AI policy template: 12 rules for employees using AI
As of 11 October 2026
An AI acceptable use policy has to answer six questions. Which tools may staff use, and for what? Which data may go into them? Who checks the output, and when must it be labelled? Who trains people, and whom do they call when something goes wrong? Below are 12 rules you can copy, written for organisations in the UK and the EU and based on UK GDPR, the EU GDPR, guidance from the Information Commission (formerly ICO) and the NCSC, and Art. 4 of the EU AI Act. Replace whatever is in square brackets.
Why the policy comes before the tool rollout
Staff already use AI at work, approved or not. In a survey of 2,003 UK employees that Microsoft commissioned in October 2025, 71 percent said they had used unapproved consumer AI tools at work. The NCSC cited that figure in September 2026 and noted that organisations' policies “have not always developed at the same pace”. Its advice since 2023: do not put sensitive information into queries to public LLMs.
In the EU there is also a legal hook. Since 27 July 2026, Art. 4 of the AI Act reads in the version amended by Regulation (EU) 2026/1744: providers and deployers “shall take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf”. An organisation whose staff use an AI assistant at work is a deployer. No specific level of literacy is required, and the European Commission says no certificate is needed. A written policy plus a short training session is the obvious measure.
UK organisations outside the AI Act's scope still have UK GDPR. Personal data typed into an AI tool is processed like any other, so you need a lawful basis, a contract with the provider and, according to the Information Commission, a data protection impact assessment “in the vast majority of cases”.
Three decisions to make first
First, pick the tool you will approve. A policy without one is a ban with an explanation attached.
Second, reuse the data classes your information security policy already has. A separate scheme for AI only creates labels nobody remembers.
Third, decide who signs off: usually the data protection officer, information security and HR. In several EU countries a works council or staff representatives must be consulted as well. Check that before the rollout date.
The template
Each rule is in a quote block, ready to copy. The note underneath says where it comes from.
1. Purpose and scope
This policy governs the use of AI applications, in particular large language models and AI assistants, for work purposes at [Organisation]. It applies to all employees and to contractors and other persons who use AI applications on our behalf.
Art. 4 covers “other persons” acting on your behalf; the Commission's examples include a contractor and a service provider. A policy alone does not bind a contractor, so reference it in the contract.
2. Approved tools and accounts
Only the AI applications listed in Appendix A may be used for work, and only through accounts provided by [Organisation]. Personal accounts and publicly available web services must not be used for work content. AI features built into software we already use count as approved only once they appear in Appendix A.
The last sentence covers assistants that arrive by software update. Without it, every new button is approved by default. The NCSC asks staff to “think carefully about which apps and services” they use before sharing data.
3. Permitted and prohibited purposes
Permitted, for example: drafting text, summarising documents, translation, research in approved knowledge sources, coding assistance. Not permitted, for example: [screening job applications], [assessing employee performance], [deciding on customer or citizen applications].
Concrete examples work better than categories. The bracketed ones are deliberate: under Annex III of the AI Act, AI used in recruitment and in decisions about workers is high-risk.
4. What may be entered
What may be entered depends on the classification of the information and on the tool (Appendix A):
| Classification | Example | Allowed in |
|---|---|---|
| Public | press release, published report | all approved tools |
| Internal | meeting notes without personal data, concepts | all approved tools |
| Confidential or personal data | client letters, HR cases, contracts | only tools that Appendix A approves for this class |
| Strictly confidential | health data, legally privileged material, trade secrets | only tools that Appendix A explicitly approves for this class; otherwise never |
This is the rule that does the real work.
5. Personal data
Anyone entering personal data enters only what the task requires. Removing names is not enough if the person can still be identified from the context.
Data minimisation is a principle under Art. 5(1)(c) of UK GDPR and EU GDPR. A review of “the only Spanish-speaking account manager in the Leeds office” identifies one person without a name. Replacing names with placeholders is pseudonymisation, and under Recital 26 GDPR pseudonymised data is still personal data.
6. Checking output
AI output is a draft. Whoever uses it checks the content, in particular figures, quotations, references and statements about people, and is responsible for it as for their own work.
Language models produce fluent text that can be wrong. The Information Commission's guidance points out that the accuracy principle applies to personal data in the output of an AI system as well as in its input.
7. Decisions about people
Decisions with legal or similarly significant effects on a person are made by a human who assesses the case. An AI suggestion must not be adopted without that assessment.
This mirrors Art. 22 of the EU GDPR. In the UK, Arts 22A to 22D of UK GDPR have replaced Art. 22 since 5 February 2026. A decision counts as solely automated if there is “no meaningful human involvement”, and safeguards such as human intervention and the right to contest apply. The rule keeps you clear of both regimes.
8. Labelling
Images, audio and video that were generated or altered with AI and appear authentic are labelled as AI-generated. Text that we publish to inform the public is reviewed and approved by a responsible person before publication, or else labelled as AI-generated.
Art. 50(4) of the AI Act has applied since 2 August 2026. For text, the duty covers publications on matters of public interest, unless the text has had human review and someone holds editorial responsibility. The rule goes further on purpose, because one habit is easier to teach than an exception.
9. Prohibited uses
The following are not permitted, among others: recognising employees' emotions, creating realistic depictions of real people without their consent, and circumventing technical blocks or safeguards.
Inferring emotions in the workplace has been prohibited in the EU since 2 February 2025 (Art. 5(1)(f) AI Act), except for medical or safety reasons. The other two items are common sense; written down, they become enforceable.
10. Training and point of contact
Before first use, staff complete an introduction to the approved tools and this policy. [Role or team] answers questions about AI use and maintains Appendix A.
This is your Art. 4 measure. Record who attended and what was covered. The Commission says staff using tools like ChatGPT should be informed about specific risks, “for example hallucination”.
11. Reporting mistakes
Anyone who has entered confidential or personal data into a tool that is not approved for it reports this without delay to [data protection contact]. Reporting a mistake promptly will not in itself lead to disciplinary action. This does not apply to deliberate breaches.
Under Art. 33 of UK GDPR and EU GDPR, a personal data breach must be reported to the regulator within 72 hours where feasible, unless it is unlikely to result in a risk to people, and every breach must be documented. Without the promise in the second sentence, you hear about mistakes too late. The NCSC makes the same point about a positive security culture.
12. New tools, review and effective date
New AI applications are added to Appendix A only after review by [information security] and [data protection]. This policy is reviewed at least once a year. It takes effect on [date].
The review before approval is often a data protection impact assessment. Annual review is a minimum, since a new model generation can change the risks faster.
Appendix A: approved tools
For each tool, Appendix A lists name and provider, the approved classifications, where data is processed, whether inputs are used for training, the contact person and the approval date.
How to make rule 4 workable
Everyone uses AI today, whether it is allowed or not. A policy only works once there is a tool people can use to follow it. Sascha Schumann, CEO Myra Security
Rule 4 asks for a decision with every single prompt. A tool that maps the classes onto settings takes most of that decision away. In Myra AI Workspace, for example, a project can be set to the access tier “Local only”. In such a project, cloud models, web search and external tools are blocked, and only Myra models are offered; they run on Myra's own EU infrastructure. The Myra-hosted models are available on paid self-service plans with the “EU-Gov” add-on.
Before sending, a coloured indicator next to the model picker shows where the text will go. Green (“Local model”, “Local + masking”) means it stays with Myra. Yellow (“Privacy on”) means personal data is replaced by placeholders before the text reaches an external provider and restored in the answer; this masking is available in every plan. Red (“Privacy off”) means the text goes to a third-party model unmasked. If the organisation enforces masking, users cannot switch it off. Myra does not use customer data to train AI models, and every answer is labelled “AI-generated”.
Myra logs admin changes and security events, and on request seals that log with a hash chain so that tampering is detectable; customer admins have no audit log view of their own. EU routing can be enforced so that requests to providers outside the EU are refused, and it is off by default. None of this replaces the policy. It makes rule 4 something people can follow on a busy afternoon.
More: Myra AI Workspace, AI for accountants and the German original, KI-Richtlinie Muster.
Frequently asked questions
Is an AI policy a legal requirement?
No law in the UK or the EU requires a document with that name. In the EU, Art. 4 of the AI Act requires deployers to take measures that support their staff's AI literacy, and a policy plus training is the easiest way to show that. Under UK GDPR and EU GDPR you must also be able to show that personal data entered into AI tools is handled lawfully.
Does the EU AI Act apply to a UK company?
Sometimes. Art. 2(1) covers deployers established in the EU and deployers in third countries “where the output produced by the AI system is used in the Union”. A UK firm with an EU subsidiary or EU clients should check the scope with counsel. UK GDPR applies regardless.
Do employees need an AI literacy certificate?
No. The European Commission says in its questions and answers on AI literacy that no certificate is needed. Since Regulation (EU) 2026/1744, employers also do not have to reach a specific level of literacy. Keep a record of the training and help you offered.
Can staff use their personal ChatGPT account for work?
The template says no. With a personal account, the organisation has no contract with the provider, no say over training settings and no way to delete what was entered. Rule 2 covers this.
Sources
- Regulation (EU) 2024/1689 (AI Act), Art. 2, 4, 5 and 50, EUR-Lex, retrieved 11 October 2026
- Regulation (EU) 2026/1744 (Digital Omnibus on AI), new Art. 4, EUR-Lex, retrieved 11 October 2026
- European Commission: AI Literacy, Questions and Answers, retrieved 11 October 2026
- Regulation (EU) 2016/679 (GDPR), Art. 4(5), 22, 33 and Recital 26, EUR-Lex, retrieved 11 October 2026
- UK GDPR, Art. 5, 22A to 22D and 33, legislation.gov.uk, retrieved 11 October 2026
- NCSC: ChatGPT and large language models, what's the risk? (14 March 2023), retrieved 11 October 2026
- Microsoft UK: Rise in shadow AI tools (Censuswide survey, 13 October 2025), retrieved 11 October 2026
- NCSC: The hidden risks of shadow AI (7 September 2026), retrieved 11 October 2026
- ICO: Guidance on AI and data protection, retrieved 11 October 2026