Home · Business · Legal & Compliance · Terms & policies

YES

As of 13 August 2026, AI can draft an AI use policy for your UK business.

This still needs a person who signs their name to it.

Can you do it?

15 minutesto a draft.

1 hourto something you’d act on.

Cost, all in£0

Skill neededchat-fluent

Who has to check ita professional

What the alternative costsGenie AI is a UK-focused AI legal assistant for drafting and reviewing everyday contracts.

If this goes wrong, staff may use AI with confidential or personal data in ways your business has not controlled, leaving you to investigate and amend the policy after the breach or dispute.

What to actually do

  1. Hand it to a person

    The route this page recommends

    Someone with a licence or accountable authority has to sign this before it counts.

  2. Use a tool built for this

    Second choice
  3. Do it yourself

    The distant third

    A chat interface, chat-fluent skill, and roughly 1 hour until you can act on the result.

    How to actually do it

    1. Open a document containing your current confidentiality, information-security, data-protection, records-retention and staff handbook rules.
    2. Gather the names of every AI tool staff use or want to use, the roles covered, and examples of permitted and prohibited work.
    3. List the kinds of personal, confidential, commercially sensitive and customer data the business handles, including anything that must never be pasted into an AI tool.
    4. Paste those materials and facts into the prompt, replacing each bracketed slot and keeping any source text that the policy must reflect.
    5. Ask the model to produce the policy, staff checklist, decision table and missing-decision list in one response.
    6. Compare every rule in the draft with your existing policies, approved-tool list and actual approval process, then remove any control the business does not operate.
    7. Check the draft's legal and data-protection points against current GOV.UK and ICO guidance, and send the final draft to a UK solicitor for review before adopting it for higher-risk uses.

    Prompt

    Draft an internal AI use policy for a UK business using only the information in this prompt and the attached source material. Do not invent laws, regulators, business facts, safeguards, approvals, suppliers or technical controls. Where information is missing, write [BUSINESS DECISION NEEDED] and list the question.
    
    Business details:
    - Business name and sector: [INSERT]
    - Business size and locations: [INSERT]
    - Staff, contractors and other users covered: [INSERT]
    - Customers, suppliers or other people affected: [INSERT]
    - AI tools currently approved or under consideration: [INSERT]
    - Business data that may be entered into AI tools: [INSERT]
    - Data that must never be entered: [INSERT]
    - Existing information-security, confidentiality, data-protection and records-retention rules: [INSERT]
    - Human approval required before using AI output: [INSERT]
    - Person or role responsible for policy questions and incidents: [INSERT]
    - Relevant business processes and higher-risk uses: [INSERT]
    
    Produce:
    1. A plain-English policy with sections for purpose, scope, permitted use, prohibited use, handling of personal and confidential data, checking AI output, intellectual property and confidentiality, human accountability, record keeping, incident reporting, training, monitoring, exceptions and review.
    2. A short staff checklist of actions and prohibited actions.
    3. A decision table showing when staff may use AI, when manager approval is needed and when a solicitor or other specialist should be consulted.
    4. A list of every assumption, missing decision and statement that needs confirmation.
    5. A source-checking list that identifies which points should be checked against current GOV.UK, ICO or other applicable official guidance. Do not claim that the policy is legally compliant or suitable without professional review.
    
    Use British English, a practical tone and headings that can be pasted into a staff handbook. Separate policy requirements from recommendations. Do not include invented penalties, legal citations or fixed review dates.

    Open it prefilled in ChatGPT or Claude, or copy it into Gemini, which takes no prefill link.

What it gets wrong

  • AI cannot decide which uses of AI are acceptable for your business risk appetite or client commitments.
  • AI cannot know whether your stated controls actually operate in practice or whether staff will follow them.
  • AI cannot confirm that the policy covers the specific personal-data processing, contracts and regulated activities in your business.
  • AI cannot take responsibility for a breach, employment dispute or regulatory response caused by an inadequate policy.
  • AI cannot replace a solicitor's judgement on unusual, high-risk or legally disputed uses.

Even on a YES, the friction has a name: legal accountability, verification cost and context depth.

How we scored this

Five axes, each scored nought to two by hand: ten means AI carries the task cleanly, and the thresholds that turn a total into YES, PARTLY or NO are published in the methodology. Each axis name links to its definition.

AxisScore (0–2)
Output2
Inputs2
Verification1
Liability1
Effort delta2
Total8 / 10

FAQ

Can ChatGPT write an AI policy for my business?
Yes, it can produce a useful first draft from your actual tools, data rules, staff roles and approval process. The result is not professional advice, and a UK solicitor should review serious legal, contractual or regulatory risks before you adopt it.
What should an AI use policy include?
It should cover approved and prohibited uses, personal and confidential data, checking AI output, human accountability, intellectual property, records, incidents, training and monitoring. It should also name who approves exceptions and what staff must do when an AI result is wrong.
Is an AI-generated business policy legally compliant?
Not automatically. You must compare it with your actual operations and current UK guidance, and the business remains responsible for its contents; this is not professional advice, so ask a UK solicitor to review a serious or high-risk case.
Can I use AI to make an AI policy GDPR compliant?
AI can organise your data-handling rules and identify questions for checking, but it cannot establish that your processing has a lawful basis or that your safeguards are adequate. For material personal-data processing, ask a solicitor or suitably qualified data-protection professional to review it.

Nearby answers

Assessed by gpt-5.6-luna (gpt-5.6-luna) on 2026-08-13, second-checked by an independent model. Wrong somewhere? Email [email protected] and it gets re-checked.

The newsletter

AI news, new answers and product picks, straight to your inbox.