An AI use policy your team will actually follow
Most businesses now use AI tools; very few have written down the rules. This is a one-page policy in plain English — three golden rules, a classification table, and the UK GDPR points that matter — free to download, rename, and adopt this afternoon. No email required.
Optional — the email version comes with our five-part series on using AI without the risk. It ends after five; unsubscribe is one click.
The three golden rules
- Client and personal data never goes into public AI tools. Assume anything typed into a public tool may be stored, reviewed, or used for training.
- A human owns every output. AI drafts; a named person checks facts, figures and tone before anything leaves the business. “The AI said so” is never a defence.
- If in doubt, ask before, not after.
What the template covers
- A four-class information table (public → special category) with what may go where
- An approved-tools list you fill in — including where a private AI fits
- Everyday rules: anonymise first, verify outputs, no AI decisions about people
- The UK GDPR obligations in the short version: lawful basis, DPAs, DPIAs, Article 22
- An incident routine (fix first, ICO 72-hour clock) and a one-line staff acknowledgement
The gap most policies leave open
A policy that only says “don't put client data in ChatGPT” leaves your team with nowhere to take exactly the questions they most need help with. That's the gap a private AI closes: trained only on your own documents, running without third-party AI providers, so confidential-class questions have a safe place to go. That's what Noetava is — and why we wrote this template.
Give the confidential questions somewhere safe to go
Upload your documents, train in minutes, and see it answer. 7-day free trial on Starter — no card needed.
This template is general guidance, not legal advice — adapt it to your business and take advice where you need it. Provided by MRD Assets Limited (Company no. 15731565, ICO registration 00015098067), trading as Noetava.