---
title: "HR policies with ChatGPT: draft, check against UK law, approve"
url: https://usingaias.com/ai-for/hr-policies/
summary: "AI drafts the structure and plain-English wording from what you already say. The legal minimums come from GOV.UK and Acas, never the AI, and a named person approves the final policy."
published: 2026-10-01
updated: 2026-10-01
author: "Jack Stovell"
publisher: "Adapt Progress Evolve Limited"
language: en-GB
---

# HR policies with ChatGPT: draft, check against UK law, approve

AI drafts the structure and plain-English wording from what you already say. The legal minimums come from GOV.UK and Acas, never the AI, and a named person approves the final policy.

## At a glance

- Difficulty: Intermediate (Suits anyone who owns the staff handbook; you need to be able to read Acas and GOV.UK guidance closely.)
- Time: About half a day for one policy, plus time for consultation and approval (our estimate, not a measured figure)
- Tools: ChatGPT, Claude, Microsoft Copilot
- You need: Your current handbook section on the topic, if there is one; The relevant terms from your employment contracts; The Acas guidance or Code of Practice for the policy area; The name of the person who approves the policy
- Role hub: [AI for HR](https://usingaias.com/ai-for/hr/)

## What you'll end up with

One HR policy, written in plain English, checked against the legal minimums from GOV.UK and Acas, and signed off by a named person with the authority to do it.

The AI does the drafting. It's good at structure and at turning clunky handbook wording into something a normal person can read. It's not reliable on what the law says, so you don't ask it. The legal side comes from the source pages and the sign-off comes from a person. Three hands on one document: you collect, the AI drafts, a named person approves.

## Before you start

Gather four things: your current handbook section on the topic, the relevant terms from your employment contracts, the Acas guidance or Code of Practice that applies, and the name of whoever approves it. "Someone senior" isn't a name. If nobody knows who signs it off, the policy just sits in a folder, so settle it now.

## Steps

### 1. Collect what you already say

Pull together everything your organisation currently says about the topic. The handbook is the obvious place, but look at contracts and past staff announcements too, and write down the things people do that aren't written anywhere. If everyone assumes a rule exists, you need to know before you write anything.

Put it all in one document. Messy is fine. Contradictions are useful, because they show where the policy needs to make a decision.

**Checkpoint:** everything you currently say on this topic sits in one place, including the unwritten bits.

### 2. Get the legal checklist from GOV.UK and Acas, not the AI

This is the step people skip, and it matters most. Find the GOV.UK page or Acas guidance for your policy area and copy the requirements into a document of their own. That's your checklist.

Why not ask the AI? Because it sounds the same whether it's right or not. It can invent a rule, get a time limit wrong, or slide in something from another country's law. You can't tell from the tone.

Some examples of what the sources give you:

- **Written statement (GOV.UK).** Employers must give employees and workers a principal statement on the first day of employment and a wider written statement within 2 months. The wider statement must include information about pensions, collective agreements, any other right to non-compulsory training, and disciplinary and grievance procedures. Sick pay and procedures, other paid leave and notice periods must also be given on day one, in the statement or a separate document staff can reasonably access.
- **Disciplinary and grievance (Acas).** The Acas Code of Practice, published 11 March 2015, is the minimum an employer should follow, and the procedure followed is taken into account if a case reaches an employment tribunal. Acas says it will be updating the Code and has consulted on a draft, so check which version is current.
- **Home and hybrid working (Acas).** A policy should open with a statement of commitment, say who it was agreed with (for example a trade union or employee representatives), define its terms, say how and when it will be reviewed, and explain how requests are made and decided. Be careful not to directly or indirectly discriminate on eligibility.

Copy what applies to your policy, from the current page, not from this list.

**Checkpoint:** a separate checklist, copied from the current GOV.UK or Acas page, that you could hand to someone else.

### 3. Draft the structure

Now the AI earns its keep. Give it what you collected in step 1 and ask for an outline. Tell it to keep your rules and add nothing, because left alone it will helpfully invent a few.

```text
Turn the wording below into a policy outline with clear headings for purpose, scope, definitions, procedure and review. Keep all the rules we currently follow, add nothing new, and keep the language simple.

[paste your existing wording here]
```

Read what comes back with the checklist beside you.

**Checkpoint:** the outline has a home for everything you currently do and for every point on your checklist. A missing heading is a gap you've found early.

### 4. Draft the wording in plain English

Work one section at a time. It's much easier to spot a problem in a few paragraphs than in ten pages.

```text
Rewrite this section in plain UK English for a general workforce. Keep every obligation and rule we currently have. Add nothing new. If anything is unclear or could mean two different things, mark it with [CHECK].

[paste the section here]
```

The [CHECK] instruction gives the AI a way to say "not sure" instead of guessing. Treat every [CHECK] as a question for a person, not something to settle by asking the AI again. Watch the vocabulary too: a term like "at-will employment" comes from US law and has no place in a UK policy.

**Checkpoint:** someone new to the organisation could read the section and know what to do, and every [CHECK] has been answered by a person.

### 5. Check the draft against the checklist

Comparison is a job AI does reasonably well, as long as you stop it adding anything of its own.

```text
Compare the draft policy below with the checklist I've pasted from [Acas / GOV.UK]. List every point on the checklist that the draft does not cover. Do not add any legal content yourself; only flag what is missing.

Draft policy:
[paste your full draft]

Checklist:
[paste the requirements from Acas or GOV.UK]
```

Fill each gap using the wording from the source, not the AI's version of it.

Then the numbers. Statutory rates change: GOV.UK says National Minimum Wage and National Living Wage rates change on 1 April every year, and it lists the current Statutory Sick Pay rate on its own page. Never let the AI supply a rate, threshold or time limit. If your policy mentions one, check it on the current GOV.UK page yourself, or point staff to the page instead of printing a figure that will go out of date.

**Checkpoint:** every missing point is filled from the source, and every rate, threshold and time limit has been checked on GOV.UK.

### 6. Approval, consultation and roll-out

Send the draft to the named approver with the checklist and the gap comparison, so they can see what it was checked against. They're approving the policy, not the AI's work.

If you have a trade union or employee representatives, involve them early, not when the thing is finished. For a hybrid working policy, Acas suggests the policy itself says who it was agreed with.

Once it's approved, tell staff where to find it. And if the change affects anything in people's written statements, GOV.UK says you must tell them within one month of making the change.

**Checkpoint:** a named approver, a record of any consultation, and a clear place where staff can find the final version.

## Common mistakes

- **Letting the AI invent a rule, rate or time limit.** It does this fluently. If a figure or deadline appears that you didn't copy from GOV.UK or Acas, treat it as unverified.
- **Out-of-date rates.** A number that was right once can be wrong now. Minimum wage rates move every 1 April.
- **Terms from another country's law.** "At-will employment" is the classic. Anything that sounds American deserves a second look.
- **Skipping consultation because the draft arrived fast.** Speed is the point of using AI, but no reason to leave out the people the policy affects.

## When to keep AI out of it

Keep it away from live cases about a named person. Don't ask it how a policy applies to a specific employee, whether a disciplinary outcome is fair, or how to handle a particular grievance. Those need human judgement, knowledge of the individual and a proper process.

The AI is for writing the policy that covers everyone. Applying it to one person is a human job.

## Review checklist

- [ ] Every rule you currently follow is either kept or deliberately changed
- [ ] Every point on the GOV.UK or Acas checklist is covered
- [ ] Legal wording came from the source page, not from the AI
- [ ] No rate, threshold or time limit came from the AI; each was checked on the current GOV.UK page
- [ ] The Acas Code or guidance used is the current version
- [ ] No terms from another country's employment law
- [ ] Every [CHECK] marker was answered by a person
- [ ] Eligibility rules do not directly or indirectly discriminate
- [ ] Trade union or employee representatives consulted where relevant
- [ ] Approved by the named person, with the date
- [ ] Staff told about any change to their written statement within one month

## Before you paste anything: confidentiality and UK GDPR

Before you paste anything, ask two questions: is there personal data in it, and is it confidential to my organisation or a client? If the answer to either is yes, use a tool your organisation has approved, under a business contract, and send only what the task needs.

**For this task:** Paste policy wording and contract terms only. Never paste a live case, an employee's name, or details of a grievance, disciplinary or absence.

Never paste these into a personal (consumer) AI account:

- Payroll reports, salaries by name, bank details or National Insurance numbers
- Named employee records: health, absence, grievance or disciplinary details
- Customer or supplier ledgers with names attached
- Unpublished results, forecasts or board papers
- Anything a client has given you
- Passwords, API keys or bank logins (in any tool, ever)

UK GDPR, in four lines:

- **Send the minimum.** UK GDPR's data minimisation principle says personal data must be adequate, relevant and limited to what is necessary for the purpose. For most tasks on this site, the personal data the AI needs is none. ([ICO: The data minimisation principle](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/data-protection-principles/a-guide-to-the-data-protection-principles/data-minimisation/))
- **Know who is controller and who is processor.** Under a business contract, the AI provider usually acts as your processor. On a personal consumer account, you are agreeing to the provider's own consumer terms instead. ([ICO: Controllers and processors](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/controllers-and-processors/))
- **Check where the data goes.** Many AI services process data outside the UK. Restricted transfers need safeguards, which a business agreement usually addresses and a personal sign-up does not. ([ICO: International transfers](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/))
- **The ICO has AI-specific guidance.** It covers accountability, transparency, accuracy and security when organisations use AI with personal data. ([ICO: Guidance on AI and data protection](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/guidance-on-ai-and-data-protection/))

Consumer plans vs business tiers (checked 2026-10-01; providers change their terms, so read the live page and your contract):

- **OpenAI (ChatGPT).** Personal plans: conversations can be used to train models unless you turn off "Improve the model for everyone" in Settings > Data controls. ChatGPT Business, Enterprise, Edu and the API: not used to improve models by default. ([OpenAI Help Centre: How your data is used to improve model performance](https://help.openai.com/en/articles/5722486-how-your-data-is-used-to-improve-model-performance); [OpenAI: Enterprise privacy at OpenAI](https://openai.com/enterprise-privacy/))
- **Anthropic (Claude).** Free, Pro and Max: chats are used to train models only when the model-improvement setting is on. With it on, data is kept for up to five years; with it off, the standard is 30 days. Claude for Work and the API: inputs and outputs are not used to train models by default. ([Anthropic: Updates to Consumer Terms and Privacy Policy](https://www.anthropic.com/news/updates-to-our-consumer-terms); [Anthropic Privacy Center: Is my data used for model training? (consumer)](https://privacy.claude.com/en/articles/10023580-is-my-data-used-for-model-training); [Anthropic Privacy Center: Is my data used for model training? (commercial)](https://privacy.claude.com/en/articles/7996868-is-my-data-used-for-model-training))
- **Microsoft (Copilot).** Personal Microsoft accounts are covered by Microsoft's consumer terms, not your organisation's. Copilot and Copilot Chat used through an organisation: covered by Microsoft's Data Protection Addendum with Microsoft as processor; your data is not used to train foundation models. ([Microsoft Learn: Enterprise data protection in Microsoft Copilot and Copilot Chat](https://learn.microsoft.com/en-us/microsoft-365/copilot/enterprise-data-protection); [Microsoft Learn: Data, privacy and security for Microsoft Copilot](https://learn.microsoft.com/en-us/microsoft-365/copilot/microsoft-365-copilot-privacy))

> General information for UK readers. Not financial, legal, tax or HR advice. Example companies and figures are fictional unless a source says otherwise. Follow your organisation's policies and your professional body's rules.

## From the same studio

Ours: made by the same studio that runs this site.

- [Forematter](https://forematter.com/): In development, not open to customers yet. Once a policy is approved, it is the kind of document Forematter answers staff questions from, showing where each answer came from.

## Related

- [AI for HR](https://usingaias.com/ai-for/hr/)
- [Job descriptions with ChatGPT (and Claude or Copilot)](https://usingaias.com/ai-for/job-descriptions/)
- [AI for performance reviews: write-ups, not judgements](https://usingaias.com/ai-for/performance-reviews/)
- [AI for office managers and admin](https://usingaias.com/ai-for/office-managers/)

## Sources

- [GOV.UK: Written statement of employment particulars](https://www.gov.uk/employment-contracts-and-conditions/written-statement-of-employment-particulars)
- [Acas Code of Practice on disciplinary and grievance procedures](https://www.acas.org.uk/acas-code-of-practice-on-disciplinary-and-grievance-procedures)
- [Acas: What to include in a home or hybrid working policy](https://www.acas.org.uk/policies-for-home-and-hybrid-working/how-to-structure-a-policy)
- [GOV.UK: National Minimum Wage and National Living Wage rates](https://www.gov.uk/national-minimum-wage-rates)
- [GOV.UK: Statutory Sick Pay](https://www.gov.uk/statutory-sick-pay)

## Questions people ask

### Can ChatGPT write an HR policy?

It can draft the structure and plain-English wording from what you already say. The legal requirements come from GOV.UK and Acas, and a named person approves the final version.

### Why not ask the AI what the law says?

It sounds equally confident whether it is right or wrong. It can invent a rule, get a time limit wrong or borrow terms from another country's law, so copy the requirements from the source instead.

### Which disciplinary and grievance rules should a policy follow?

The Acas Code of Practice on disciplinary and grievance procedures is the minimum an employer should follow, and the procedure followed is taken into account at an employment tribunal. Acas is updating the Code, so check the current version.

### Should a policy include statutory rates?

Only if you check them. GOV.UK says National Minimum Wage and National Living Wage rates change on 1 April every year, so check the current GOV.UK page, or point staff to it instead of printing a figure.

### Do I have to tell staff when a policy changes?

GOV.UK says employers must tell staff about any change to their written statement within one month of the change, and the wider written statement includes disciplinary and grievance procedures.
