Skip to main content
PolicyGovernance

How to Write an Acceptable Use Policy Staff Will Actually Follow

How to Write an Acceptable Use Policy Staff Will Actually Follow
Published 1 October 2026Last reviewed 1 October 20265 min readBy Simon Steggles· Fractional AI Director
Who this is for:UK SME owners, directors and council leaders who have an AI policy on paper and no evidence staff follow it.

TL;DR

Your staff are already using AI. A policy that bans it, or one that runs to 12 pages, will not change that. This article shows you how to write an acceptable use policy people read, understand and follow.

Key takeaways

  • Write the policy for the person using AI, not for the auditor reading it.
  • Name the approved tools. Staff cannot follow a rule about tools they cannot identify.
  • Use three data tiers: never enter, ask first, free to use.
  • Name one person who answers questions within one working day.
  • Review the policy every quarter and publish what changed.

A Deloitte survey of 25,000 UK workers found one in three use generative AI for work of their own accord. That is your staff, today, whether you have a policy or not.

Most policies fail for the same reason. They are written for auditors, not for the person at a desk at 4pm with a deadline. Fix that and compliance follows.

Why most policies get ignored

Red Eagle Tech surveyed 200 UK desk workers in February 2026. 54.5% said they lack a clear, enabling AI policy from their employer. 41% said they work in a total policy vacuum. The sample is small, so treat the figures as indicative. The direction matches what I see in practice.

The same survey found 32% of respondents admitted to using AI tools at work without their employer's knowledge. A further 13.5% said their employer bans AI outright. Bans do not stop use. They move it out of sight.

I have reviewed policies that run to 15 pages. Nobody reads them. Staff sign the acknowledgement, close the document and carry on as before. A signature is not compliance.

Write it for the person at the desk

Keep the policy to two pages. If you cannot fit it on two pages, you have written a governance framework, not an acceptable use policy. Keep both. Do not confuse them.

Use plain words. Replace "personal data shall not be processed through unapproved systems" with "Do not paste customer names, addresses or account details into any AI tool unless it is on the approved list." Staff must be able to apply the rule without asking a lawyer.

Lead with what staff can do. Open with the approved tools and the tasks they suit. Staff who see a clear yes are far more likely to respect the no.

Name the tools and sort your data into three tiers

Publish a list of approved tools, with the version or plan you pay for. A free consumer account and a business account often have different data terms. Say which one staff must use.

Then split your data into three tiers. Staff remember three. They do not remember thirty.

  • Never enter: customer personal data, staff records, contracts under negotiation, passwords, anything covered by an NDA.
  • Ask first: internal financial figures, draft board papers, supplier pricing, anything you are unsure about.
  • Free to use: public information, your own published marketing, generic drafting with no names or figures.

Print the three tiers on one page and put it where staff work. Do not bury it in the intranet.

Give staff a person to ask

Name one person who answers AI questions within one working day. Give their name, email and a backup. If staff wait three days for an answer, they will guess.

Tell staff what happens when they get it wrong. Say that reporting a mistake within 24 hours will not lead to discipline. You want the report. Staff who fear punishment hide incidents, and hidden incidents are the ones that reach the ICO.

Make the rule on human review explicit. Anyone who sends AI-drafted text to a customer, a regulator or the public is responsible for every word of it.

Review it every quarter

AI tools change every month. A policy written in January is out of date by April. Set a quarterly review on the calendar now. Put the date in the policy itself.

At each review, ask three questions. Which new tools are staff asking for? What questions came to the named contact? What incidents were reported? Add the answers to the next version and tell staff what changed in two sentences.

What to do this week

Do these in order. First, list the AI tools your staff use today. Ask them. Do not guess. Second, choose which of those you will approve and which you will stop. Third, write the two-page policy using the three data tiers. Fourth, name your contact person. Fifth, book the first quarterly review.

Use the Staff AI Acceptable Use Policy Template resource on this site as your starting structure. Then test it on three members of staff who did not write it. If they cannot explain it back to you in a minute, rewrite it.

About the author

Simon Steggles - Fractional AI Director

Simon helps UK SMEs and councils put AI to work safely. Royal Navy 1984–90 (Cat 3 PV at the time, now superseded by DV); current NPPV3 Police vetting for public-sector work; ISACA AI Governance certified. Based in Birmingham. £300K+ recovered for councils, 43% cost reduction in manufacturing, zero data-protection incidents across every engagement.

More about Simon

Want help applying this?

Grab the free AI Readiness Checklist or book a 30-minute strategy call with Simon - no pitch, no slide deck, just practical advice for your situation.

Free AI Readiness Checklist

Find Out Where AI Can Save or Generate Money in Your Organisation

Book a free 30-minute call with Simon. Bring a real problem - staff time, governance worry, vendor proposal, failing pilot - and leave with a concrete first step you can take next week.

Call