An AI policy for employees: what belongs in it
An AI policy states which AI tools your team may use, which data may go into them, who approves, and when the use of AI is marked. It protects against hidden use of AI with company data, and it is the basis for training. Here are the eight points a policy should cover. This page is general information, not legal advice.
The structure in eight points
- 1. Purpose: why the policy exists and whom it covers.
- 2. Permitted tools: which AI tools are approved, and how a new one gets approved.
- 3. Types of data: what is free, internal, confidential or personal, and what may go into which tool.
- 4. Approval: who decides on new uses, and what is checked first.
- 5. Marking: when the use of AI must be made visible, for example towards customers.
- 6. Training: who must learn what before using a tool.
- 7. Responsible persons: one owner in-house and a contact in every department.
- 8. Review: the date of the next review, because tools and rules change.
Why the types of data matter most
Most questions in practice come down to one: may I put this into this tool? A simple classification helps. Free data, such as published texts, may go into most tools. Internal data needs an approved tool. Confidential data, such as offers with prices or contract details, needs a tool for which the data flows have been described and approved. Personal data requires particular care, because data protection law applies; here the policy should refer to the person responsible for data protection.
A table that lists the permitted tools against the data types, on one page, is more useful than three pages of prose.
Template or tailor-made?
A template helps you start. The policy must fit your tools and processes, though: a list of permitted tools that does not match what people actually use will be ignored, and then it protects nobody. A policy that is hidden in a folder has the same effect. It has to be announced, explained and trained.
We draft the policy in the assessment (ORDO) or during adoption (ACTUS), together with you and based on the tools that your team really uses. We provide no legal advice; for a binding legal check, involve your own legal adviser.
Keep it short and keep it alive
A policy that fits on two pages is read more often than one that fills twenty. Name an owner, put the review date on the first page, and treat each change in tools as a reason to review. A policy is also a good place to note that employees may ask for approval of a new use, and who they should ask.
Frequently asked questions
Are we legally required to have an AI policy?
This guide does not claim so. Article 4 of the EU AI Act asks for measures to support AI literacy. A written policy is one sensible measure; whether it is needed in your case is a question for your legal adviser.
Who should write the policy?
Ideally management together with the person responsible for AI in-house, with input from the departments that use the tools.
How often should we update it?
At least once a year, and whenever you introduce a new tool or a rule changes. The review date belongs on the first page.
Sources
- EU AI Act Service Desk, Article 4: AI literacy (consolidated text as at 27 July 2026, with the amendments by the Digital Omnibus marked) — https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-4 (As of 2026-10-08)
As of 2026-10-08