Ask a UK small business owner whether their team uses AI at work. Most say yes, informally. Someone drafts client emails with ChatGPT. Someone else pastes meeting notes into Copilot for a summary.
Nobody wrote the rule that made either one fine. Nobody wrote a rule at all.
That gap, between what staff actually do and what you have decided is safe, is where incidents start. A client's name typed into a free chatbot. A pricing sheet copied into a prompt. A report sent out that nobody checked.
Most businesses answer that gap in one of two ways. Both fail the same way in the end.
Some ban AI outright. That mostly teaches staff to use it quietly, on personal accounts, further from view than before. Others say nothing, which leaves the same hidden use in place with no rules attached to it.
Neither one changes what people do at their desks. It only changes whether you can see it.
Our free AI policy generator turns that gap into a document in minutes. But a policy only earns its place if every clause is doing a job. Here is what the generator produces, clause by clause, and why each one exists.
The tools allowlist
Without a stated list, staff each pick which AI product to trust with company information. Usually whichever one they already use at home. On a free consumer account nobody at the business can see into.
Naming the approved tools turns that unspoken default into a written one. It also forces a second decision alongside it. Who signs off anything not on the list?
Skip that second part and the list dies within a month. A new tool slips in through someone's personal login the moment the approved ones feel slow.
The point is not to be strict for its own sake. A short, named list people actually read beats a long compliance document nobody opens. And it gives you one place to update when a tool gets dropped or a better one replaces it.
Data handling
This clause decides what a well-meaning employee is allowed to type into a chat window. At the moment they are about to type it.
The generator offers a real choice rather than a single stance. Block personal and client data outright. Allow it once identifying details are stripped. Or allow it only with written consent and a named sign-off.
None of these read as box-ticking. Each is a rule a busy employee can remember and apply without opening the full document.
Training
Most policy templates skip this one. It is about what AI vendors do with what you type, not what the tool gives back.
Many consumer AI accounts use submitted prompts to train future versions of the model. That stops only when an enterprise setting or a "do not train on my data" switch is turned on. It is rarely on by default.
Put a pricing strategy or an unreleased plan into a free-tier account with that switch off. There is no way to pull it back out of a future training run.
The clause exists to make that setting a deliberate choice. Not a default nobody in the business ever noticed.
Human review
AI output reads confidently whether or not it is correct. That is exactly the problem this clause addresses.
It draws one line. Nothing AI-assisted leaves the business without a person reading it first. Client work, published content, a set of figures. Someone reads it, and that someone is accountable for sending it.
This is the clause that stops "the AI wrote it" becoming an excuse once something has gone out wrong. Accountability stays with whoever pressed send, not with the tool.
That single sentence does more work than any amount of general caution about AI being fallible. It gives every piece of AI-assisted work a named human owner before it leaves the building. That is the actual control, not a reminder to use your judgement.
Disclosure
Disclosure is about honesty with the people your work reaches. It is not a badge stamped on every output.
It commits you to a straight answer when a client or customer asks how something was produced. Better that than letting them assume more manual effort went in than really did.
It matters most exactly where trust matters most. Contract work. Regulated content. Anything a client is paying for the judgement behind, not just the words.
Incidents
Policies fail quietly when there is no route for someone to admit a mistake.
This clause names who to tell if personal or confidential data ends up somewhere it should not. And it says plainly that reporting early gets treated better than staying silent and hoping.
Without it, the first real slip becomes the moment everyone learns the policy had no way to handle exactly this. They learn it the hard way.
Review dates
AI tools change faster than most businesses update their internal documents.
This clause puts a date in the calendar, on whichever cycle fits you. Otherwise the policy gets signed once and left to go stale. Meanwhile the tools named in the allowlist get swapped out underneath it.
A policy with no review date quietly stops matching how the business actually works. Usually without anyone deciding that on purpose.
Put the rules in writing
None of this needs a lawyer to start. Answer a short set of questions in the AI policy generator. You get a complete policy filled in for your business, in plain English, ready to download and adapt.
Generate it. Change anything that does not fit how your team actually works. Then walk through it together in one short meeting, rather than an email nobody opens.
Would you rather talk through where your AI use carries risk before you write anything down? Talk to us and bring whichever part of it worries you most.
Either way, the aim is the same. What your team already does quietly becomes something you decided on purpose.
