AI Acceptable Use Policies: What Should UK Businesses Include?
With AI developing at a rapid pace and organisations desperate to reap the benefits, how does governance keep up and stay effective?
In their haste to adopt the latest tools, many organisations have yet to define what acceptable usage of AI is within their business. That leaves a series of problematic grey areas; for example, employees may be unknowingly uploading sensitive data into AI tools and relying on inaccurate outputs. This can also expose the organisation to regulatory and contractual risks as well as raise concerns for intellectual property.
Most organisations operate with acceptable use policies for their IT systems and internet usage in place, and AI acceptable use policies work in the exact same fashion. They provide clear guidance to your employees of how they should use AI and what the boundaries of usage are.
Inconsistencies with AI guidance can increase the risk of data leakage, breaches and ultimately reputational damage. Conversely, a clear AI Acceptable Use Policy demonstrates that the organisation is taking AI seriously and is taking a structured and responsible approach to managing its usage by employees.
What should be included in AI Acceptable Use Policies?
1. A List of Company-approved AI Tools
This should include clearly identifying approved AI platforms and services that corporate accounts must use and prohibited tools.
2. Prohibited Data
Define what data should not be entered into AI platforms, such as personal data, special category data, client confidential information, financial records, legal documents or security credentials, as a starting point.
3. Account Usage Requirement
Ensure there are rules in place for using AI platforms. For instance, all employees should use approved corporate accounts, ensure they protect API keys and access credentials, as well as reporting suspected compromise of accounts immediately.
4. Output Accuracy and Validation
AI-generated content should never be taken as 100% accurate. Policy should make clear that users are responsible for reviewing outputs for accuracy, whether that’s verifying facts and references, or identifying misleading information. The bottom line should be that AI should not replace professional judgement.
5. Human Review
Ensuring that the accountability still sits with the user and that it assists instead of replacing decision-making. Significant business decisions should not rely on AI-generated recommendations, and the accountability for important outputs is validated by human oversight.
6. Intellectual Property Considerations
When it comes to risk exposure, ensuring you’ve covered all IP bases can protect you from significant legal headaches. Establish ownership of AI-generated work, the use of copyright material, the risks associated with training data, requirements for attribution where necessary and the protection of organisational intellectual property.
7. Client and Customer Data
Whether customer data disclosure is permitted into AI platforms, if approvals are required, if contractual commitments apply, if additional privacy or security reviews are necessary.
8. Record Keeping
This includes risk assessments, approval documents, testing results, human review evidence, supplier assessments, output or prompt records.
9. Escalation Procedures
Employees are given the ability to officially raise concerns, including security or ethical concerns, suspected data breaches, compliance questions, inaccurate or even harmful outputs and requests for new AI tools.
10. Other Considerations
Finally, we advise that your policies should also cover acceptable use for the following:
Browser-used AI tools
Supplier-provided AI
Internal AI systems
Embedded AI tools
What else should be considered?
As standard, UK GDPR should be front of mind when crafting effective policies and include the core principles:
Lawfulness
Transparency
Fairness
Accuracy
Data minimisation
Accountability
Alongside an Acceptable Usage AI policy, organisations should ensure that they are supporting the policy in other ways. This could include conducting regular AI awareness training, maintaining an approved AI tool register, maintaining AI risk assessments, conducting ongoing monitoring and review
The final step of this is the introduction of an AI Management System (AIMS). While acceptable use policies are focused on a set of rules for employees to consider in their day-to-day work, an AIMS is the framework for institutional governance and confirms how AI tools and systems are managed throughout their lifecycle by the or, from procurement to decommissioning.
ISO 42001 is the first international standard for AIMS management, and provides a framework for establishing the required policies, risk management, continual improvement and governance processes when it comes to the use of AI. Beyond improved security posture, successful certification also minimises regulatory disruption and offers clear expectations for AI usage for both customers and vendors.
How can we help?
Organisations best primed to reap the benefits of AI are those that know how to use it without exposing themselves to increased risk. Employees are already using AI tools in their day-to-day roles, so it’s up to business leaders to ensure that these tools are being responsibly used to avoid data breaches and company disruption. For help crafting effective AI acceptable use policies and help prepare you for ISO42001 certification, contact our expert team.