AI at work 11 min read

Does your employer have an AI policy? What to check

Does your employer have an AI policy? What to check
Share this article
Facebook LinkedIn X WhatsApp

Most UK professionals are already using artificial intelligence tools at work, whether their employer knows about it or not. A recent pattern is emerging in offices, warehouses, schools and hospitals across the country: someone discovers a generative AI tool, starts using it quietly to draft emails or summarise documents, and then wonders, sometimes weeks later, whether they were actually supposed to. The question of whether you can use AI at work is almost always secondary to whether you should, and that depends entirely on what your organisation has decided, documented and communicated.

This article walks you through what a sensible workplace AI policy covers, what it means if your employer has not written one yet, and the things you should never put into an AI tool regardless of what any policy says. If you are studying, or considering studying, a qualification in this area, you will recognise this as the territory covered in Unit 03 (data) and Unit 04 (responsible use) of the NCFE AI qualifications we deliver at DAIS.

Why a workplace AI policy matters now

Generative AI tools became widely accessible to the general public from late 2022 onwards. For most UK employers, that was faster than their legal, HR and IT teams could respond. The result is that many organisations are operating in a gap: staff are using tools, data is moving through systems that the organisation does not control, and no one has formally decided what the rules are.

That gap carries genuine risk. When something goes wrong, and things do go wrong, the question of accountability becomes urgent. Our blog post on who is accountable when an AI system gets it wrong explores this in detail, but the short version is this: the organisation is almost always liable for the actions of its employees, even when those employees were acting without explicit guidance. A missing policy is not a legal defence.

From your perspective as an employee, not knowing the rules puts you in a professionally uncomfortable position. You may be using a tool that your employer has contractually prohibited. You may be exposing personal data in a way that breaches UK GDPR. You may be producing outputs that your organisation will later treat as authoritative, when those outputs were generated without any human verification. None of that is hypothetical. All of it has already happened in UK workplaces.

What a sensible workplace AI policy actually covers

A well-written workplace AI policy is not a list of bans. It is a framework that helps staff make good decisions quickly. The following sections are what you should expect to find in a mature policy, and what you should be looking for if you are reviewing one for the first time.

1. Scope: which tools, which tasks

The policy should specify which AI tools are approved for use, under what circumstances, and for which types of work. A blanket statement that says "staff may use AI tools" without naming them or defining approved use cases is almost useless in practice. Equally, a blanket ban with no rationale is likely to be ignored. Good policies name specific tools or categories of tools, distinguish between approved tools that have been procured through IT and free public tools that staff might access independently, and make clear which tasks are in scope.

2. Data classification: what you must never input

This is the section that matters most for day-to-day practice, and the one most often missing from early-stage employer policies. Any AI tool that processes your input on external servers, which includes every major consumer-grade generative AI tool currently available, is potentially storing, processing and in some cases using that input for further model training.

A sensible policy will define categories of information that must never be entered into an external AI tool. These typically include:

  • Personal data about colleagues, clients or service users, including names, contact details, health information and financial records
  • Commercially sensitive information, such as pricing strategies, contract terms, product development plans and unreleased financial data
  • Information that is subject to a duty of confidentiality, including legally privileged communications and regulated sector data
  • Any data that your organisation holds under a data processing agreement with a third party, where that agreement does not permit onward transfer to AI platforms

Even if your employer has not written a formal AI policy, these categories are not discretionary. UK GDPR applies regardless. Inputting personal data into a consumer AI tool without a lawful basis and appropriate safeguards is a potential data breach, and the individual who made the input may share in the accountability.

3. Output verification: who is responsible for what the AI produces

AI tools generate plausible text. They do not generate accurate text, and the distinction is critical. A policy should be explicit that any output produced by an AI tool must be reviewed, verified and owned by a human being before it is used in any professional context. The person who submits the output is responsible for its accuracy, not the tool and not the tool's vendor.

This matters particularly in regulated sectors. In legal, financial, healthcare and education settings, reliance on unverified AI output can constitute a professional failure and, depending on context, a regulatory breach.

4. Intellectual property and copyright

The policy should address who owns content produced with AI assistance, and what the organisation's position is on submitting AI-generated content as original work. In contexts where originality matters, including academic work, creative commissions and certain professional reports, the use of generative AI without disclosure may constitute a form of misrepresentation. This is an area where UK law is still developing, but the professional and reputational risks are already real.

5. Transparency and disclosure

Some organisations require staff to disclose when AI tools have been used in producing a piece of work. Others do not. What matters is that the policy takes a clear position, so that staff are not left guessing. If your organisation communicates externally using AI-generated content, there may also be considerations under the UK Code of Non-broadcast Advertising and Sales Promotion (the CAP Code) regarding accuracy and substantiation of claims.

6. Governance and review

A policy written in 2023 may already be out of date. The technology is moving quickly, and a well-governed AI policy will include a named owner, a review cycle and a process for staff to raise questions or report concerns. If the policy your employer has produced has no version date and no review mechanism, treat it as a starting point rather than a settled framework.

What it means if your employer has no AI policy yet

A significant number of UK employers, particularly small and medium-sized organisations, had not produced a formal AI policy as of early 2025. That does not mean there are no rules. It means the rules are implied rather than stated, which is worse for everyone.

In the absence of an explicit policy, the following apply by default:

  • UK GDPR and the Data Protection Act 2018 govern any processing of personal data, including processing via AI tools
  • Your contract of employment almost certainly includes confidentiality obligations that cover commercially sensitive information, whether or not AI is mentioned
  • Sector-specific regulation continues to apply: financial services firms, healthcare providers, legal practices and others operate under regulatory frameworks that do not pause because a staff member is using a new tool
  • Your employer's IT acceptable use policy, if one exists, may already address the use of non-approved external software, which would include most consumer AI tools

If you are in a position to influence your organisation's approach, the most useful thing you can do is raise the question clearly and constructively. Frame it as a risk management issue, not a technology discussion, and point to the data protection obligations as the starting point. Most legal and compliance teams will engage with that framing immediately.

The absence of an AI policy is not permission. It is a gap that leaves both the organisation and its staff exposed. The sensible response is to apply the same standards you would apply to any sensitive information: if you would not email it to a stranger, do not put it into an AI tool.

What you should never put into an AI tool, regardless of policy

Policies can be silent on particular scenarios, or out of date, or simply wrong. Regardless of what any document says, the following categories of information should never be entered into a consumer AI tool without specific, documented authorisation and appropriate legal safeguards in place.

Category Examples Why it matters
Special category personal data Health records, ethnicity, religion, biometric data, trade union membership Highest protection under UK GDPR Article 9; processing without explicit consent or Schedule 1 condition is unlawful
Children's data Pupil records, safeguarding notes, family contact details Additional protections under the Children's Code and sector-specific regulation
Legally privileged communications Correspondence with solicitors, internal legal advice Privilege may be waived by disclosure to a third party, including an AI platform
Payment and financial account data Card numbers, bank account details, payroll records PCI DSS and UK GDPR obligations; potential fraud risk from data exposure
Unreleased commercial information Acquisition targets, pricing models, unreleased product details Market abuse regulation and commercial confidentiality obligations
Information about named third parties without their knowledge Client complaints, performance data about colleagues, witness statements UK GDPR transparency obligations; potential breach of confidence

How understanding AI policy connects to formal qualifications

If you are navigating these questions and finding that you do not have a confident framework for thinking about them, that is a gap a structured qualification can address directly. The topics covered in this article, data handling, responsible use, accountability and governance, map directly onto the units within NCFE's regulated AI qualifications.

The NCFE Level 2 Award in Artificial Intelligence (AI) for the Workplace provides a grounded introduction to using AI tools responsibly in a professional context. It covers the practical considerations that most online tutorials and YouTube explainers never reach: what the data risks actually are, what responsible use looks like in a UK regulatory environment, and how to think critically about AI outputs before you act on them. It is an Ofqual-regulated qualification, which means it appears on the Ofqual register and carries recognised credit, not just a completion certificate. If you want to understand the difference that makes to employers, our post on Ofqual recognition versus unrecognised certificates sets it out clearly.

For those who want to go further, the NCFE Level 2 Certificate in Artificial Intelligence (AI) for the Workplace extends the coverage and provides a more substantial body of regulated learning. Both qualifications are delivered online through DAIS and are designed for working adults, so the study model is built around the reality of a full-time job.

If your interest is less about your own practice and more about how AI is being adopted in your sector or organisation, our practical guide to generative AI in the UK workplace for 2026 gives a broader picture of where things currently stand.

What you can do this week

Knowing about AI policy as a concept is less useful than actually checking what your employer has decided. Here are four concrete steps you can take in the next few working days.

  1. Search your organisation's intranet or policy library for any document that mentions artificial intelligence, AI, machine learning or large language models. Note the version date and whether it has a named owner.
  2. Check your existing IT acceptable use policy for references to non-approved external software or cloud-based tools. Most policies written in the last five years will include language that is relevant even if it predates generative AI.
  3. If you use any AI tool at work, identify exactly which tool it is, whether it is a paid enterprise version with a data processing agreement or a free consumer tier, and what the terms say about your input data.
  4. If your organisation has no policy, consider raising it through your line manager or a relevant team such as legal, compliance or IT. Frame it as a data protection question and you will find a more receptive audience than if you frame it as a technology question.

None of this requires you to be a data scientist or a lawyer. It requires you to be a careful professional who understands that the tools have changed faster than the rules, and that filling that gap is a practical responsibility, not an abstract one.

Ready to build a confident, qualified understanding of AI at work?

At The Data and AI School of London, we deliver Ofqual-regulated qualifications online, designed for UK professionals who are working full-time and want to upskill without stepping away from their careers. Our AI qualifications address exactly the questions this article raises: data responsibility, accountable use, and how to work with AI tools in a way that protects you, your colleagues and your organisation.

Start with the NCFE Level 2 Award in Artificial Intelligence (AI) for the Workplace if you want a focused, practical introduction, or explore the full NCFE Level 2 Certificate in Artificial Intelligence (AI) for the Workplace for a broader body of regulated learning. Both are delivered entirely online through DAIS, an NCFE-approved centre delivering Ofqual-regulated qualifications.

Visit www.dataaischool.com to find out more and speak to our team about the right starting point for you.

Found this useful? Share it
Facebook LinkedIn X WhatsApp

Before you pay for a course

A free guide: how to check in five minutes that a qualification is genuinely regulated, the seven questions to ask any provider including us, and what your fee should actually buy. Enter your email and we will send you a confirmation link. Confirm it and the guide is yours, along with an email whenever we publish something new. No spam, unsubscribe any time.