AI for managers
Simple team AI rules: a one-page starter
Written by AI Tools AcademyChecked against the sources listed below on 27 September 2026
Helpful first: How to manage a team that uses AI · Privacy and safety
Practice files for this page
Team AI rules starter template (Markdown, one page)
Fictional practice data. No real people or organisations.
Priya Shah has had the conversation with her team at Fernway. She knows who uses AI and for what. Now she needs to write it down: something short enough that people read it, clear enough that they can follow it on a busy Tuesday, and honest enough that nobody pretends it's more than it is.
This guide gives you a starter framework for team AI rules. It has eight sections, each with an example of Fernway's wording and the decisions you need to make. There's a one-page template to download and adapt.
This is not legal advice. It's a practical starting point for a team's working rules. Your organisation's own policies come first, and your data protection officer or legal adviser has the final say on anything involving personal data, contracts or regulated work. Your organisation's policy and approved tools still take priority.
Before you write anything
Check what already exists. Your organisation may already have an AI policy, an acceptable use policy or data handling rules. Team rules sit underneath these and must not contradict them. If a policy exists, your team rules may just translate it into your team's everyday tasks.
Know your team's work. The rules should be built around the information you actually handle and the tasks you actually do. The team conversation guide helps you find out.
Keep it to one page. A long document gets skimmed once and forgotten. One page can be pinned up, read in two minutes and remembered.
Two free starting points on this site
You don't have to start from a blank page.
- The AI policy starter is a free tool that builds a draft from your answers: which tools are approved, what information your team handles, how much review you want and which uses are off limits. It runs in your browser and nothing is saved or sent.
- The AI-Safe Desk is a free short course. Its fourth module, writing the page, walks individuals through writing a one-page personal AI rulebook. Asking your team to write their own before you agree a shared version is a good way to surface how people really work.
The template in this guide sits between the two: a fixed one-page layout for a team, with placeholders to fill in.
The eight sections
1. Approved systems
Say which AI tools the team may use for work, on which accounts, and for what. Be specific about account type, because the same product name can cover consumer and business versions with different terms.
Fernway's wording: "Use Microsoft 365 Copilot Chat, signed in with your Fernway work account. Don't use personal AI accounts for Fernway work. To suggest another tool, ask Ravi Menon."
Decide: which tools, which accounts, who approves new ones, and how quickly they'll respond.
2. Prohibited data
Say plainly what never goes into an AI tool, and what only goes into approved ones. Use examples from your own team's work, because people recognise their own information more easily than abstract categories.
Fernway's wording: "Never put these into any AI tool: passwords or access codes; bank or card details; health, sickness or disability information about anyone; anything about a disciplinary, grievance or complaint about a person. Only in Copilot Chat on your work account, and only the minimum needed: customer names and order details; supplier contract terms."
Sensitive personal data has extra protection under UK data protection law. The ICO lists the special categories: racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data used for identification, health, sex life and sexual orientation. Criminal offence data is treated separately with similar safeguards. Removing a name doesn't always make information anonymous, so say that in the rules too.
Decide: what's never allowed, what's allowed only in approved tools, and who to ask when unsure. The Can I put this in ChatGPT? tool is useful to share alongside this section.
3. Verification
Say what must be checked before AI-assisted work is used or sent. Scale it to the risk.
Fernway's wording: "Check everything AI produces before you use or send it. Check every name, date, figure, price and quote against the source. For anything going to a customer or informing a decision, check every line."
Decide: the minimum check for all work, the extra checks for higher-risk work, and whether some work needs a second person. The reviewing AI-assisted work guide has a checklist.
4. Human accountability
Say who is responsible for AI-assisted work. The simplest rule is also the fairest.
Fernway's wording: "If you send it, submit it or act on it, you're responsible for it, exactly as if you'd written it yourself."
Decide: whether anything needs sign-off from a manager as well as the author.
5. Record keeping, where appropriate
Some work may need a note that AI was used, especially where it informs a decision or goes outside the organisation. Keep this proportionate. A note on every email is unworkable. A note on a report that informs a buying decision may be sensible.
Fernway's wording: "Tell the person checking your work when AI drafted a substantial part of it. For reports that inform a decision, add a line at the end saying which tool was used and for what."
Decide: when AI use should be disclosed to colleagues or recipients, and whether anything needs recording on file. If your organisation has records management rules, follow them.
6. High-risk decisions
Say which decisions AI must not make or recommend on its own. Decisions about people come first.
Fernway's wording: "Don't use AI to make or recommend decisions about people: hiring, shortlisting, discipline, pay, performance ratings or references. A named person makes those decisions and must be able to explain them in their own words. Talk to HR before using AI for any task that involves them."
The ICO's guidance on explaining decisions made with AI sets out what organisations should consider when AI plays a part in decisions about people. The task suitability guide explains why these decisions need extra care.
Decide: which decisions are off limits, and which need HR or data protection input before AI is involved at all.
7. External and customer-facing work
Say what extra care applies to anything that leaves the organisation.
Fernway's wording: "Anything sent to a customer, supplier or the public is checked by the sender before it goes. Quotes and prices are always checked against the current price list. Don't send AI-drafted replies to complaints without Maya Roberts or Priya Shah reading them first. If a customer asks whether AI was used, answer honestly."
Decide: what needs a second pair of eyes, and your approach to telling customers when AI was involved.
8. Escalation
Say who to ask, and what to do if something goes wrong. This section matters most when it's needed, so make it very clear.
Fernway's wording: "Not sure? Ask Priya Shah before you paste. Think something went into a tool that shouldn't have? Tell Priya straight away, even if you're not certain. Don't delete anything until you've spoken to her. Reporting quickly matters more than blame."
Decide: the named person for questions, the route for incidents (including your data protection contact), and a clear statement that reporting is welcome. The shadow AI guide covers what happens after a report.
Download the template
The team AI rules starter template is a one-page Markdown file you can open in any text editor, paste into Word or Google Docs, or put on your intranet. It has the eight sections with [placeholders] to fill in, and is marked "Template. Not legal advice." Keep that line, or replace it with your organisation's own status note, until someone with the authority to approve it has done so.
Show what Fernway's filled-in page looks like at a glance
Fernway operations team: how we use AI tools (interim, reviewed every six months, owner Priya Shah)
- Tools. Microsoft 365 Copilot Chat on your Fernway work account. No personal AI accounts for Fernway work. Ask Ravi about other tools.
- Never put in. Passwords, bank or card details, health or sickness information, anything about a disciplinary, grievance or complaint about a person.
- Work tool only, minimum needed. Customer names and order details. Supplier contract terms.
- Check. Every name, date, figure, price and quote against the source. Every line for anything going to a customer or informing a decision.
- Responsibility. If you send it, you own it.
- Say so. Tell your checker when AI drafted a large part. Note the tool on reports that inform decisions.
- Not for AI. Decisions about people: hiring, discipline, pay, ratings, references.
- Customers and suppliers. Sender checks everything. Complaint replies read by Maya or Priya first.
- Help. Unsure? Ask Priya before pasting. Something went wrong? Tell Priya straight away. Reporting quickly matters more than blame.
This is a fictional example for a fictional company.
Adapting the template with AI
You can use an approved AI tool to help adapt the template to your team. Give it the template and a description of your work, and keep anything confidential out.
I'm a manager adapting a one-page template of team AI rules. Below is the template, followed by a description of my team. Fill in the placeholders using only what I've told you. Keep it to one page, in plain UK English, written as short instructions to the team. Where I haven't given you enough information to fill a placeholder, leave it in square brackets and add a note saying what I need to decide. Do not invent rules, legal requirements or approved tools. Keep the line "Template. Not legal advice." at the top. My team: [what the team does, the kinds of information it handles, the AI tools and accounts that are approved, who approves new tools, who staff should ask, and our data protection contact's role] [paste the template]
Why this works: It keeps the AI inside the template's structure, uses your real situation, and makes it flag gaps for you to decide instead of inventing policy.
Read the result line by line. An AI tool can produce confident rules that sound official but don't reflect your organisation's policy. Every rule should be one you actually mean and your organisation actually supports.
Agreeing the rules with your team
Rules people helped write are rules people follow.
- Share a draft, clearly marked as a draft, and ask for comments within a week.
- Ask specific questions. "Is there anything here that would stop you doing your job?" "Is there any information we handle that isn't covered?"
- Get a check from your data protection contact, and HR if the rules touch people decisions.
- Agree and publish. Put it somewhere everyone can find it. Mark it as interim if your organisation's policy is still coming.
- Set a review date. Tools, licences and your team's work change. Six months is a reasonable starting point, sooner if your tools or their terms change.
Common mistakes
Writing a policy instead of rules. If it runs to several pages with definitions and clauses, people won't read it. Keep it to one page and link to the full policy.
Listing bans with no approved route. Say what people can do, as well as what they can't.
Vague data rules. "Use common sense with personal data" gives people nothing to go on. Name the information your team handles.
No named person. "Ask your manager" doesn't help when the manager is on leave. Name a person and a backup.
Treating the rules as finished. The first version will be wrong somewhere. Plan to change it.
Assuming the rules make AI output reliable. Rules reduce risk. They don't stop a tool producing a confident wrong answer. Checking still has to happen every time.
Questions people ask
- Is this template a legal policy?
- No. It is a starting point for a team's working rules, and it is not legal advice. Your organisation's own policies come first, and your data protection officer or legal adviser should check anything that touches personal data, contracts or regulated work.
- Our organisation already has an AI policy. Do we still need team rules?
- Possibly not. If the policy is clear and people know it, point to it. Team rules can still help translate a long policy into the specific tasks, information and checks your team deals with, as long as they never contradict it.
- How is this different from the AI policy starter tool?
- The AI policy starter builds a draft from your answers to a few questions. This template is a fixed one-page layout with placeholders to fill in by hand. Use whichever suits you, or use the tool for a first draft and the template to check nothing is missing.
Sources and further reading
- Guidance on AI and data protection (ICO)
- What is special category data? (ICO)
- Explaining decisions made with AI (ICO)
This page explains good practice in plain English. It is not legal advice. Your organisation's policy and approved tools take priority.