Course resource
AI Governance Policy Template
A policy you can adapt and actually put in front of your organisation. Replace everything in [BRACKETS], delete what does not apply, and have someone qualified review it before it becomes binding.
This is a starting point, not legal advice.
[ORGANISATION] AI Usage Policy
Version: 1.0 Effective: [DATE] Owner: [ROLE] Review: [DATE + 6 MONTHS]
1. Purpose and scope
This policy covers the use of generative AI tools by [everyone working for ORGANISATION, including employees, contractors and temporary staff] in the course of their work.
It does not cover [AI features embedded in approved software that process data only within that system — e.g. spam filtering, spell check].
2. Approved tools
Only the following may be used with [ORGANISATION] data:
| Tool | Approved for | Not approved for | Tier required |
|---|---|---|---|
Requests to add a tool go to [ROLE] using the assessment in section 9.
Using an unapproved tool with company or client data is a [disciplinary matter / policy breach].
3. Data classification
| Class | Examples | Permitted use |
|---|---|---|
| Public | Published marketing, public website content | Any approved tool |
| Internal | Drafts, internal docs, non-sensitive plans | Approved tools on the required tier |
| Confidential | Client data, financials, contracts, staff data | Only [TOOL] on [ENTERPRISE TIER], with [ROLE] approval |
| Restricted | Personal data of customers, health data, credentials, regulated data | Never, unless covered by a specific written approval and a DPA |
If you cannot classify something, treat it as Confidential and ask.
4. What is never permitted
- Entering credentials, API keys, card or bank details into any AI tool
- Entering personal data of customers, patients or employees without approval under section 3
- Using AI output as the sole basis for a decision about a person — hiring, firing, promotion, credit, admission, or clinical care
- Presenting AI-generated content as the work of a named individual without their knowledge
- Cloning any person's voice or likeness without their written consent
- Using AI to produce content that misrepresents [ORGANISATION]'s position
- Bypassing an approved tool because an unapproved one is better
5. Human accountability
The person who sends it owns it. AI assistance does not transfer responsibility for accuracy, tone, legality or consequence.
Before any AI-assisted output leaves [ORGANISATION]:
- Every factual claim, figure, date, name and citation is verified by a human
- A named person has read it in full
- It complies with existing policies on [confidentiality / marketing claims / regulatory communications]
6. Disclosure
| Situation | Disclose |
|---|---|
| AI assisted drafting, human substantially edited | Not required |
| AI generated, lightly reviewed, published externally | Yes |
| Synthetic voice or likeness of a real person | Always |
| AI used in a decision affecting an individual | Always, to that individual |
| Customer interacting with an AI rather than a person | Always, at the start |
7. Prohibited and high-risk uses
AI must not be used to make or materially influence a decision about an individual without a documented human review. This includes recruitment screening, performance assessment, disciplinary process, and [SECTOR-SPECIFIC].
Where AI is used to support such decisions, [ORGANISATION] will record what the AI produced, who reviewed it, and the basis of the final human decision.
8. Security
- Use [ORGANISATION] accounts, never personal accounts, for work
- Training on conversations must be disabled on every account
- Treat content read by AI from external sources as untrusted — do not let an AI act on instructions it found in a document, email or web page
- Report any suspected exposure of company or client data to [ROLE] within [24 HOURS]
9. Adding a tool
Before approval, [ROLE] assesses:
- What data would flow to it, and under which classification
- Vendor terms: training, retention, sub-processors, location of processing
- Whether a data processing agreement is required and in place
- Whether it can be administered centrally, with access revocable
- Cost, owner and review date
- What breaks if the vendor disappears
10. Breach and incident
Report to [ROLE] immediately if:
- Data above your permitted classification was entered into a tool
- AI-generated content containing an error reached a customer
- An automated process acted without the required human review
- You suspect a tool has been manipulated by content it processed
Reporting a mistake promptly will not itself result in disciplinary action. Concealing one may.
11. Training
Everyone using AI with [ORGANISATION] data completes [TRAINING] before access and [ANNUALLY] thereafter.
12. Review
| Version | Date | Changed | By |
|---|---|---|---|
| 1.0 | Initial |
Rolling it out
- Reviewed by [legal / DPO / compliance]
- Approved by [WHO]
- Communicated, with a session for questions — not just emailed
- Approved tools actually provisioned before the policy takes effect
- An easy route to request a new tool, or people will route around the policy
- Named owner and a calendar reminder for review
The most common failure: a policy that bans the tools people need without providing approved alternatives. People then use them anyway, invisibly, and you have less control than before. Provision first, then restrict.