United Kingdom - Generative AI Use Guidelines
Guidance to civil servants on use of generative AI
United Kingdom
RAI-GB-NA-GCSUGXX-2023Issued by the Cabinet Office, Government Digital Service and Central Digital & Data Office on 29 June 2023 (last updated 29 January 2024), this guidance sets out general principles for civil servants on safe, lawful and responsible use of generative AI (including LLMs). It emphasises avoiding input of classified or sensitive personal data, maintaining human oversight, validating outputs, and following data protection and security obligations.
Summary
The UK Cabinet Office guidance 'Guidance to civil servants on use of generative AI' (published 29 June 2023, updated 29 January 2024) provides practical and principle-based direction to civil servants across central government on the appropriate use of generative artificial intelligence, including Large Language Models (LLMs) and multimodal generative systems. The policy encourages curiosity about generative AI and responsible experimentation while stressing the importance of risk awareness and protection of sensitive information. It explains the technology's basic mechanics (probabilistic text generation), its limitations (susceptibility to hallucination, bias, and lack of domain expertise), and the three 'Hows' civil servants must consider when using these tools: how input data will be used by the model, how generated answers can mislead, and how the systems operate.
The guidance lists appropriate and inappropriate use-cases, notably permitting research, summarisation of public material, and specialist expert-led analysis on government-controlled infrastructure, while prohibiting entry of classified or non-public government intent, personal data or other sensitive information into public LLM services. Practical requirements include citing AI-generated outputs, using gov.uk accounts when appropriate, seeking legal, security and data-protection advice before deploying models for operational tasks, and performing Data Protection Impact Assessments (DPIAs) for projects that process personal data. It also instructs teams to prefer controlled, private or on-premise model deployment for sensitive use-cases, to maintain human-in-the-loop decision-making for high-impact situations, and to log and audit AI use.
Although the guidance itself does not create new statutory powers, it interfaces with existing legal frameworks — notably the Data Protection Act 2018 / UK GDPR, the Civil Service Code, and security guidance from the National Cyber Security Centre (NCSC). The document was followed and expanded by subsequent government instruments such as the Generative AI Framework for HMG (January 2024) and the AI Playbook (2025), which provide lifecycle and procurement guidance. The guidance sets expectations for departmental governance, directing civil servants to consult the Central Digital & Data Office (CDDO) and other cross-government forums and emphasising that misuse may lead to disciplinary action and regulatory enforcement (including ICO action) where data protection or security rules are breached.
Full article
Read full text ↗Overview
The "Guidance to civil servants on use of generative AI" (Cabinet Office, Government Digital Service, Central Digital & Data Office) is a concise, principle-led document published on 29 June 2023 and updated on 29 January 2024. It provides cross-government general principles for using generative artificial intelligence (AI) systems, including Large Language Models (LLMs) such as ChatGPT and Bard, and multimodal models for images or code. The guidance aims to balance curiosity and innovation with caution and duty of care: civil servants are encouraged to explore the potential benefits of generative AI for research, summarisation and productivity gains while avoiding the disclosure of classified, sensitive or personal data to public tools. The page links into further HMG materials including the wider Generative AI Framework for HMG and later AI playbooks that expand lifecycle, procurement and operational controls.
Definitions
"Generative AI" is defined as AI that can create new text, imagery, audio, or code. "Large Language Models (LLMs)" are noted as a common subset that generate text via probabilistic selection of tokens. The guidance clarifies terms used throughout: "publicly available tools" (e.g., ChatGPT, Bard), "private/managed instances" (commercial models hosted within a government-managed tenancy), "on-premise/open-source models" (self-hosted alternatives), "sensitive information" (classified material, non-public policy intent, and personal data), and "human-in-the-loop" (meaningful human oversight and decision-making at critical stages). These operational definitions are intended to help non-technical civil servants make consistent risk-based choices.
Governance and Institutional Framework
The guidance places responsibility on individual civil servants and departmental governance structures, and points to central enablers: Cabinet Office, Government Digital Service (GDS) and the Central Digital & Data Office (CDDO). Departments are instructed to maintain local policies aligned to central guidance and to consult expert functions (legal, security, data protection) for higher-risk deployments. For lifecycle governance it references the need to integrate procurement, security (NCSC guidance), legal reviews and Data Protection Impact Assessments (DPIAs) into project gates. The document advises use of departmental registers and logging to ensure accountability, and encourages use of private or managed model instances rather than public offerings when handling controlled information. Relevant cross-government forums and working groups led by the CDDO and DSIT are signposted for sharing learning and escalating issues.
Key Focus Areas
The guidance highlights several risk domains and operational controls. Data protection and privacy: civil servants must not input personal data or classified information into public generative AI services and should follow UK GDPR and Data Protection Act obligations; DPIAs and data minimisation are emphasised. Security: choose secure deployment options (private tenancy, cloud-managed private instances or on-premise hosting) and apply NCSC cloud security principles. Safety, trust and quality: outputs can contain hallucinations, bias and misinformation — all AI-generated content should be validated, referenced and not relied upon as sole evidence for policy or decision-making. Human oversight: generative AI should not be used for fully automated decisions in high-impact scenarios; meaningful human control is required. Transparency: where outputs are used, they should be cited, including URL and tool name; the guidance suggests footnotes and provenance tracking. Procurement and supplier assurance: teams must understand model provenance and training data limitations and prefer contractual commitments on data usage, retention and security from vendors. Operational use-cases: appropriate use includes research, summarisation of public materials, and specialist workflows on secure infrastructure; inappropriate uses include drafting non-public policy positions, inputting third-party personal data without consent, and using public LLMs for sensitive analytics.
Implementation Framework
The guidance sets out pragmatic steps for departments and individuals to implement safe generative AI usage. Start with a risk assessment to determine public vs private use, conduct DPIAs where personal data is involved, consult legal and security teams, and document decision rationale. For development or deployment, adopt a lifecycle approach: design (use-case and data minimisation), procurement (contractual safeguards and supplier due diligence), build/test (bias and robustness testing), deploy (access controls, logging, retention policies) and decommission (secure deletion and asset retirement). The paper recommends cataloguing AI tools, providing training for staff, and establishing reporting lines for incidents. It also encourages departments to favour managed instances or internal deployments for sensitive projects and to follow the NCSC and Technology Code of Practice for secure cloud and coding practices. For technical teams, it stresses code review and supply-chain awareness when incorporating LLM-generated code.
Monitoring and Evaluation
Monitoring arrangements should include usage logs, audit trails, periodic review of model outputs for drift and bias, and mechanisms for reporting harms or errors. Departments are advised to establish metrics for safety and effectiveness, run ongoing validation against trusted sources, and schedule regular reassessments of vendor commitments and data handling. The guidance anticipates rapid change in the technology and requires six-month reviews of practice and policy evolution; it also points to central repositories and forums to share lessons. For higher-risk projects, continuous post-deployment monitoring and independent assurance (e.g., third-party audits, red-team testing) are recommended to detect emergent vulnerabilities and to demonstrate accountability.
Penalties, Liability, and Appeals
The guidance itself does not create new criminal penalties but sets behavioural expectations and interfaces with existing disciplinary and regulatory regimes. Misuse of generative AI that results in data protection breaches may lead to enforcement action by the Information Commissioner’s Office (ICO) under the Data Protection Act 2018 and UK GDPR (including fines and orders). Internal consequences include Civil Service disciplinary action under the Civil Service Code and departmental HR policies. Where outputs cause third-party harm, civil liabilities may arise under general tort and contractual law; the guidance requires teams to seek legal advice for redress and indemnity arrangements in vendor contracts. The document also directs civil servants to established internal appeal and grievance mechanisms where disciplinary outcomes are contested.
Relationship to Other Instruments
The June 2023 guidance is positioned as an early, cross-government practical note that complements and is superseded in part by more detailed frameworks published subsequently, notably the Generative AI Framework for HMG (Jan 2024) and later the AI Playbook and departmental AI policies. It operates alongside statutory regimes (Data Protection Act 2018/UK GDPR), the Civil Service Code, NCSC security guidance, and procurement rules managed by the Crown Commercial Service. Departments should interpret the guidance in light of these instruments and integrate them into internal governance, procurement and assurance processes.
International Alignment
The guidance reflects UK policy aims to be pro-innovation while managing risk, aligning conceptually with international approaches that stress human oversight, transparency, data protection and safety (for example, OECD AI principles and emerging EU AI Act concepts). It references the need to follow best practice in accountability and vendor assurance consistent with international norms and to take into account multinational supplier commitments where models are hosted outside the UK. Civil servants deploying models used cross-border must consider data transfer rules and international law enforcement requests and coordinate with legal and security advisers for compliance.
Implementation Timeline
| Milestone | Date |
|---|---|
| Guidance published | 2023-06-29 |
| Added Central Digital & Data Office link / update | 2023-09-29 |
| Linked to Generative AI Framework for HMG | 2024-01-29 |
| Generative AI Framework for HMG published | 2024-01-18 |
Sources and References
| Source | Type |
|---|---|
| Guidance to civil servants on use of generative AI | Primary Source |
| Generative AI Framework for HMG | Primary Source |
| Information Commissioner’s Office (ICO) — AI and data protection guidance | Primary Source |
Requirements for a company
What an organisation has to do under United Kingdom - Generative AI Use Guidelines, at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Must do
14- Do not input classified, sensitive, or personal data into public generative AI tools.Civil servants using generative AI tools.
- Follow UK GDPR and Data Protection Act obligations when using generative AI.Civil servants using generative AI systems.
- Conduct Data Protection Impact Assessments (DPIAs) for projects involving personal data.Departments and civil servants.
- Ensure meaningful human oversight and control for all generative AI decisions.Civil servants using generative AI.
- Validate and reference all AI-generated content, not relying on it as sole evidence.Civil servants using generative AI.
- Obtain legal, security, and procurement clearance for high-risk generative AI deployments.Departments deploying generative AI.
- +8 more in the table below
Must not do
0Nothing in this category.
Should do
0Nothing in this category.
Should not do
0Nothing in this category.
Who must do what
The obligations under United Kingdom - Generative AI Use Guidelines, most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | Civil servants using generative AI tools. | Do not input classified, sensitive, or personal data into public generative AI tools. “civil servants must not input personal data or classified information into public generative AI services” | — | Key Focus Areas | Critical |
| 2 | Civil servants using generative AI systems. | Follow UK GDPR and Data Protection Act obligations when using generative AI. “should follow UK GDPR and Data Protection Act obligations; DPIAs and data minimisation are emphasised.” | — | Key Focus Areas | Critical |
| 3 | Departments and civil servants. | Conduct Data Protection Impact Assessments (DPIAs) for projects involving personal data. “integrate procurement, security... legal reviews and Data Protection Impact Assessments (DPIAs) into project gates.” | Before processing personal data | Governance and Institutional Framework | Critical |
| 4 | Civil servants using generative AI. | Ensure meaningful human oversight and control for all generative AI decisions. “meaningful human control is required.” | — | Key Focus Areas | Important |
| 5 | Civil servants using generative AI. | Validate and reference all AI-generated content, not relying on it as sole evidence. “all AI-generated content should be validated, referenced and not relied upon as sole evidence” | — | Key Focus Areas | Important |
| 6 | Departments deploying generative AI. | Obtain legal, security, and procurement clearance for high-risk generative AI deployments. “consult expert functions (legal, security, data protection) for higher-risk deployments.” | Before deployment | Governance and Institutional Framework | Important |
| 7 | Departments and technical teams. | Choose secure deployment options and apply NCSC cloud security principles. “choose secure deployment options... and apply NCSC cloud security principles.” | Before deployment | Key Focus Areas | Important |
| 8 | Departments. | Maintain local departmental policies aligned with central generative AI guidance. “Departments are instructed to maintain local policies aligned to central guidance” | — | Governance and Institutional Framework | Important |
| 9 | Civil servants using generative AI. | Cite AI-generated outputs, including the URL and tool name, where used. “where outputs are used, they should be cited, including URL and tool name” | — | Key Focus Areas | Important |
| 10 | Departments and civil servants. | Conduct a risk assessment to determine appropriate public versus private generative AI use. “Start with a risk assessment to determine public vs private use” | Before using generative AI | Implementation Framework | Important |
| 11 | Departments and civil servants. | Document decision rationale for generative AI deployments and usage. “document decision rationale.” | — | Implementation Framework | Important |
| 12 | Departments developing or deploying generative AI. | Implement a lifecycle approach for generative AI, from design to decommissioning. | — | Implementation Framework | Important |
| 13 | Departments. | Review generative AI practices and policies every six months. “requires six-month reviews of practice and policy evolution” | Every 6 months | Monitoring and Evaluation | Important |
| 14 | Teams procuring generative AI. | Seek legal advice for redress and indemnity arrangements in vendor contracts. “the guidance requires teams to seek legal advice for redress and indemnity arrangements in vendor contracts.” | Before contract signing | Penalties, Liability, and Appeals | Important |
Related Regulations
Generative AI Framework for HMG
United Kingdom95% similar
Artificial Intelligence Playbook for the UK Government
United Kingdom94% similar
Responsible AI Guidance for the Public Service: GenAI
New Zealand93% similar
Fact sheet on the use of generative AI tools in the Federal Administration
Switzerland92% similar
Generative AI Guidelines for Government (SDAIA)
Saudi Arabia92% similar
© Regulations.AI · updated on 13-Jun-2026