a generator that needs six answers, and offers eight more if you want it more specific, then drafts one round them, marking the decisions only you can make.

If you’d sooner understand the shape first, what to include in an AI policy covers the headings and the reasoning behind each one. And if the policy sits inside a wider question about how your organisation runs its AI, what AI governance is puts the pieces together.