Skip to content
Evans Sales Consultancy - international sales growth, market entry and expansionEvansSales Consultancy
Call 0330 043 8477Email

Insights — AI Workflow & Commercial Automation — 3 min read

Does My Business Need an AI Policy? What It Should Cover

Staff are already using AI tools at work, with or without a policy. The question is not whether to have a view on it, but whether that view is written down.

A manager reviewing a written policy document at a desk alongside a laptop.

In short

Most businesses handling customer data, confidential information or decisions that affect customers should have a short written AI policy. It should cover which tools are approved, what information can and cannot be entered into them, when human review is required, and who is accountable for AI-assisted work. This is a practical governance measure, not a legal document, and specialist legal advice may still be needed for regulated sectors.

Most businesses now have staff using AI tools in some form — drafting emails, summarising documents, researching, or generating first-draft content — whether or not anyone has formally agreed that this is allowed.

An AI policy does not need to be long or legalistic. It needs to answer a small number of practical questions clearly enough that staff know what to do, and what not to do, without asking each time.

Why this question comes up now

Generative AI tools are free or cheap to access, require no IT approval to sign up for, and genuinely help with everyday tasks. That combination means adoption usually happens from the bottom up, one person at a time, well before any business decision is made about it. By the time a policy question is raised, AI use is often already underway across several departments.

What is 'shadow AI' and why does it matter?

Shadow AI
The use of AI tools by staff without the knowledge, approval or oversight of the business — typically free consumer tools used to handle work tasks, including tasks involving customer or confidential information.

Shadow AI is not usually malicious. It is normally a well-intentioned employee trying to work faster. The risk is that nobody has checked what happens to the information pasted into the tool, whether the output is accurate, or whether a customer would be comfortable knowing their details were processed that way.

What should an AI policy actually cover?

Approved tools

A short list of tools staff are permitted to use, and a route for requesting a new one to be assessed, rather than a blanket ban that simply pushes use underground.

Confidential and customer information

Clear rules on what must never be entered into a general-purpose AI tool — customer records, financial data, contracts, personal details, anything covered by a confidentiality agreement — and where that line sits for borderline cases.

Human review

A statement that AI-generated content and recommendations are drafts, not finished outputs, and naming which categories of work always require a named person's sign-off before anything goes to a customer, supplier or regulator — proposals, pricing, legal or financial documents, and customer communications among them.

Copyright and intellectual property

A position on using AI-generated text or images in external materials, and on not entering a competitor's or third party's proprietary material into an AI tool. This is an area where specialist legal advice may be needed, particularly for published or client-facing content.

Data handling and retention

Where inputs and outputs are stored, for how long, and whether the chosen tools are used in a way that keeps data out of third-party model training — covered in more depth in our related article on data safety.

Accountability

Who is responsible when an AI-assisted output is wrong — the person who used the tool, not the tool itself. A policy should state plainly that AI use does not transfer responsibility away from the employee or the business.

A practical policy checklist

  • List of tools currently approved for use, and a request process for new ones
  • Explicit statement of what must never be entered into a general AI tool
  • List of work types that always require human sign-off before external use
  • A short note on copyright and attribution for AI-assisted content
  • A data retention and storage position for the approved tools
  • A named accountable person for AI use within each team
  • A route for reporting a mistake or a misuse concern without blame
  • A review date, since tools and risks change quickly

How detailed does it need to be?

For most small and mid-sized businesses, a one or two-page policy that is actually read and understood is more useful than a long document modelled on enterprise compliance frameworks. The aim is a shared, written understanding of boundaries — not an exhaustive legal instrument.

Where this fits with wider automation work

A written policy is a sensible first step before any formal AI automation work, because it forces clarity on what data can be used and where human review sits — decisions that also shape how automated workflows should be designed. Evans' AI Workflow & Commercial Automation work starts from the same questions, applied to specific business processes rather than general staff use.

Not sure which processes are worth automating?

The free automation diagnostic asks a few questions about how work moves through your business and points to the processes most likely to be worth automating. No email required.

Related services

Written by

By Tom Evans

Founder, Evans Sales Consultancy

Published 4 October 2026 — 3 min read

Common questions

  • There is no single standalone legal requirement to have an AI policy, but existing data protection and employment obligations still apply to AI use, so a written policy helps demonstrate reasonable care. Specialist legal advice should confirm requirements for a specific sector.

  • Yes. Many everyday tools now include built-in AI features, and the same principles around confidential data and human review apply whether the AI is a standalone chatbot or embedded in existing software.

  • Typically a senior manager or owner drafts it with input from whoever handles data protection, with legal review where the business is regulated or handles sensitive personal data.

  • At least annually, and sooner if new tools are adopted, a data incident occurs, or guidance from regulators such as the ICO changes materially.

  • It helps to name the approved tools, but the policy should also set general principles so it still applies to tools not yet in use.

  • That is an internal disciplinary and management matter, but a written policy at least gives the business a clear basis to address misuse, which is harder without one.

Still working out the right approach?

If your question is specific to your company, product or target market, we can help you work through the commercial options.

Discuss your market entry

More opportunities. Better conversion. Stronger sales. More revenue.

If your business could sell more than it currently does, the fastest way to find out why is to look at the numbers together.