Most UK small businesses did not decide to start using AI. It arrived through the side door, when someone on the team pasted a customer email into a chatbot to draft a reply, and it worked. That is the moment an AI policy stops being optional. Not because a regulator is at the door, but because unwritten rules become whatever the busiest person guesses on a Tuesday. This guide walks through how to write an AI policy template for a UK small business that people will actually read, without a legal department and without pretending the risks are larger or smaller than they are.
Why does a UK small business need an AI policy at all?
The gap is not adoption, it is control. Adoption at small firms is real but uneven, and it is climbing without a plan behind it. According to the Bennett School of Public Policy at Cambridge, drawing on the ONS Business Insights and Conditions Survey, small firms with fewer than fifty employees reached 26% AI adoption in 2025, while large firms nearly doubled to 44%. The point for a small business owner is that a quarter of your peers already have staff using these tools, and most of them have no policy governing it.
The risk is concrete. UK GDPR treats a customer name typed into a chatbot as processing personal data, and you remain accountable for it. A written policy is the cheapest way to show you have considered that, and to give staff a clear line they can follow.
What should an AI policy template for UK businesses include?
Keep the structure tight so people read it. The six sections that matter:
- Scope: who and what the policy covers, including contractors.
- Approved tools: the named services and tiers staff may use.
- Banned inputs: what must never be entered, such as client personal data or anything confidential.
- Data protection: how the policy sits under UK GDPR and your existing privacy notice.
- Human accountability: who checks AI output and who owns a decision.
- Review: a named owner and a date the policy is next checked.
If you already run a documented process library, an AI policy slots in beside it. The habit of writing down how work is done, covered in our guide to AI business process documentation, makes the policy easier to keep current because the tools live inside processes you have already mapped.
Which AI tools should the policy approve or ban?
A long approved list is a liability because you cannot track the data terms of ten services. Name a small number, state the tier, and require anything new to be requested from the policy owner.
The free versus paid distinction matters more than the brand. Many free consumer tiers may reuse your inputs to improve their models, which is a genuine problem the moment staff enter client data. Business tiers usually let you turn that off. When you cost this out, factor it into your wider AI cost planning for 2026, because a paid tier is often the control that makes a free tool safe to approve.
How do you handle data protection and UK GDPR in the policy?
You do not need a new legal framework. You need to connect AI to the accountability principle you already sit under. Three practical rules cover most of it:
- Personal data, whether customer or staff, only goes into a tool whose data terms you have checked and whose tier does not train on your inputs.
- Special category data, such as health or ethnicity, is banned from AI tools unless you have run a proper assessment.
- Any AI use that affects a person's rights, such as screening job applicants, gets a human decision-maker and a route to challenge it.
Who is accountable when AI gets it wrong?
This is the principle that keeps you safe. AI can draft, summarise and suggest, but it cannot be responsible. The UK Government's 2023 AI white paper built accountability and governance into its five cross-sectoral principles for exactly this reason. In a small team, name the accountable person by role rather than by name so the policy survives staff changes. State plainly that AI output is a draft until a human has checked it against a source or their own judgement.
How do you write the policy without a legal team?
Borrowed templates fail when they describe a company you are not. A ten-page policy written for a bank will be ignored by a six-person agency. Draft it in the language your team uses, keep it to two to four pages, and put concrete examples in: "Do summarise this public report. Do not paste the client contract." If you use AI to help draft the policy itself, that is fine, as long as a human owns the final version, which is the same rule the policy sets for everything else. Teams handling staff data should also read across to AI for small HR teams, because employee records carry stricter duties than marketing copy.
How do you roll the policy out to staff?
A policy that lands as an unread attachment changes nothing. Spend twenty minutes with the team. Show the one action that matters most, the risky paste, and the safe alternative. Make it easy to ask for a new tool, because a hard request route just pushes people back to their personal accounts where you have no visibility. Record who has acknowledged the policy, and repeat the walkthrough for new starters as part of induction.
How often should you review and update the AI policy?
The single biggest failure mode is a policy that was accurate in spring and stale by autumn. Pricing tiers, data terms and model behaviour move quickly, so a static document quietly drifts out of date. A light quarterly check is enough: confirm the approved list still matches reality, log any incidents, and update the banned inputs if a new risk appeared. Treat the front-page review date as a promise, not decoration.
The pattern in those numbers is the argument for writing your policy now. Small firms are adopting fast enough that unwritten rules will not hold, but slow enough that you still have time to set the boundary before an incident sets it for you.
What common mistakes should you avoid?
A blanket ban drives usage underground onto personal accounts. A blanket approval hands your data to services you have never read. A twenty-page document goes unread. A policy with no review date rots. Avoid all four by keeping the document short, the approved list honest, and the review date real. The goal is not a perfect policy. It is a policy people follow, updated often enough to stay true.
An AI policy is not paperwork for its own sake. It is the difference between AI helping your team on your terms and AI leaking your data on nobody's terms. Write the short version this week, name an owner, and put a review date on it. That single page does more for a UK small business than any tool you could buy.
AI Policy Template for UK Small Businesses — FAQ
Is an AI policy a legal requirement for UK small businesses?
There is no single law that says you must have an AI policy with that title. What does apply is UK GDPR, which requires you to document how personal data is processed and to stay accountable for it. If staff paste customer details into a chatbot, that is processing, and a written policy is the simplest way to show you have thought about it. The UK Government's 2023 white paper set out five cross-sectoral principles that regulators use, so aligning your policy to safety, transparency, fairness, accountability and contestability keeps you close to the direction of travel. A policy is not legally named, but the obligations behind it are real.
What is the difference between an AI policy and an acceptable use policy?
An acceptable use policy is usually one section inside a broader AI policy. The acceptable use part tells staff which tools are approved, what they can and cannot put into them, and what outputs need checking before use. The wider AI policy adds the governance around that: who owns the policy, how you assess new tools, how you handle data protection, and how someone appeals a decision an AI helped make. Small teams often merge the two into a single short document, which is fine. Keep the acceptable use rules near the top so people read the part that changes their daily work, and put the governance detail below it.
Which AI tools should a small business approve?
Approve tools where you understand who processes the data and where it is stored, and where a business or paid tier gives you controls the free version does not. Many free consumer tiers may use your inputs to train the underlying model, which is a problem the moment staff enter client or staff data. A short approved list beats a long one: name two or three tools, state the tier, and require anything else to be requested. Ban the practice of pasting personal or confidential data into any tool not on the list. Review the list every quarter, because pricing tiers and data terms change often.
How long should an AI policy be for a small team?
For a team under fifty people, aim for two to four pages. Anything longer tends to go unread, and an unread policy protects nobody. Cover scope, approved tools, banned inputs, data protection, human accountability, and review dates. Use plain English and short examples rather than legal wording, because the goal is behaviour change on Monday morning, not a document that impresses a lawyer. You can always attach a longer appendix for the person who owns the policy. The test is simple: could a new starter read it in ten minutes and know what they are allowed to type into a chatbot? If yes, the length is right.
How often should you review your AI policy?
Review it at least every quarter while the tools are changing this fast, and immediately after any new tool is approved or any incident. AI pricing, data terms and model behaviour shift month to month, so a policy written in spring can be stale by autumn. Put a named owner and a review date on the front page so the review actually happens rather than drifting. A light review is enough most of the time: confirm the approved list is current, check whether any near misses happened, and update the banned inputs if new risks appeared. Treat it as a living document, not a one-off compliance task.



