1. Purpose, scope and status
This policy governs the use of artificial intelligence tools at Northstar Analytics Ltd. It applies to employees, contractors and temporary workers, whether or not they use a device Northstar Analytics Ltd provides.
It has been written for this operating context: UK professional services handling client-confidential information.
This policy takes effect on 1 October 2026.
It covers tools bought deliberately and AI features that arrive switched on inside software already licensed.
2. Our position
Northstar Analytics Ltd's position is to enable by role, with review. Access follows role and data exposure, and higher-risk uses need sign-off. The common landing place, and the one that survives an audit best.
Access to approved tools follows role. Uses involving sensitive data or consequential decisions require approval before they begin.
3. Approved tools, accounts and use cases
The following classes of tool are in use at Northstar Analytics Ltd:
- General assistants (chat, drafting, research)
- AI features inside software you already licence
- Coding assistants
- Meeting transcription and note-takers
The specifically approved tools and account tiers are:
- Microsoft 365 Copilot (business tenant)
- GitHub Copilot Business
Approved uses include:
- Drafting and summarising non-confidential material
- Research with primary-source verification
- Code assistance with normal review and testing
Work may be performed only through organisation-managed accounts on approved business or enterprise tiers. Personal accounts must not be used for work.
A new tool or use case must be requested through the IT service desk, with Security and Privacy review where required before use.
4. Data handling
Credentials, keys and secrets must never be entered into an AI tool. Use an authorised secrets-management process instead.
The following additional data classes must not be entered unless that specific tool, account tier and use case have been approved for them in writing:
- Personal data about identifiable people
- Special category data (health, biometrics, beliefs)
- Client or customer confidential information
- Unpublished financial information
- Legally privileged material
- Employee records and HR case material
This covers pasting, uploading, screen sharing, connectors, retrieval indexes and leaving a transcription tool in a meeting where the material is discussed.
Before approving sensitive data, verify the supplier's retention, training, residency, access-control and deletion terms rather than relying on the product name alone.
5. Prohibited uses and human accountability
AI must not make a final decision about recruitment, performance, credit, access to a service, safety or another material outcome affecting a person without competent human review and an accountable decision owner.
Do not use AI to impersonate a person, fabricate evidence or citations, evade security controls, create deceptive synthetic media, or infringe copyright, contractual or licensing obligations.
AI output is a draft, not a source. Verify facts, calculations, citations and code through the same review, testing and approval process that applies to human work.
Do not present AI output as independent corroboration of something you already believe. It is not a second opinion.
6. Transparency
Tell people when they are dealing with an AI system rather than a person. Mark synthetic images, audio and video as machine-generated where they could reasonably be mistaken for real.
The organisation has determined that applicable EU AI Act transparency duties must be implemented and evidenced for the systems and content they cover.
7. Incidents, concerns and exceptions
Report accidental disclosure, unsafe output, suspected bias, a security concern or an unapproved tool immediately through security@northstar.example or the security incident form. Preserve enough information to investigate, but do not copy sensitive material into an ordinary ticket. Good-faith reporting will not attract disciplinary action for the disclosure itself.
Exceptions are decided through the policy owner; every exception must name an owner and expiry date. Every exception must record its scope, owner, reason, safeguards and expiry date.
8. AI literacy and support
Northstar Analytics Ltd will provide material appropriate to each affected group: what the tools are for, how they fail, what must not go into them, and how to check output in that person's work.
This policy supports the organisation's measures under Article 4 of the EU AI Act, as replaced by Regulation (EU) 2026/1744. It does not discharge that obligation by itself: the organisation must also provide, resource and record support appropriate to people's knowledge, experience, training, usage context and affected groups.
9. Building, configuring and integrating AI
Teams at Northstar Analytics Ltd that build, configure or integrate AI must record what each system does, what data it uses, who owns it, its permitted actions and its dependencies.
Systems that read untrusted content, including web pages, documents, email and tickets, must treat that content as data that may contain hostile instructions. Tools and credentials must be limited to the task, and consequential actions require proportionate approval and logging.
Assess effects on people before deployment. This is separate from a data protection impact assessment, which addresses privacy rather than every fairness, safety or accuracy consequence.
10. Ownership, acknowledgement and review
This policy is owned by the Head of IT and Cyber Security, who is responsible for keeping it current, maintaining the approved-tools record and deciding or routing exceptions.
Everyone covered by this policy must confirm that they have read and understood it before receiving access to approved AI tools.
It will be reviewed every quarter, and sooner after a material tool, legal, contractual or risk change or an incident.
Breach is handled through the organisation's normal disciplinary or contractual process, proportionate to intent, impact and whether the person reported the issue promptly.