Home · Business · HR & People · Policies & handbooks
As of 13 August 2026, AI can only partly create a bring your own device policy.
This still needs a person who signs their name to it.
Can you do it?
15 minutesto a draft.
1 hourto something you’d act on.
Cost, all in£0
Skill neededchat-fluent
Who has to check ita professional
What the alternative costsThe supplied tool data gives no price for a specialist HR or employment solicitor service.
If this goes wrong, the policy can conflict with your actual security controls or employee rights and expose the business to a data breach, dispute or enforcement problem.
What to actually do
Hand it to a person
The route this page recommends
Someone with a licence or accountable authority has to sign this before it counts.
Use a tool built for this
Second choiceDo it yourself
The distant thirdA chat interface, chat-fluent skill, and roughly 1 hour until you can act on the result.
How to actually do it
- Open your current information security policy, privacy notice, employment handbook and any mobile device management or remote access documentation.
- Ask your IT lead or managed service provider for the actual controls on personal devices, including permitted systems, authentication, encryption, updates, remote wipe, logging and incident response.
- Gather the business decisions on who may use personal devices, permitted personal use, payment of costs, support, accessibility, lost devices and access removal when someone leaves.
- Paste the gathered facts into the prompt, replacing each bracketed slot with a confirmed answer and leaving genuinely unknown items marked as unknown.
- Paste the resulting draft into your policy template and compare every operational statement against your actual IT controls, staff handbook and privacy notice.
- Send the draft and its unresolved decisions to your data protection lead and employment solicitor, then record their changes and approval before issuing it.
- Publish the approved policy through your normal staff channel and obtain any required acknowledgement without treating acknowledgement as a substitute for lawful monitoring or fair employment practice.
Prompt
Create a UK bring your own device policy for [BUSINESS NAME], a [BUSINESS TYPE] with [NUMBER OR DESCRIPTION OF WORKERS] workers. Use the facts below and do not invent any business rule, technical control, legal requirement, supplier, retention period or monitoring practice. If information is missing, mark it [DECISION NEEDED] and ask a concise question rather than guessing. Business facts: - Who may use personal devices: [STAFF, CONTRACTORS, OTHERS] - Devices and operating systems allowed: [DETAILS] - Business systems and data accessible from personal devices: [DETAILS] - Required security controls, such as passwords, screen lock, encryption, updates, antivirus, remote wipe or mobile device management: [DETAILS] - Whether personal use is allowed: [DETAILS] - Whether the business monitors devices, accounts, traffic or activity: [DETAILS] - What happens when a device is lost, stolen, shared or compromised: [DETAILS] - Who pays for devices, repairs, mobile data and support: [DETAILS] - Joiners, movers and leavers process: [DETAILS] - Incident reporting contact and timescale: [DETAILS] - Accessibility or reasonable adjustment requirements: [DETAILS] - Existing privacy notice, information security policy and disciplinary policy: [DETAILS] Draft a plain-English policy with these sections: purpose and scope; permitted use; security requirements; access to business data; personal use; monitoring and privacy; costs and support; lost or compromised devices; reporting incidents; leaving the business; breaches of the policy; accessibility and exceptions; responsibilities; approval and review. Separate employee obligations from the business's obligations. Identify every point that needs confirmation from our IT lead, data protection lead or employment solicitor. Do not claim that consent automatically makes monitoring lawful, do not give a definitive legal conclusion, and include the sentence "This draft is not professional advice." End with a short implementation checklist and a list of unresolved decisions.
Open it prefilled in ChatGPT or Claude, or copy it into Gemini, which takes no prefill link.
What it gets wrong
- AI cannot know which security controls your business actually operates, so it can describe safeguards you do not have.
- AI cannot decide whether proposed monitoring of personal devices is lawful and proportionate in your circumstances.
- AI cannot resolve how the policy interacts with contracts, collective arrangements, disciplinary procedures or reasonable adjustments.
- AI cannot take responsibility for the policy, its implementation or the consequences of a data breach or employee dispute.
What caps this at PARTLY: legal accountability, verification cost and private data access.
How we scored this
Five axes, each scored nought to two by hand: ten means AI carries the task cleanly, and the thresholds that turn a total into YES, PARTLY or NO are published in the methodology. Each axis name links to its definition.
| Axis | Score (0–2) |
|---|---|
| Output | 2 |
| Inputs | 1 |
| Verification | 1 |
| Liability | 1 |
| Effort delta | 2 |
| Total | 7 / 10 |
The methodology and its thresholds are published in full.
FAQ
- Can ChatGPT write a BYOD policy?
- Yes, it can produce a useful first draft from your business facts. It cannot know your real technical controls or decide whether monitoring and data access are lawful, so the finished policy needs checking by your IT and data protection leads and, for serious issues, an employment solicitor.
- What should a UK BYOD policy include?
- It should cover permitted devices, security controls, access to business data, personal use, monitoring and privacy, costs, support, lost devices, incident reporting, offboarding, accessibility and breaches. It should also match your privacy notice, information security controls and employment procedures.
- Is a BYOD policy a legal requirement in the UK?
- There is no single standard BYOD policy that every UK business must use. Your arrangements still need to deal properly with data protection, security, privacy and employment responsibilities, and this draft is not professional advice.
- Can my employer monitor my personal phone under a BYOD policy?
- A policy alone does not make monitoring lawful. The business needs a clear, proportionate and properly explained approach that fits its data protection and employment responsibilities, and a serious or disputed case needs advice from a data protection specialist or employment solicitor.
Nearby answers
- Can AI create a company car policy for my UK business?PARTLY
- Can AI create a menopause policy for my UK workplace?PARTLY
- Can AI create an equal opportunities policy for my UK business?PARTLY
- Can AI write a grievance policy for my UK business?PARTLY
- Can AI write a mental health policy for my UK employees?PARTLY
- Can AI write an AI use policy for my UK workplace?PARTLY
Assessed by gpt-5.6-luna (gpt-5.6-luna) on 2026-08-13, second-checked by an independent model. Wrong somewhere? Email [email protected] and it gets re-checked.
The newsletter
AI news, new answers and product picks, straight to your inbox.