Knowledge · AI at work · 8 minutes

AI use policy for companies: template and what it must cover

A short AI use policy template you can copy. What the GDPR and Article 4 of the EU AI Act actually require, which data staff may enter and how to roll it out.

Last updated: October 5, 2026

Does a company need an AI use policy?

No law requires a document with that name. There are, however, two obligations you cannot credibly demonstrate without written rules.

The first is the GDPR. Articles 24 and 32 require a controller to implement appropriate technical and organisational measures and, where proportionate, data protection policies. When an employee pastes customer data into a personal AI chat account, the company is responsible for that processing, not the employee.

The second is Article 4 of the AI Act, Regulation (EU) 2024/1689. It has applied since 2 February 2025. Regulation (EU) 2026/1744, in force since 27 July 2026, softened the wording: providers and deployers must take measures to support the development of AI literacy of their staff. You do not have to guarantee a specific level of knowledge, but you do have to do something real.

A deployer is any company that uses an AI system in its business. A team drafting emails or summarising documents with an AI chat is enough.

What should an AI policy for a company include?

A good policy answers five questions: which tools may be used, what data may go into them, what we do not use them for, who checks the output and what to do when something goes wrong.

It does not need to be long. A policy nobody has read will not help you in an audit or an incident. Two pages of specifics beat twenty pages of generalities.

On 6 August 2026 the Polish data protection authority (UODO) published question lists for assessing an AI tool before deployment, including a separate version for small and medium companies using off-the-shelf tools. Run it for every tool you plan to approve.

AI use policy template (copy and adapt)

Copy the points below, add your company name and fill in the square brackets. This is a working template, not legal advice. If you use AI for decisions about people, have a lawyer review it.

1. Purpose and scope. This policy sets the rules for using artificial intelligence tools by everyone working for [company name]: employees, contractors and interns. It covers company devices and personal devices used for work.

2. Approved tools. For work we use only the tools listed in the annex [tool, plan, data it is approved for, owner, review date]. A tool is added after checking the data processing agreement, model training settings and where data is processed. Request a new tool via [person or address]; you get an answer within [5] business days.

3. Accounts. We use company accounts for work. We do not use personal AI accounts for company matters.

4. Data. We do not enter customer or employee personal data, health data or other special category data, passwords, API keys and tokens, contract text or trade secrets into AI tools, unless a listed tool is explicitly approved for it. When in doubt, remove identifying details or ask [person].

5. Uses that need approval. Without approval from [person or board] we do not use AI for hiring decisions, employee evaluation, customer creditworthiness or other decisions that significantly affect people.

6. Reviewing output. The person who uses a text, code, analysis or decision is responsible for it. Check AI output before it leaves the company, especially numbers, quotes, legal references and sources.

7. Labelling content. When we publish images, video or audio generated or altered by AI that could be taken as real, we label them. The same applies to text on matters of public interest that no human has edited. Customers chatting with our bot know they are talking to AI.

8. Literacy. Everyone who uses AI completes an introductory training within [30] days of starting and a refresher [once a year]. [Person] keeps the training register.

9. Incidents. If something that should not have gone into an AI tool did, or a tool behaves oddly, report it immediately to [person or address]. Reporting is never a reason for sanctions; hiding a problem is.

10. Review. The policy owner [person] reviews the policy and the tool list every [6] months, after every change in the law and after every incident.

What data can employees enter into AI tools?

The simplest scheme has three levels. Green: public and generic content, such as a draft post, style edits or a question about a concept. Amber: internal documents without personal data, only in a listed tool and on a company account. Red: personal data, trade secrets, passwords and keys, only in a tool explicitly approved for them, or not at all.

Plans of the same tool follow different rules. According to OpenAI's documentation, conversations in ChatGPT Business and Enterprise are not used for model training by default, while on individual plans you have to switch training off yourself. We cover the details in can you paste company data into ChatGPT.

Keys and tokens end up in chats more often than people think, because they sit in logs and config files. Before you paste a snippet, you can check it for secrets. The check runs in your browser and nothing is sent anywhere.

AI literacy under Article 4 of the AI Act: what to do in practice

In its AI literacy Q&A (updated 27 July 2026) the European Commission says no certificate is required and no documentation format is prescribed. An internal record of who completed which training is enough. According to the Commission, national market surveillance authorities supervise and enforce this provision from 2 August 2026. In Poland the act's provisions on inspections and fines apply from 28 October 2026.

In practice: a short general session for everyone (what a language model is, why it gets things wrong, what happens to data), separate modules for teams using AI for higher-stakes work (HR, legal, developers) and an attendance list. The provision asks you to consider knowledge, experience and context of use, so where AI supports higher-stakes decisions, one general session is usually not enough.

The AI Act does not attach a specific fine to Article 4. Poland's Act of 3 July 2026 on artificial intelligence systems (Journal of Laws 2026, item 1003) refers to the fines in Chapter XII of the AI Act, and the supervisory authority is the Commission for the Development and Safety of Artificial Intelligence (KRiBSI). A lack of training can still count against a company when another breach, such as a data leak, is assessed. Key dates are in EU AI Act: what it is and who it applies to.

How to roll out an AI policy so it actually works

Step 1. List the AI tools your team already uses. Ask directly and anonymously, without looking for culprits. What you cannot see is called shadow AI, and most companies have more of it than management assumes.

Step 2. Pick one or two tools on a business plan with a data processing agreement and give people access. A ban without an alternative pushes work onto personal accounts.

Step 3. Publish the policy, run the training and record who attended. Step 4. Name one person who answers questions and receives reports. Step 5. Revisit the tool list after six months.

In short

  • No law requires a document called an 'AI policy', but the GDPR and Article 4 of the AI Act require measures that are easiest to demonstrate with written rules.
  • The template above has ten points: scope, tools, accounts, data, uses needing approval, output review, labelling, training, incidents, review.
  • The list of approved tools, with plan and permitted data, matters most. Without it the other rules have nothing to refer to.
  • AI literacy does not require a certificate. Role-appropriate training and a record of who completed it are enough.

Have a website, app or email address that looks suspicious?

Frequently asked questions

Is an AI policy mandatory for companies?

The document itself is not named in the law. What is mandatory are the GDPR's organisational measures (Articles 24 and 32) and measures supporting AI literacy under Article 4 of the AI Act, and a policy is the simplest way to show them.

Does a small business also have to comply with Article 4 of the AI Act?

Yes, if it uses AI systems in its business. After the 2026 amendment the provision is less demanding and the Commission recommends a proportionate approach, so a short training and an attendance record are enough in a small company.

Can an employer ban the use of ChatGPT?

Yes, through work instructions and internal rules. In practice a ban alone often moves usage to personal phones, so approving one tool on a business plan with clear rules works better.

Do you need a certificate for AI literacy training?

No. According to the European Commission's Q&A, no certificate is required. An internal register of trainings and initiatives is enough.

How often should an AI policy be updated?

Every six months is reasonable, plus after any change in the law, any change in a tool's plan and after an incident. AI tools change their privacy settings more often than typical software.

Sources

  1. Regulation (EU) 2024/1689 (AI Act), EUR-Lex
  2. Regulation (EU) 2026/1744 (Digital Omnibus on AI), EUR-Lex
  3. European Commission: AI Literacy, Questions & Answers (updated 27.07.2026)
  4. Regulation (EU) 2016/679 (GDPR), EUR-Lex
  5. Personal Data Protection Office (UODO): GDPR question lists for AI tools (06.08.2026)
  6. Polish Act of 3 July 2026 on artificial intelligence systems, Journal of Laws 2026 item 1003

Accurate as of the article's last update. Laws and vendor terms change, so check the source before you decide.

See also