Home · Business · HR & People · Policies & handbooks

PARTLY

As of 13 August 2026, AI can only partly write an AI use policy for your UK workplace.

This still needs a person who signs their name to it.

Can you do it?

15 minutesto a draft.

1 hourto something you’d act on.

Cost, all in£0

Skill neededchat-fluent

Who has to check ita professional

What the alternative costsThe available tool data gives no price for a human UK HR policy service.

If this goes wrong, staff may follow unclear or unlawful rules about AI, personal data, monitoring or employment decisions, leaving your organisation to deal with the consequences.

What to actually do

  1. Hand it to a person

    The route this page recommends

    Someone with a licence or accountable authority has to sign this before it counts.

  2. Use a tool built for this

    Second choice
  3. Do it yourself

    The distant third

    A chat interface, chat-fluent skill, and roughly 1 hour until you can act on the result.

    How to actually do it

    1. Open your current data protection, information security, equality, monitoring, conduct and disciplinary policies, then record their owners, approval routes and review dates.
    2. Gather an inventory of the AI tools and AI-enabled features staff currently use or want to use, including where they process personal, confidential or customer data.
    3. Ask HR, IT, information governance and senior management to list permitted uses, prohibited uses, required human checks, reporting routes and consequences for misuse.
    4. Paste those details into the prompt and ask the chatbot to produce the policy, unresolved decisions and launch checklist.
    5. Compare every operational instruction in the draft with your existing policies, approved tools, data flows, retention rules and incident process, correcting anything that does not match.
    6. Send the marked draft to your HR lead, data protection lead and, for serious or uncertain issues, an employment solicitor or data protection specialist for review.
    7. Record the approval decision, consult affected workers where required, publish the final policy with an owner and review date, and provide staff training on the approved uses and reporting route.

    Prompt

    Draft a UK workplace AI use policy for [organisation name], a [sector] organisation with approximately [number] workers in [locations]. Use the information below and invent nothing.
    
    Organisation details:
    - Main services and worker groups: [details]
    - AI tools currently used or under consideration: [list]
    - Business processes where AI may be used: [list]
    - Uses that management wants to permit: [list]
    - Uses that management wants to prohibit: [list]
    - Existing policies on data protection, information security, equality, conduct, monitoring and disciplinary action: [summaries or links]
    - Internal owner and approval route: [details]
    - Consultation requirements: [details]
    - Retention, access and incident-reporting processes: [details]
    
    Write a practical policy with these headings: purpose and scope; definitions; permitted uses; prohibited uses; personal and confidential data; human review and decision-making; accuracy, bias and accessibility; intellectual property and confidentiality; approved tools and account controls; monitoring and records; training and reporting concerns; breaches and consequences; governance, review and approval.
    
    Make clear that AI must not be the sole basis for employment, performance, disciplinary, recruitment or other significant decisions. Do not create new legal duties, guarantees, tool approvals, retention periods or disciplinary sanctions. Where UK law or a specialist judgement is relevant, mark the point [CHECK WITH HR OR LEGAL ADVISER] and explain what must be checked. Distinguish legal requirements from optional organisational controls. Use plain British English, short sections and operational wording. End with a list of unresolved decisions and a launch checklist for the policy owner. This is a working draft, not professional advice.

    Open it prefilled in ChatGPT or Claude, or copy it into Gemini, which takes no prefill link.

What it gets wrong

  • AI cannot decide which uses your organisation is willing to accept, especially where productivity, confidentiality, surveillance or job security conflict.
  • AI cannot know whether your proposed controls match your contracts, collective arrangements, systems, data flows or existing disciplinary process.
  • AI cannot take responsibility for discrimination, unlawful monitoring, a data breach or an employment dispute caused by the policy.
  • AI cannot replace consultation with workers or approval by the people who own HR, information governance and operational risk.
  • The draft still needs specialist scrutiny where employment law or data protection consequences are serious; it is not professional advice.

What caps this at PARTLY: legal accountability, context depth and judgement under ambiguity.

How we scored this

Five axes, each scored nought to two by hand: ten means AI carries the task cleanly, and the thresholds that turn a total into YES, PARTLY or NO are published in the methodology. Each axis name links to its definition.

AxisScore (0–2)
Output2
Inputs1
Verification1
Liability1
Effort delta2
Total7 / 10

FAQ

Can ChatGPT write an AI use policy for my workplace?
Yes, it can produce a useful first draft for a UK workplace. It cannot decide your organisation's risk boundaries or confirm that the policy fits employment, equality and data protection requirements, so HR and an appropriate specialist must check it.
What should an AI use policy include?
It should cover permitted and prohibited uses, personal and confidential data, human review, accuracy and bias, approved tools, monitoring, reporting, training, breaches and governance. It should also name the policy owner, approval route and unresolved decisions rather than inventing rules.
Is it legal to use AI at work in the UK?
It can be lawful, but the answer depends on how the tool is used, what data it receives and whether it affects workers or employment decisions. This is not professional advice, and a serious case needs an employment solicitor or data protection specialist.
Can I use an AI-generated policy without HR or legal review?
You can use AI for the draft, but publishing it without checking creates avoidable organisational risk. Your HR, information governance and policy owners should verify it, with specialist legal review for serious or uncertain employment and data protection issues.

Nearby answers

Assessed by gpt-5.6-luna (gpt-5.6-luna) on 2026-08-13, second-checked by an independent model. Wrong somewhere? Email [email protected] and it gets re-checked.

The newsletter

AI news, new answers and product picks, straight to your inbox.