
Guide · AI in Institutions
From an AI-use policy to decisions staff can actually follow
An AI policy that nobody applies is worse than none. Build it in a workshop, around the decisions staff actually face, and leave nothing important undecided.
The short answer
Write an AI acceptable-use policy by deciding, with the people who will follow it: which uses are allowed, which data must never go into AI tools, which tools are approved, when outputs need human review, when AI use is disclosed, who is accountable and where to report problems. List every open decision rather than papering over it.
Start from real decisions
Staff do not need a philosophy of AI. They need to know whether they may paste a client report into a chatbot, use AI to translate a beneficiary survey, or draft a funding proposal with it. Build the policy from questions like these.
The core choices
Allowed uses; banned data, such as personal data, health data, credentials and confidential bids; approved tools; review rules; disclosure rules; the accountable owner; and the incident route.
High-risk uses need more
Screening job applicants, public-facing chat and decisions about credit, health or education carry legal and ethical risks. Treat them as separate decisions, with specialist advice where needed.
A worked example
The AI policy template turns these choices into draft clauses and lists what is still open. In its worked example, the approved tools and the incident route are not yet decided, so both appear as “[Decision open]” for the workshop to settle.
What this guide does not cover
A policy draft is not legal advice. Have it reviewed against the laws that apply to you before adoption, and back it with training.
Responsible for this guide
Examples in this guide are illustrative, not client results. Figures come from the free tool’s worked example; change the inputs in the tool to see your own.
Related services
The same method, delivered with you: scoped in writing, with a named principal and a fee agreed before any work begins.
Executive AI literacy and board AI-governance day
A sector-specific session for boards and executives on what AI means for their institution: the real uses, the real risks and the governance decisions only leadership can make. You leave with draft actions for approval, not a signed policy.
See the serviceServiceAI-literacy training
We assess the AI literacy each staff group needs, deliver role-specific training and keep the attendance and assessment evidence. Since 27 July 2026, Article 4 of the EU AI Act, as amended by the Digital Omnibus on AI, asks providers and deployers to take measures to support the development of AI literacy; this programme helps you take those measures and show what you did.
See the serviceMore from AI in Institutions
6-minute readWhat to define before automating a workflow
6-minute readBuild an AI inventory with owners, evidence and a review cycle
7-minute readHow to evaluate an internal knowledge assistant before release
6-minute readCalculate automation value after exception handling and running costs Also in Regulation Watch.
What needs to move forward?
Tell us the decision, the challenge or the opportunity. We reply with a scoped approach, a named principal and a fee before any work begins.
No charge to submit an enquiry.
