What the code should contain

  • Purpose of AI in the organisation
  • Approved and prohibited uses
  • Data handling and privacy rules
  • Human review requirements
  • Transparency expectations with colleagues and customers
  • Reporting path for concerns and incidents

If it cannot fit on two sides of a page (plus a one-page pocket card), it will not be trained. Long policies have their place; they are not substitutes for rules people remember on a Tuesday afternoon.

Make it local

Generic internet policies fail. Add examples from your offices: chancery, school, charity shop, clinic admin. People remember stories. “Do not paste safeguarding emails into free chatbots” is clearer than “comply with applicable data protection principles.”

Rollout that sticks

Launch with leadership endorsement, short training and a pocket version. Revisit annually. Tie acknowledgements to onboarding for staff and long-term volunteers who use digital tools. Contractors need the same rules—or you have expanded processing without documentation.

Enforcement without fear culture

Prefer coaching for first honest mistakes; escalate for reckless or repeated violations. Celebrate good catches. Fear drives shadow AI underground. The point is formation and protection of persons—not a gotcha culture that makes people hide tools.

Sample prohibited-use lines you can adapt

Adapt with counsel: no pasting safeguarding files into unapproved tools; no automated employment decisions without human review; no generating official liturgical texts for public use without authorised review; no using AI to impersonate a named pastor or superior. Short, concrete lines train better than abstract virtue lists.

Review the list yearly. New tools create new temptations; the code should name them before an incident does.