
The AI policy clauses most templates miss
A workable AI policy is short. But most templates skip the clauses that decide whether it protects you: what your tools are allowed to do, firm limits on what data can go in, who owns the output, when you tell clients, and a standing training line. Each comes with copy-paste wording.
Most downloadable AI policies are either too long to read or too vague to use. The ones that look complete usually skip the handful of clauses that actually decide whether the document protects you.
A usable policy is short.
Most templates also still assume the risk is a person pasting something into a chatbot. In 2026, AI tools act as well as answer. A policy has to cover what they are allowed to touch, not only what staff type in.
This piece gives you copy-paste wording for the five clauses templates miss: what your approved tools may do, the data that must never go in, who owns the output, what you tell clients, and a standing line on training. Adapt each to your firm and you have a policy that protects you when something goes wrong.
This is general information, not legal advice. Where an AI use touches personal data, regulated advice or client contracts, take proper advice on your own situation.
Why the shift from chatbots to agents breaks old templates
That shift is what dates most templates. They were written for a world where the risk was an employee pasting something sensitive into a public chatbot. That risk is real and still worth a clause. But it is now only half the picture.
These assistants do more than answer questions. They read across your files, draft in your systems, and, with the arrival of tools like ChatGPT's work connectors, reach into email, storage and internal apps under per-app permissions.
A policy that only governs what a person types in has nothing to say about what a tool is allowed to touch on their behalf. That gap is where the next avoidable problem is most likely to start.
So the clauses below are written for both: what people may do with AI, and what AI is allowed to do inside your business.
The five clauses templates miss
Here is the wording we use with firms. Each clause is one decision in plain language. Lift it, change the names and specifics to match your firm, and keep it to a line or two.
1. Approved tools, and what they are allowed to do
The common template names approved tools and stops. In the agent era you also have to say what those tools may reach. An assistant that can only answer questions is a different risk from one wired into your inbox and your client folders.
Approved tools. Staff may use [named tools, for example ChatGPT Team, Microsoft Copilot] for work. Any other AI tool, and any new connector, integration or automation that lets a tool read from or act in our systems, needs sign-off from [named owner] before it is switched on. Personal AI accounts are not to be used for client or company work.
The second sentence is the one templates leave out. It means a member of staff cannot quietly grant an assistant access to the shared drive without anyone deciding that was sensible.
2. The data red lines
"Be sensible with data" is not a rule. A rule names the things that must never go into a general AI tool, in words someone can act on without a lawyer.
Data that must never be entered. Do not put the following into any AI tool that is not on our approved list and covered by a business agreement: client or customer personal data, anything under an NDA, unpublished financial figures, login credentials or security details, and identifiable information about staff. If in doubt, treat it as off-limits and ask.
Keep the list specific to your firm. A recruiter's red lines are candidate records; an accountant's are client financials. The point is that a person reading it at four on a Friday knows exactly what not to do.
3. Who owns the output
This is the clause that is almost always missing, and it is the one that protects you. AI produces a confident draft, someone sends it, and when it turns out to be wrong there is no one who was clearly responsible for checking. The policy has to close that gap.
Accountability for AI output. AI output is a draft, not a decision. The named person doing the work is responsible for its accuracy, tone and suitability before it is used, exactly as they would be for their own writing. "The AI produced it" is not an explanation for an error that reaches a client.
This is not a new idea. The United States National Institute of Standards and Technology puts clear lines of accountability at the centre of its AI Risk Management Framework. You do not need the framework to borrow the point: name who owns the output.
4. What you tell clients
Firms tie themselves in knots over disclosure because the policy never settled it. Decide the default once, write it down, and the awkward case-by-case judgement disappears.
Disclosure. We use AI to help with drafting, research and routine work, and we are comfortable saying so. Where a client asks how we use AI, we answer plainly. Where AI has a material role in advice or work product a client relies on, we tell them without being asked. We do not present AI-generated work as bespoke human analysis when it is not.
Set the default that fits your firm and your client contracts. The point is to decide in advance, so no one has to improvise an answer while a client waits on the phone. Our note on what to say when a client asks how you use AI walks through it.
5. A standing line on training
The clause almost every template omits is training: a commitment that people are actually taught to use these tools well, not left to work it out alone. A policy assumes a level of judgement that only training builds.
Training and literacy. Everyone who uses AI for work will have basic training in what these tools do well, where they fail, and the rules in this policy. New joiners cover it in induction. We review this policy every [six months] as the tools change.
There is a regulatory reason to have this line too, though it needs care for a UK reader. The EU AI Act asks organisations that provide or deploy AI systems to see that their staff have a sufficient level of AI literacy. That duty, in the Act's Article 4, has applied since February 2025, and national enforcement of the Act opens in August 2026.
Two things matter for you. First, it reaches a UK firm only where it operates in the EU market or its AI outputs are used there. There is no equivalent standalone AI-literacy duty in UK law. Second, the duty looks set to be softened as the Act is amended, from a hard obligation to ensure literacy toward a lighter one to support it.
So treat the training line as good practice that also happens to cover you if the EU rules touch your work, not as an EU deadline you have to beat.
Keeping it to one page
Five clauses, plus the basics most templates get right (permitted uses, a checking step, where to ask for help), is a one-page document. That is the target, and keeping it that short is harder than it sounds.
A policy people can hold in their heads is one they follow on a Tuesday without asking anyone. A twenty-page policy is one nobody has read, so it protects you no better than having none at all. If your current document runs longer than a page, the useful edit is almost always cutting, not adding.
If you have no policy at all yet, start with our short, seven-line version and add these clauses to it.
Making people actually follow it
A policy is followed when three things are true. People have read it, which means it is short and someone walked them through it. People know who to ask, which means a name, not a mailbox. And the tools they are given make the safe choice the easy one, which is why the approved-tools clause matters more than any warning.
Most breaches happen because someone was unsure and guessed instead of asking.
The related trap is shadow use, the AI quietly running on personal accounts because the sanctioned option is worse. If your staff are working around your policy, the policy is usually the problem, not the people. We cover that signal in shadow AI is a management signal.
Write the five clauses this week. Put a name against each tool and each red line. That is a morning's work, and it is the difference between a document that sits in a folder and one that holds up when something goes wrong.
If you would like a second pair of eyes on your policy, or help making it one your team will use, book a call and we will walk through it with you.
Common questions
How long should an AI policy be? One page. Short enough that an ordinary member of staff can read it once and apply it without asking. A long policy is not a thorough one, and a policy nobody finishes reading protects no one.
Do we legally need an AI policy in the UK? There is no single UK law that says "have an AI policy". But your existing duties under data protection law, employment law and your client contracts all apply to AI use, and a short policy is the practical way to meet them. Where an AI use is higher-risk, take proper advice.
Does the EU AI Act apply to a UK business? Only where you operate in the EU market or your AI outputs are used there. For a purely UK firm it generally does not apply, though the way the rules are heading, and the training habit they encourage, are worth adopting anyway.
This article is general information, not legal advice. AI, data protection and contract obligations depend on your specific circumstances; take advice on your own situation before relying on any of the above.