Insights — AI Workflow & Commercial Automation — 3 min read
Does My Business Need an AI Policy? What It Should Cover
Staff are already using AI tools at work, with or without a policy. The question is not whether to have a view on it, but whether that view is written down.

In short
Most businesses handling customer data, confidential information or decisions that affect customers should have a short written AI policy. It should cover which tools are approved, what information can and cannot be entered into them, when human review is required, and who is accountable for AI-assisted work. This is a practical governance measure, not a legal document, and specialist legal advice may still be needed for regulated sectors.
Most businesses now have staff using AI tools in some form — drafting emails, summarising documents, researching, or generating first-draft content — whether or not anyone has formally agreed that this is allowed.
An AI policy does not need to be long or legalistic. It needs to answer a small number of practical questions clearly enough that staff know what to do, and what not to do, without asking each time.
Why this question comes up now
Generative AI tools are free or cheap to access, require no IT approval to sign up for, and genuinely help with everyday tasks. That combination means adoption usually happens from the bottom up, one person at a time, well before any business decision is made about it. By the time a policy question is raised, AI use is often already underway across several departments.
What is 'shadow AI' and why does it matter?
- Shadow AI
- The use of AI tools by staff without the knowledge, approval or oversight of the business — typically free consumer tools used to handle work tasks, including tasks involving customer or confidential information.
Shadow AI is not usually malicious. It is normally a well-intentioned employee trying to work faster. The risk is that nobody has checked what happens to the information pasted into the tool, whether the output is accurate, or whether a customer would be comfortable knowing their details were processed that way.
What should an AI policy actually cover?
Approved tools
A short list of tools staff are permitted to use, and a route for requesting a new one to be assessed, rather than a blanket ban that simply pushes use underground.
Confidential and customer information
Clear rules on what must never be entered into a general-purpose AI tool — customer records, financial data, contracts, personal details, anything covered by a confidentiality agreement — and where that line sits for borderline cases.
Human review
A statement that AI-generated content and recommendations are drafts, not finished outputs, and naming which categories of work always require a named person's sign-off before anything goes to a customer, supplier or regulator — proposals, pricing, legal or financial documents, and customer communications among them.
Copyright and intellectual property
A position on using AI-generated text or images in external materials, and on not entering a competitor's or third party's proprietary material into an AI tool. This is an area where specialist legal advice may be needed, particularly for published or client-facing content.
Data handling and retention
Where inputs and outputs are stored, for how long, and whether the chosen tools are used in a way that keeps data out of third-party model training — covered in more depth in our related article on data safety.
Accountability
Who is responsible when an AI-assisted output is wrong — the person who used the tool, not the tool itself. A policy should state plainly that AI use does not transfer responsibility away from the employee or the business.
A practical policy checklist
- List of tools currently approved for use, and a request process for new ones
- Explicit statement of what must never be entered into a general AI tool
- List of work types that always require human sign-off before external use
- A short note on copyright and attribution for AI-assisted content
- A data retention and storage position for the approved tools
- A named accountable person for AI use within each team
- A route for reporting a mistake or a misuse concern without blame
- A review date, since tools and risks change quickly
How detailed does it need to be?
For most small and mid-sized businesses, a one or two-page policy that is actually read and understood is more useful than a long document modelled on enterprise compliance frameworks. The aim is a shared, written understanding of boundaries — not an exhaustive legal instrument.
Where this fits with wider automation work
A written policy is a sensible first step before any formal AI automation work, because it forces clarity on what data can be used and where human review sits — decisions that also shape how automated workflows should be designed. Evans' AI Workflow & Commercial Automation work starts from the same questions, applied to specific business processes rather than general staff use.
Not sure which processes are worth automating?
The free automation diagnostic asks a few questions about how work moves through your business and points to the processes most likely to be worth automating. No email required.
