P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

Completed worked example

AI Acceptable Use Policy Example

A complete fictional example for a UK professional-services company, showing how operational decisions become an issuable policy and a concise staff guide.

Policy version 2026-09-19

Northstar Analytics Ltd

All required decisions resolved

1. Purpose, scope and status

This policy governs the use of artificial intelligence tools at Northstar Analytics Ltd. It applies to employees, contractors and temporary workers, whether or not they use a device Northstar Analytics Ltd provides.

It has been written for this operating context: UK professional services handling client-confidential information.

This policy takes effect on 1 October 2026.

It covers tools bought deliberately and AI features that arrive switched on inside software already licensed.

2. Our position

Northstar Analytics Ltd's position is to enable by role, with review. Access follows role and data exposure, and higher-risk uses need sign-off. The common landing place, and the one that survives an audit best.

Access to approved tools follows role. Uses involving sensitive data or consequential decisions require approval before they begin.

3. Approved tools, accounts and use cases

The following classes of tool are in use at Northstar Analytics Ltd:

  • General assistants (chat, drafting, research)
  • AI features inside software you already licence
  • Coding assistants
  • Meeting transcription and note-takers

The specifically approved tools and account tiers are:

  • Microsoft 365 Copilot (business tenant)
  • GitHub Copilot Business

Approved uses include:

  • Drafting and summarising non-confidential material
  • Research with primary-source verification
  • Code assistance with normal review and testing

Work may be performed only through organisation-managed accounts on approved business or enterprise tiers. Personal accounts must not be used for work.

A new tool or use case must be requested through the IT service desk, with Security and Privacy review where required before use.

4. Data handling

Credentials, keys and secrets must never be entered into an AI tool. Use an authorised secrets-management process instead.

The following additional data classes must not be entered unless that specific tool, account tier and use case have been approved for them in writing:

  • Personal data about identifiable people
  • Special category data (health, biometrics, beliefs)
  • Client or customer confidential information
  • Unpublished financial information
  • Legally privileged material
  • Employee records and HR case material

This covers pasting, uploading, screen sharing, connectors, retrieval indexes and leaving a transcription tool in a meeting where the material is discussed.

Before approving sensitive data, verify the supplier's retention, training, residency, access-control and deletion terms rather than relying on the product name alone.

5. Prohibited uses and human accountability

AI must not make a final decision about recruitment, performance, credit, access to a service, safety or another material outcome affecting a person without competent human review and an accountable decision owner.

Do not use AI to impersonate a person, fabricate evidence or citations, evade security controls, create deceptive synthetic media, or infringe copyright, contractual or licensing obligations.

AI output is a draft, not a source. Verify facts, calculations, citations and code through the same review, testing and approval process that applies to human work.

Do not present AI output as independent corroboration of something you already believe. It is not a second opinion.

6. Transparency

Tell people when they are dealing with an AI system rather than a person. Mark synthetic images, audio and video as machine-generated where they could reasonably be mistaken for real.

The organisation has determined that applicable EU AI Act transparency duties must be implemented and evidenced for the systems and content they cover.

7. Incidents, concerns and exceptions

Report accidental disclosure, unsafe output, suspected bias, a security concern or an unapproved tool immediately through security@northstar.example or the security incident form. Preserve enough information to investigate, but do not copy sensitive material into an ordinary ticket. Good-faith reporting will not attract disciplinary action for the disclosure itself.

Exceptions are decided through the policy owner; every exception must name an owner and expiry date. Every exception must record its scope, owner, reason, safeguards and expiry date.

8. AI literacy and support

Northstar Analytics Ltd will provide material appropriate to each affected group: what the tools are for, how they fail, what must not go into them, and how to check output in that person's work.

This policy supports the organisation's measures under Article 4 of the EU AI Act, as replaced by Regulation (EU) 2026/1744. It does not discharge that obligation by itself: the organisation must also provide, resource and record support appropriate to people's knowledge, experience, training, usage context and affected groups.

9. Building, configuring and integrating AI

Teams at Northstar Analytics Ltd that build, configure or integrate AI must record what each system does, what data it uses, who owns it, its permitted actions and its dependencies.

Systems that read untrusted content, including web pages, documents, email and tickets, must treat that content as data that may contain hostile instructions. Tools and credentials must be limited to the task, and consequential actions require proportionate approval and logging.

Assess effects on people before deployment. This is separate from a data protection impact assessment, which addresses privacy rather than every fairness, safety or accuracy consequence.

10. Ownership, acknowledgement and review

This policy is owned by the Head of IT and Cyber Security, who is responsible for keeping it current, maintaining the approved-tools record and deciding or routing exceptions.

Everyone covered by this policy must confirm that they have read and understood it before receiving access to approved AI tools.

It will be reviewed every quarter, and sooner after a material tool, legal, contractual or risk change or an incident.

Breach is handled through the organisation's normal disciplinary or contractual process, proportionate to intent, impact and whether the person reported the issue promptly.

One-page staff companion

Using AI safely at Northstar Analytics Ltd

Allowed

  • Use Microsoft 365 Copilot (business tenant) through the approved account.
  • Use GitHub Copilot Business through the approved account.
  • Drafting and summarising non-confidential material
  • Research with primary-source verification
  • Code assistance with normal review and testing
  • Check facts, calculations, citations and code before relying on or sharing the output.

Ask first

  • A new tool, connector or use case: request it through the IT service desk, with Security and Privacy review where required.
  • Personal data about identifiable people in a specifically approved tool or workflow.
  • Special category data (health, biometrics, beliefs) in a specifically approved tool or workflow.
  • Client or customer confidential information in a specifically approved tool or workflow.
  • Unpublished financial information in a specifically approved tool or workflow.
  • Legally privileged material in a specifically approved tool or workflow.
  • Employee records and HR case material in a specifically approved tool or workflow.
  • Any use that could materially affect recruitment, performance, access to a service, safety or another person.

Never

  • Use a personal AI account for organisation work.
  • Paste credentials, keys or secrets into an AI tool.
  • Treat AI output as evidence or as an independent second opinion.
  • Use AI to impersonate someone, fabricate evidence, evade controls or create deceptive synthetic media.
  • Hide a mistake or accidental disclosure.

Report mistakes, accidental disclosure, unsafe output or unapproved use immediately through security@northstar.example or the security incident form.

Turn the example into your policy

Use the generator to replace every fictional decision with your organisation's owners, approved products, account tiers, data boundaries and reporting routes. The draft is created in your browser and can be downloaded as Word or copied as Markdown.