Skip to content

Since 2003Our team has helped over 20,000 UK businessesCollection from Unit 3, 116 Bury New Road, Manchester M8 8EB

Call 0161 315 1151WhatsApp 07737 902425hello@webprintsigns.co.uk

AI 500 · AI

AI Policy and Governance Manchester

We help organisations write a staff AI use policy and set up the governance behind it: approved tools, data rules, human review and a register of AI systems in use. Our Manchester team works alongside your solicitor or data protection officer, turning published guidance into rules people can follow.

  • Since 2003trading in Manchester
  • 20,000+UK businesses helped
  • Collect M8Unit 3, 116 Bury New Road
  • A personchecks every file

Why AI use needs written rules

In most organisations, AI use has already started, whether or not anyone approved it. Staff draft emails in free chatbots and paste meeting notes into summarisers, yet few businesses have written down what is allowed.

A policy fixes that by naming approved tools, stating what data may go into them and making clear that a person checks and owns any output before it is used. Governance keeps it current: a register of AI systems, a named approver for new ones and regular reviews.

None of this is legal advice. Our drafts follow published guidance, and your organisation should get legal advice on how the rules apply to it.

Organisations that need a policy now

Any organisation using AI tools benefits, some more urgently than others.

  • Professional services firms handling confidential client files.
  • Charities and care providers processing sensitive personal data.
  • Recruiters and HR teams, where AI may influence decisions about people, as with AI lead qualification or CV screening.
  • Exporters and software firms with customers or users in the EU.

How we put policy and governance in place

1

Find current AI use

A short staff survey shows what is already in use, including tools nobody approved.

2

Classify uses by risk

Each use is sorted by the data involved and its effect on people, from low-risk drafting to decisions about individuals.

3

Draft the policy

We write a plain-English policy covering approved tools, data rules, human review, disclosure to customers and how to request a new tool.

4

Set up the register

A simple register records each AI system, its purpose, owner, data used and review date.

5

Review with your advisers

Your solicitor or DPO reviews the drafts, and we revise them before staff briefing and sign-off.

What you receive

  • A staff AI use policy written for non-specialists.
  • An approved tools list with permitted data types for each.
  • An AI systems register template, populated with your current uses.
  • A request and approval process for new AI tools.
  • Customer disclosure wording for AI use.
  • DPIA screening questions for higher-risk uses.
  • A review calendar for the policy and register.

The guidance and rules a policy should reflect

In the UK, personal data used with AI remains subject to UK GDPR. The ICO has published guidance on AI and data protection covering fairness, transparency, lawful basis and accountability, and we draft with it open. Where an AI use is likely to result in high risk to individuals, a data protection impact assessment is needed before it starts. We draft screening questions and DPIA content for your DPO to own.

The EU AI Act can be relevant to UK businesses whose AI systems or their outputs are used in the EU, such as software sold to EU customers. Obligations depend on your role and the system’s risk category, so the register notes possible scope for your advisers.

The policy also decides when customers are told AI was involved, for instance when an AI chatbot answers enquiries on your website.

Frequently asked questions

Is this legal advice?

No. We draft policies and set up processes in line with published guidance from bodies such as the ICO Legal interpretation of your obligations belongs with your solicitor or data protection officer, and we build in time for them to review every document.

Do we need a policy if staff only use ChatGPT occasionally?

Occasional use still involves data. A short policy saying which tools are allowed, what must never be pasted in and who checks the output reduces the chance of an avoidable mistake. For light use, a couple of pages is enough.

When is a DPIA needed for an AI tool?

UK GDPR requires one where processing is likely to result in high risk to individuals, and the ICO lists types of processing that usually qualify. We help you screen each use against that guidance and draft the assessment, but your DPO or legal adviser makes the final judgement.

Does the EU AI Act apply to a UK business?

It can, depending on whether your AI systems or their outputs reach people in the EU and what role you play. We flag possible exposure for your advisers to assess.

How often should an AI policy be reviewed?

We suggest a fixed review at least once a year, plus an extra review whenever you adopt a significant new tool or guidance changes. Each register entry carries an owner and review date, so nothing quietly lapses.

Related services

For clear AI rules your staff will actually read, drafted with your advisers, ask us for a fixed quote. Ask about an AI policy, call 0161 315 1151 or send a WhatsApp message to 07737 902425.

Ready to get started?

Tell us what you need and we'll come back with an honest, fixed-price quote — no obligation.