AI Policy for UK Businesses: What to Include in 2026

A practical guide to the controls a UK business AI policy should cover, from approved tools and confidential data to human oversight, incidents and staff responsibilities.

By Clausely Team

What an AI policy is actually for

An AI policy should tell people what they may do with AI at work, where the boundaries are, who is accountable and what happens when something goes wrong. The useful version is operational: it should reflect the tools your organisation actually uses and the risks those tools create.

For businesses within scope of the EU AI Act, Article 4 requires providers and deployers to take measures to support AI literacy among relevant staff and other people using AI systems on their behalf. The law does not prescribe a document called an AI policy, but written governance can help turn those measures into repeatable practice and evidence. Read the EU AI Act checklist for the wider framework.

Eight controls worth putting in writing

  • Approved AI tools and an approval route for new tools.
  • Rules for confidential, personal, client and commercially sensitive information.
  • Human review requirements before AI output is relied on or sent externally.
  • Prohibited or restricted uses, including decisions that could significantly affect people.
  • Accuracy, bias and hallucination checks proportionate to the use case.
  • Copyright, intellectual property and source-verification expectations.
  • Incident reporting, escalation and record keeping.
  • Named ownership for policy review, staff guidance and updates.

AI policy and AI literacy are related, but not identical

A policy can set the rules; literacy measures help people understand how to apply them. Article 4 has applied since 2 February 2025. Following the 2026 amendments, no single prescribed level of AI literacy is mandated, so measures should be proportionate to people's knowledge, experience, training and the context in which AI is used.

That makes a one-size-fits-all policy weak evidence on its own. A small accountancy practice using generative AI for drafting has different risks from a recruitment firm using AI to rank candidates.

Do not forget data protection

If AI use involves personal data, your AI policy should connect to your privacy and data-protection controls. A DPIA is mandatory where processing is likely to result in high risk to people's rights and freedoms. The ICO specifically identifies innovative technology, including AI, as one factor that can contribute to high-risk processing. Check when a DPIA is required.

When Article 50 transparency rules matter

Article 50 transparency obligations apply from 2 August 2026, but they are use-case specific. They include rules around direct interaction with certain AI systems and disclosure for deployers in situations such as deepfakes and certain AI-generated public-interest text. They are not a blanket instruction to label every piece of AI-assisted business content.

Your policy should therefore tell staff when a disclosure is required and who decides, rather than using a generic 'AI was used' notice everywhere.

Template versus tailored policy

A free template can be a useful prompt, but the work is deciding which controls fit your business. The policy should match your sector, AI tools, data, client obligations and actual workflows. Clausely's EU AI Act Essentials pack is designed for businesses that want that baseline documented without drafting it all from scratch.

Recommended next step

Turn the checklist into business-specific documents.

Clausely's Essentials pack creates tailored baseline AI governance documents from your business, tools and use cases, rather than leaving you to adapt a generic download.

Build your Essentials packRun the free risk check

Prefer to see what is included first? The EU AI Act Essentials brochure is a one-page summary of the documents in the pack.

This guide provides general compliance information and does not constitute legal advice. If you require advice on your specific legal position, consult a qualified solicitor.