AI policy workshop

Leave with a written AI policy, not notes about one

This is a facilitated half day that ends with your marketing or communications team holding a drafted AI use policy. Disclosure, approval and sign off, client confidentiality, what must never go into a prompt, approved tools and record keeping. From £1,200 for up to six people, in your offices or online.

Book a scoping call See all AI training

A communications team working through an AI policy workshop
Half dayFacilitated, your team, your decisions
£1,200Up to six people, excluding VAT
24 decisionsWorked through and written down
One documentDrafted in the room, not afterwards

Why do most AI policies never get used?

Because they were downloaded rather than decided. A template tells you an AI policy should cover disclosure and confidentiality. It cannot tell you who in your team signs off an AI assisted press release, or whether a client’s unannounced results can go into a summarisation tool, or what you do when a freelancer uses a model you have not approved.

Those are decisions, and they need the people who will live with them in the room. That is the whole design of this session. We bring the framework and the current regulatory picture, your team brings the arguments, and by the end there is a document with your name on it that people have agreed to out loud.

It is worth saying plainly what this is not. It is not legal advice, it is not ISO certification, and it is not a tour of AI tools. It is a facilitated decision session that produces a usable internal policy.

Is there a UK AI Act your policy has to comply with?

No. As of August 2026 there is no dedicated United Kingdom AI statute and none was announced in the King’s Speech. The government’s position is that existing law already covers AI, applied through sector regulators rather than through a single horizontal act.

That does not mean nothing applies. It means the obligations arrive through several doors at once, which is exactly why a comms team’s policy is harder to write than it looks.

Source What it actually says What your policy needs
ICO and UK data protection The ICO now carries a statutory duty to produce a code of practice on AI and automated decision making, with the code expected to take effect in 2027. Draft guidance stresses that human review must be active and by somebody trained to understand the system. Rules on personal data in prompts, and named people trained to review AI output
ASA and the CAP Code The Code is media neutral. There is no blanket AI disclosure rule, but disclosure is needed where the audience would otherwise be misled, and disclosure never fixes a misleading claim. A disclosure position you can defend, written down
CMA Guidance published in March 2026 on consumer law and AI agents. Businesses remain fully responsible for what their AI says and does, including where a third party built it. Accountability, human oversight and a record of who approved what
EU AI Act Amended by the Digital Omnibus, in force 27 July 2026, deferring several high risk deadlines. It reaches third country organisations whose AI output is used in the Union. An honest answer on whether it touches you at all
ISO/IEC 42001 The AI management system standard. UKAS granted its first accreditation in January 2026, so accredited certification is now available in the UK. Control areas your policy can map to, if certification is ever asked for

Last reviewed August 2026, and we check it again before every session because this is the fastest moving part of the material. This is training rather than legal advice, and where something is genuinely a question for your lawyers we will say so instead of guessing.

Does the EU AI Act apply to us if we only work in the UK?

Usually not, and most content on this subject implies otherwise. The Act reaches providers and deployers outside the European Union where the output of the AI system is used in the Union. A UK marketing team using ChatGPT or Copilot internally, publishing to a UK audience, is largely outside its scope.

It starts to matter when you have an EU entity, EU clients, or you publish AI generated output into EU markets. The transparency and synthetic content labelling obligations are the part most likely to reach a marketing function.

Getting this right in your policy matters more than it sounds. Overstating the obligation makes the whole document look like it was written by somebody who had not read the source, and teams stop trusting the rest of it.

What should an AI use policy actually cover?

Six sections do the work for a marketing or communications team. Everything else is commentary.

1. Approved tools

Which models and products are allowed, at which tier, and how somebody gets a new one added. Unapproved tools are where most incidents start.

2. What never goes in

Unannounced news, embargoed material, client confidential information, personal data about identifiable people, anything under NDA. Written as a list people can remember.

3. Approval and sign off

Who reviews AI assisted content before it publishes, what they are checking for, and what they are accountable for afterwards.

4. Disclosure

When you tell an audience, a client or a journalist. Where the line sits for images, voices and quotes as against drafting assistance.

5. Verification

Every factual claim and every statistic checked against a source. This is the clause that prevents the incident nobody recovers from quickly.

6. Record keeping

What you log, for how long, and who can see it. Enough to answer a client or a regulator without becoming a second job.

How does the half day run?

Time Block What comes out of it
09:30 Where you actually are An honest map of what your team is already doing with AI, including the parts nobody has mentioned
10:00 The regulatory picture, briefly A shared understanding of what applies to you and what does not
10:30 The twenty four decisions Worked through as a team, argued out, written down as you go
11:45 Drafting the document The policy itself, built from the decisions rather than from a template
12:30 Sign off and rollout Who owns it, who approves it, how you tell the wider team and when you review it

A full day version adds a practical session applying the policy to live examples from your own channels, which is usually where the gaps in the first draft show up. That is £1,800 for the same group.

Can we put client information into ChatGPT?

It depends entirely on which product, which tier and which client, and getting that distinction into the policy is one of the more useful hours of the session. Consumer tiers and enterprise tiers treat your input differently, and the difference matters far more for confidentiality than for output quality.

The harder question is the one policies usually skip. Even where a tool is technically safe, a client may have contractual expectations about how their material is handled, and an agency that has not asked is exposed regardless of the tool. We work through both the technical rule and the client conversation, because in practice they are the same problem.

Who should be in the room?

The people who publish

Content, social and press office staff. If they are not in the room the policy describes work they do not recognise.

The person who signs off

Head of marketing or communications. Somebody has to own the document afterwards and it should not be a surprise to them.

One sceptic

Legal, compliance, data protection or the most cautious person on the team. The policy is better for the argument.

Six is the right number. Fewer and you miss the disagreement that makes the policy real. More and the decisions take all day instead of half of it.

Is a downloadable AI policy template not enough?

A template is a reasonable place to start and a bad place to finish. Every free template we have read is written for a generic business, which means the sections a comms team most needs are the thinnest ones. None of them cover embargoes. None cover client confidentiality in an agency relationship. Almost none cover disclosure in advertising, which for a marketing team is the clause with actual regulatory weight behind it.

The deeper problem is that adopting a template unchanged transfers no understanding. When somebody has to make a judgement call on a Friday afternoon, what helps is having been in the argument about where the line sits. That is what the room is for.

We are not a law firm, and we do not hand out a document for you to adopt unread. What you leave with is a policy your own team drafted and can explain.

Who runs the session?

The Prohibition PR team in Leeds

I am Chris Norton and I facilitate these sessions myself. I founded Prohibition, the PR, social and content agency behind this site, I have worked in public relations for more than twenty years, and I have been running training since 2009. I co-authored Share This Too, the social media handbook published by the Chartered Institute of Public Relations.

We have written and live with our own AI policy across a working agency, which is a different thing from having read about one. Where the session runs into a genuine legal question we say so and you take it to your lawyers, rather than us improvising an answer that sounds confident.

What does your team leave with?

  • A drafted AI use policy covering approved tools, prohibited inputs, approval and sign off, disclosure, verification and record keeping
  • A written record of the twenty four decisions behind it, so the next person to read it understands why each line is there
  • An agreed disclosure position for advertising, social content and media relations
  • A named owner, a named approver and a review date
  • A short version, one page, that the wider team will actually read
  • The current regulatory picture summarised, with the sources so you can check it yourself

Is this the right AI session for your team?

You are here

Writing an AI policy. Governance, disclosure, confidentiality and sign off, ending in a written document.

Microsoft Copilot

Practical use across documents, decks and email. See Microsoft Copilot training.

AI and social content

Posts, captions, video and brand voice. See AI for social media content training.

Teams that book the policy session first tend to have had a near miss. Teams that book it second have usually realised that speed without rules is how the near miss happens.

AI policy questions we get asked

Does my UK business legally need an AI policy?

There is no law requiring one. What the law does require is that you comply with data protection, advertising and consumer rules however your content is produced, and a written policy is the practical way a team stays on the right side of that. Clients and tender questionnaires increasingly ask whether you have one, which is often the real prompt.

Is there a UK AI Act?

No. As of August 2026 there is no dedicated UK AI statute and none was in the King’s Speech. The government’s approach is to apply existing law through sector regulators, so obligations reach you through the ICO, the ASA and the CMA rather than through a single act.

Does the EU AI Act apply to a UK only business?

Usually not. It reaches organisations outside the European Union where the output of the AI system is used in the Union. It becomes relevant if you have an EU entity, EU clients, or you publish AI generated output into EU markets.

What must never go into an AI prompt?

Unannounced news, embargoed material, client confidential information, personal data about identifiable people, and anything covered by an NDA. The useful version of this rule is short enough that people remember it under time pressure.

Do we have to disclose AI generated content in advertising?

There is no blanket UK requirement. The CAP Code is media neutral, so the same rules apply however content was made. Disclosure is needed where the audience would otherwise be misled, or where AI features prominently and would not be obvious. Disclosure does not cure a misleading claim.

Who should sign off AI assisted content?

A named person, not a role in the abstract, and somebody who understands enough about the tool to review its output properly rather than rubber stamp it. Draft ICO guidance on automated decision making makes the point that human review has to be active and informed.

What records should we keep about AI use?

Enough to answer a client or a regulator without creating a second job. In practice that usually means which tool, who used it, what it was used for, and who approved the output, held for a period you decide and write down.

How long does it take to write an AI policy?

Half a day with the right six people in the room produces a usable draft. Done by circulating a document for comment it typically takes months and arrives watered down, because nobody had the argument.

Do we need ISO 42001?

Most marketing and communications teams do not. It matters if AI is becoming a procurement question for you, and UKAS granted its first accreditation in January 2026 so certification is now available in the UK. We map your policy to its control areas so that if you certify later you are not starting from nothing.

Is this legal advice?

No. It is training and facilitation delivered by communications practitioners. Where a decision genuinely needs a lawyer we will tell you rather than guess, and the policy you leave with is yours to have reviewed.

How do we stop people using tools we have not approved?

Not by banning things, which drives it underground. A short approved list, a fast route to add something, and an honest conversation about why the list exists works better than a prohibition nobody follows.

Get the policy written, with the arguments settled

Half day £1,200, full day £1,800, up to six people, excluding VAT. Delivered UK wide or online.

Book a scoping call AI misinformation training

Part of our AI training for marketing and communications teams. Training and facilitation, not legal advice. Last reviewed August 2026.