In this guide
A useful AI policy tells people what they may do today, what needs a decision and where to ask for help. It should be understandable to a volunteer writing an event description as well as a worker considering an assistant connected to internal files.
The example below is a starting point for discussion, not a legal compliance template. Adapt it to your actual work, information and governing arrangements. Approval by a committee does not itself provide a lawful basis for processing somebody's personal information, and democratic agreement does not remove individual rights.
Agree the purpose and scope
Proposed opening: “We use approved AI tools where they support useful work and where we can manage their effects on people, information and decisions. A named person remains responsible for checking and using the output. This policy applies to work carried out for the co-op, including work done on personal devices.”
List approved tools and approved uses in a short register that can change without rewriting the entire policy. Each entry should show its owner, account type, permitted data, connections, review date and support contact. Make clear that a new feature or connector may need a fresh review.
Discuss the proposal through the co-op's normal decision process. Include workers and volunteers who will use the tools, people responsible for member information and those likely to be affected. Record material concerns and the decisions made about them.
Set clear example rules
- Approved starting uses: drafting from public information, brainstorming and organising fictional examples in the listed tools.
- Confidential information: do not enter member records, personnel matters, complaints, passwords or unpublished commercial information unless that specific use and service have been assessed and authorised.
- Connected access: do not connect an inbox, shared drive or application through a personal experiment. Use the approved access process.
- Human checking: verify factual statements, calculations, sources and practical instructions before relying on or publishing them.
- Consequential decisions: do not delegate membership, employment, payment or complaint decisions to an unapproved automated process.
- External actions: review the actual message, recipient or record change before sending, publishing or applying it.
- Problems: report suspected disclosure, unexpected actions and harmful or misleading outputs through the known support route.
These are proposed organisational rules, not a claim that every listed activity is legally prohibited in every setting. The co-op can consider a specific higher-risk use through a more detailed assessment rather than quietly creating exceptions in day-to-day work.
Review the service and information
Before approving personal-data use, identify the purpose, necessary information, lawful basis and applicable rights. Check whether a data protection impact assessment is required. Use the ICO's AI guidance and appropriate advice for the circumstances.
Record the provider's current account terms: retention, training use, human access, deletion, data locations, international transfers and subprocessors where relevant. The ICO's AI contracts and third-parties material is useful for assessing roles and supply-chain arrangements.
Removing names may not make a case anonymous if the remaining detail identifies the person. A description of the only worker in a particular role can still reveal who is involved. Prefer fictional examples or properly assessed information rather than assuming a quick edit resolves confidentiality.
Make the policy usable in ordinary work
Run a short exercise with three scenarios. Drafting a public event introduction in an approved tool may be within scope. Summarising a confidential member complaint needs a separate decision. Connecting the entire board drive to a new assistant is an access and information review, not merely a writing preference.
Assign a person to answer questions promptly so uncertainty does not encourage hidden experimentation. Keep a simple record of approved exceptions, their conditions and expiry or review date. Review the policy when tools, suppliers or working practices change.
Use the AI assistant guide for a bounded pilot and the member-data guide for information decisions. If you need help turning an agreed policy into permissions and operating procedures, bring it to a technology support discussion.