

Scope note: This article looks at how UK employers are approaching AI use policies. It refers to UK GDPR, the Data (Use and Access) Act 2025 and ICO guidance as regulatory context and direction of travel only. It is not legal advice. Sabiha is a talent acquisition practitioner, not a lawyer. For decisions about your organisation’s specific obligations, a qualified employment or data protection specialist can advise you.
A hiring manager has twelve CVs for one role and a deadline on Friday. So he copies all twelve into a free chatbot and asks it which three to interview. It takes about ten seconds. Nobody told him not to. Nobody told him he could, either.
I see versions of this in almost every organisation I work with. The tools are already in the building. The rules usually are not.
That gap is exactly what an AI policy for employees closes. The organisations that get it right treat it as a people document first and a technology document second. Here is how to write one that your teams will actually follow, including the hiring section most templates leave out.
An AI policy for employees is a short, plain-English document that tells your people which AI tools they can use for work, what information must never go into them, and who is accountable for what AI produces.
It sits alongside your data protection, IT security and code of conduct policies. It covers the everyday generative AI your staff already reach for: tools like ChatGPT, Microsoft Copilot, Gemini and Claude, used to draft emails, summarise documents, write job adverts or prepare interview questions.
The best policies are short enough that a new starter can remember the core rules without looking them up. If yours needs a contents page, it is probably too long to change behaviour.
Because your employees are already using AI, and many of them are doing it without approved tools or clear rules.
Research commissioned by Microsoft and carried out by Censuswide in October 2025 surveyed 2,003 UK employees. It found that 71% had used unapproved consumer AI tools at work, and 51% still do so every week. For HR, the more revealing figure is this: 28% said their employer does not provide a work-approved option, so they had no choice but to find their own.
That last number matters. Shadow AI is often a gap in provision rather than a discipline problem. People reach for whatever helps them get the job done.
Employers are responding, but slowly. The CIPD’s Autumn 2025 Labour Market Outlook found that 61% of UK organisations now allow employees to use generative AI for work-related tasks. Yet only 31% of employers reported working on a generative AI policy in the past 12 months, up from 16% previously. Over the same period, privacy and security concerns rose to 48% of employers, from 36% in autumn 2023.
Put those figures side by side and the pattern is clear. Use is running well ahead of guidance. In a 100-person business, the space between “people are using it” and “we have told them how” is where data leaks, inconsistent hiring decisions and quiet mistrust take hold.
Because an AI policy only works if it changes how people behave, and behaviour change is an HR job.
IT has a vital role. It assesses tools, manages accounts and sets the technical controls. But the questions that decide whether a policy succeeds are people questions. How do you explain the rules at induction? How should a manager respond when someone breaks them? What happens when AI touches a decision about a person’s job, pay or career?
There is a second reason. HR and hiring managers handle the most sensitive personal information in the business: CVs, interview notes, absence records, performance reviews and salary data. When personal data ends up in an unapproved chatbot, it is often because a busy hiring manager was trying to save an hour. The function writing the policy is also the function with the most to protect.
The strongest policies I see are co-owned. HR writes the rules in plain English, IT confirms what is technically possible, and a named senior leader signs them off. The CIPD’s practical guide to AI use in the workplace takes the same view: people professionals are central to responsible adoption.
A workable policy covers seven areas and fits on two pages.
Write each section in the language your people actually use. “Never paste a candidate’s CV into a personal AI account” will be remembered. Three paragraphs on data classification will not.
It should say that AI can support hiring decisions but a trained person makes them, and it should explain how you will show that.
This is the section most templates skip, and it matters most for UK SMEs. Hiring is where AI touches people’s livelihoods, and where regulatory attention is sharpest.
In March 2026 the ICO published Recruitment Rewired, based on evidence from over 30 employers that engaged with it voluntarily between March 2025 and January 2026. Its key finding was that many employers using automated recruitment are likely relying on solely automated decisions, without meaningful human involvement. The ICO is signalling that those decisions attract a wider range of safeguards than its evidence suggests are currently in place. It also points to better transparency with candidates, and to human involvement being applied consistently to every candidate at the same stage.
Your policy can reflect that direction of travel in four practical rules.
If you are building these rules into a wider process, my guide to implementing AI in hiring walks through each stage, and the post on AI CV screening covers where screening tools help and where they need a human check.
Launch it through onboarding and training rather than as an email attachment.
A policy nobody reads protects nobody. The rollout matters as much as the wording.
Start by asking, not telling. Before you write anything, ask each team which AI tools they already use and what for. You will get an honest baseline, and the policy will describe how work actually happens. People who have been using unapproved tools are far more likely to come forward if the first conversation is curious rather than disciplinary.
Build it into induction. Every new starter should meet the AI policy in their first week, alongside data protection and IT security. It sets expectations before habits form.
Pair rules with skills. Telling people what not to do is half the job. Show them what good use looks like in their own role: how to write a clear prompt, how to check an output, and how to spot when AI has confidently got something wrong. In the CIPD’s survey, 35% of employers had provided training and support to help employees use generative AI at work, an activity it associates with organisations further along their AI journey.
Make it safe to report mistakes. Someone will paste the wrong document into the wrong tool. If they fear punishment, you will never hear about it. A simple “tell us straight away” route turns an incident into a fix.
The most common mistake is a policy that bans everything useful, which simply pushes AI use out of sight.
A blanket ban feels safe. In practice, if the approved route is slower than the workaround, people take the workaround. The CIPD found that in one in four UK organisations, employees are not allowed to use generative AI and there are no plans to change that. Set against the Microsoft findings, it is fair to ask how many of those bans are being followed.
The other mistakes I see most often are copying a template without adapting it to how your teams really work, leaving decisions about people out of the policy entirely, and never reviewing it. A policy written two years ago may not mention AI meeting note-takers, AI agents or the AI features now built into many applicant tracking systems, all of which your people may be using today.
An AI policy for employees is one of the cheapest risk controls available to a UK SME, and one of the few that also makes people better at their jobs. Written well, it tells your teams that you trust them with these tools, shows them how to use them safely, and makes clear that a person is always accountable for decisions about people.
Start with a conversation rather than a document. Ask your managers this week which AI tools their teams rely on. Their answers will tell you how urgently you need the policy, and exactly what it needs to say.
There is no single UK law that requires a standalone AI policy. Existing duties under UK GDPR, the Data Protection Act 2018 and the Equality Act 2010 still apply when staff use AI, and a written policy is practical evidence that you take those duties seriously. A qualified specialist can advise on your organisation’s specific position.
Aim for one to two pages. Staff should be able to recall the core rules, especially the data red lines, without looking them up.
That depends on your policy. Many employers allow AI tools for low-risk tasks such as drafting and summarising, while keeping personal and confidential data to approved business accounts. Decide and say so clearly, because silence tends to be read as permission.
Every six months is a sensible cadence while tools and regulation are changing quickly, with an immediate review whenever you introduce a new AI tool into hiring or people management.
Sabiha is a Talent Acquisition Director, speaker and author with 16+ years of international hiring experience across the UK, Dubai, South Africa and Malaysia. She has advised 300+ businesses on hiring and retention and was shortlisted for Best Career Coach UK by the CDI. She advises UK SMEs on AI-enabled hiring and retention. Her book, How to Use AI to Win Talent and Retain People, is published by Trotman in Autumn 2026.

Global Talent. Ethical AI. Strategic Hiring. Sustainable Retention.
WhatsApp us