United Kingdom - Generative AI Use Guidelines

Guidance to civil servants on use of generative AI

United Kingdom

RAI-GB-NA-GCSUGXX-2023
Effective: June 29, 2023
In Force(In Force)
GuidelineGovernance and OversightData Protection and PrivacyAccountability and Documentation
Export PDF

Issued by the Cabinet Office, Government Digital Service and Central Digital & Data Office on 29 June 2023 (last updated 29 January 2024), this guidance sets out general principles for civil servants on safe, lawful and responsible use of generative AI (including LLMs). It emphasises avoiding input of classified or sensitive personal data, maintaining human oversight, validating outputs, and following data protection and security obligations.

Summary

The UK Cabinet Office guidance 'Guidance to civil servants on use of generative AI' (published 29 June 2023, updated 29 January 2024) provides practical and principle-based direction to civil servants across central government on the appropriate use of generative artificial intelligence, including Large Language Models (LLMs) and multimodal generative systems. The policy encourages curiosity about generative AI and responsible experimentation while stressing the importance of risk awareness and protection of sensitive information. It explains the technology's basic mechanics (probabilistic text generation), its limitations (susceptibility to hallucination, bias, and lack of domain expertise), and the three 'Hows' civil servants must consider when using these tools: how input data will be used by the model, how generated answers can mislead, and how the systems operate.

The guidance lists appropriate and inappropriate use-cases, notably permitting research, summarisation of public material, and specialist expert-led analysis on government-controlled infrastructure, while prohibiting entry of classified or non-public government intent, personal data or other sensitive information into public LLM services. Practical requirements include citing AI-generated outputs, using gov.uk accounts when appropriate, seeking legal, security and data-protection advice before deploying models for operational tasks, and performing Data Protection Impact Assessments (DPIAs) for projects that process personal data. It also instructs teams to prefer controlled, private or on-premise model deployment for sensitive use-cases, to maintain human-in-the-loop decision-making for high-impact situations, and to log and audit AI use.

Although the guidance itself does not create new statutory powers, it interfaces with existing legal frameworks — notably the Data Protection Act 2018 / UK GDPR, the Civil Service Code, and security guidance from the National Cyber Security Centre (NCSC). The document was followed and expanded by subsequent government instruments such as the Generative AI Framework for HMG (January 2024) and the AI Playbook (2025), which provide lifecycle and procurement guidance. The guidance sets expectations for departmental governance, directing civil servants to consult the Central Digital & Data Office (CDDO) and other cross-government forums and emphasising that misuse may lead to disciplinary action and regulatory enforcement (including ICO action) where data protection or security rules are breached.

Full article

Read full text ↗

Overview

The "Guidance to civil servants on use of generative AI" (Cabinet Office, Government Digital Service, Central Digital & Data Office) is a concise, principle-led document published on 29 June 2023 and updated on 29 January 2024. It provides cross-government general principles for using generative artificial intelligence (AI) systems, including Large Language Models (LLMs) such as ChatGPT and Bard, and multimodal models for images or code. The guidance aims to balance curiosity and innovation with caution and duty of care: civil servants are encouraged to explore the potential benefits of generative AI for research, summarisation and productivity gains while avoiding the disclosure of classified, sensitive or personal data to public tools. The page links into further HMG materials including the wider Generative AI Framework for HMG and later AI playbooks that expand lifecycle, procurement and operational controls.

Definitions

"Generative AI" is defined as AI that can create new text, imagery, audio, or code. "Large Language Models (LLMs)" are noted as a common subset that generate text via probabilistic selection of tokens. The guidance clarifies terms used throughout: "publicly available tools" (e.g., ChatGPT, Bard), "private/managed instances" (commercial models hosted within a government-managed tenancy), "on-premise/open-source models" (self-hosted alternatives), "sensitive information" (classified material, non-public policy intent, and personal data), and "human-in-the-loop" (meaningful human oversight and decision-making at critical stages). These operational definitions are intended to help non-technical civil servants make consistent risk-based choices.

Governance and Institutional Framework

The guidance places responsibility on individual civil servants and departmental governance structures, and points to central enablers: Cabinet Office, Government Digital Service (GDS) and the Central Digital & Data Office (CDDO). Departments are instructed to maintain local policies aligned to central guidance and to consult expert functions (legal, security, data protection) for higher-risk deployments. For lifecycle governance it references the need to integrate procurement, security (NCSC guidance), legal reviews and Data Protection Impact Assessments (DPIAs) into project gates. The document advises use of departmental registers and logging to ensure accountability, and encourages use of private or managed model instances rather than public offerings when handling controlled information. Relevant cross-government forums and working groups led by the CDDO and DSIT are signposted for sharing learning and escalating issues.

Key Focus Areas

The guidance highlights several risk domains and operational controls. Data protection and privacy: civil servants must not input personal data or classified information into public generative AI services and should follow UK GDPR and Data Protection Act obligations; DPIAs and data minimisation are emphasised. Security: choose secure deployment options (private tenancy, cloud-managed private instances or on-premise hosting) and apply NCSC cloud security principles. Safety, trust and quality: outputs can contain hallucinations, bias and misinformation — all AI-generated content should be validated, referenced and not relied upon as sole evidence for policy or decision-making. Human oversight: generative AI should not be used for fully automated decisions in high-impact scenarios; meaningful human control is required. Transparency: where outputs are used, they should be cited, including URL and tool name; the guidance suggests footnotes and provenance tracking. Procurement and supplier assurance: teams must understand model provenance and training data limitations and prefer contractual commitments on data usage, retention and security from vendors. Operational use-cases: appropriate use includes research, summarisation of public materials, and specialist workflows on secure infrastructure; inappropriate uses include drafting non-public policy positions, inputting third-party personal data without consent, and using public LLMs for sensitive analytics.

Implementation Framework

The guidance sets out pragmatic steps for departments and individuals to implement safe generative AI usage. Start with a risk assessment to determine public vs private use, conduct DPIAs where personal data is involved, consult legal and security teams, and document decision rationale. For development or deployment, adopt a lifecycle approach: design (use-case and data minimisation), procurement (contractual safeguards and supplier due diligence), build/test (bias and robustness testing), deploy (access controls, logging, retention policies) and decommission (secure deletion and asset retirement). The paper recommends cataloguing AI tools, providing training for staff, and establishing reporting lines for incidents. It also encourages departments to favour managed instances or internal deployments for sensitive projects and to follow the NCSC and Technology Code of Practice for secure cloud and coding practices. For technical teams, it stresses code review and supply-chain awareness when incorporating LLM-generated code.

Monitoring and Evaluation

Monitoring arrangements should include usage logs, audit trails, periodic review of model outputs for drift and bias, and mechanisms for reporting harms or errors. Departments are advised to establish metrics for safety and effectiveness, run ongoing validation against trusted sources, and schedule regular reassessments of vendor commitments and data handling. The guidance anticipates rapid change in the technology and requires six-month reviews of practice and policy evolution; it also points to central repositories and forums to share lessons. For higher-risk projects, continuous post-deployment monitoring and independent assurance (e.g., third-party audits, red-team testing) are recommended to detect emergent vulnerabilities and to demonstrate accountability.

Penalties, Liability, and Appeals

The guidance itself does not create new criminal penalties but sets behavioural expectations and interfaces with existing disciplinary and regulatory regimes. Misuse of generative AI that results in data protection breaches may lead to enforcement action by the Information Commissioner’s Office (ICO) under the Data Protection Act 2018 and UK GDPR (including fines and orders). Internal consequences include Civil Service disciplinary action under the Civil Service Code and departmental HR policies. Where outputs cause third-party harm, civil liabilities may arise under general tort and contractual law; the guidance requires teams to seek legal advice for redress and indemnity arrangements in vendor contracts. The document also directs civil servants to established internal appeal and grievance mechanisms where disciplinary outcomes are contested.

Relationship to Other Instruments

The June 2023 guidance is positioned as an early, cross-government practical note that complements and is superseded in part by more detailed frameworks published subsequently, notably the Generative AI Framework for HMG (Jan 2024) and later the AI Playbook and departmental AI policies. It operates alongside statutory regimes (Data Protection Act 2018/UK GDPR), the Civil Service Code, NCSC security guidance, and procurement rules managed by the Crown Commercial Service. Departments should interpret the guidance in light of these instruments and integrate them into internal governance, procurement and assurance processes.

International Alignment

The guidance reflects UK policy aims to be pro-innovation while managing risk, aligning conceptually with international approaches that stress human oversight, transparency, data protection and safety (for example, OECD AI principles and emerging EU AI Act concepts). It references the need to follow best practice in accountability and vendor assurance consistent with international norms and to take into account multinational supplier commitments where models are hosted outside the UK. Civil servants deploying models used cross-border must consider data transfer rules and international law enforcement requests and coordinate with legal and security advisers for compliance.

Implementation Timeline

MilestoneDate
Guidance published2023-06-29
Added Central Digital & Data Office link / update2023-09-29
Linked to Generative AI Framework for HMG2024-01-29
Generative AI Framework for HMG published2024-01-18

Sources and References

SourceType
Guidance to civil servants on use of generative AIPrimary Source
Generative AI Framework for HMGPrimary Source
Information Commissioner’s Office (ICO) — AI and data protection guidancePrimary Source

Requirements for a company

What an organisation has to do under United Kingdom - Generative AI Use Guidelines, at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Must do

14
  • Do not input classified, sensitive, or personal data into public generative AI tools.Civil servants using generative AI tools.
  • Follow UK GDPR and Data Protection Act obligations when using generative AI.Civil servants using generative AI systems.
  • Conduct Data Protection Impact Assessments (DPIAs) for projects involving personal data.Departments and civil servants.
  • Ensure meaningful human oversight and control for all generative AI decisions.Civil servants using generative AI.
  • Validate and reference all AI-generated content, not relying on it as sole evidence.Civil servants using generative AI.
  • Obtain legal, security, and procurement clearance for high-risk generative AI deployments.Departments deploying generative AI.
  • +8 more in the table below

Must not do

0

Nothing in this category.

Should do

0

Nothing in this category.

Should not do

0

Nothing in this category.

Who must do what

The obligations under United Kingdom - Generative AI Use Guidelines, most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Civil servants using generative AI tools.Do not input classified, sensitive, or personal data into public generative AI tools.
civil servants must not input personal data or classified information into public generative AI services
Key Focus AreasCritical
2Civil servants using generative AI systems.Follow UK GDPR and Data Protection Act obligations when using generative AI.
should follow UK GDPR and Data Protection Act obligations; DPIAs and data minimisation are emphasised.
Key Focus AreasCritical
3Departments and civil servants.Conduct Data Protection Impact Assessments (DPIAs) for projects involving personal data.
integrate procurement, security... legal reviews and Data Protection Impact Assessments (DPIAs) into project gates.
Before processing personal dataGovernance and Institutional FrameworkCritical
4Civil servants using generative AI.Ensure meaningful human oversight and control for all generative AI decisions.
meaningful human control is required.
Key Focus AreasImportant
5Civil servants using generative AI.Validate and reference all AI-generated content, not relying on it as sole evidence.
all AI-generated content should be validated, referenced and not relied upon as sole evidence
Key Focus AreasImportant
6Departments deploying generative AI.Obtain legal, security, and procurement clearance for high-risk generative AI deployments.
consult expert functions (legal, security, data protection) for higher-risk deployments.
Before deploymentGovernance and Institutional FrameworkImportant
7Departments and technical teams.Choose secure deployment options and apply NCSC cloud security principles.
choose secure deployment options... and apply NCSC cloud security principles.
Before deploymentKey Focus AreasImportant
8Departments.Maintain local departmental policies aligned with central generative AI guidance.
Departments are instructed to maintain local policies aligned to central guidance
Governance and Institutional FrameworkImportant
9Civil servants using generative AI.Cite AI-generated outputs, including the URL and tool name, where used.
where outputs are used, they should be cited, including URL and tool name
Key Focus AreasImportant
10Departments and civil servants.Conduct a risk assessment to determine appropriate public versus private generative AI use.
Start with a risk assessment to determine public vs private use
Before using generative AIImplementation FrameworkImportant
11Departments and civil servants.Document decision rationale for generative AI deployments and usage.
document decision rationale.
Implementation FrameworkImportant
12Departments developing or deploying generative AI.Implement a lifecycle approach for generative AI, from design to decommissioning.Implementation FrameworkImportant
13Departments.Review generative AI practices and policies every six months.
requires six-month reviews of practice and policy evolution
Every 6 monthsMonitoring and EvaluationImportant
14Teams procuring generative AI.Seek legal advice for redress and indemnity arrangements in vendor contracts.
the guidance requires teams to seek legal advice for redress and indemnity arrangements in vendor contracts.
Before contract signingPenalties, Liability, and AppealsImportant

© Regulations.AI · updated on 13-Jun-2026