Staff are already using AI tools at work, approved or not. A policy tells them which tools, which data and whose check comes first.
A Generative AI Policy for Staff: What It Needs to Contain
By James Cotton · Last updated · 9 min read
Part of our topic guides on AI Governance & Data Strategy and AI Skills for Business.
By James Cotton, Founder, iO-Sphere
Use has outrun the rules. The CIPD Labour Market Outlook for autumn 2025 found employees in 76% of UK organisations using AI tools at work. CIPD's analysis of the same survey's generative AI questions, published January 2026, reports that 31% of employers had worked on a generative AI policy in the past 12 months, up from 16% previously.
The policy at a glance
Seven headings cover what staff need to know. Each records one decision:
- Approved tools and accounts: which tools, through which accounts and devices, and what staff use for everyday tasks.
- What never goes into a prompt: the kinds of information that stay out, tool by tool.
- Checking output: who checks what, against which source, and which low-impact uses are exempt.
- Labelling and ownership: when AI use is declared, and how the business keeps hold of what it publishes.
- Reporting: who to tell, how soon, and how a tool is paused.
- Training: who is trained, on what, and before which tool goes live.
- Owner, review and consequences: who owns the rules, when they are reviewed, and what follows a breach.
For a small firm, a one-page record of tools and rules is a sound first step, as our guide to AI governance for SMEs explains. These headings are how that page grows as people and tools multiply.
The worked example throughout is the Internal AI Use Policy that the Information Commissioner's Office (ICO) applies to its own staff, version 1.3, dated 6 March 2026. The regulator has been the Information Commission since 30 September 2026. The policy covers all ICO employees, temporary and seconded colleagues, and third parties working with it under contract, and it reaches AI embedded in software-as-a-service platforms as well as in-house tools.
Its foreword names one of the risks it answers: "we don't have the confidence to use the AI capabilities available to us because we aren't clear how to do that responsibly."
Each user rule in section 4.1 is worded "should", bar one "must" about consulting its automated decision-making guidance. Section 5, for the people introducing AI, asks for an "AI inventory" of tools and uses "must" where it requires "a mechanism to pause or stop" a deployment. Security classifications and public-sector logging belong to a public body; the shape travels to any employer.
The headings in turn
Approved tools and accounts
Name the approved tools, whether staff reach them through a work account or a personal one, and which devices are allowed. Include assistants switched on inside software you already pay for, and make sure staff have an approved option for the tasks they already do with AI.
The ICO's version: "You should only use AI that has been approved by the ICO for internal use (following the appropriate ICO governance process). You should only use ICO approved devices to access AI tools and systems for corporate work." Acas advises that "it is wise to check with IT teams for approved platforms."
The government's AI Playbook of February 2025 treated embedded tools, naming "Slack GPT and Microsoft Copilot", separately from public ones.
The approved list matters because the alternative is already in use. The National Cyber Security Centre's blog The hidden risks of shadow AI, published 7 September 2026, says shadow AI "likely increases the risk of data breaches, intellectual property loss and failure to meet regulatory requirements".
For scale, the blog repeats a 71% figure. It comes from a Microsoft-commissioned survey, run by Censuswide in October 2025 among 2,003 UK employees aged 18 and over, and Microsoft sells an approved alternative. It found "71% of UK employees have used unapproved consumer AI tools at work, and 51% continue to do so every week."
Asked why, 41% said it is what they are used to in their personal life, and 28% said their employer provides no work-approved option. A list with nothing on it for everyday drafting is a list staff will route around. Tools that take actions on their own, such as AI agents, need rules beyond this heading.
What never goes into a prompt
List the kinds of information staff will recognise, such as customer records, staff files, contracts and pricing, and say for each whether it may go into an approved tool, a public tool, or neither.
The ICO says staff should use AI with personal, sensitive or confidential information only "when permitted by the ICO", keeping to data minimisation. Its response on generative AI misconceptions adds that "there are no carve-outs or sweeping exemptions for generative AI". The professional body ICAEW took a more cautious line in its guide to the legal considerations, written as of August 2023: "Organisations should not put confidential information or personal data into a Generative AI tool."
A tribunal decision shows how this goes wrong in practice. In UK v SSHD, decided 17 November 2025 and reported as [2026] UKUT 81 (IAC), the Upper Tribunal recorded that an accredited adviser "had put client emails he had drafted explaining Home Office decisions into ChatGPT to try to improve them and he had uploaded Home Office decision letters to this platform to summarise them for clients."
He told the tribunal he "now realises that this is a data breach". The tribunal observed that putting client letters and Home Office decision letters "into an open source AI tool, such as ChatGPT, is to place this information on the internet in the public domain", breaching confidentiality and waiving privilege.
The decision concerned legal professionals. What the adviser was doing, improving emails and summarising letters for clients, is everyday work, and that is the use a prompt rule has to reach.
A written rule may also protect what the business knows. Under the Trade Secrets (Enforcement, etc.) Regulations 2018, information qualifies only if it "has been subject to reasonable steps under the circumstances" to keep it secret. A staff rule on what may be entered into AI tools looks like one of those steps. That is an inference from the regulation's wording, not a court holding.
Checking output before it is relied on
Say who checks an output before anyone relies on it, against what source, and which low-impact uses an approver may exempt. Advice normally given by accountants or lawyers should come from those professionals, as the ICO's policy puts it.
The ICO asks that "all AI outputs are reviewed by a human reviewer, unless agreed otherwise by the appropriate approval body", and accepts that review of every output "may not be necessary, where the impact is low". The Playbook gave the reason: models are "vulnerable to creating content that appears plausible but may actually be factually incorrect".
In R (Ayinde) v London Borough of Haringey, handed down on 6 June 2025, the Divisional Court was dealing with lawyers whose submissions cited cases that did not exist. It said: "The critical safeguard is to check any output by reference to an authoritative source."
In the second case in the same judgment, Al-Haroun, the judgment records "forty five citations... In eighteen instances, the case cited does not exist". The client says the citations "were generated using publicly available artificial intelligence tools, legal search engines and online sources". The court was addressing lawyers; the same check suits any output a business relies on.
Labelling and ownership
Say when staff declare that AI helped, when content is marked as AI-generated, and that it is checked for third-party intellectual property before it is published.
The ICO's policy says content that is "substantially or wholly AI-generated" should be marked as generated by AI, while a document the author has "substantially edited or thoroughly reviewed" need not say where AI helped draft it. Acas is briefer: "AI should be cited when used". Customer-facing output is the subject of our page on AI governance in marketing operations.
Ownership belongs under the same heading. Section 9(3) of the Copyright, Designs and Patents Act 1988 gives authorship of a computer-generated work to "the person by whom the arrangements necessary for the creation of the work are undertaken."
A government report presented to Parliament in March 2026 proposed removing that protection for wholly computer-generated works while keeping copyright for works created with AI assistance. No legislation has followed and section 9(3) remains in force.
The report said work whose creative expression comes from a human creator will in general meet the originality requirement, so where the business needs to own a report, design or code, the policy can ask staff to add and record their own contribution.
Reporting
Name the person to tell, the timescale, and what counts as worth raising. The ICO does it in one sentence: "You should flag any concerns, incidents or questions relating to internal AI use at the earliest opportunity to your manager and/or the system owner." With a way to pause or stop a tool behind it, a mistake becomes a report.
Training
Say who is trained, on what, and before which tool goes live. The ICO puts the duty on senior leadership, who "should ensure all staff have access to high-quality general AI literacy training". Users of a new tool "should be given relevant training, prior to product deployment", including "how to provide feedback and report incidents."
CIPD's January 2026 analysis reports that 35% of employers provided training and support to help employees use generative AI.
Where a tool can be configured, the Playbook said departments "should build in safeguards and put technical controls in place". For public tools it said "you cannot easily control the data input to the models: you must rely on educating users". For those tools, the rule and the training are the whole control.
iO-Sphere trains both groups this policy depends on: team training in data and AI fluency for everyone who uses the tools, and the Data & AI Governance apprenticeship (Level 4) for the person who owns the policy.
Owner, review and consequences
Name an owner and a review date, say how compliance is checked and what follows a breach, and consult staff before the rules change their work. The ICO's policy names its Director of Data as owner with a review date of August 2026, checks compliance through "internal audits of controls and processes", and warns that breach may lead to "disciplinary action, up to and including termination of employment".
Acas advises that employers "should develop clear policies regarding the use of AI at work and should consult workers and any representatives on its introduction", and that expecting certain roles to use AI "could mean a change of terms and conditions."
Who signs the rules is the subject of who is responsible for AI governance, within a wider AI governance framework; decisions about people need the further care described in data and AI skills for HR teams.
In Ayinde the court said "practical and effective measures must now be taken" by legal leaders such as heads of chambers and managing partners. It also raised "questions" about potential failings by those responsible for training and supervising the pupil barrister in one of the cases.
Those words were for the legal profession. For any other employer the parallel is plain enough: whoever owns the policy also answers for whether anyone was taught to follow it.
Frequently asked questions
Is an AI policy a legal requirement in the UK?
No UK law requires a document with that title; AI regulation in the UK in 2026 lists the laws that apply. One sector regulator sets governance duties without naming a policy: the SRA's warning notice on misuse of AI, August 2026, tells the solicitors' firms it regulates that they "must also have effective governance structures, systems and controls in place to manage any risks, including those arising from use of AI".
Should we ban ChatGPT at work?
You can: CIPD's January 2026 analysis reports that in 25% of UK organisations employees are not allowed to use generative AI, with no plans to change. Whether a ban suits you turns on what you approve instead and on account settings; the Playbook said in February 2025 that OpenAI would use prompts entered directly on the ChatGPT website to improve its models, although individual users could opt out.
Who should write it?
It is joint work. The CIPD guide Generative AI policies, published 1 October 2026, describes a process HR can lead or contribute to and says teams such as learning, data protection, legal and IT need to work together. Acas Chief Executive Niall Mackenzie gave the aim: "A good, clear policy will help businesses stay safe, transparent and reassure staff that they are valued."
Upskilling a whole team?
Tailored data and AI training for organisations, from data literacy to technical upskilling, built around your team's real work.