Artificial intelligence is rarely out of the headlines. Whether it is the latest advances in generative AI, increasing investment in AI-powered tools, or growing debate around regulation and ethics, there is no doubt that AI is changing the way businesses operate. Yet many organisations are still asking a surprisingly simple question – Do we actually need an AI policy?
From a commercial lawyer’s perspective, the answer is becoming increasingly clear.
Whilst there is currently no general legal requirement in the UK for businesses to have an AI policy, that does not mean businesses can ignore the legal and commercial risks associated with AI. Existing obligations around data protection, confidentiality, intellectual property, cybersecurity and regulatory compliance still apply, regardless of the technology being used. Guidance on AI governance consistently highlights these risks and the need for organisations to establish appropriate safeguards.
The more interesting question is not whether an AI policy is legally required. It is whether businesses can realistically afford to operate without one.
AI is no longer an IT Issue
Many organisations still view AI through a narrow lens. They see it as an IT project, a productivity tool, or perhaps an HR issue requiring guidance on whether employees can use ChatGPT or Microsoft Copilot.
In reality, AI affects almost every part of a business. Marketing teams are using AI to create content. Finance teams are analysing data using AI-powered tools. Customer service teams are exploring automation. Procurement teams are assessing suppliers who increasingly incorporate AI into their products and services. Board members are making strategic decisions about investment in technology.
What begins as a simple productivity tool can quickly raise questions about confidentiality, data ownership, intellectual property rights, contractual liability and governance. These are issues businesses are already required to manage, regardless of whether specific AI legislation applies.
An AI Policy is about Governance, not restriction
One of the biggest misconceptions is that an AI policy exists to prevent employees from using AI.
In our experience, the most effective policies do the opposite. They provide a framework that enables businesses to embrace new technology whilst managing risk appropriately.
A well-designed AI policy should help organisations answer questions such as:
- Which AI tools are approved for business use?
- What information can be shared with those tools?
- What workplace activities can AI be used for?
- Who is responsible for checking AI-generated outputs?
- How should suppliers’ use of AI be managed?
- What approval processes should apply when adopting new technology?
- How will future AI tools be assessed and implemented?
Those questions extend far beyond employee conduct. They go to the heart of how an organisation approaches innovation, risk and decision-making. Guidance on workplace AI use increasingly recommends governance frameworks, approved tool lists, training and oversight mechanisms rather than blanket restrictions.
The Commercial Risks Often Sit Within Contracts
One area receiving increasing attention is the interaction between AI and commercial contracts. Businesses are beginning to ask:
- Can our suppliers use our data to train AI models?
- Who owns content created using AI?
- What happens if AI-generated information proves inaccurate?
- Does our technology provider assume any liability for AI-related losses?
- Are confidentiality protections still effective when AI tools are involved?
- Does our use of AI risk the security of personal data?
These are not theoretical concerns. They are commercial issues that can have significant consequences for organisations adopting AI at scale.
As AI becomes embedded within products, services and business operations, contractual protections will become an increasingly important part of risk management.
Looking beyond today’s technology
Perhaps the strongest reason to consider an AI policy is not the technology available today. It is the technology that will emerge tomorrow.
The pace of change in AI is extraordinary. New tools, new capabilities and new regulatory developments are appearing at a speed that few organisations have experienced before.
Businesses that try to assess every new tool from scratch may find themselves constantly reacting to change. Those with clear governance frameworks are likely to be in a stronger position.
Rather than creating rules for one specific platform or technology, an effective AI policy can establish principles that remain relevant as innovation continues. It creates a framework for assessing new opportunities, identifying risks and making informed decisions when the next generation of tools arrives. Governance frameworks and ongoing policy reviews are widely recognised as important elements of responsible AI adoption.
A question for Business Leaders
The conversation around AI often focuses on what the technology can do.
A more important question may be whether your business has considered how it wants to use AI, what risks it is prepared to accept and what safeguards should be in place.
An AI policy will not eliminate risk. However, it can help businesses demonstrate a thoughtful, structured approach to adopting new technology, protecting valuable information and supporting innovation in a way that aligns with their wider commercial objectives.
The organisations that achieve the greatest benefit from AI may not be the ones adopting it fastest. They may be the ones that take the time to put the right foundations in place first.
For more information, please contact...
Jenny Wade
Partner and Head of Commercial
Jenny Wade is a Partner and Head of Commercial and lead of the Construction team at Swinburne Maddison, having joined the firm to lead…