Do not ask three chatbots to define your organisation’s AI policy and treat the overlap as authority. A usable policy must reflect your data, law, contracts, risk tolerance, approved services and real work.
Use AI to help draft questions if you wish. Build the policy from accountable decisions and current primary guidance.
The minimum policy structure
1. Scope and ownership
State who and what the policy covers: staff, contractors, approved AI services, built-in assistants, APIs, agents and connected tools.
Name the policy owner, security contact, privacy contact and route for approving new use cases. Define how often the policy is reviewed and which product or legal changes trigger an early review.
2. Approved and prohibited uses
Give concrete examples.
Approved use might include drafting non-sensitive internal text with human review. Prohibited use might include entering authentication secrets, making an unsupervised employment decision or connecting an unapproved agent to customer records.
Avoid “use AI responsibly” as the main rule. Staff need observable boundaries.
3. Data handling
Define which data classes may enter each approved service. Cover prompts, uploaded files, connected repositories, outputs, conversation history, logs and feedback.
The account matters. Microsoft says eligible work accounts using Copilot Chat receive enterprise data protection, while consumer experiences differ. OpenAI says its business products and API do not use organisational inputs and outputs to train models by default. Google’s consumer Gemini privacy notice describes a different set of activity and connected-app controls.
Those provider statements do not complete your privacy assessment. Check contracts, retention, subprocessors, locations, access controls and the organisation’s lawful basis where personal data is involved.
The UK Information Commissioner’s AI and data protection risk toolkit provides a practical starting point for risks to people’s rights and freedoms.
4. Human decisions and review
State which outputs require verification and which decisions must remain with an authorised person.
For high-consequence uses, specify the reviewer’s competence, evidence they must inspect, the right to challenge and the route for escalation. “Human in the loop” is meaningless if the person lacks time, authority or source material.
5. Accuracy, testing and records
Require users to verify consequential claims against primary sources. For built systems, define test sets, acceptance thresholds, failure cases, change control and monitoring.
Keep enough records to explain the approved purpose, data, model or service, evaluation, owner and material changes. Avoid logging secrets or excessive personal data.
NIST’s Generative AI Profile provides voluntary actions organised around governing, mapping, measuring and managing risk.
6. Security and connected tools
Treat agents and connectors as access paths, not harmless chat features.
Microsoft warns that untrusted sources such as emails or support tickets can manipulate agents into incorrect answers or actions. Its security guidance recommends trusted sources and careful human intervention before sensitive operations.
Require least privilege, approved authentication, secret management, environment separation, tool allow-lists and revocation when a service or employee leaves scope.
7. Transparency, intellectual property and acceptable content
Define when people must disclose AI assistance to colleagues, customers or the public. Address confidential information, copyright, attribution, impersonation, discriminatory content and synthetic media.
Do not promise that an AI detector can reliably determine authorship. Focus on process, records and accountability.
8. Incidents and exceptions
Tell staff how to report accidental disclosure, harmful output, unexpected tool action or suspected policy breach without hiding it.
Define who can grant a time-limited exception, what evidence is required and when it expires.
A policy is not the whole control system
Back the document with technical controls, procurement checks, role-based access, staff guidance, evaluation and incident response. Microsoft Purview and Power Platform controls can support parts of this work, but availability depends on licensing and configuration.
EU AI Act obligations apply on a phased timeline, and UK data protection law may apply to personal-data processing. Obtain competent legal advice for the organisation and jurisdiction rather than copying a generic compliance claim.
Proof boundary, checked 24 August 2026
This structure is a policy checklist, not legal advice or a certification. A signed document does not prove safe use. Evidence comes from configured controls, evaluated systems, recorded decisions and observed practice.
For practical policy and Copilot governance discussions, join the Microsoft Copilot Adopters Space.
