nerdster.ai

Free resource · Updated June 2026

The UK AI governance policy template every business should have.

A clear, one-page AI acceptable-use and governance policy you can adopt this week, written in plain English and updated for the Data (Use and Access) Act 2025. Set out which tools are allowed, what data can go in, and when a human must review.

Free · no email required · guidance, not legal advice

Why it matters

Do UK businesses need an AI policy?

Short answer: if your team touches AI, yes. Here is why, as the law stands in 2026.

There is no single UK AI law

The UK regulates AI through existing law and sector regulators, not one "AI Act". That does not mean no rules. It means the duties sit across data protection, your regulator, and employment and IP law. A short policy is how you join them up.

Your team already uses AI

Staff are pasting work into ChatGPT, Copilot and Gemini today. Without a policy that is an unmanaged risk to confidential and personal data. With one, it becomes something you control.

Data protection still applies

The Data (Use and Access) Act 2025 updated UK data-protection and automated-decision rules. Personal data in an AI tool still needs a lawful basis, the right contracts, and safeguards where AI makes significant decisions about people.

The template

The one-page AI policy template

Download as PDF

[Company name]: AI Acceptable Use & Governance Policy

Owner: [name / role] · Effective: [date] · Next review: [every 6 months]

  1. 1

    Purpose and scope

    Who the policy covers (staff, contractors) and what counts as an AI tool, public tools, AI features in your existing software, and any custom or private models.

  2. 2

    Approved tools

    The AI tools and accounts staff may use, and how to request a new one. Nothing gets connected to company systems without approval.

  3. 3

    What must never go into a public AI tool

    Client confidential information, personal and special category data, credentials and trade secrets, unless using an approved private deployment with contractual protection.

  4. 4

    Data protection (UK GDPR + DUAA 2025)

    Personal data only where you have a lawful basis and a contract, the provider does not train on your data unless agreed, and it is covered by your privacy notice. Special category data needs extra care.

  5. 5

    Automated decisions about people

    Where AI makes or materially influences a significant decision (hiring, credit, eligibility), apply the DUAA 2025 safeguards: tell the person, let them contest it, and provide a genuine human review.

  6. 6

    A human is always accountable

    AI output is a draft, not a decision. A named person reviews and approves anything produced with AI before it is relied on, sent to a client, or published.

  7. 7

    Accuracy, disclosure and professional duties

    Check facts, figures, citations and code. Be transparent where customers or a regulator would expect it. Never breach SRA, FCA, CQC or other professional obligations.

  8. 8

    Security

    Approved accounts only, multi-factor authentication, no shared logins, and a clear route to report any AI-related incident.

  9. 9

    If you sell into the EU

    The EU AI Act can reach UK firms whose AI output is used in the EU. Prohibited practices are already banned; high-risk obligations apply from 2 December 2027.

  10. 10

    Breaches and review

    Who owns the policy, the consequence of breaching it, and a review at least every six months as the law and your tools change.

Provided by nerdster.ai for general guidance only, not legal advice. Adapt to your business and take professional advice before relying on it.

The 2026 position

What changed, and what it means for you.

No UK AI Act

The UK is regulating AI through existing law and sector regulators, not a single statute. Your duties sit across data protection, your regulator and employment and IP law.

DUAA in force

The Data (Use and Access) Act 2025 took effect on 5 February 2026, updating UK GDPR and the rules on automated decisions, with mandatory safeguards where AI decides about people.

EU AI Act: Dec 2027

If your AI output is used in the EU, the EU AI Act can apply. Banned practices are already live; high-risk obligations were deferred to 2 December 2027.

Good questions

AI policy, answered.

What is an AI governance policy?

An AI governance policy is the short document that sets out how your business uses AI responsibly: which tools are approved, what data may go into them, who is accountable for AI-assisted work, and how you meet UK GDPR, the Data (Use and Access) Act 2025 and your sector regulator. The template below is exactly that, in one page, so governance is something you can adopt this week rather than a project.

Does my UK business legally need an AI policy?

There is no law that says "you must have an AI policy" by name. But if your staff use AI with personal or confidential data, you already have duties under UK GDPR and the Data (Use and Access) Act 2025, plus your sector regulator. A written policy is the simplest way to meet those duties and show you are managing the risk.

Is there a UK AI Act?

No. As of 2026 the UK has chosen an incremental, sector-led approach rather than a single AI statute. AI is governed through existing law (data protection, equality, IP, consumer and sector rules) and regulators such as the ICO, FCA and SRA. A private member’s bill exists but is not government-backed.

What changed with the Data (Use and Access) Act 2025?

Its core data-protection reforms came into force on 5 February 2026. Most relevant to AI, it reshaped the rules on automated decision-making: you can now rely on a wider range of lawful bases for significant automated decisions, but you must give people information, a route to challenge the decision, and human review. Special category data stays more tightly controlled.

Does the EU AI Act apply to a UK company?

It can. Like GDPR, it has extraterritorial reach: if you place an AI system on the EU market, or its output is used in the EU, it can apply regardless of where you are based. Banned practices are already in force; obligations for high-risk systems were deferred to 2 December 2027.

Can I just use this template as-is?

It is a strong starting point, but every business is different. Fill in the bracketed sections, align it with your existing policies, and take professional advice before you rely on it. It is guidance, not legal advice.

Beyond the template

Want AI working safely, not just documented?

A policy is the start. Our 90-minute AI & Data Readiness Audit shows where AI should actually run in your business, what it costs and what it saves, with the governance built in. Keep the report either way.

Prefer to read more first? See the one-page AI policy explained and AI compliance for UK businesses.

Book a 90-minute audit

Replies in ~1 working day

Tell us a little about you and we’ll be in touch within one working day.

By sending this you agree we can contact you about your enquiry. We never sell your data or add you to a list.