Updated

AI Policy Template

An AI-positive policy that tells people what they can do with AI, not only what they can't, with clear rules for data, accounts and agents that act on their behalf.

What's inside this template

Who it's for

CIOs, programme leads, legal, DPOs and HR teams writing or updating the policy that governs how employees use AI tools

When to use

Before you roll out Claude or another AI tool, when you add agents or connectors, or when your current policy was written before either existed

Key benefit

A short policy people read and follow: encouraging by default, precise about data, and current on agents, connectors and personal accounts

Sections included

  • Our AI policy in plain English
  • Purpose and scope
  • Our approach to AI
  • Approved tools, and company versus personal accounts
  • Encouraged uses
  • Data rules, by type of information
  • Agents, connectors and automation
  • Checking and owning the output
  • Getting a new tool approved
  • Training, support and AI literacy
  • Monitoring
  • Review
  • Getting help
  • Appendix: approved tools

Complete template content

Claude skill ai-policy

This page comes with an installable skill. Install it, tell Claude what you are working on, and it works through the method on this page with you and produces the output.

Claude desktop or Claude.ai

Download the .zip, then go to Settings, Capabilities, Skills, and upload it.

Claude Code

Unzip it into ~/.claude/skills/ for every project, or .claude/skills/ for one. Then run /ai-policy.

Prefer Google Docs? Open this template in Google Docs to make a copy and customise it directly. Open the 2025 version in Google Docs →

NOTE: To use this template, copy the content using the “Copy page” button above, then replace the example text with your own. This template is a starting point, not legal advice. Updated September 2026.

[Organisation] AI policy

Version [x.x] · Owner: [name, role] · Last reviewed: [date] · Next review: [date]

Our AI policy in plain English

We want you to use AI. It makes our work better and faster, and it helps us win.

Please:

  1. Use our company AI tools for your work, and try new ways of using them
  2. Share what works with your team
  3. Ask if you’re unsure; you’ll get a quick answer, not a telling-off

Always:

  1. Use your company account for company or customer information, never a personal one
  2. Check AI output before you rely on it or send it outside the company
  3. Confirm before an AI agent sends, changes, buys or deletes anything
  4. Tell us straight away if something goes wrong

That’s it. The rest of this policy is detail for when you need it.


Purpose and scope

Why the policy exists, and who and what it covers.

Example text: “[Organisation] sees AI as a way to do better work, faster. This policy helps you use it well while protecting our customers, our people and our information. It applies to all employees, contractors and partners using AI for [Organisation] work, including chat assistants, agents, coding tools, image tools and AI features inside other software, now and as new tools arrive.”

Our approach to AI

Set the tone. An AI-positive organisation says so plainly.

Example text: “We use AI to complement people, not replace their judgement. We encourage everyone to experiment, and we recognise people who find better ways of working. You don’t have an AI job and a real job; using AI well is part of doing your job.”

Approved tools, and company versus personal accounts

List what people can use, and why the account matters.

Example text: “Use the tools listed in the appendix, signed in with your [Organisation] account. Company accounts are set up with our security controls and contractual data terms. Personal accounts are not: depending on the plan and settings, what you put into them can be used to improve the provider’s models, and we can’t protect it. Personal accounts must never be used for company or customer information.”

Encouraged uses

Show people what good looks like in their own work. Say the list is illustrative.

Marketing
• Draft and refine copy
• Develop creative concepts
• Analyse campaign results and customer feedback
Sales
• Research accounts before meetings
• Prepare for negotiations
• Rehearse difficult calls
Finance
• Draft variance commentary
• Reconcile and check data
• Prepare audit documentation
Legal
• First-pass contract review
• Summarise regulatory changes
• Prepare due diligence questions
HR
• Draft job descriptions and policies
• Prepare training materials
• Summarise survey themes
Engineering and IT
• Write, review and document code
• Troubleshoot problems
• Draft runbooks

Data rules, by type of information

Be precise. This is the section people need most.

Type of informationCompany AI toolsPersonal accounts or unapproved tools
Public (published material, public websites)YesYes
Internal (plans, internal documents)YesNo
Confidential (customer data, financials, contracts, source code)Yes, where the tool is approved for itNo
Personal data about customers, colleagues or anyone elseOnly where needed, using the minimum, in approved toolsNo
Special category data (health, ethnicity, beliefs and similar), criminal records, and anything under a legal or regulatory restrictionOnly with sign-off from [DPO / legal]No

The only information you can use in personal accounts or unapproved tools is information that’s already public.

Example text: “Personal data is covered by UK GDPR wherever it goes, including into an AI tool. Use only what the task needs, and don’t use AI to make significant decisions about people without a person reviewing them. If a new use of AI involves personal data at scale or decisions about people, speak to [DPO] first; processing likely to result in a high risk to people needs a data protection impact assessment.”

Agents, connectors and automation

The section older policies miss. Agents and connectors let AI act and reach your systems, not only answer questions.

Example text:

  1. “Connectors reach what you can reach. When you connect Claude to email, drives or other systems, it can see what your account can see. Connect only what the task needs.”
  2. “Confirm before an agent acts. Check what an agent is about to send, change, buy or delete before you approve it.”
  3. “Outside content can carry instructions. Web pages, emails and documents from outside the company can contain hidden instructions aimed at AI (prompt injection). If an agent does something you didn’t ask for, stop it and report it.”
  4. “Automations need an owner. Any agent or workflow that runs without someone watching needs a named owner, approval from [IT / programme lead], and a record in our agent register.”

Our guide to prompt injection risks for AI agents explains the controls, for Claude and ChatGPT, in more detail.

Checking and owning the output

Example text: “You’re responsible for anything you use or send, however it was made. Treat AI output like a first draft from a capable new colleague: check facts, figures, names and sources before relying on it. Where a client contract or regulator requires you to say AI was used, say so.”

Getting a new tool approved

Default to yes, and keep it quick, or people use tools you can’t see.

Example text: “If you’d like to use an AI tool that isn’t on the list, submit the short request form. [IT / security] will respond within [2] working days, and the default is to approve unless there’s a specific risk.”

Training, support and AI literacy

Example text: “Everyone gets foundation training in using AI well at [Organisation]. Every team has a Claude Champion who runs short sessions and answers everyday questions, and there are weekly office hours for anything else.”

If you operate in the EU, or your AI output is used there, Article 4 of the EU AI Act requires organisations that deploy AI to take measures to support their staff’s AI literacy (amended in July 2026). Your training records are how you show it.

Monitoring

Keep it short and honest.

Example text: “We look at how AI is used across teams to learn what works and where to help. Our AI tools keep audit logs that security can use to investigate incidents. We don’t use this policy to watch individuals’ conversations, except to investigate a specific security incident. Use AI openly; we’ll thank you for it.”

Review

Example text: “[Owner] reviews this policy every quarter, and whenever we turn on a new capability such as agents or connectors. We’ll add new tools and uses, and remove restrictions that are no longer needed.”

Getting help

Example text: “Not sure? Ask your team’s Claude Champion, post in [#ai-help], or come to office hours. You can also ask the AI policy project in Claude, which has this policy loaded.”

Appendix: approved tools

ToolApproved forAccount
[Claude Enterprise]Internal, confidential and personal data within these rulesCompany SSO
[Other approved tool]

Implementation notes

  1. Keep the summary to one page. It’s the part everyone reads, so make it complete.
  2. Name the owner and the dates at the top, and keep them current.
  3. Fill in your data classes to match your existing information classification, rather than inventing new ones.
  4. Put the policy in a Claude project so people can ask questions of it, and link it from the tool itself.
  5. Match it to your controls. If the policy says agents need confirmation, make sure the admin settings require it.
  6. Have legal, the DPO, security and HR sign off their sections. This template is a starting point, not legal advice.
  7. The skill does the drafting. The downloadable skill interviews you about your organisation and writes the policy, the one-page summary and the Claude project instructions.

Get started

How to Use This Template

01

Copy the template, or use the skill

Use the 'Copy page' button and edit the example text, or download the Claude skill and have Claude draft the policy for your organisation

02

Fill in your specifics

Your approved tools, your data classes, your support channels and the names of the people who own the policy

03

Review with legal, the DPO, security and HR

This is a starting point, not legal advice; have the people accountable for each area check their section

04

Publish it where people work

Share the one-page summary, and put the policy in a Claude project so people can ask it questions

Questions

Frequently Asked Questions

Common questions about AI policies

Is an AI policy a legal requirement in the UK?
No law requires a document called an AI policy. UK GDPR still applies to any personal data people put into AI tools, and the ICO expects organisations to manage that, so a policy is the practical way to show you do. If you operate in the EU, or your AI output is used there, Article 4 of the EU AI Act requires organisations deploying AI to take measures to support their staff's AI literacy. It has applied since 2 February 2025 and was amended in July 2026. Take legal advice on your own position.
Should an AI policy be permissive or restrictive?
Permissive, with precise data rules. Blocking tools pushes use into personal accounts you can't see. A policy that encourages use of approved company tools, and is exact about which information may go where, gets more use and less risk.
Can employees use personal AI accounts for work?
Not for company or customer information. Personal accounts sit outside your organisation's controls, and their data terms differ from commercial plans: depending on the plan and settings, conversations can be used to improve models. Company accounts on commercial plans give you admin controls, audit logs and contractual data terms.
What should an AI policy say about agents and connectors?
That connectors reach only what the user can already reach, so permissions must be scoped; that agents which act (send, change, buy or delete) need a person to confirm; that content from outside the organisation can carry hidden instructions (prompt injection); and that anything unexpected is reported, not ignored.
How often should we update our AI policy?
Review it every quarter, and whenever you turn on a new capability such as agents, connectors or a new tool. AI products change faster than policies, so date the policy and say who owns it.
Should we monitor employees' AI use?
Use admin analytics to understand adoption at team level and audit logs for security investigations. Don't use the policy to watch individuals' prompts outside a specific security investigation; people stop talking about how they use AI, and you lose the learning.
Who should own the AI policy?
One named owner, the person leading the AI programme, with legal, the DPO, security and HR each signing off their part. Put the owner's name and the review date at the top.

Ready when you are

Want the policy built into the rollout?

Kowalah agrees data rules, admin controls and the AI policy with your DPO and security team before users arrive, as part of every Claude programme.

Book a Conversation