AI & Copilot

Do I need an AI usage policy — and what should it include?

If your team uses AI — and they almost certainly do — you need a simple policy. Here’s why, and what to put in it.

Greater Manchester & UK-wide · free, no-obligation advice

Why Foresight

  • Cyber Essentials Plus certified
  • Microsoft CSP & Copilot specialists
  • We reply within one working hour
  • Plain-English, no jargon

Quick answer

If your staff use AI tools — Copilot, ChatGPT, Gemini or anything else — then yes, you need an AI usage policy. It’s a short, plain-English document that tells your team which AI tools they can use, what data they must never paste into them, when to check AI output, and who’s responsible. It protects you from data leaks, inaccurate output and compliance problems, and it’s now part of the Cyber Essentials scope. It doesn’t need to be long — clear and practical beats a 20-page policy nobody reads.

Why you need one

Your staff already use AI

Here’s the reality: your team are already using AI, whether you’ve approved it or not. Without a policy, you’re exposed to three things — data leaks (someone pasting client or company data into a public AI tool), bad decisions (acting on confident-but-wrong AI output), and compliance gaps. A short policy turns “wild west” into safe, confident use.

What to include

Keep it short and practical

IncludeIn plain terms
Approved toolsWhich AI tools are OK to use (e.g. Microsoft 365 Copilot)
Never paste thisClient data, personal data, passwords, anything confidential — into public AI tools
Check the outputTreat AI as a draft — a human checks anything that matters
AccountabilityThe person using the AI owns the result
Privacy & disclosureWhen to tell clients AI was used, and respecting confidentiality
Who to askWhere to go with questions or to request a new tool

The compliance angle

It’s now expected

From 2026, AI tools come into scope for Cyber Essentials, and insurers and clients increasingly expect a policy. It pairs naturally with getting Copilot rolled out safely and your wider AI security. We can help you put a simple, practical one in place.

FAQs

Common questions

Does my business need an AI usage policy?
Yes, if your staff use any AI tools. A short policy protects you from data leaks, inaccurate output and compliance gaps — and it’s now part of the Cyber Essentials scope.
What should an AI usage policy include?
Approved tools, what data must never be pasted into AI, a rule to check important output, who’s accountable, privacy/disclosure expectations, and who to ask with questions.
How long should an AI policy be?
Short — one or two pages. A clear, practical policy people actually read beats a long document that gets ignored.
Is an AI policy required for Cyber Essentials?
From 2026 AI tools come into scope for Cyber Essentials, so having clear rules for their use supports certification and is increasingly expected by insurers and clients.
Can Foresight help us create one?
Yes — we’ll help you put a simple, practical policy in place and roll it out to staff.

Get your AI use under control — simply

A short, clear AI policy protects your data and keeps you compliant. We’ll help you put one in place.