- Policies
-
Terms & Conditions
- General Terms & Conditions
- Advertising Terms & Conditions
- Lead Generation Solus Email and Engagement Signal Campaigns Terms & Conditions
- Webinars, Virtual & Live Event Sponsorship Terms & Conditions
- Content and Asset Terms & Conditions
- eGOLD Terms & Conditions
- myGrapevine+ Subscription Terms & Conditions
AI Acceptable Use & Governance Policy
This policy enables EGIL to use artificial intelligence productively while controlling risks to people, confidential information, editorial standards, clients, intellectual property and security. It applies to everyone using AI for EGIL and requires each use to be classified before it begins. Low-risk uses may proceed in approved tools. Controlled uses require recorded assessment and approval. Prohibited uses must not proceed.
1. Purpose and scope
This policy applies to employees, workers, contractors, temporary staff, directors and third parties acting for EGIL. It covers AI systems that EGIL buys, configures, develops, embeds or uses, including generative AI, machine learning, recommendation systems, profiling, automated agents, transcription, image generation, code assistants and AI features built into other software.
It applies to internal work, editorial output, marketing, sales, data and insight products, client delivery, product development and decisions concerning individuals. Suppliers must meet equivalent requirements through contract and due diligence where their services involve material AI use for EGIL.
2. Definitions
AI system means a machine-based system that produces predictions, content, recommendations or decisions from inputs. Generative AI produces text, images, audio, video, code or other content. Profiling means automated processing used to evaluate or predict aspects of a person, including interests, behaviour, role or likely intent. Solely automated decision-making means a decision made without meaningful human involvement.
Personal data, special category data, controller, processor, anonymisation and pseudonymisation have the meanings given by applicable data protection law. Pseudonymised data remains personal data where it can be reconnected to a person.
3. Core principles
- Lawful and accountable. EGIL remains responsible for the purpose, inputs, outputs and consequences of its AI use.
- Necessary and proportionate. Use AI only where it provides a clear business benefit and does not create avoidable risk.
- Human responsibility. People make and own material editorial, commercial, employment and data decisions.
- Privacy and security by design. Minimise inputs, restrict access, assess suppliers and retain information only as needed.
- Accuracy and fairness. Test material outputs, consider affected groups and correct unreliable or discriminatory results.
- Transparency. Explain material AI use to staff, clients and individuals where it affects them or the law requires it.
4. Governance and responsibilities
The Chief Digital Officer is accountable for this policy, the approved-tools register, the AI systems inventory and the AI risk register. The Data Protection Lead advises on lawful basis, transparency, rights, DPIAs, international transfers and automated decision-making. Senior leadership approves controlled uses with material commercial, editorial, employment or reputational impact.
System owners must document the purpose, users, data, supplier, risk level, controls, testing, retention and review date. Managers must ensure staff use approved tools and complete training. Every user remains responsible for following this policy, checking outputs at the level required by the risk, and reporting incidents.
5. Risk classification and approval
|
Level |
Typical uses |
Required controls |
Approval |
|
Standard |
Drafting, summarising public or non-confidential material, ideation, formatting and low-risk code assistance. |
Approved tool, no restricted data, proportionate checking and normal records. |
Manager or tool owner |
|
Controlled |
Personal data, intent or engagement scoring, public or client deliverables, recommendation engines, agents, material code, images of people or business decisions. |
Documented assessment, named owner, testing, security and supplier review, transparency, monitoring and DPIA where needed. |
CDO plus relevant owner and Data Protection Lead where personal data is used |
|
Prohibited |
Unlawful manipulation, discriminatory or deceptive uses, unauthorised surveillance, prohibited biometric or emotion uses, or unapproved consequential decisions. |
Must not be used. A proposed exception cannot override law and otherwise requires written board approval before any testing with live data. |
No routine approval |
If there is doubt, treat the use as Controlled until it has been assessed. A pilot is still a use and must be classified before live, confidential, client or personal data is introduced.
6. Approved tools and procurement
Only tools listed in EGIL’s approved-tools register may be used for EGIL work. Approval must consider security, contractual terms, confidentiality, model-training settings, data location, subprocessors, retention, deletion, access controls, incident notification, intellectual-property terms and exit arrangements.
Free consumer accounts must not be used for confidential, client or personal data. Enterprise settings that prevent provider training do not remove the need for a lawful basis, data minimisation or supplier assessment. New tools, plug-ins, agents, integrations and material feature changes must be reassessed before use.
7. Acceptable use
Approved tools may support research, planning, summarisation, transcription, drafting, translation, coding, testing, design, data quality, workflow improvement, audience analysis and campaign optimisation when the relevant risk controls are met.
Users must provide only the minimum information needed, verify material factual claims and calculations, check sources rather than relying on generated citations, review code and security implications, respect licences and confidentiality, and keep an appropriate record where an output informs a public, client or material internal decision.
8. Prohibited use
Users must not use AI to:
- make unlawful, discriminatory, deceptive or manipulative decisions or content;
- fabricate quotations, evidence, sources, testimonials, engagement or identities;
- impersonate a real person or create a realistic synthetic representation of them without authority and appropriate disclosure;
- infer special category data or highly sensitive characteristics unless specifically approved, necessary and lawful;
- conduct covert employee surveillance, emotion recognition in the workplace, social scoring, or biometric categorisation based on sensitive characteristics;
- select, reject, discipline or dismiss a worker, candidate or supplier solely through automated processing;
- make a solely automated decision producing legal or similarly significant effects unless the use has been specifically approved as lawful and all required safeguards are operating;
- circumvent security, access controls, contractual restrictions or intellectual-property rights; or
- place confidential, client, unpublished, credential, payment, special category or personal data into an unapproved tool.
9. Personal data profiling and intent signals
AI used to analyse reader behaviour, enrich business contacts, recommend content or generate engagement and intent scores must be treated as a Controlled use. Before deployment, EGIL must define the purpose and lawful basis, identify the data and inferences used, test whether the model is necessary and proportionate, complete an LIA and a DPIA where required, and provide clear privacy information.
A score or prediction is an inference, not a fact. It must be labelled accordingly, tested for accuracy and bias, time-limited, and not presented to a client as proof that a person intends to buy. Named signals may be shared only where the Privacy Policy and the notice at the relevant interaction clearly cover that disclosure, the lawful basis has been documented, individuals can object where applicable, and the client contract limits use, retention, onward sharing and consequential decisions.
10. Human review and output assurance
Review must be proportionate to risk. Routine internal brainstorming does not require formal sign-off. Public, client-facing, editorial, legal, financial, employment, security-sensitive or material analytical outputs require review by a person with appropriate subject knowledge before use.
Meaningful human review requires authority and enough information and time to challenge the result. A person must not merely approve an AI recommendation automatically. Material errors must be corrected at source where practicable and affected outputs or recipients notified when necessary.
11. Editorial content images and transparency
AI may assist editorial and marketing teams, but EGIL’s named editor or content owner remains responsible for accuracy, originality, tone, attribution and compliance with the Editorial Policy. AI must not invent interviews, quotations or sources. Generated images must not misleadingly depict a real event or person as authentic.
AI assistance should be disclosed where a reasonable audience would otherwise be materially misled, where synthetic content appears real, where an individual is interacting directly with a bot, where a client contract requires disclosure, or where applicable law requires it. Minor assistance such as spelling, formatting or brainstorming does not normally require a public label.
12. Intellectual property and confidential information
Users must check that prompts, source material and outputs may lawfully be used. AI output must not be assumed to be original, exclusive or capable of copyright protection. Material public or client outputs should be checked for close copying, third-party marks and other rights risks. Confidential information must be shared only under approved contractual and technical safeguards.
EGIL content or data must not be used to train or fine-tune an external or internal model unless the CDO has approved the business case, rights position, security, data protection assessment, retention and withdrawal arrangements in writing.
13. Security development and agents
AI accounts must use EGIL-controlled access, least privilege and multi-factor authentication where available. Secrets, credentials and production data must not be placed in prompts or source repositories available to a provider without approval. Generated code must undergo normal peer review, testing, dependency checks and security scanning before production.
Agents that can browse, send messages, change records, publish, purchase, delete, execute code or call external systems require a Controlled assessment, limited permissions, logging, spending or action limits, test environments and a human confirmation step for material or irreversible actions.
14. Records monitoring and review
EGIL will maintain an inventory of material AI systems showing owner, purpose, supplier, risk level, data categories, affected people, legal assessment, controls, approval date and review date. Controlled uses must have documented testing and monitoring appropriate to their risk, including accuracy, bias, drift, complaints, incidents and continued necessity.
Records must be retained under EGIL’s retention schedule and be sufficient to explain a material output or decision. Prompts and outputs must not be retained indefinitely by default.
15. Incidents complaints and individual rights
Suspected data leakage, harmful or discriminatory output, unauthorised automation, security compromise, copyright concern or unexpected system behaviour must be reported promptly to the CDO and Data Protection Lead. Users must preserve relevant evidence and stop or isolate the system where safe to do so.
EGIL will assess containment, correction, supplier notification, contractual duties, personal-data breach reporting, client communication and support for individual rights. Complaints or objections concerning profiling or automated processing must be routed promptly to [email protected].
16. Training compliance and exceptions
Staff must complete role-appropriate AI literacy and security training before using approved tools and receive refreshers after material changes. Higher-risk system owners require additional training in data protection, testing, bias, documentation and human oversight.
A breach may lead to access removal, investigation, disciplinary action or contract remedies, applied fairly and under the relevant procedure. Exceptions must be written, time-limited, recorded in the risk register and approved by the CDO and the relevant control owner. No exception can authorise unlawful activity.
17. Legal framework and policy review
AI use must comply with applicable law, including the UK GDPR, Data Protection Act 2018, Data Use and Access Act 2025, equality, employment, consumer, intellectual-property, confidentiality and communications law. The EU AI Act and EU GDPR must also be assessed where EGIL provides or deploys an AI system in scope in the European Union or its output is used there. References to laws in this policy do not assume that every provision applies to every use.
The CDO will review this policy at least annually and sooner after a material incident, regulatory change, new high-impact system or significant change in EGIL’s services. The policy owner will maintain related procedures, including the approved-tools register, AI assessment form, AI inventory, risk register, incident process and staff guidance.
18. Contacts
AI governance and tool approval Chief Digital Officer
Data protection and individual rights [email protected]
Legal and intellectual-property queries [email protected]
Executive Grapevine International Ltd
Registered in England & Wales: 2789779 | VAT: 6259453 20
Gate House, Fretherne Road, Welwyn Garden City, AL8 6NS, United Kingdom | +44 (0)1707 351451
Last reviewed by: Helen Fish, Director, 11 September 2026