Only 17% of UK small businesses have an AI policy of any kind, not just a formal one but any one at all. That is from the Department for Science, Innovation and Technology’s UK Business Data Survey 2026, fieldwork October 2025 to January 2026. The same survey found 51% of small firms that handle digitised data already using AI-based technologies.
Different bases, so do not do the subtraction too neatly. But the shape is clear: the tools are in the building and the rules are not.
Below is what a small UK business AI policy should contain, what each clause is doing, and what a policy will not fix. The template is published in full on this page, not behind a form. A document you have to trade your email address for is one most people never read.
Why you need one even with five staff
The objection is reasonable. Five people, one office, everybody talks to everybody. Why write a policy?
Because the usage is already there and it is invisible. The surveys disagree on the level, as they always do, but not on the direction. The ONS and DSIT Business Insights and Conditions Survey, fieldwork 15 to 28 June 2026, found 35% of firms with 10 or more employees using at least one AI technology, up from around 12% in late 2023, and 28% of those with 0 to 9. Enterprise Nation and Strand Partners, from 1,320 UK SMEs surveyed in May 2026, put regular use at 21% and any use at 39%. The British Chambers of Commerce and Atos, in March 2026, had 54% of firms actively using AI, up from 23% in 2023.
Pick whichever you find most credible. Every one is above 17%.
What people are doing with it should focus your mind. DSIT found 36% of small businesses using AI for researching information and 13% for data analysis or model-building. Enterprise Nation’s adopters reported research at 59%, writing and editing content at 57% and customer service at 42%. That is your proposal drafts and your customer replies, and whatever got pasted in to write them.
A policy for five people is not bureaucracy. It is one page that means nobody has to guess, and that you have an answer when a client asks. Clients have started asking.
The eight clauses that matter, and what each is for
Everything else is padding. These eight do the work:
- Scope and who it applies to. Contractors, freelancers and volunteers use the newest tools and read the fewest policies. Naming them closes the biggest gap.
- Approved tools. Not to restrict people, but to give them somewhere to go. A list with nothing on it produces the shadow use you were trying to prevent.
- What must never be entered. The most protective value per word in the policy. Keep it concrete: categories staff will recognise, not abstractions.
- Human review and accountability. Makes the output the person’s work product, not the tool’s, and removes “the AI wrote it” as a defence, which is worth more than any technical control.
- Disclosure and transparency. Decides in advance when you tell clients, members or candidates that AI was involved, so nobody improvises it under pressure.
- Data protection and confidentiality. Connects the policy to obligations you already have rather than inventing a parallel set.
- Intellectual property and client work. Who owns what, and the contractual promises you may already have made without checking.
- Review date and named owner. Without these it is a document; with them it is a process. This is what stops the policy being sixteen months out of date.
The UK GDPR angle, handled carefully
Here is the honest version. If personal data (a customer’s name, a member’s complaint, an applicant’s CV, a sickness record) goes into an AI tool, your existing data protection obligations follow it. Nothing about the tool being new suspends them. Anyone telling you more than that in a free article is guessing at your circumstances.
Enterprise Nation found data protection concerns cited as a barrier by 38% of SMEs, behind cost at 53% and skills at 46%. Well placed, but not a reason to do nothing, since doing nothing is what produces uncontrolled use.
The Information Commissioner’s Office is the UK regulator here and publishes guidance for organisations at ico.org.uk. Read it there, directly. If you handle special category data (health, biometrics, ethnicity, trade union membership) or work in a regulated sector, take advice before adopting anything, including this.
The template
Read this first. What follows is a starting point, not legal advice. Ampus is a business and marketing consultancy, not a law firm. This template does not make you compliant with UK GDPR, the Data Protection Act 2018 or anything else, and no template can. If you are in a regulated sector, handle special category data, or have contractual obligations about confidentiality or subprocessors, take professional legal and data protection advice before adopting it. Adapt it; do not paste it in unchanged.
Copy from here.
AI Acceptable Use Policy for [Organisation name]. Version [1.0]. Effective [date]. Owner [name and role].
1. Scope. This policy applies to all employees, directors, contractors, freelancers, temporary staff and volunteers working for or on behalf of [Organisation]. It covers all use of generative AI and AI-assisted tools in connection with our work, whether provided by us or a client, or used on a personal account or device.
2. Approved tools. The following are approved for the uses described: [tool: permitted uses]; [tool: permitted uses]. Free or personal-account versions are [permitted / not permitted] for work. To request a new tool, contact [owner] before using it. Where a paid tier gives us better data handling terms, we use it.
3. What must never be entered into an AI tool. Unless a tool has been explicitly approved for it, never enter: personal data about customers, members, employees or applicants; special category data such as health, ethnicity, religion, trade union membership or biometrics; anything given to us in confidence; commercially sensitive material including pricing, contracts, tenders and unpublished financials; passwords and credentials; anything covered by an NDA. If you are unsure, ask [owner] before entering it, not afterwards.
4. Human review and accountability. AI output is a draft. A named person reviews and approves anything produced with AI assistance before it is sent, published or acted on, and is accountable for it as if they had written it. Check facts, figures, quotations, names and calculations against a reliable source. “The tool generated it” is not an acceptable explanation for an error.
5. Disclosure and transparency. We disclose material AI involvement where a reader would reasonably expect to know. In practice: [set your rules, for example: we do not mark routine internal drafting; we do tell clients when AI has been used on their deliverables; we tell candidates if AI is used in recruitment]. If anyone asks whether AI was used, we answer honestly.
6. Data protection and confidentiality. Our obligations under UK data protection law apply to AI tools exactly as they apply to everything else. Where personal data is involved, use only tools approved for that purpose by [owner], and only consistently with the privacy notice given to the individual. Where a tool offers a setting to exclude our inputs from model training, it must be on. Report any suspected exposure of personal or confidential data to [owner] within [24] hours, under our incident procedure.
7. Intellectual property and client work. Do not enter third-party copyrighted material into an AI tool beyond what our licences permit. Check client and member contracts first: some prohibit AI use, some require notice, some restrict subprocessors. AI output may not be protectable as our intellectual property and may resemble other outputs, so do not rely on it for brand assets (logos, names, straplines) without independent checks.
8. Review and ownership. This policy is owned by [name, role]. It will be reviewed by [date, no more than 12 months from the effective date] and whenever we adopt a new tool, take on a client with different requirements, or the regulatory position changes. Questions and suggested changes go to [owner]. Breaches are dealt with under our disciplinary procedure.
Copy to here.
What a policy cannot do
It cannot detect anything. There is no enforcement mechanism in a Word document, and consumer AI tools leave few traces on your systems. Write one and change nothing else, and you have documented an intention.
It cannot make an unsuitable tool suitable: “use approved tools only”, while approving nothing usable, is how you get staff on personal accounts. And it will not survive contact with a tool nobody had heard of when you wrote it. That is why clause eight exists.
And it will not tell you what AI is actually worth to you. The BCC and Atos found 95% of SMEs using AI reporting no impact on workforce size and 86% saying job roles were unchanged. Adoption is running well ahead of measurable transformation. A policy tells people how to use the tools safely; deciding which are worth using is a separate exercise, and the one we spend most of our AI implementation time on.
How to get it adopted rather than filed
Four things, none of which take long.
Ask before you publish. Twenty minutes finding out what people already use teaches you more than the policy does, and stops you banning something that is quietly holding a process together.
Approve at least two tools on day one. The policy has to give more than it takes away or it will be routed around within a fortnight.
Name a real person and make it easy to ask them. Most breaches here are not defiance. They are someone with a deadline who could not find out in time. The owner needs to be reachable in minutes, not through a form.
Walk it through once, out loud. Ten minutes in a team meeting using two real pieces of your own work, one fine to put in a tool and one not, beats any amount of circulation for acknowledgement. Then diarise the review date. Skills are the second most reported barrier for SMEs in the Enterprise Nation research, at 46%, behind cost at 53%; a document solves neither, but an unread one makes both worse.
Where to start
Take the template, spend an hour filling in the brackets with real people and real tools, and diarise the review date before you circulate it. For most small organisations that hour is the whole job.
If you would rather have someone go through it with you, or work out which tools are worth approving before you write the list, get in touch.
