Free resource · Updated June 2026
Adopt the AI policy every UK business should have.
A clear, one-page AI acceptable-use and governance policy you can adopt this week, written in plain English and updated for the Data (Use and Access) Act 2025. Set out which tools are allowed, what data can go in, and when a human must review.
Download the template (PDF)Free · no email required · guidance, not legal advice.
Why it matters
Do UK businesses need an AI policy?
Short answer: if your team touches AI, yes. Here is why, as the law stands in 2026.
There is no single UK AI law
The UK regulates AI through existing law and sector regulators, not one "AI Act". That does not mean no rules — the duties sit across data protection, your regulator, and employment and IP law. A short policy is how you join them up.
Your team already uses AI
Staff are pasting work into ChatGPT, Copilot and Gemini today. Without a policy that is an unmanaged risk to confidential and personal data. With one, it becomes something you control.
Data protection still applies
The Data (Use and Access) Act 2025 updated UK data-protection and automated-decision rules. Personal data in an AI tool still needs a lawful basis, the right contracts, and safeguards where AI makes significant decisions about people.
The template
The one-page AI policy, section by section.
Provided by nerdster.ai for general guidance only, not legal advice. Adapt to your business and take professional advice before relying on it.
The 2026 position
What changed, and what it means for you.
No UK AI Act
The UK is regulating AI through existing law and sector regulators, not a single statute. Your duties sit across data protection, your regulator and employment and IP law.
DUAA in force
The Data (Use and Access) Act 2025 took effect on 5 February 2026, updating UK GDPR and the rules on automated decisions, with mandatory safeguards where AI decides about people.
EU AI Act: Dec 2027
If your AI output is used in the EU, the EU AI Act can apply. Banned practices are already live; high-risk obligations were deferred to 2 December 2027.
Good questions
AI policy, answered.
What is an AI governance policy?
An AI governance policy is the short document that sets out how your business uses AI responsibly: which tools are approved, what data may go into them, who is accountable for AI-assisted work, and how you meet UK GDPR, the Data (Use and Access) Act 2025 and your sector regulator. The template on this page is exactly that, in one page.
Does my UK business legally need an AI policy?
There is no law that says "you must have an AI policy" by name. But if your staff use AI with personal or confidential data, you already have duties under UK GDPR and the Data (Use and Access) Act 2025, plus your sector regulator. A written policy is the simplest way to meet those duties and show you are managing the risk.
Is there a UK AI Act?
No. As of 2026 the UK has chosen an incremental, sector-led approach rather than a single AI statute. AI is governed through existing law (data protection, equality, IP, consumer and sector rules) and regulators such as the ICO, FCA and SRA. A private member's bill exists but is not government-backed.
What changed with the Data (Use and Access) Act 2025?
Its core data-protection reforms came into force on 5 February 2026. Most relevant to AI, it reshaped the rules on automated decision-making: you can now rely on a wider range of lawful bases for significant automated decisions, but you must give people information, a route to challenge the decision, and human review. Special category data stays more protected.
Does the EU AI Act apply to a UK company?
It can. Like GDPR, it has extraterritorial reach: if you place an AI system on the EU market, or its output is used in the EU, it can apply regardless of where you are based. Banned practices are already in force; obligations for high-risk systems were deferred to 2 December 2027.
Can I just use this template as-is?
It is a strong starting point, but every business is different. Fill in the bracketed sections, align it with your existing policies, and take professional advice before you rely on it. It is guidance, not legal advice.
Want the gaps found for you?
The two-week audit includes a governance and shadow-AI check: which tools your team already uses, what data goes into them, and the shortest path to compliant.
Book a free call0330 043 7414 hello@nerdster.ai Mon–Fri 9–5:30