How to write a generative AI policy for your workplace
A practical template and drafting guide for a generative AI policy — approved tools, confidential data rules, disclosure requirements, accountability for output, and how to handle misuse fairly.
Most organisations discover their generative AI problem after the fact: an employee pastes a redundancy list into a public chatbot, or a manager submits an AI-drafted investigation report with invented case citations. A short, clear policy prevents most of this. A long, aspirational one prevents none of it.
This guide covers what to include, what to leave out, and how to enforce it fairly.
Start with a decision, not a document
Before drafting, senior leadership needs to answer three questions:
- Which tools are approved? An enterprise deployment with a no-training-on-your-data agreement is a different risk from a personal free account. Name the approved tools explicitly; everything else is unapproved by default.
- What may never go in? Draw a hard line around personal data, HR case files, health information, unpublished financials, customer data and anything under NDA.
- Who is accountable for output? The answer should be the person who submits it. AI is a drafting aid, not a signature.
The sections a workable policy needs
Scope. Who it covers (employees, contractors, agency workers), which devices, and whether personal accounts on personal devices are in scope when used for work.
Approved tools and access. A named list, with a route to request additions. Include a short line on browser extensions and AI features bundled inside tools people already use — meeting-note takers are the common blind spot.
Data rules. Set out categories that must never be entered, with concrete examples rather than abstractions. State whether the approved tool trains on inputs, because employees usually assume it does not.
Verification. Anyone using AI output is responsible for accuracy. Require checking of facts, figures, legal references and citations. Say plainly that fabricated content submitted as work product is a conduct matter.
Disclosure. Decide when AI use must be flagged: typically in HR documents, investigations, performance reviews, code committed to production, and external-facing content. Internal drafting usually needs no disclosure — say so, otherwise the rule is ignored everywhere.
Prohibited uses. Common list: final decisions on hiring, discipline, performance or dismissal; generating content about identifiable colleagues; producing anything designed to mislead; circumventing security controls.
Employee-facing AI. If you use AI to monitor, score or evaluate staff, the policy should cross-reference the monitoring policy and the right to human review. Keeping this in the same document builds trust.
Support and escalation. A named contact for "am I allowed to do this?" questions. Most breaches come from uncertainty, not defiance.
Review date. Twelve months maximum, given how fast tools change.
Consultation makes it enforceable
A policy introduced without consultation is harder to rely on in a disciplinary process, and where unions or works councils are recognised, monitoring and evaluation elements will normally require consultation as a matter of law or agreement. Run the draft past employee representatives, and record the response.
Decide too whether the policy is contractual. Most employers keep AI policies non-contractual so they can update them, while making clear that breach may lead to disciplinary action.
Training beats prohibition
Blanket bans push usage underground and remove your visibility. The organisations with the fewest incidents tend to approve a safe tool, train people on it, and explain why the data rules exist. Cover:
- what happens to data you paste into a consumer tool
- how confident-sounding fabrication works, with an example from your own sector
- bias in AI-drafted people documents
- the specific HR contexts where AI must not be the decision-maker
Handling misuse fairly
Treat AI misuse like any other conduct issue. That means the rule must have been communicated, applied consistently, and matched to seriousness. Pasting a customer list into a public chatbot is a data-protection incident; using AI to tidy an email is not. A policy that treats both as gross misconduct will not survive a tribunal's reasonableness test, and staff will ignore it.
Also plan the incident route: if confidential data has been entered into an external tool, it may be a personal-data breach requiring assessment and, potentially, notification within 72 hours.
A one-page skeleton you can adapt
- Purpose and scope
- Approved tools (list) and how to request more
- Never enter: personal data, HR case data, health data, customer data, unpublished financials, third-party confidential information
- You are responsible for anything you submit; verify all facts, figures and citations
- Disclose AI assistance in: HR documents, investigations, performance reviews, external publications, production code
- Never use AI as the decision-maker in hiring, discipline, performance or dismissal
- Report incidents to [contact] immediately
- Questions to [contact]; policy reviewed annually
The practical takeaway
The best AI policies are short enough to read, specific enough to follow, and honest about what the organisation itself does with AI. If yours cannot be summarised on one page, staff will not follow it — and the risk you were managing is still there.
This guide is general information for HR professionals, not legal advice. Take advice on your own facts before acting.
Related guides
EU AI Act for HR
How the EU AI Act classifies recruitment, monitoring and people-management systems as high risk, which obligations fall on employers as deployers, and the compliance deadlines that matter for HR.
UK employee monitoring law
A practical guide to lawful workplace monitoring in the UK — the UK GDPR lawful basis, ICO expectations, when a DPIA is mandatory, covert monitoring, and how AI-driven productivity tracking changes the analysis.
AI hiring and discrimination law
How the Equality Act 2010 applies to CV screening, video interviews and candidate scoring, what a defensible bias audit looks like, and the vendor questions that protect employers from tribunal claims.
Get AI & HR insights every week
One email a week with the latest cases, regulations and practical guidance on AI in the workplace.