Course resource

AI Governance Policy Template

A policy you can adapt and actually put in front of your organisation. Replace everything in [BRACKETS], delete what does not apply, and have someone qualified review it before it becomes binding.

This is a starting point, not legal advice.


[ORGANISATION] AI Usage Policy

Version: 1.0 Effective: [DATE] Owner: [ROLE] Review: [DATE + 6 MONTHS]

1. Purpose and scope

This policy covers the use of generative AI tools by [everyone working for ORGANISATION, including employees, contractors and temporary staff] in the course of their work.

It does not cover [AI features embedded in approved software that process data only within that system — e.g. spam filtering, spell check].

2. Approved tools

Only the following may be used with [ORGANISATION] data:

Tool Approved for Not approved for Tier required

Requests to add a tool go to [ROLE] using the assessment in section 9.

Using an unapproved tool with company or client data is a [disciplinary matter / policy breach].

3. Data classification

Class Examples Permitted use
Public Published marketing, public website content Any approved tool
Internal Drafts, internal docs, non-sensitive plans Approved tools on the required tier
Confidential Client data, financials, contracts, staff data Only [TOOL] on [ENTERPRISE TIER], with [ROLE] approval
Restricted Personal data of customers, health data, credentials, regulated data Never, unless covered by a specific written approval and a DPA

If you cannot classify something, treat it as Confidential and ask.

4. What is never permitted

5. Human accountability

The person who sends it owns it. AI assistance does not transfer responsibility for accuracy, tone, legality or consequence.

Before any AI-assisted output leaves [ORGANISATION]:

6. Disclosure

Situation Disclose
AI assisted drafting, human substantially edited Not required
AI generated, lightly reviewed, published externally Yes
Synthetic voice or likeness of a real person Always
AI used in a decision affecting an individual Always, to that individual
Customer interacting with an AI rather than a person Always, at the start

7. Prohibited and high-risk uses

AI must not be used to make or materially influence a decision about an individual without a documented human review. This includes recruitment screening, performance assessment, disciplinary process, and [SECTOR-SPECIFIC].

Where AI is used to support such decisions, [ORGANISATION] will record what the AI produced, who reviewed it, and the basis of the final human decision.

8. Security

9. Adding a tool

Before approval, [ROLE] assesses:

10. Breach and incident

Report to [ROLE] immediately if:

Reporting a mistake promptly will not itself result in disciplinary action. Concealing one may.

11. Training

Everyone using AI with [ORGANISATION] data completes [TRAINING] before access and [ANNUALLY] thereafter.

12. Review

Version Date Changed By
1.0 Initial

Rolling it out

The most common failure: a policy that bans the tools people need without providing approved alternatives. People then use them anyway, invisibly, and you have less control than before. Provision first, then restrict.

Back to dashboard