Skip to main content

    AI acceptable use policy template for care providers

    Published 19 September 2026 · 7 minute read · General information, not legal advice

    Most care services now have staff using AI to help with notes, reports and letters, and most policies still say nothing about it, or only say "don’t". This is a ready-to-adapt AI acceptable use policy for UK care providers: care homes, home care, children’s homes, fostering agencies and supported living.

    It names an approved route instead of only banning things, covers personal data, checking what AI produces, training and incidents, and follows the principles in CQC’s May 2026 statement on AI. The full text is below, and as a Word file you can edit. It is general information, not legal advice.

    Download the policy template

    Editable .docx, about 14 KB. Free, no sign-up.

    Download Word file

    Why a care provider needs an AI policy now

    In May 2026 the Care Quality Commission set out what it expects from providers that use AI. It does not approve tools, but it expects the provider to govern them:

    “A DPIA assesses and documents risks to privacy and data subject rights to understand and minimise any interference with people’s rights, to enable lawful use of AI.”
    CQC, Artificial intelligence in health and social care, 21 May 2026 [1]

    The same statement expects staff who are "sufficiently trained and confident in using the technology" and AI outputs that are "continuously monitored and evaluated". UK GDPR also expects "appropriate data protection policies" where they are proportionate. A written AI policy is where those expectations become rules your staff can follow, and it is the first document an inspector or your DPO will ask for.

    The other reason is simpler. If your staff already use ChatGPT on their phones, a policy that only says no will not stop it; it will stop you seeing it. Our guide on ChatGPT and case notes explains why that use is a data protection problem.

    How to use this template

    • Download the Word file and replace everything in [square brackets] with your own details.
    • Decide which AI tools you will approve and list them in section 4. Complete a DPIA for each one first; our DPIA template for AI in social care is pre-filled for this.
    • Get a written data processing agreement from the provider of every approved tool. If a provider cannot offer one, do not approve the tool.
    • Share the policy with all staff, add it to induction and supervision, and train staff before they use an approved tool.
    • Review it at least once a year, and whenever you approve a new tool.

    The template

    The full text of the policy, as it appears in the Word download. Fill in the [highlighted fields] with your own details.

    1. Purpose

    This policy sets out how staff at [Organisation name] may use artificial intelligence (AI) tools in their work, so that we get the benefit of these tools without putting the people we support, their families or our staff at risk.

    It applies to everyone who works for or on behalf of [Organisation name], including employees, bank and agency staff, volunteers and students, on any device, including personal phones.

    2. What this policy covers

    An AI tool means any service that writes, rewrites or summarises text, images or audio in response to what you type, say or upload. This includes chatbots such as ChatGPT, Copilot and Gemini, AI features built into other apps, and transcription, note-taking and translation tools.

    Personal data means any information that identifies a living person directly or indirectly. It includes names, initials, nicknames, addresses, dates of birth, NHS numbers, case and reference numbers, schools, GP practices, photographs and voice recordings. Information about health, disability, ethnicity, religion and sex life is special category data and needs extra protection under UK GDPR.

    3. Our principles

    We follow the principles the Care Quality Commission set out in May 2026 for providers using AI:

    • AI supports people's decisions. It never replaces the judgement of the person responsible for the care or the record.
    • A person checks every AI output before it is used, and remains accountable for it.
    • People who use our services can find out how AI is used in their care.
    • Staff who use AI are trained to use it safely.
    • We complete a data protection impact assessment (DPIA) before any AI tool is used with information about the people we support.

    4. Approved AI tools

    Only the tools listed below may be used for work that involves the people we support, our staff or our organisation. Any other AI tool, including a personal ChatGPT account, is not approved for that work.

    ToolApproved forWho may use itDPIA referenceProcessing agreement
    [Approved tool][e.g. drafting and tidying care notes, reports and letters][e.g. all care staff][DPIA reference][Yes, dated]
    [Approved tool][Approved use][Staff group][DPIA reference][Yes, dated]

    To request a new tool, speak to [name of data protection lead or nominated individual]. A tool is added only after a DPIA has been completed and a written data processing agreement is in place.

    5. What you may do

    • Use an approved tool to help draft, tidy or summarise notes, reports, letters and emails, following section 7 whenever information about a person is involved.
    • Use any AI tool for tasks that involve no personal data and no confidential information, such as general research, planning an activity or writing a generic training quiz.
    • Ask your manager if you are unsure whether a task is allowed. Asking is always the right choice.

    6. What you must not do

    • Do not enter personal data about anyone we support, their family or a colleague into any AI tool that is not approved in section 4.
    • Do not use a personal AI account for work, even with names removed, unless the tool is listed in section 4.
    • Do not upload photographs, documents, recordings or screenshots of records to an AI tool that is not approved.
    • Do not let AI make or recommend decisions about someone's care, safety, medication or support. Those decisions are made and recorded by the responsible person.
    • Do not put anything into a care record that you did not observe or have not checked.
    • Do not use AI to record a conversation with someone we support without their informed consent and without the tool being approved for recording.

    7. Using AI with information about people

    Where an approved tool is used with information about the people we support, identifying details must be removed before any text is sent to the AI. Our approved route for this is [approved tool, e.g. Caredact], which replaces names, addresses, NHS numbers and other identifiers with placeholders and restores them only in the finished document.

    • Check the highlighted detections before sending, and add anything the tool missed.
    • Never type identifying details back into the AI conversation.
    • Keep the finished document in [our care records system], not in the AI tool.

    8. Checking what AI produces

    AI tools can be wrong, can leave out important detail, and can present guesses as facts. You are responsible for everything you record or send, whether or not AI helped you write it.

    • Read every line of AI-assisted text and check it against what actually happened.
    • Make sure the text says only what you observed or were told, and says who told you.
    • Remove anything the AI has added, softened or exaggerated. For example, "ate about half" must not become "ate well".
    • If you are not sure the text is accurate, do not use it.

    9. Being open with the people we support

    People who use our services, and their families or representatives, can ask how AI is used in their care. [Name or role] will explain in plain language which tools we use, what they are used for and how personal data is protected. Our privacy notice describes this.

    10. Training

    Staff must complete [name of training] before using an approved AI tool, and refresh it [every year]. Training covers this policy, how to use the approved tool, how to check AI outputs, and what to do if something goes wrong. Completion is recorded in [training system].

    11. Monitoring

    [Name or role] reviews the use of approved tools [every month], using the tool's audit log where it has one, and reports to [the registered manager or board] [every quarter]. We may ask staff about their use of AI tools as part of supervision.

    12. If something goes wrong

    If you think personal data has been entered into an AI tool that is not approved, or an AI output has been used that was wrong, tell [name of data protection lead] straight away. Do not delete anything first.

    We will assess the risk. If a personal data breach is likely to result in a risk to people's rights and freedoms, we must report it to the Information Commissioner's Office as soon as possible, and where feasible within 72 hours of becoming aware of it. Reporting a mistake quickly is always treated more favourably than hiding it.

    13. Review

    Policy owner[Name and role]
    Approved by[Name and role]
    Date approved[Date]
    Next review[Date, no more than 12 months later]
    Version[1.0]

    Download the policy template (Word)

    Questions

    Is an AI policy a legal requirement for care providers?

    No law requires a document called an AI policy. But UK GDPR expects appropriate data protection policies where they are proportionate, CQC expects providers to govern their use of AI, and the ICO expects a DPIA before AI is used with personal data. A written AI policy is the simplest way to show all three.

    Should the policy just ban ChatGPT?

    A ban with no approved alternative tends to push AI use out of sight rather than stop it. It is better to approve a route that removes personal data before anything reaches the AI, and to ban personal AI accounts for work.

    Do we need a DPIA as well as a policy?

    Yes. The policy says what staff may do; the DPIA records the risks of a specific tool and how you reduce them. Start from our DPIA template for AI in social care.

    Sources

    1. [1]CQC, Artificial intelligence in health and social care: CQC’s role, expectations and plans (21 May 2026)
    2. [2]UK GDPR, Article 24 (responsibility of the controller)
    3. [3]ICO, Examples of processing likely to result in high risk
    4. [4]ICO, Personal data breaches: a guide
    5. [5]Community Care, First practice guidance for AI in social work warns of bias and data privacy risks (11 April 2025)