
AI Governance Policies for UK Organisations
We help you understand how AI is being used across your organisation, decide what should and shouldn’t be permitted, and put the right governance in place.
We help organisations understand how AI is already being used, decide which systems and uses should be permitted, and put practical governance in place. This can range from a staff AI policy to a wider framework covering approvals, DPIAs, suppliers, responsibilities, training and ongoing oversight.
If you’re considering AI or already have it in place but don’t have a policy set up. Download our one-page AI governance readiness guide. Download the AI governance guide →

Clara Westbrook
25+ Years PQE
Founder | Qualified Solicitor | Data Protection Specialist
07976 939 016
Is AI already being used across your organisation?
A common issue we find is employees using tools such as ChatGPT, Copilot and other AI systems before the organisation has decided which tools are approved or what information may be entered into them.
This can mean personal data, confidential information or commercially sensitive material is being entered into AI systems without the organisation having assessed how that information will be handled, what contractual safeguards apply or who is responsible for overseeing the use of the tool.
AI governance can range from a staff policy setting clear rules on permitted use to a wider framework covering approvals, suppliers, DPIAs, responsibilities, training and ongoing oversight.
Read the ICO guidance on AI and data protection →
Why does an AI policy matter?
We have dealt with situations where employees were entering personal and client information into publicly available AI tools to speed up reading and responding to requests. The organisation had not approved the tools or assessed how information submitted to them would be handled.
That created risks around confidentiality, data protection, supplier terms and information security which the organisation had not previously identified.
An AI policy is one part of controlling that risk. It should sit alongside appropriate approval processes, supplier and privacy checks, clear responsibility for AI use, staff training and DPIAs where required.
A clear AI policy is one part of controlling this risk and puts your organisation a stronger position if a breach were to happen.
What to expect from our AI governance service
We start by understanding how AI is already being used within your organisation and what you want to achieve by having it in place. Some organisations simply need an acceptable-use policy for staff. Others need a wider governance framework covering multiple systems, business functions, approval processes and higher-risk uses of AI. We tailor the scope to what your organisation actually needs.
Our process:
1
Understand how
AI is being used
2
Identify the risks
and design the framework
3
Put the governance
into practice
How our AI governance service works
1. We discuss which AI systems are already in use, how employees are using them, what information is being entered and whether there are any proposed new AI projects. We also review any existing policies, procurement processes and governance arrangements.
2. We identify areas where AI use creates data protection, confidentiality, contractual or governance risk and agree the controls that should be put in place. This may include approval routes, restricted uses, responsibility for oversight and circumstances in which a DPIA or further assessment is required.
The ICO states that AI involving processing likely to create a high risk to individuals may require a DPIA, and its governance guidance recommends integrating DPIAs into AI governance processes.
3. We prepare the agreed framework and policy documentation and explain how it should operate in practice. Where required, we can also support implementation, staff training and the ongoing review of new AI use cases.
AI governance pricing
The cost will depend on whether you require a standalone AI policy or a wider governance framework and on the number and complexity of AI systems already being used.
Fixed Fee | From £750 – £2,500 + VAT | Fixed |
Hourly Rate | £375 + VAT | Ongoing |
Daily Rate | From £1,000 + VAT | Better for long-term projects which may take a few days to a few weeks |
Retainer | Ongoing | Ongoing legal support |
We confirm the scope and fee before work begins, whether you need a standalone staff policy, a review of existing AI use or a wider governance framework with approval processes and training.
Why organisations choose to work with us
WDPS is a solicitor-led data protection organisation with more than 25 years’ experience in privacy, data protection and commercial law.
We approach AI governance from a practical perspective. Rather than producing a generic AI policy, we look at how AI is actually being used, the information involved and the risks the organisation needs to control.
Our team’s previous experience includes work involving organisations such as WarnerMedia, Yum! Brands, Burberry, Expedia and Société Générale across technology, media, retail, travel, financial services and other commercial environments.
Request AI governance support
Speak directly with a data protection specialist about how AI is being used within your organisation. +44 (0)7976 939 016 (Mon – Fri: 9:00 am – 6:00 pm Sat: 10 – 4pm).
If you would like us to review existing AI use, prepare an AI policy or design a wider governance framework, send us a short description of the tools involved and how they are being used. We will confirm the information required, the appropriate scope and the fee before work begins.
Westbrook Data Protection Services Limited, 2nd Floor, Midas House, 62 Goldsworth Road Woking, Surrey, GU21 6LQ
View our Privacy Policy here
Explore More Data Protection & Privacy Services
Our team has a deep understanding of the following areas of law and continue to add value to our clients’ businesses.
Latest Insights
- The GDPR Accountability Principle: From Paper to PracticeAccountability principle As a new consultant at Westbrook Data Protection Services, one of the first […]
- Changes to employment law and the rise in Data Subject Access RequestsChanges to employment law and the rise in Data Subject Access Requests Employment Rights Act […]
Stay ahead with expert data protection tips
Get practical advice, legal updates, and exclusive insights.
Frequently asked questions
Does every organisation need a separate AI policy?
There is no single UK rule requiring every organisation to use the same standalone policy. However, organisations using AI should have governance and documentation proportionate to the risks, including clear approval routes, assigned responsibilities and controls for personal data.
When is a DPIA needed for an AI system?
A DPIA is required where the proposed use of AI is likely to result in a high risk to individuals. This may include significant automated decision-making, systematic monitoring or large-scale use of sensitive information. The assessment should begin before the system is deployed.
Can staff enter personal data into public generative AI tools?
Only where the tool and the intended use have been approved following appropriate privacy, security and contractual checks. Staff should not enter personal or confidential information into unapproved tools, and the organisation should provide clear rules and training.
Who is responsible for personal data when an AI supplier is used?
Responsibility depends on who decides the purposes and essential means of the processing. The parties may be controller and processor, separate controllers or joint controllers. The roles should be assessed and documented rather than assumed from the supplier’s standard terms.



