Using generative AI at Chelsea

The standards every colleague must follow when using AI tools and handling Club data. Applies whether a tool is approved, embedded in another app, or accessed through a website.

Always

Log in with your Club email, and review every output before you use or forward it.

Never

Personal accounts, unapproved tools, Club IP, credentials or others' personal data.

Ask first

techsupport@chelseafc.com for a new tool; Legal for personal data or a contract.

01About this policy

This Generative AI Policy sets out the standards all staff must follow when using AI tools, handling Club data, and operating on Chelsea-owned or authorised devices and systems. The Club recognises the rapid development of AI and the benefits it can bring when used responsibly and securely, and is currently reviewing enterprise-grade tools that may be made available for approved use.

This policy applies at all times — regardless of whether a tool is formally approved, embedded within another application, or accessed through a website. Improper use can compromise data and expose the Club to regulatory or legal consequences.

02Who it applies to

The policy applies to all colleagues of the Club and our affiliated charity, The Chelsea Foundation, across every business area and location — Cobham Training Ground, Stamford Bridge, Kingsmeadow and any satellite training or development centres.

  • Permanent and casual employees, contractors, interns and volunteers.
  • Any third party who accesses, processes or interacts with Club data through an AI tool.
  • All Club-owned or authorised devices, accounts and networks.

03Roles and responsibilities

The Director of Technology, supported by Legal, Information Security and Technology, reviews and distributes this policy at least once every two years and ensures it remains compliant with legal, regulatory and contractual obligations including GDPR. All colleagues are responsible for reading, understanding and complying with it.

  • Mandatory training on information security, data protection, cyber awareness and safe AI use is required — communicated by Technology, Legal and HR.
  • The Technology Service Desk logs and tracks all AI-related incidents and ensures investigation or remediation takes place, working with the outsourced Security Operations Centre where needed.
  • The Data Protection Officer assesses and escalates any data breach, including those arising from unauthorised AI use.
Key contacts — Director of Technology: James Grove (james.grove@chelseafc.com). Data Protection Officer: Amy Pallister (amy.pallister@chelseafc.com). Technology Service Desk: techsupport@chelseafc.com.

04Getting a tool approved

As with any new application, you must work with the Technology Department to evaluate an AI tool before using it. Technology reviews the tool's security features, terms of service and privacy policy, checks the reputation of the developer and any third-party services it uses, and confirms it works with existing infrastructure.

  • Start the process by logging a request via techsupport@chelseafc.com.
  • Use is also subject to a contractual agreement reviewed by Legal — submit this through the Contract request portal on the Intranet homepage, answering all the AI-specific questions.
  • Only tools reviewed and approved by both Technology and Legal may be used for Club business.

Be aware that AI features are often built into websites and existing applications; those count too.

05Approved tools

The Club does not prescribe specific purposes for which AI may be used, but every tool must be formally reviewed and approved before use. Until further tools are approved and communicated, only those below may be used for Club business.

AI solutionAvailable from
Microsoft Copilot (Enterprise)June 2024
Microsoft 365 and Edge browser AI featuresJune 2024

See Tools for what you can access today and how to request more.

06Protecting data

Do not upload or share data that is confidential, proprietary or protected by regulation without prior approval from the appropriate department — including financial data, API keys, login credentials, and anything legally restricted.

  • Personal data. Processing personal data with an AI tool is likely to trigger the need for a Data Protection Impact Assessment. Speak to Legal first so the processing complies with GDPR, and take extra care with special categories of personal data.
  • The test to apply. Before uploading anything, ask: would I be comfortable sharing this outside the company? Would we be okay with it being leaked publicly?
  • Access control. Don't give anyone outside the Club access to AI tools, or share login credentials, without prior approval.
  • Retention. Delete Club data, IP and references from a tool once they're no longer needed, and when the Club stops using that tool.

07Acceptable use

When using AI tools at work you must:

  • Use a Club-provided email address to log in.
  • Avoid offensive, discriminatory or inappropriate content.
  • Review every output thoroughly before using it or forwarding it — check it isn't biased, offensive or discriminatory, that it doesn't disclose personal or confidential information, and verify any facts against trusted sources.
  • Apply the same security practices as for any Club data: strong passwords, up-to-date software, and our retention and disposal policies.

AI should not replace judgement, legal advice, or decision-making affecting individuals, and AI-generated content must be clearly identified.

08What is prohibited

What you enter into an AI tool can reappear, in whole or in part, in results generated for other people. Unless Legal has approved otherwise, never upload:

  • Trade secrets, or research that could later be subject to patent protection.
  • Club intellectual property — logos, brands, video and photo content, imagery, statistical data.
  • Confidential information about the Club or third parties, or anything we're obliged not to disclose.
  • Sensitive market information, computer source code, or legally privileged material.
  • Personal data relating to other people, including private information.

You must also not use your Club email address for personal AI use, use a personal account for any Club business (including on a work phone), or use a tool that isn't on the approved list. AI tools must not be used to conduct or solicit illegal activity, infringe anyone's privacy or intellectual property rights, or interfere with your work or a colleague's.

09Monitoring and breaches

Use of AI tools through Club accounts, devices or networks may be logged and monitored in line with the Club's Information Security, Acceptable Use and Monitoring policies — to protect Club data and intellectual property, ensure compliance with legal and regulatory obligations, and support safe use of AI.

A breach of this policy may result in formal action under the Club's Disciplinary Policy. Training is delivered through onboarding, annual compliance and workshops. If something has gone wrong, report it to the Technology Service Desk straight away — see Get help.