AI Use Policy – Subcontractors
For subcontractors engaged by Kirsty Holden of Holden Operations Limited (“the Business”). This is a contractual document, not an employment policy – it sets out the terms on which AI tools may be used in connection with work carried out for the Business.
1. Policy Statement
The Business uses generative AI in parts of its own work and supports subcontractors doing the same, where it genuinely improves the quality or efficiency of work delivered. AI use also carries real risk – to client confidentiality, data protection compliance, copyright, and the accuracy of what’s produced. This policy sets out what’s expected when you use AI tools on work for the Business.
2. Who This Applies To
This applies to you as a subcontractor engaged by the Business, for any work carried out under your contract with the Business — whether paid per project, retainer, or otherwise. It forms part of the terms on which you are engaged and a breach of it may be treated as a breach of contract (see Section 9).
3. What Counts as Generative AI
Generative AI means tools such as ChatGPT, Claude, Gemini, or similar, that generate new text, images, or other content in response to a prompt, rather than retrieving existing information. This policy covers any use of these tools in connection with work for the Business.
4. Acceptable Use
You may use generative AI tools for work carried out for the Business for tasks such as:
- brainstorming ideas;
- basic research (which you then verify independently — see Section 8);
- drafting marketing or content material;
- transcription or dictation, using only the tools agreed with you in writing;
- proofreading and editing.
Any other use of AI on work for the Business should be agreed with Kirsty Holden of Holden Operations Limited in writing first.
5. Prohibited Use
You must not use generative AI to:
- produce anything with legal or financial consequences for the Business (contracts, formal correspondence, terms and conditions, etc.) without this being separately reviewed and approved;
- create or edit any material that includes a real, identifiable client’s name, contact details, business name, or specific circumstances — see Section 6;
- input any of the Business’s confidential information — client lists, pricing, unreleased offers, internal strategy, or anything you’d reasonably understand to be confidential;
- generate content that is then presented as entirely human-written where this would be misleading to a client or third party (see Section 7 on transparency).
6. Client Data and Confidentiality
This is the section that matters most, so it’s worth being specific rather than general.
- Never input identifiable client information into any AI tool. This includes names, but also anything that could identify someone even without a name attached — their specific business, role, sector combined with location, exact circumstances, or distinctive quotes. Removing a name alone is often not enough; the rest of the detail can still point to one identifiable person.
- Pseudonymised is not the same as anonymised. Swapping a name for “Client A”, while everything else about the situation stays the same, still counts as personal data under UK GDPR if the person could be identified by anyone, including you, from what’s left. Treat this as the standard to meet, not name-removal alone.
- If in doubt, leave it out. If you’re not sure whether something could identify a real client, don’t put it into an AI tool — check with Kirsty Holden of Holden Operations Limited first.
- Special category data: given the nature of the Business’s work, some client information relates to health conditions (e.g. ADHD, Autism). This is “special category data” under UK GDPR and carries a higher bar of protection than ordinary personal data — it should never be put into an AI tool in identifiable or pseudonymised form.
7. Transparency
If you produce content using generative AI that will be published, sent to a client, or used externally on behalf of the Business, let Kirsty Holden of Holden Operations Limited know that AI was used and what it was used for (e.g. “first draft only, fully rewritten” vs “used for research, content is my own”). This isn’t about banning AI-assisted work — it’s so the Business can stand behind what it puts out and explain its use of AI if ever asked to.
8. Accuracy and Verification
AI tools can produce fluent, confident, and completely incorrect information — this isn’t a rare glitch, it’s how the technology works. Before anything generated by AI is used in work for the Business:
- treat it as a first draft, never as finished work;
- independently verify any fact, figure, statistic, or claim before it’s used;
- don’t rely on AI for anything requiring professional or ethical judgement — that responsibility stays with you and with the Business, not the tool.
9. Your Responsibility for AI-Assisted Work
Using an AI tool does not transfer responsibility for the work you deliver. If you use AI to draft, research, or produce something for the Business, you remain accountable for its accuracy and quality — in exactly the same way as if you’d written or researched it entirely yourself.
- If an error, inaccuracy, or inappropriate content reaches the Business or a client because it wasn’t checked, the responsibility sits with you as the person who produced and delivered the work — not with the AI tool used to help produce it.
- “The AI got it wrong” is not an acceptable explanation for work that hasn’t been properly checked. The expectation is that you’ve verified anything that needed verifying before it was handed over (see Section 8).
- This applies however the AI was used — a full first draft, a research summary, a proofread, or anything in between.
10. AI Tool Account Type
Different AI tool subscriptions handle data differently, and this matters for anything connected to work for the Business:
- Consumer/personal accounts (e.g. a personal ChatGPT or Claude subscription) may use conversations to improve the AI model unless this is specifically turned off in the account’s privacy settings, and may retain data for an extended period as a result. These do not carry the same contractual data protections as business-tier accounts.
- If you use a personal AI account for work on the Business: check that data-training/model-improvement settings are switched off, and never input anything covered by Section 6 regardless of the setting.
- Where Kirsty provides or specifies a particular AI tool or account for a piece of work, that tool should be used instead of a personal account.
11. Copyright
AI-generated output can unintentionally reproduce copyrighted material. Don’t copy substantial passages of AI output directly into final work without review, and flag anything that looks like it might be drawn closely from an existing copyrighted source.
12. If You’re Not Sure
If you’re unsure whether a particular use of AI is appropriate for a piece of work, ask before doing it rather than after. This is a normal, expected question — not a sign you’ve done something wrong.
13. Breach of This Policy
As this policy forms part of the terms of your engagement with the Business, a breach of it (in particular Section 6 on client data, and Section 9 on accountability for AI-assisted work) may be treated as a breach of contract and could affect your ongoing engagement, separate from any wider legal obligations that may arise from a data protection breach.
14. Review
This policy may be updated from time to time, particularly as AI tools and data protection guidance evolve. The current version will be shared with you directly.