A good AI policy is short and practical. It should cover:
- Approved tools: which AI tools are allowed.
- Data rules: what must never be entered, such as personal data, client confidential information and passwords.
- Checking outputs: AI results must be checked before they’re used or sent.
- Disclosure: when to tell clients that AI was used.
- Accountability: who owns AI decisions.
- Reporting: how to report a mistake or data leak.
- Review: how often the policy is reviewed.
It should match your data protection and information security policies. ABCOM writes AI policies as part of the AI Readiness Sprint (Week 3).
Want this looked after for you?
ABCOM has supported Sussex businesses and charities since 1996 and is an NCSC Assured Service Provider – Cyber Advisor (Cyber Essentials). Talk to a real person about your IT.
Also read
How ABCOM can help
Talk to a real person at our Burgess Hill office. We are an NCSC Assured Service Provider and have supported Sussex businesses since 1996.