RETROSPECTIVE RECORD · PREPARED 16 SEPTEMBER 2026The archive · 100 retrospective records ↗
productivityatlas.

The archive / Workflow

Workflow / Method record · Documentation record · prepared 16 September 2026

Staff already use AI tools; a policy has to assume that

UK government and NCSC guidance describe the actual risks of employee AI use and what a written policy needs to cover.

Visual for this record: shadow-ai-and-acceptable-use-policies
Visual published by gov.uk, shown for identification of the record. Credit: gov.uk · source page ↗ Rights: owner-review-pending.

What the guidance documents actually say

The UK's Generative AI Framework for HMG, published 18 January 2024 and later withdrawn on 10 February 2025 in favour of a successor playbook, set out ten principles for civil servants, including knowing a tool's limitations, keeping meaningful human control at the right stage, and not letting private or sensitive data train a generative model without the data owner's knowledge or consent. The National Cyber Security Centre's blog post of 14 March 2023 takes a narrower, more technical angle: it warns that queries submitted to a public large language model are stored by the provider and may be used in model development, and advises organisations to keep sensitive information out of those queries or to consider a self-hosted or privately contracted model instead. The US National Institute of Standards and Technology's AI Risk Management Framework, released 26 January 2023, offers a voluntary structure for building trustworthiness considerations into how an organisation designs, develops and uses an AI system, rather than a specific workplace rule.

Why staff use these tools before any policy exists

None of these three documents were written because an employer asked first; they exist because assistants built into browsers, phones and productivity software are already available to an individual employee regardless of what an employer has approved. A policy written as though adoption is a future decision is already behind the actual behaviour in most organisations. The realistic starting assumption, drawn from all three documents, is that some staff are already pasting text into a public assistant, and a policy has to change that behaviour rather than merely permit or forbid a hypothetical future one.

What an acceptable-use policy needs to cover

Combining the three sources, a workable policy needs to state which categories of data must never go into a public tool's prompt box, who has authority to approve a private or self-hosted alternative for sensitive work, what human review is required before an AI-assisted output is used or sent externally, and how the policy itself will be revisited as tools change. It also needs a channel for staff to disclose the tools they are already using, since a policy nobody discloses against is unenforceable.

  • Can a member of staff name what they are and are not allowed to paste into a public assistant, without checking a document first?
  • Who signs off on a private or self-hosted alternative when a public tool's terms are not acceptable for a piece of work?
  • Does anyone revisit the policy on a schedule, or only after an incident forces the question?

This is best read as an editorial synthesis of three separate documents rather than a single settled standard: government guidance in this area has already been withdrawn and replaced once, and a workplace policy modelled on it should expect to be revised on a similar timeline.

Sources & reading trail

Generative AI Framework for HMG ↗

Sets out ten principles for using generative AI safely in UK government work; withdrawn 10 February 2025 and superseded by the AI Playbook for the UK Government.

Source published: 18 January 2024 · Retrieved: 16 September 2026

ChatGPT and large language models: what's the risk? ↗

Advises organisations not to enter sensitive information into public LLM queries, and to weigh self-hosted or private models for sensitive tasks.

Source published: 14 March 2023 · Retrieved: 16 September 2026

AI Risk Management Framework ↗

Describes NIST's voluntary framework for building trustworthiness considerations into the design, development and use of AI systems.

Source published: 26 January 2023 · Retrieved: 16 September 2026

Announcements and papers establish the record; the friction reading and the adoption questions are Productivity Atlas editorial analysis. This retrospective draft does not imply the site published on the event date.