Home · Business · Legal & Compliance · Terms & policies

PARTLY

As of 13 August 2026, AI can only partly draft an information security policy for your UK business.

This still needs a person who signs their name to it.

Can you do it?

15 minutesto a draft.

2 hoursto something you’d act on.

Cost, all in£0

Skill neededchat-fluent

Who has to check ita professional

What the alternative costsNo price for a human alternative is supplied in the available tool data.

If this goes wrong: your policy promises controls that do not exist, leaving staff misled and your business exposed after a security incident or compliance challenge.

What to actually do

  1. Hand it to a person

    The route this page recommends

    Someone with a licence or accountable authority has to sign this before it counts.

  2. Use a tool built for this

    Second choice
  3. Do it yourself

    The distant third

    A chat interface, chat-fluent skill, and roughly 2 hours until you can act on the result.

    How to actually do it

    1. Open a document containing your current systems, devices, cloud services, suppliers, data types, staff arrangements, existing controls and incident contact details.
    2. Gather your contracts, insurance requirements, customer security questionnaires and any existing data protection or business continuity documents that affect security duties.
    3. Paste the supplied prompt into an AI chatbot and replace every bracketed slot with confirmed business information, leaving unknown points marked [TO CONFIRM].
    4. Paste relevant existing policies or extracts after the business facts, removing passwords, access keys, personal details and other unnecessary confidential information first.
    5. Ask the model to produce the policy and a separate list of unanswered questions, unsupported assumptions and controls that the business does not currently operate.
    6. Compare every stated control with your actual systems and procedures, ask the policy owner and technical lead to correct the draft, then send the revised policy to a solicitor or qualified information security professional for a serious compliance or risk review before approval.

    Prompt

    Draft an information security policy for a UK business using the facts below. This is a working draft, not professional advice. Do not invent controls, certifications, systems, suppliers, legal obligations or procedures. Where information is missing, write [TO CONFIRM] and add a short question explaining what must be decided.
    
    Business name: [BUSINESS NAME]
    Business type and sector: [SECTOR]
    Staff and contractors: [WHO USES SYSTEMS]
    Locations and remote-working arrangements: [LOCATIONS AND WORKING ARRANGEMENTS]
    Information handled: [PERSONAL DATA, CONFIDENTIAL DATA, FINANCIAL DATA AND OTHER INFORMATION]
    Important systems and devices: [SYSTEMS, CLOUD SERVICES, LAPTOPS, PHONES AND NETWORKS]
    Key suppliers and outsourced services: [SUPPLIERS]
    Current security controls: [BACKUPS, MULTI-FACTOR AUTHENTICATION, ANTIVIRUS, PATCHING, ACCESS REVIEWS, TRAINING AND OTHER CONTROLS]
    Incident reporting contact: [NAME OR ROLE AND CONTACT METHOD]
    Business continuity arrangements: [BACKUPS, RECOVERY ARRANGEMENTS AND ALTERNATIVE WORKING]
    Relevant customer, insurer or supplier requirements: [REQUIREMENTS]
    Policy owner and approval date: [OWNER AND DATE]
    Review interval: [INTERVAL]
    
    Structure the policy with these headings: purpose and scope; information security responsibilities; acceptable use; access control and passwords; multi-factor authentication; devices and remote working; software and updates; data handling and sharing; backups and recovery; suppliers and third parties; incident reporting and response; staff training; monitoring and enforcement; exceptions; review and approval. For each section, state the actual rule, who is responsible and what evidence would show it is being followed. Separate confirmed facts from recommendations and open questions. Keep the language suitable for UK staff and avoid claiming that the policy guarantees compliance with UK GDPR, the Data Protection Act 2018 or any certification standard.

    Open it prefilled in ChatGPT or Claude, or copy it into Gemini, which takes no prefill link.

What it gets wrong

  • AI cannot know whether your stated controls operate in practice or whether staff follow them.
  • AI cannot decide which security risks your business should accept, reduce, transfer or avoid without informed business judgement.
  • AI cannot confirm that the policy meets every customer contract, insurer condition, regulatory duty or certification requirement.
  • AI cannot take responsibility for the policy or respond to an incident when its wording is wrong.
  • AI cannot replace implementation, such as configuring access controls, testing backups or training staff.

What caps this at PARTLY: legal accountability, verification cost and context depth.

How we scored this

Five axes, each scored nought to two by hand: ten means AI carries the task cleanly, and the thresholds that turn a total into YES, PARTLY or NO are published in the methodology. Each axis name links to its definition.

AxisScore (0–2)
Output2
Inputs1
Verification1
Liability1
Effort delta2
Total7 / 10

FAQ

Can ChatGPT write an information security policy?
Yes, it can produce a useful first draft from your business facts, systems and existing controls. It cannot confirm that the controls exist or that the policy meets your legal, contractual and insurance requirements.
Is an AI-generated information security policy legally valid in the UK?
There is no general rule that makes an AI-generated policy valid simply because a model wrote it. The policy must accurately describe your organisation and fit its duties and contracts, and this is not professional advice.
What information does AI need to write a security policy?
Give it your systems, devices, data types, staff and remote-working arrangements, suppliers, current controls, incident process, backup arrangements and external requirements. Do not paste passwords, access keys or unnecessary personal data.
Should a solicitor review my information security policy?
A solicitor should review it where the policy affects contractual duties, regulated activity, data protection risk or a serious dispute. A qualified information security professional should also check whether the technical controls are realistic and implemented.

Nearby answers

Assessed by gpt-5.6-luna (gpt-5.6-luna) on 2026-08-13, second-checked by an independent model. Wrong somewhere? Email [email protected] and it gets re-checked.

The newsletter

AI news, new answers and product picks, straight to your inbox.