Free tool · 13 questions · about 5 minutes
Build your own AI policy
The ICO publishes the AI policy it holds its own staff to. It is good, and it is 30 pages written by a regulator for a regulator, so most of it will not apply to you. Answer the questions below and we will build the version that does, with a plain note on what each clause actually commits you to.
Nothing is stored unless you choose to download at the end.
Who this policy is for
This sets the front page and the words the policy uses. It does not change which rules you end up with.
1.What is your organisation called?
It goes on the front of the policy and into the wording of each clause.
2.Who will own this policy once it exists?(optional)
A name or a job title. If you genuinely do not know yet, leave it blank and the policy will say so rather than inventing someone.
3.What do you call the people you serve?
The policy uses your word throughout, so it reads like yours rather than a template's.
More about this
Why not just copy the ICO’s
You can, and you should read it, it is right here. But its section 5 assumes an organisation with a Data, AI and Automation programme board, product owners, an Architecture Design Authority and a service catalogue. If you have thirty staff you have none of that, and some clauses are actively wrong to copy. The algorithmic transparency logging is a public sector standard that does not apply to a private company at all.
The real problem is subtler. A policy you do not follow is worse than no policy.
That document commits you to maintaining an inventory of your AI, logging every governance decision, running a documented validation phase before anything is deployed, and monitoring performance. Adopt it wholesale and do none of it, and you have not become compliant. You have written down the standard you are failing against and handed it to whoever asks next.
What you get
A policy in your name
Drawn from a library of 56 clauses, each one labelled as the ICO’s wording, adapted from it, or written by us.
What each clause commits you to
A plain note beside every clause. In the download our guidance is kept to one closing part, so you can remove it before you adopt the document.
What was left out, and why
Including what would bring it back, so nothing vanishes quietly.
What you now have to do
A short list, with the items that block the rest of it marked.
A prompt to take it further
Built on CRIT, so your own AI tool interviews you before it rewrites anything.
The honest bit
This is a cookie cutter. It knows 13 things about you and it cannot know whether your particular obligations, contracts or regulator require something it has never heard of. Get it looked over by someone qualified before you adopt it. It is a starting point and it is not legal advice.
There is no AI behind it either, which is deliberate. The same answers always produce the same document, because a compliance artifact that came out slightly different every time would be one nobody could stand behind.
We make no claim to the ICO’s work. It is theirs, credited clause by clause, and where we have added something we say so.
One more thing worth knowing. This is built on version 1.3 of the ICO’s policy, which carries an application date of August 2025 and a review date of August 2026. The ICO asks people reusing its material to work from the current version, so if they publish a newer one this builder will lag it until we catch up.
Want a second pair of eyes on it?
Building the policy is the easy part. Working out what it means for how your organisation actually runs is the bit worth talking about. No pitch, just a conversation.
Email OliContains public sector information licensed under the Open Government Licence v3.0. Information Commissioner’s Office, Internal AI Use Policy. The ICO has not reviewed, approved or endorsed this builder or anything it produces.