Two pages, written in the second person, leading with what staff are permitted to do, and naming a person they can ask. That is the version people follow. Most of the AI policies I am shown run to eleven pages, lead with prohibitions, and name a mailbox.
The long kind is not a policy. It is evidence for an audit. Staff read the first paragraph, decide the safe course is to do nothing, then paste a customer email into a consumer chatbot on their phone.
If the document does not tell someone which tool to open for the task in front of them, it has no effect on what they do next.
The two pages
Six headings, in this order.
- What you may use. Name the products and the tenant: “Microsoft 365 Copilot and Copilot Chat, signed in with your work account.” Then what is not approved, and why, in one clause.
- What you may put into it. Use the data classes from the classification scheme you already have. State the one or two absolute limits plainly. If everything is forbidden, nobody believes any of it.
- What you must check before it leaves you. You own the output the moment you send it. Say who is accountable for an error in an AI-assisted document: the person whose name is on it.
- What you must tell other people. When to disclose that AI was involved, in the cases that occur in your organisation: customer correspondence, published material, recruitment, meeting notes.
- Decisions about people. Covered below, and the section with the legal weight.
- Who to ask, and when this is next reviewed. A name, a channel, and a date.
Then worked examples: three things that are fine, three that are not, one “ask first” case. People work from the examples.
The clauses that are not optional
Automated decisions about people. The UK position changed on 5 February 2026 under the Data (Use and Access) Act 2025. The restriction on solely automated decision-making now applies only where the decision is based entirely or partly on special category data. For everything else, the full range of lawful bases, including legitimate interests, is available for significant automated decisions. Four safeguards remain in all cases: tell people automated decision-making is being used, let them make representations, provide meaningful human intervention, and let them contest the decision. Those four belong in your policy nearly verbatim.
The ICO’s draft guidance on automated decision-making and profiling, consulted on between 31 March and 29 May 2026, reframes the rules from a prohibition with exceptions to a right of challenge with safeguards, and says human involvement must be active rather than tokenistic, carried out by trained, qualified reviewers who understand the system’s logic and limitations. It is draft, and the final version is not published, so cite it as direction of travel rather than law. A manager rubber-stamping a shortlist is not human intervention, and writing “a human reviews all decisions” commits you to something you may not be doing.
Disclosure, if you touch the EU. Article 50 of the EU AI Act took effect on 2 August 2026. In force now: tell people they are interacting with an AI system unless that is obvious to a reasonably well-informed, observant and circumspect person; mark synthetic audio, image, video and text in machine-readable format to the extent technically feasible; inform people exposed to emotion recognition or biometric categorisation; disclose deepfake content, with exceptions for artistic and creative work; and disclose AI-generated text published on matters of public interest, except where there is human review or editorial control. The Act reaches third-country providers and deployers where the output of the system is used in the Union, so “we are a UK organisation” is not an answer.
Not due now: the high-risk regime for employment and worker management. The Digital Omnibus adopted on 8 July 2026 moved the Annex III standalone high-risk obligations to 2 December 2027. That date belongs in the policy’s review schedule, not this year’s controls.
The paragraph everyone leaves out
Monitoring. The moment you summarise meetings, analyse messages or report on individual usage, you are processing workers’ data, and the policy has to say on what basis.
The ICO’s guidance on monitoring workers, last updated 16 June 2026 and carrying a notice that it is under review because of the Data (Use and Access) Act, is direct about what most policies fudge: “Consent is not usually appropriate in the employment context, due to the imbalance of power between you and your workers.” So a consent tick-box in onboarding is not your lawful basis. Pick a real one, write it down, and expect to produce the balancing test.
The same guidance requires you to tell workers about monitoring “in a way that is accessible and easy to understand”, and a DPIA before any processing likely to result in high risk. Name where the DPIA lives, because in a year somebody will ask and nobody will remember.
The Department for Business and Trade opened a consultation, Make Work Pay: workplace monitoring technologies, on 8 July 2026, closing at 11:59pm on 30 September 2026. It covers AI and algorithmic management, and one of the three options tested is a legislative duty on employers to consult and negotiate with workers on monitoring technologies. There is no such duty today. Write the section as though it exists and you will not have to rewrite it.
Put the date on the front
ICO guidance on agentic AI is in drafting with no public consultation planned and is expected in Winter 2026. A policy without a visible date and owner asserts that it is permanently true, which is the one thing you know it is not.
Print it. If it does not fit on two sides, cut the part that was written for the auditor. The auditor has the standards. Your staff have a deadline and a browser tab.