In 2026, regulators, auditors, insurers, and the Cyber Essentials scheme itself treat the absence of an AI acceptable use policy as a governance failure. Under the Danzell update, any AI service handling business data is in scope as a cloud service. If your team is using ChatGPT, Copilot, Gemini, or any other AI tool, you need to be able to evidence how those tools are managed, who can access them, and what data they can and cannot process. This article gives you a practical framework to build that policy.
The days of treating AI tools as a productivity question rather than a security question are over. The Danzell update, which applies to all Cyber Essentials assessments created from 27 April 2026, makes no distinction between AI tools and any other cloud service. If it stores or processes your organisation’s data, it is in scope. If MFA is not enabled on it, the assessment fails automatically. If your team is using it without IT approval, you have a scope problem you may not know about yet.
Find out what the April 2026 Danzell Update Means for Your Mac Fleet.
Why your AI policy is now a cyber essentials matter
What the Danzell update says about AI tools in scope
The Danzell question set (v3.3) formally defines cloud services for the first time and removes the previous ambiguity that allowed organisations to exclude SaaS platforms from their assessment scope. The definition is straightforward: any cloud service that stores or processes organisational data is in scope. ChatGPT Enterprise, Microsoft 365 Copilot, Google Gemini for Workspace, and Claude for Work all meet that definition the moment an employee uses them to draft, summarise, or process business content. Monday’s article on the Danzell update covers the full scope and patching changes in detail.
What assessors will want to see at renewal
The minimum assessors need to confirm for each in-scope AI tool: that it is known to IT, that MFA is active on every account, and that the organisation can account for it within their Cyber Essentials scope statement. They are not requiring deep technical audits of each tool’s data handling. They are requiring that you have not simply ignored that these services exist. A Red Eagle Tech survey of 200 UK desk workers conducted in February 2026 found that 54.5% of workers said their employer has no clear AI policy, while 63% use AI at work at least weekly, and about a third use tools their employer has not approved. Those numbers describe a significant, common compliance exposure under Danzell.
The shadow AI Audit: find out what your team is already using
How to identify unsanctioned AI tools on a managed Mac fleet
Shadow AI, tools employees are using without IT approval, is now a Cyber Essentials problem rather than just a governance concern. On a Jamf or Addigy-managed fleet, application inventory reporting shows every installed application and, depending on configuration, browser-based tools accessed through managed browsers. This is the starting point. Pull an application inventory report, filter for AI tools and AI-adjacent services, and cross-reference the output against your approved list. On a DMS (formerly MDM)-managed Mac fleet, this process takes less time than most IT leads expect. The harder work is what you do with the results.
What DMS telemetry tells you about application usage
Jamf Pro’s inventory reporting surfaces installed applications with version data, last-used timestamps, and device-level attribution. Addigy provides equivalent reporting through its software management view. Neither platform will show you browser-based AI tools accessed via an unmanaged browser, which is worth noting: a staff member using ChatGPT through a personal Chrome profile on a managed Mac may not appear in application telemetry. Content filtering profiles, configured via DMS, can extend visibility to web-based tool access. The telemetry is a strong first signal, not a complete picture.
How to ask your team without creating anxiety
Shadow AI exists in most businesses because employees found a useful tool and nobody told them it was out of policy, not because they were trying to circumvent IT. An amnesty-style disclosure works significantly better than a punitive discovery process. Frame the ask as: we are building our approved tools list, we need to know what is genuinely useful, and there will be no consequences for disclosure. The goal is accuracy. The goal is not enforcement for its own sake.
What an AI acceptable use policy needs to cover in 2026
The sanctioned tools list: what goes on it and how to maintain it
The sanctioned tools list is the operational core of an AI acceptable use policy. Any tool not on the list is unsanctioned by definition, which means the list needs to be specific rather than categorical. “AI writing tools approved” is not a sanctioned list. “Claude for Work, approved for drafting and summarising; not approved for processing client PII or financial records” is. The list needs a named owner, a review cadence, and a clear process for employees to request additions. A list that is accurate when created but never updated becomes a liability faster than having no list at all.
Data classification: what must never enter an AI prompt
Acceptable use policy for AI tools should specify, not imply, what categories of data must not be entered into AI tools, regardless of which platform is being used. At minimum: client’s personally identifiable information, financial records, HR correspondence, legal advice and privilege-protected communications, and unpublished intellectual property. The framing should be positive where possible: specify what AI tools are for, not just what they are not for. Staff who understand the rationale are more likely to follow the policy than staff who receive a prohibition without context.
Agentic AI and MCP Tools: The Emerging Gap Most Policies Miss
The majority of AI acceptable use policies written in 2024 and early 2025 address prompt-and-response tools. They do not address AI agents that take actions on behalf of users. The distinction matters. As covered in Dr Logic’s reactive piece on Gemini Spark, persistent AI agents can draft and send emails, access files, and connect to third-party platforms via MCP integrations, all without the user being present. Your policy needs to explicitly address this category: which agentic AI tools are sanctioned, what actions they are permitted to take, and what human review is required before agent-initiated communications or decisions are finalised. This is not a future concern. Gemini Spark is live.
What happens when someone breaks the policy
The enforcement framework should be proportionate and progressive. A first violation resulting from a genuine misunderstanding warrants a conversation and a reminder. Repeated violations or bulk data exposure events are a different matter. The policy should state the progression clearly: informal warning, manager escalation, and formal disciplinary action for serious data exposure. The goal is not a punitive framework. The goal is a credible one. A policy with no stated consequences is a policy that signals the organisation does not take it seriously.
How DMS helps you enforce an AI policy on managed devices
What can be enforced at the device level versus what requires process controls
DMS enforcement closes some gaps and leaves others open. Understanding the distinction is essential for building a policy that reflects reality. At the device level, via Jamf or Addigy, IT can block specific applications, restrict access to unsanctioned websites through content filtering profiles, and enforce browser policies that prevent certain classes of tool from running on managed devices. This works well for AI tools distributed as native applications.
Content filtering and application controls via Jamf or Apple Business DMS
Content filtering profiles deployed via DMS can block access to specific domains on managed devices. If your policy prohibits the use of a particular AI tool, IT can enforce that prohibition at the network layer for managed Macs. Jamf Pro’s content filtering integration with third-party DNS services extends this to web-based tools. Application controls prevent unsigned or unapproved applications from running. For AI tools that exist primarily as web services, content filtering is the primary enforcement mechanism.
What DMS cannot do and where the policy has to carry the weight
DMS cannot inspect what an employee types into a permitted AI tool. It cannot see whether staff are accessing browser-based AI tools on personal devices connected to the company network. It cannot prevent an employee from using a personal laptop to access a work system and then feeding the output into an unsanctioned AI tool. These gaps are real and should be stated in the policy itself. Technical enforcement closes the obvious routes. The policy and the culture that surrounds it close the rest. A policy that says no AI tools but does nothing to enforce it is actively worse than no policy, because it creates documented non-compliance while achieving no actual protection.
The Data (Use and Access) Act 2025: what it adds to your obligations
Automated decision-making and what safeguards the act requires
The Data (Use and Access) Act 2025 received Royal Assent in June 2025, with key provisions coming into force in February 2026. For AI tools, the relevant obligation concerns significant decisions made solely or partly through automated processing. Where a significant decision affects an individual and relies on automated processing, the organisation must have documented safeguards in place: providing the individual with information about the decision, enabling them to make representations about it, and enabling human intervention and the right to contest the outcome.
What this means for AI tools used in HR, recruitment, or client-facing decisions
For Dr Logic’s typical client audience, the main exposure sits in two areas. First, recruitment and performance management: if an AI tool is used to screen applications, score performance, or contribute to decisions about an individual’s employment, the Act’s safeguards apply. Second, client-facing decisions: if AI tools are used to generate client assessments, risk ratings, or recommendations that a client acts upon, documented human oversight and an explicit review process are required. The practical approach is straightforward: document which decisions involve AI processing, name the person responsible for human review, and record what the human review step looked like before the decision was communicated. That documentation is what the Act requires, and it is also what a sensible IT policy should require independently of any legal obligation.
If you need help identifying which AI tools are in scope for your Cyber Essentials renewal and building a policy that satisfies the Danzell requirements, Dr Logic can advise.
Related articles
- Cyber Essentials Has Changed. Here’s What the April 2026 Danzell Update Means for Your Mac Fleet.
- Your Staff Now Have AI Agents Running in Their Google Accounts Around the Clock
- What Cyber Essentials Certification Actually Looks Like for an All-Mac Office
FAQs
Do AI tools count as cloud services under Cyber Essentials, Danzell?
Yes. Under Danzell (v3.3, in force from 27 April 2026), any cloud service that stores or processes organisational data is in scope for Cyber Essentials. AI tools, including Microsoft Copilot, Google Gemini, and ChatGPT Enterprise, meet this definition whenever they are used to process business content. MFA must be enabled on all such tools, or the assessment fails automatically.
What should an AI acceptable use policy cover to satisfy Danzell?
At minimum: a specific list of sanctioned AI tools with permitted and prohibited uses, a data classification section identifying what must never enter an AI prompt, and confirmation that MFA is active on every sanctioned tool. The policy should also address agentic AI tools that take actions on behalf of users, which are not covered by most policies written before 2025.
What is shadow AI, and why does it matter for Cyber Essentials?
Shadow AI refers to AI tools employees are using without IT approval. Under Danzell, these tools are in scope for Cyber Essentials the moment organisational data passes through them, regardless of whether IT knows about them. On a managed Mac fleet, DMS application inventory and content filtering reports are the starting point for identifying shadow AI in use. An IT-led audit before assessment, rather than after, is the recommended approach.



















































