Your team is already using AI. Does anyone know the rules?
Why every business needs a simple AI policy in 2026
AI adoption has happened incredibly quickly.
People are using ChatGPT, Copilot, Claude and dozens of other tools to write emails, summarise documents, research clients, analyse spreadsheets, prepare reports and solve everyday problems.
In many businesses, that started before anyone at leadership level had really decided how AI should be used.
And that’s becoming a problem.
According to the UK Business Data Survey 2026, only 17% of small businesses using AI reported having a formal written AI policy. In other words, 83% did not report one. Here, “small” means 10–49 employees; fieldwork ran from October 2025 to January 2026.
That doesn’t mean 83% of businesses are doing something wrong.
It does mean that, in many organisations, individual employees may be making their own decisions about AI.
Without a policy, everyone makes their own rules
Imagine a business with 50 people.
One person uses ChatGPT to tidy up an email.
Another uploads a client document to summarise it.
Someone in HR uses AI to help assess job applications.
A manager asks it to analyse employee performance.
Someone in finance drops a spreadsheet into a tool they’ve found online.
Another member of staff pays for their own AI account because the company hasn’t provided one.
Every one of those people might believe they are acting completely reasonably.
But without some shared guidance, you’ve potentially got 50 people making 50 different decisions about what tools are safe, what information can be shared and what AI-generated work can be trusted.
That’s the problem an AI policy starts to solve.
This isn’t about stopping people using AI
Quite the opposite.
A good AI policy should make it easier for people to use AI confidently.
The NCSC advises organisations not to put sensitive information into public LLMs and to understand how providers handle the information entered into their tools. Its guidance also highlights inaccurate outputs, hallucinations and injection attacks.
And where personal information is involved, businesses still have responsibilities under UK data-protection law. The ICO’s AI governance guidance discusses accountability, policies, roles, responsibilities and risk management. The ICO currently notes that this guidance is under review following the Data (Use and Access) Act.
So the aim isn’t to ban ChatGPT.
It’s to answer a few simple questions:
- What tools can we use?
- What information can we put into them?
- What shouldn’t we use AI for?
- When does a human need to check the result?
- Who do we speak to if we’re unsure?
For a lot of SMEs, you don’t need a 40-page AI governance manual to begin answering those questions.
You could start with something as simple as this.
A simple AI policy
Purpose
We encourage the responsible use of AI where it can help us work more effectively, improve our service or reduce repetitive work.
AI should support human judgement, not replace it where important decisions are being made.
1. Use approved tools
Employees should use AI tools approved by the business. New tools should be checked before being used for company work.
2. Protect company and personal information
Do not enter confidential company information, client information, employee data, passwords, commercially sensitive material or other personal data into public AI tools unless that use has been specifically approved.
3. Check AI-generated work
AI can produce incorrect or misleading information. Employees remain responsible for checking the accuracy and suitability of anything they use.
4. Keep humans involved in important decisions
AI should not make significant decisions about customers, employees, recruitment, legal matters, finance or other high-impact areas without appropriate human review.
5. Be careful with external content
AI-generated material used externally should be reviewed for accuracy, confidentiality, copyright, tone and suitability before publication or distribution.
6. Ask if you’re unsure
If you’re unsure whether an AI tool or use case is appropriate, ask the person responsible for AI, IT, data protection or management before proceeding.
7. Report problems
Any accidental disclosure of information, unexpected AI behaviour or other concern involving AI should be reported promptly.
8. Keep learning
Our approved tools and guidance will change as AI develops. This policy will be reviewed regularly and employees will be kept informed of significant changes.
That’s enough to start a conversation and establish shared expectations. Before adopting it, name your approved tools, responsible owner, reporting contact and review date, and adapt it to your risks. This example is not legal advice or a complete governance framework.
A business still needs to understand what tools are actually being used, where its particular risks sit, who owns AI internally and where AI could create commercial value.
But it gives everyone a common starting point.
Because the biggest risk isn’t necessarily that people are using AI.
It’s that everyone is using it differently and nobody has a clear view of what’s happening.
Are you Good To Go?
Good To Go helps established businesses understand how AI is already being used, identify the risks and gaps, put practical governance in place and find where AI can genuinely make the business work better.
Need practical rules first? Our £1,500 AI Policy Sprint includes light discovery, a tailored policy, a one-page staff guide and leadership handover, for organisations with up to 100 employees.
Delivered within 10 working days from the agreed start, with the required information in place. The £1,500 Sprint fee is fully credited against a Good to Go Review booked within 60 days of your Sprint handover, for the same organisation. A Review priced at £5,000 therefore has £3,500 remaining after the credit. Larger Review scopes are quoted separately.