Free Resource · AI Governance

Free AI Usage Policy Template

A ready-to-use, editable AI usage policy for UK businesses — covering approved tools, what staff must never paste into AI, Copilot data security, MFA and Cyber Essentials v3.3. Download it free, tailor it to your organisation, and roll it out.

Free & editable · no sign-up required

Editable Word docUK GDPR awareCyber Essentials v3.3Ready in minutes

Quick answer

An AI usage policy tells your staff which AI tools are approved, what they must never put into them, and how to use AI safely. Ours is a free, editable Word template covering approved tools, prohibited data, Copilot data security, MFA and Cyber Essentials v3.3 — ready to tailor to your organisation and roll out in minutes.

What’s inside

A complete policy, not a blank page

The template is written in plain English and structured so you can adopt it quickly. It covers:

  • Purpose, scope and clear definitions (including “shadow AI”)
  • An approved-tools table to record which AI your business allows
  • Acceptable use — what staff can use AI for
  • What must never be put into AI tools (personal data, client info, credentials, and more)
  • Data protection & confidentiality (UK GDPR aware)
  • Accuracy and human oversight
  • Security requirements — company accounts and mandatory MFA
  • An AI & Cyber Essentials section reflecting the v3.3 rules
  • Roles, incident reporting, breaches, review, and a staff acknowledgement

Why now

Shadow AI is the fastest-growing governance gap

Staff are already using Microsoft 365 Copilot, ChatGPT and AI features in your CRM — often without anyone signing off. That “shadow AI” is a data risk, and since the April 2026 Cyber Essentials update it’s a compliance risk too: AI tools are in-scope cloud services that can’t be excluded. A written policy is the quickest way to get a grip. Read more on shadow AI and AI & Cyber Essentials.

Beyond the policy

Words backed by guardrails

A policy is the foundation — but it works best with the technical controls behind it. That’s our AI security service: discovering shadow AI, enforcing MFA, applying data loss prevention and hardening Microsoft 365 Copilot so your policy is enforced, not just written. Want it tailored to your organisation? Get in touch.

FAQs

Common questions

Is the AI usage policy template free?
Yes — it’s a free, editable Word document. Download it, tailor it to your organisation and roll it out. If you’d like us to adapt it to how your business actually works, we’re happy to help.
Can I edit it?
Yes. It’s a Word (.docx) file with clearly marked [placeholders] to complete. Replace the bracketed text with your details, delete anything that doesn’t apply, and it’s ready.
Does it cover Cyber Essentials?
Yes. It includes a section explaining that under Cyber Essentials v3.3 (April 2026) AI tools are in-scope cloud services that need MFA, and it builds MFA and an approved-tools inventory into the policy.
Do we really need an AI usage policy?
If your staff use AI — and they almost certainly do — then yes. A clear policy is the quickest, cheapest way to turn ungoverned ‘shadow AI’ into safe, sanctioned use, and it’s the foundation the technical controls sit on.
Can you tailor it for us?
Absolutely. We help organisations across Greater Manchester and the UK adopt AI safely — from discovering shadow AI to policy, data loss prevention and Cyber Essentials. Get in touch and we’ll make it fit your business.

Download it now, or let us tailor it for you

Grab the free template and roll it out today — or ask us to adapt it to your tools, your risks and your Cyber Essentials scope.

Free and editable — general guidance, not legal advice.