Why is it that so many employers still don’t have an AI Use Policy?
Published on: 01/10/2026
Issues Covered:
Article Authors The main content of this article was provided by the following authors.
Barry Phillips Chairperson, Legal Island
Barry Phillips Chairperson, Legal Island
Barry Phillips Resized
LinkedIn

Barry Phillips (CEO) BEM founded Legal Island in 1998. He is a qualified barrister, trainer, coach, and meditator, and a regular speaker here in the UK and Ireland, and abroad.


Barry has completed the Oxford University course “Leading AI Implementation” in June 2026. He has trained hundreds of HR Professionals on how to use GenAI in the workplace and is the author of the book “ChatGPT in HR – A Practical Guide for Employers and HR Professionals” 

Legal Island

This week Barry Phillips asks whether the sheer pace of change is deterring many employers from getting an AI use policy.

Transcript: 

Hello Humans, I’m Barry Phillips and welcome to AI for HR -the weekly podcast that aims to cover an important AI topic in around five minutes.

This week we’re asking why is it that so many employers still don’t have an AI use policy?

A 2026 report published recently from Trinity Business School, in association with Microsoft Ireland, found that just 43.6 per cent of the organisations surveyed had a formal AI policy. 

Why is this? We’re all using AI at work. So where’s the AI policy explaining the guardrails.

What follows are five possible explanations -  each with a relevant solution or response.

First, the exercise belongs to several people not just one, the HR person.

HR understands the workforce implications. IT understands the systems. The data protection specialist asks what happens to people’s information. And the person at the top must decide what risks the organisation will accept.

This takes co-ordination. When everyone has a stake, it’s easy for everyone to assume somebody else is leading.

The solution is one named owner, supported by those specialists, with a senior sponsor and a deadline. Shared expertise still needs clear accountability.

Second explanation, AI moves ridiculously quickly.

Who wants to spend weeks writing something that looks out of date before the next management meeting?

And the response? Keep the core policy focused on lasting rules: protect confidential information, check outputs for accuracy and bias, and keep people responsible for decisions. Put the changing details, including approved tools and settings, in a separate register that’s easier to update.

Third, employers may still be deciding what they’re actually going to use, and where the boundaries belong.

Are we standardising on Copilot? Allowing ChatGPT? What about AI built into software we already own?

Copilot can feel like the safe option. But a familiar badge isn’t a risk assessment. With any  product, the version, account type, settings, data access and intended use matter.

So approve specific tools for specific tasks and data. Permission to draft a job advert should never be treated as permission to upload somebody’s medical records.

Fourth reason, this feels like an unfamiliar kind of policy.

We know how to write policies. Keeping one useful when the technology changes every few weeks is a different challenge.
So make it a living document with an actual maintenance routine. Name the person responsible, record each version and set a review date. I’d start with quarterly reviews, plus an earlier check when you introduce a significant new tool, change how it’s used or encounter a problem. Explain updates to staff.

Fifth and finally, doing this properly means getting your hands dirty.

A good policy should start with an audit of actual AI use. Which tools are people using? Through which accounts? What information goes in, and what decisions depend on the output?

That’s harder than checking the software budget. Personal accounts and AI features inside existing systems can escape that view. Staff may also hesitate to admit what they’re doing.

In conclusion remember if you leave the rules unclear, employees will fill in the gaps themselves. Get a workable policy in place, put someone in charge and keep it current. Your first AI incident is a very expensive way to discover what your rules should have been.

That’s it for this week.

Until next week bye for now.

Disclaimer The information in this article is provided as part of Legal Island's Employment Law Hub. We regret we are not able to respond to requests for specific legal or HR queries and recommend that professional advice is obtained before relying on information supplied anywhere within this article. This article is correct at 01/10/2026
AI for HR: Tools, Prompts, Speed and Safety
Online
Artificial Intelligence
Popular
Events
CPD Certificate in AI for HR
Online
Artificial Intelligence
Popular
Events
Get the Most from Copilot (Level 1): A Practical Guide for HR
Online
Artificial Intelligence
Popular
Events
Discover the smarter way to deliver staff training (without the stress)! Streamline your company-wide training, enhance your staff's skills, and in increase productivity with our learning management system, AppLI LMS