Home · Business · Legal & Compliance · Terms & policies

PARTLY

As of 13 August 2026, AI can only partly draft an acceptable use policy for your UK business.

This still needs a person who signs their name to it.

Can you do it?

15 minutesto a draft.

1 hourto something you’d act on.

Cost, all in£0

Skill neededchat-fluent

Who has to check ita professional

What the alternative costsA solicitor is the appropriate alternative when the policy needs legal review or must support serious disciplinary, employment or contractual action.

If this goes wrong: the policy omits an important restriction or uses wording you cannot enforce consistently, creating operational or legal problems when an incident occurs.

What to actually do

  1. Hand it to a person

    The route this page recommends

    Someone with a licence or accountable authority has to sign this before it counts.

  2. Use a tool built for this

    Second choice
  3. Do it yourself

    The distant third

    A chat interface, chat-fluent skill, and roughly 1 hour until you can act on the result.

    How to actually do it

    1. Open a document and record the business name, sector, people covered, systems covered and the policy owner.
    2. Gather your current IT, information security, data protection, employee handbook and disciplinary documents, and note any rules that the acceptable use policy must match.
    3. Ask the people responsible for IT, HR and data protection to supply the permitted uses, prohibited uses, personal-use rules, monitoring practices, reporting route and enforcement process.
    4. Paste the collected information into the prompt, replacing every bracketed slot and leaving a slot marked unknown where the business has not decided the answer.
    5. Paste the generated policy into the document and compare each rule against your actual systems, contracts, staff handbook, monitoring notices and disciplinary process.
    6. Send the draft, its missing-information table and its professional-review flags to a UK solicitor, then apply their changes before issuing the policy.
    7. Give the approved version a policy owner, effective date, review process and distribution route, and keep evidence of which users received it.

    Prompt

    Draft an acceptable use policy for a UK business using the information below.
    
    Business name: [business name]
    Business type and sector: [description]
    People covered: [employees, contractors, agency workers, customers, suppliers or other users]
    Systems and equipment covered: [email, messaging, cloud services, devices, networks, software, AI tools and other systems]
    Permitted uses: [list]
    Prohibited uses: [list]
    Rules on personal use: [details]
    Rules on confidential information and personal data: [details]
    Rules on passwords, access, devices and software: [details]
    Rules on monitoring and logging: [details]
    Rules on generative AI: [details]
    Reporting route for suspected misuse: [details]
    How breaches are handled: [details]
    Related policies or contracts: [list]
    Policy owner and review process: [details]
    
    Write in clear UK English for the intended readers. Do not invent business facts, legal obligations, monitoring practices or penalties. Where information is missing, insert a clearly labelled question rather than guessing. Separate operational rules from legal commentary. Flag clauses that need a UK employment or commercial solicitor to review, especially monitoring, personal data, disciplinary action, intellectual property, confidentiality and use by customers or contractors. Include sections for purpose and scope, acceptable use, prohibited use, security, personal data and confidentiality, generative AI, monitoring, reporting concerns, breaches and enforcement, exceptions, related documents, ownership and review. After the policy, provide a table of missing information and a list of points requiring professional review.

    Open it prefilled in ChatGPT or Claude, or copy it into Gemini, which takes no prefill link.

What it gets wrong

  • AI cannot decide which uses your business should permit or prohibit when the risk appetite has not been agreed.
  • AI cannot know whether the proposed monitoring matches your actual systems, privacy notices and employment arrangements.
  • AI cannot confirm that disciplinary wording is lawful, proportionate and consistent with your contracts and procedures.
  • AI cannot take responsibility for the policy or approve it for use with employees, contractors, customers or suppliers.
  • AI cannot replace a solicitor where the policy creates contractual, employment, data protection or enforcement consequences.

What caps this at PARTLY: legal accountability, judgement under ambiguity and verification cost.

How we scored this

Five axes, each scored nought to two by hand: ten means AI carries the task cleanly, and the thresholds that turn a total into YES, PARTLY or NO are published in the methodology. Each axis name links to its definition.

AxisScore (0–2)
Output2
Inputs1
Verification1
Liability1
Effort delta2
Total7 / 10

FAQ

Can ChatGPT write an acceptable use policy?
Yes, it can produce a useful first draft from your business rules, systems and intended audience. It cannot decide your rules, confirm that monitoring and enforcement wording is lawful, or take responsibility for the final policy.
Is an AI-generated acceptable use policy legally valid in the UK?
The fact that AI drafted it does not make it valid or invalid. A UK solicitor should check the policy against your contracts, employment procedures, data protection arrangements and how you intend to enforce it.
What should an acceptable use policy include?
It usually covers scope, permitted and prohibited use, security, personal data, confidentiality, generative AI, monitoring, reporting concerns and consequences of breaches. The exact content depends on your systems, users, contracts and enforcement process.
Should a solicitor review my acceptable use policy?
Yes, particularly if it applies to employees, contractors or customers, or includes monitoring, disciplinary action, personal data, confidentiality or contractual obligations. This is not professional advice, and a UK solicitor should carry the risk of serious legal decisions.

Nearby answers

Assessed by gpt-5.6-luna (gpt-5.6-luna) on 2026-08-13, second-checked by an independent model. Wrong somewhere? Email [email protected] and it gets re-checked.

The newsletter

AI news, new answers and product picks, straight to your inbox.