AI Policy for Employees: Why HR Should Write It and What It Needs to Say

Shape1
Shape2
AI Policy for Employees: Why HR Should Write It and What It Needs to Say

Scope note: This article looks at how UK employers are approaching AI use policies. It refers to UK GDPR, the Data (Use and Access) Act 2025 and ICO guidance as regulatory context and direction of travel only. It is not legal advice. Sabiha is a talent acquisition practitioner, not a lawyer. For decisions about your organisation’s specific obligations, a qualified employment or data protection specialist can advise you.

A hiring manager has twelve CVs for one role and a deadline on Friday. So he copies all twelve into a free chatbot and asks it which three to interview. It takes about ten seconds. Nobody told him not to. Nobody told him he could, either.

I see versions of this in almost every organisation I work with. The tools are already in the building. The rules usually are not.

That gap is exactly what an AI policy for employees closes. The organisations that get it right treat it as a people document first and a technology document second. Here is how to write one that your teams will actually follow, including the hiring section most templates leave out.

What is an AI policy for employees?

An AI policy for employees is a short, plain-English document that tells your people which AI tools they can use for work, what information must never go into them, and who is accountable for what AI produces.

It sits alongside your data protection, IT security and code of conduct policies. It covers the everyday generative AI your staff already reach for: tools like ChatGPT, Microsoft Copilot, Gemini and Claude, used to draft emails, summarise documents, write job adverts or prepare interview questions.

The best policies are short enough that a new starter can remember the core rules without looking them up. If yours needs a contents page, it is probably too long to change behaviour.

Why do UK employers need an AI policy now?

Because your employees are already using AI, and many of them are doing it without approved tools or clear rules.

Research commissioned by Microsoft and carried out by Censuswide in October 2025 surveyed 2,003 UK employees. It found that 71% had used unapproved consumer AI tools at work, and 51% still do so every week. For HR, the more revealing figure is this: 28% said their employer does not provide a work-approved option, so they had no choice but to find their own.

That last number matters. Shadow AI is often a gap in provision rather than a discipline problem. People reach for whatever helps them get the job done.

Employers are responding, but slowly. The CIPD’s Autumn 2025 Labour Market Outlook found that 61% of UK organisations now allow employees to use generative AI for work-related tasks. Yet only 31% of employers reported working on a generative AI policy in the past 12 months, up from 16% previously. Over the same period, privacy and security concerns rose to 48% of employers, from 36% in autumn 2023.

Put those figures side by side and the pattern is clear. Use is running well ahead of guidance. In a 100-person business, the space between “people are using it” and “we have told them how” is where data leaks, inconsistent hiring decisions and quiet mistrust take hold.

Why should HR own the AI policy rather than IT?

Because an AI policy only works if it changes how people behave, and behaviour change is an HR job.

IT has a vital role. It assesses tools, manages accounts and sets the technical controls. But the questions that decide whether a policy succeeds are people questions. How do you explain the rules at induction? How should a manager respond when someone breaks them? What happens when AI touches a decision about a person’s job, pay or career?

There is a second reason. HR and hiring managers handle the most sensitive personal information in the business: CVs, interview notes, absence records, performance reviews and salary data. When personal data ends up in an unapproved chatbot, it is often because a busy hiring manager was trying to save an hour. The function writing the policy is also the function with the most to protect.

The strongest policies I see are co-owned. HR writes the rules in plain English, IT confirms what is technically possible, and a named senior leader signs them off. The CIPD’s practical guide to AI use in the workplace takes the same view: people professionals are central to responsible adoption.

What should an AI policy for employees include?

A workable policy covers seven areas and fits on two pages.

  1. Purpose and scope. Who the policy applies to, including contractors and agency workers, and which tools it covers. Name the tools. Generic wording gets ignored.
  2. Approved tools. The specific AI tools and account types sanctioned for work. A free personal account and a business subscription can handle your data very differently, so be precise.
  3. Data red lines. What must never go into an AI tool: personal data about candidates, employees or customers unless the tool has been assessed and approved for it, confidential commercial information, and anything covered by a client contract.
  4. Human accountability. Whoever uses AI owns the output. AI can draft, summarise and suggest. A named person checks, edits and signs off.
  5. Decisions about people. A clear rule that AI does not decide on hiring, pay, promotion, performance or dismissal by itself. This is where most policies fall short, so it gets its own section below.
  6. Transparency. When staff should tell colleagues, clients or candidates that AI was used.
  7. Training, reporting and review. Who to ask when unsure, how to report a mistake without fear, and when the policy will be reviewed. Every six months is sensible while the technology and regulation keep moving.

Write each section in the language your people actually use. “Never paste a candidate’s CV into a personal AI account” will be remembered. Three paragraphs on data classification will not.

What should an AI policy say about hiring?

It should say that AI can support hiring decisions but a trained person makes them, and it should explain how you will show that.

This is the section most templates skip, and it matters most for UK SMEs. Hiring is where AI touches people’s livelihoods, and where regulatory attention is sharpest.

In March 2026 the ICO published Recruitment Rewired, based on evidence from over 30 employers that engaged with it voluntarily between March 2025 and January 2026. Its key finding was that many employers using automated recruitment are likely relying on solely automated decisions, without meaningful human involvement. The ICO is signalling that those decisions attract a wider range of safeguards than its evidence suggests are currently in place. It also points to better transparency with candidates, and to human involvement being applied consistently to every candidate at the same stage.

Your policy can reflect that direction of travel in four practical rules.

  • Candidate data stays in approved tools. CVs, application forms and interview notes only go into AI tools your business has assessed and approved.
  • A person reviews before anyone is rejected. If a tool ranks, scores or screens applicants, a trained reviewer checks the output before any candidate is progressed or turned down, for every candidate at that stage and not only the borderline ones.
  • Candidates are told. Your job adverts or privacy notice explain where AI is used in your process and how a candidate can ask for a person to look again.
  • You have a stance on candidates’ own AI use. Candidates are using AI to write applications. Decide what is acceptable, such as polishing a CV, and what is not, such as AI answering live interview questions, and say so upfront.

If you are building these rules into a wider process, my guide to implementing AI in hiring walks through each stage, and the post on AI CV screening covers where screening tools help and where they need a human check.

How do you roll out an AI policy so people follow it?

Launch it through onboarding and training rather than as an email attachment.

A policy nobody reads protects nobody. The rollout matters as much as the wording.

Start by asking, not telling. Before you write anything, ask each team which AI tools they already use and what for. You will get an honest baseline, and the policy will describe how work actually happens. People who have been using unapproved tools are far more likely to come forward if the first conversation is curious rather than disciplinary.

Build it into induction. Every new starter should meet the AI policy in their first week, alongside data protection and IT security. It sets expectations before habits form.

Pair rules with skills. Telling people what not to do is half the job. Show them what good use looks like in their own role: how to write a clear prompt, how to check an output, and how to spot when AI has confidently got something wrong. In the CIPD’s survey, 35% of employers had provided training and support to help employees use generative AI at work, an activity it associates with organisations further along their AI journey.

Make it safe to report mistakes. Someone will paste the wrong document into the wrong tool. If they fear punishment, you will never hear about it. A simple “tell us straight away” route turns an incident into a fix.

What mistakes do employers make with AI policies?

The most common mistake is a policy that bans everything useful, which simply pushes AI use out of sight.

A blanket ban feels safe. In practice, if the approved route is slower than the workaround, people take the workaround. The CIPD found that in one in four UK organisations, employees are not allowed to use generative AI and there are no plans to change that. Set against the Microsoft findings, it is fair to ask how many of those bans are being followed.

The other mistakes I see most often are copying a template without adapting it to how your teams really work, leaving decisions about people out of the policy entirely, and never reviewing it. A policy written two years ago may not mention AI meeting note-takers, AI agents or the AI features now built into many applicant tracking systems, all of which your people may be using today.

Where to start this week

An AI policy for employees is one of the cheapest risk controls available to a UK SME, and one of the few that also makes people better at their jobs. Written well, it tells your teams that you trust them with these tools, shows them how to use them safely, and makes clear that a person is always accountable for decisions about people.

Start with a conversation rather than a document. Ask your managers this week which AI tools their teams rely on. Their answers will tell you how urgently you need the policy, and exactly what it needs to say.

Frequently asked questions

Is an AI policy a legal requirement for UK employers?

There is no single UK law that requires a standalone AI policy. Existing duties under UK GDPR, the Data Protection Act 2018 and the Equality Act 2010 still apply when staff use AI, and a written policy is practical evidence that you take those duties seriously. A qualified specialist can advise on your organisation’s specific position.

How long should an AI policy for employees be?

Aim for one to two pages. Staff should be able to recall the core rules, especially the data red lines, without looking them up.

Can employees use ChatGPT at work?

That depends on your policy. Many employers allow AI tools for low-risk tasks such as drafting and summarising, while keeping personal and confidential data to approved business accounts. Decide and say so clearly, because silence tends to be read as permission.

How often should we review our AI policy?

Every six months is a sensible cadence while tools and regulation are changing quickly, with an immediate review whenever you introduce a new AI tool into hiring or people management.

About the author

Sabiha is a Talent Acquisition Director, speaker and author with 16+ years of international hiring experience across the UK, Dubai, South Africa and Malaysia. She has advised 300+ businesses on hiring and retention and was shortlisted for Best Career Coach UK by the CDI. She advises UK SMEs on AI-enabled hiring and retention. Her book, How to Use AI to Win Talent and Retain People, is published by Trotman in Autumn 2026.

Leave a Reply

Your email address will not be published. Required fields are marked *