
March 2, 2026
Hacker Hub - March 2026
Think hackers wear hoodies? Think again. Explore 7 surprising facts about hacker history, viruses, social engineering and cybersecurity culture.
Read MoreIt’s a question I’m hearing moreand more. And on the face of it, the answer is pretty straightforward:
No.
Nowhere in ISO/IEC 27001 does it say “thou shalt have an AI policy.”
So, if that’s the question you’re asking, congratulations, you already have your answer.
But that’s where things get interesting.
Because if that is the question, I’d argue you’re probably asking the wrong one.
Now That, Detective, Is the Right Question
There’s a moment in "I, Robot" where Will Smith’s character realises he’s been focusing on the wrong detail. The rules weren’t broken, the interpretation of them was.
That’s exactly what’s happeningwith AI and ISO 27001. ISO 27001 is deliberately technology agnostic. It doesn’t care whether you’re using:
What it does care about is this:
Do you understand the risks toyour information assets, and are you managing them appropriately?
So maybe the better question isn’t “Do I need an AI policy?”
Maybe the right question is:
“Do I need to assess the impact to my information assets if we use AI within the business?”
"Now that, detective, is the right question."
ISO 27001 Has Always Been About Risk, Not Artefacts
One of the most common traps with ISO 27001 is treating it as a document collection exercise.
Policies, Procedures, Registers,Templates. They’re important, but they’re not the point.
ISO 27001 requires you to:
If AI is being used in yourorganisation, whether that’s
then AI isn’t “a future consideration”, It’s already in scope. And once it’s in scope, the standard is very clear, you assess the risk.
After a proper risk assessment, you might conclude that:
At that point, an AI policy mightbe a sensible control.
But notice the order, Risk first, Controls second, Documents last
If you start with “we need an AI policy because auditors will ask for it”, you’ve already missed the spirit of the standard. Auditors don’t certify documents; they certify systems of management. The real risk isn’t failing an audit because you don’t have an AI policy.
The real risk is:
That’s the sort of thing auditors do care about, because it shows the ISMS isn’t keeping up with how the business actually operates.
So… Do You Need One?
If you’re asking:
“Do we need an AI policy for ISO27001?”
The answer is still no.
But if you’re asking:
“Do we understand how AI affects our information risks, and have we addressed that within our ISMS?”
That question might lead you to a policy, or it might lead you to training, technical controls, supplier assurances, or usage restrictions instead.
And that’s exactly how ISO 27001 is supposed to work.

March 2, 2026
Think hackers wear hoodies? Think again. Explore 7 surprising facts about hacker history, viruses, social engineering and cybersecurity culture.
Read More
March 23, 2026
How much does ISO 27001 certification cost in the UK? Realaudit and consultancy pricing from £3,315 + UKAS fees. Use our cost calculator.
Read More
February 25, 2026
ISO 27001 explained clearly. Learn certification requirements, ISMS setup, costs and how UK software businesses implement it properly.
Read More