AI Policy Template
An AI-positive policy that tells people what they can do with AI, not only what they can't, with clear rules for data, accounts and agents that act on their behalf.
What's inside this template
Who it's for
CIOs, programme leads, legal, DPOs and HR teams writing or updating the policy that governs how employees use AI tools
When to use
Before you roll out Claude or another AI tool, when you add agents or connectors, or when your current policy was written before either existed
Key benefit
A short policy people read and follow: encouraging by default, precise about data, and current on agents, connectors and personal accounts
Sections included
- Our AI policy in plain English
- Purpose and scope
- Our approach to AI
- Approved tools, and company versus personal accounts
- Encouraged uses
- Data rules, by type of information
- Agents, connectors and automation
- Checking and owning the output
- Getting a new tool approved
- Training, support and AI literacy
- Monitoring
- Review
- Getting help
- Appendix: approved tools
Complete template content
ai-policy This page comes with an installable skill. Install it, tell Claude what you are working on, and it works through the method on this page with you and produces the output.
Claude desktop or Claude.ai
Download the .zip, then go to Settings, Capabilities, Skills, and upload it.
Claude Code
Unzip it into ~/.claude/skills/ for every project, or
.claude/skills/ for one. Then run
/ai-policy.
NOTE: To use this template, copy the content using the “Copy page” button above, then replace the example text with your own. This template is a starting point, not legal advice. Updated September 2026.
[Organisation] AI policy
Version [x.x] · Owner: [name, role] · Last reviewed: [date] · Next review: [date]
Our AI policy in plain English
We want you to use AI. It makes our work better and faster, and it helps us win.
Please:
- Use our company AI tools for your work, and try new ways of using them
- Share what works with your team
- Ask if you’re unsure; you’ll get a quick answer, not a telling-off
Always:
- Use your company account for company or customer information, never a personal one
- Check AI output before you rely on it or send it outside the company
- Confirm before an AI agent sends, changes, buys or deletes anything
- Tell us straight away if something goes wrong
That’s it. The rest of this policy is detail for when you need it.
Purpose and scope
Why the policy exists, and who and what it covers.
Example text: “[Organisation] sees AI as a way to do better work, faster. This policy helps you use it well while protecting our customers, our people and our information. It applies to all employees, contractors and partners using AI for [Organisation] work, including chat assistants, agents, coding tools, image tools and AI features inside other software, now and as new tools arrive.”
Our approach to AI
Set the tone. An AI-positive organisation says so plainly.
Example text: “We use AI to complement people, not replace their judgement. We encourage everyone to experiment, and we recognise people who find better ways of working. You don’t have an AI job and a real job; using AI well is part of doing your job.”
Approved tools, and company versus personal accounts
List what people can use, and why the account matters.
Example text: “Use the tools listed in the appendix, signed in with your [Organisation] account. Company accounts are set up with our security controls and contractual data terms. Personal accounts are not: depending on the plan and settings, what you put into them can be used to improve the provider’s models, and we can’t protect it. Personal accounts must never be used for company or customer information.”
Encouraged uses
Show people what good looks like in their own work. Say the list is illustrative.
| Marketing • Draft and refine copy • Develop creative concepts • Analyse campaign results and customer feedback | Sales • Research accounts before meetings • Prepare for negotiations • Rehearse difficult calls |
|---|---|
| Finance • Draft variance commentary • Reconcile and check data • Prepare audit documentation | Legal • First-pass contract review • Summarise regulatory changes • Prepare due diligence questions |
| HR • Draft job descriptions and policies • Prepare training materials • Summarise survey themes | Engineering and IT • Write, review and document code • Troubleshoot problems • Draft runbooks |
Data rules, by type of information
Be precise. This is the section people need most.
| Type of information | Company AI tools | Personal accounts or unapproved tools |
|---|---|---|
| Public (published material, public websites) | Yes | Yes |
| Internal (plans, internal documents) | Yes | No |
| Confidential (customer data, financials, contracts, source code) | Yes, where the tool is approved for it | No |
| Personal data about customers, colleagues or anyone else | Only where needed, using the minimum, in approved tools | No |
| Special category data (health, ethnicity, beliefs and similar), criminal records, and anything under a legal or regulatory restriction | Only with sign-off from [DPO / legal] | No |
The only information you can use in personal accounts or unapproved tools is information that’s already public.
Example text: “Personal data is covered by UK GDPR wherever it goes, including into an AI tool. Use only what the task needs, and don’t use AI to make significant decisions about people without a person reviewing them. If a new use of AI involves personal data at scale or decisions about people, speak to [DPO] first; processing likely to result in a high risk to people needs a data protection impact assessment.”
Agents, connectors and automation
The section older policies miss. Agents and connectors let AI act and reach your systems, not only answer questions.
Example text:
- “Connectors reach what you can reach. When you connect Claude to email, drives or other systems, it can see what your account can see. Connect only what the task needs.”
- “Confirm before an agent acts. Check what an agent is about to send, change, buy or delete before you approve it.”
- “Outside content can carry instructions. Web pages, emails and documents from outside the company can contain hidden instructions aimed at AI (prompt injection). If an agent does something you didn’t ask for, stop it and report it.”
- “Automations need an owner. Any agent or workflow that runs without someone watching needs a named owner, approval from [IT / programme lead], and a record in our agent register.”
Our guide to prompt injection risks for AI agents explains the controls, for Claude and ChatGPT, in more detail.
Checking and owning the output
Example text: “You’re responsible for anything you use or send, however it was made. Treat AI output like a first draft from a capable new colleague: check facts, figures, names and sources before relying on it. Where a client contract or regulator requires you to say AI was used, say so.”
Getting a new tool approved
Default to yes, and keep it quick, or people use tools you can’t see.
Example text: “If you’d like to use an AI tool that isn’t on the list, submit the short request form. [IT / security] will respond within [2] working days, and the default is to approve unless there’s a specific risk.”
Training, support and AI literacy
Example text: “Everyone gets foundation training in using AI well at [Organisation]. Every team has a Claude Champion who runs short sessions and answers everyday questions, and there are weekly office hours for anything else.”
If you operate in the EU, or your AI output is used there, Article 4 of the EU AI Act requires organisations that deploy AI to take measures to support their staff’s AI literacy (amended in July 2026). Your training records are how you show it.
Monitoring
Keep it short and honest.
Example text: “We look at how AI is used across teams to learn what works and where to help. Our AI tools keep audit logs that security can use to investigate incidents. We don’t use this policy to watch individuals’ conversations, except to investigate a specific security incident. Use AI openly; we’ll thank you for it.”
Review
Example text: “[Owner] reviews this policy every quarter, and whenever we turn on a new capability such as agents or connectors. We’ll add new tools and uses, and remove restrictions that are no longer needed.”
Getting help
Example text: “Not sure? Ask your team’s Claude Champion, post in [#ai-help], or come to office hours. You can also ask the AI policy project in Claude, which has this policy loaded.”
Appendix: approved tools
| Tool | Approved for | Account |
|---|---|---|
| [Claude Enterprise] | Internal, confidential and personal data within these rules | Company SSO |
| [Other approved tool] |
Implementation notes
- Keep the summary to one page. It’s the part everyone reads, so make it complete.
- Name the owner and the dates at the top, and keep them current.
- Fill in your data classes to match your existing information classification, rather than inventing new ones.
- Put the policy in a Claude project so people can ask questions of it, and link it from the tool itself.
- Match it to your controls. If the policy says agents need confirmation, make sure the admin settings require it.
- Have legal, the DPO, security and HR sign off their sections. This template is a starting point, not legal advice.
- The skill does the drafting. The downloadable skill interviews you about your organisation and writes the policy, the one-page summary and the Claude project instructions.
Get started
How to Use This Template
Copy the template, or use the skill
Use the 'Copy page' button and edit the example text, or download the Claude skill and have Claude draft the policy for your organisation
Fill in your specifics
Your approved tools, your data classes, your support channels and the names of the people who own the policy
Review with legal, the DPO, security and HR
This is a starting point, not legal advice; have the people accountable for each area check their section
Publish it where people work
Share the one-page summary, and put the policy in a Claude project so people can ask it questions
Questions
Frequently Asked Questions
Common questions about AI policies
Is an AI policy a legal requirement in the UK?
Should an AI policy be permissive or restrictive?
Can employees use personal AI accounts for work?
What should an AI policy say about agents and connectors?
How often should we update our AI policy?
Should we monitor employees' AI use?
Who should own the AI policy?
More templates
Related templates.
Ready when you are
Want the policy built into the rollout?
Kowalah agrees data rules, admin controls and the AI policy with your DPO and security team before users arrive, as part of every Claude programme.