10 sections, free, no sign-up

AI policy template for companies A free acceptable use policy, ready to copy.

An AI policy is an internal set of rules that defines which AI tools employees may use, which data is off limits, who checks the output and how the company supports its staff's AI literacy. No law requires one as such. For companies in the EU, it's the simplest way to turn the duties from the GDPR and the EU AI Act into everyday practice.

Below is a complete template with 10 sections, from scope to review. Replace the placeholders in square brackets with your details, then copy each section on its own or the whole policy at once.

As of September 25, 2026 · GDPR and EU AI Act incl. Digital Omnibus · not legal advice

The structure

What should an AI policy include?

Ten sections cover what employees need to know day to day and what data protection, employee representatives and regulators will ask about. If you only use a few tools, a few sentences per section are enough. Don't skip any of them, though.

  1. Purpose and scope

    Who does the policy apply to, and which tools? Contractors too, AI features inside existing software too, and use in a web browser too.

  2. Approved and prohibited AI tools

    A list of approved tools with their purpose and permitted data, plus the route for getting a new tool approved. Without that route, people fall back on personal accounts and nobody in the company finds out.

  3. Confidential and personal data

    The most important section: which class of data may go into which tool. Personal data only with a legal basis and a data processing agreement under Art. 28 GDPR, credentials never.

  4. Labeling AI-generated content

    When a disclosure is legally required (Art. 50 EU AI Act, applicable since August 2, 2026) and where your company chooses to disclose more.

  5. Responsibilities and approval

    Who maintains the tool list, who answers questions, who signs off on output? Responsibility for a piece of work stays with a person, even if AI helped write it.

  6. AI literacy and training

    Art. 4 of the EU AI Act requires measures that support the AI literacy of staff. The policy sets out who gets trained, when, and how you record it.

  7. Copyright and third-party rights

    What may be entered, and why output generated purely by AI often isn't protected by copyright.

  8. Errors and hallucinations

    AI sounds convincing even when it's wrong. So: check facts, report errors, escalate data incidents immediately.

  9. Violations

    Clear consequences, written so that people ask first instead of using tools on the quiet.

  10. Review and effective date

    Tools and the law change quickly. A fixed review date and a named owner keep the policy current.

The template

AI policy template: ten sections to copy

The template is written for companies in the EU and cites the legal basis wherever a rule rests on a legal duty. The EU AI Act can also apply outside the EU, for example when a company offers AI systems in the EU or their output is used there. Otherwise, adapt the legal references to your local law. Fill in tools, owners and data classes, and have the final version checked by your data protection officer.

Policy on the Use of Artificial Intelligence at [Company]

Version [1.0] · effective [date] · owner: [name, role]

1. Purpose and scope

This policy sets out how employees of [Company] use AI tools at work. It is meant to make working with AI possible while protecting confidential information, personal data and the rights of third parties. It applies to all employees, trainees and interns, and to contractors working on behalf of [Company]. It covers all work-related use, whether on company devices, personal devices or in a web browser. AI tools under this policy are any applications that use artificial intelligence to generate, translate, summarize or analyze text, images, audio, video or code. Examples include chat assistants, writing and translation aids, image generators, transcription services and AI features built into existing software.

2. Approved and prohibited AI tools

Only AI tools approved by [approving function, e.g. the IT department] may be used for work. The current list is kept at [location, e.g. intranet page] and forms part of this policy. Currently approved: - [Tool 1]: for [purpose], permitted data up to [data class] - [Tool 2]: for [purpose], permitted data up to [data class] Not permitted: - AI tools that have not been approved, including free versions - personal accounts with AI services for work tasks - browser extensions and apps with AI features that have not been approved - recording or transcribing calls and meetings with AI unless [approving function] has approved the tool and everyone taking part has consented in advance Anyone who wants to use a new tool requests approval from [approving function]. The review covers at least data protection, information security, contract terms and whether the provider uses submitted data for training.

3. Confidential and personal data

Which data may go into which AI tool depends on the data class: - Public (e.g. published texts, website content): any approved tool. - Internal (e.g. internal processes, non-confidential emails): only tools whose provider has a contract with [Company] that covers confidentiality and data protection. - Confidential (e.g. trade secrets, quotes, contracts, source code, financial figures, customer documents): only tools explicitly approved for this class. [Alternative: not at all.] - Personal data of customers, employees, applicants or business partners: only if the tool is approved for it, there is a legal basis and a data processing agreement under Art. 28 GDPR is in place. Where possible, names and other identifiers are removed or replaced first. - Special categories of personal data under Art. 9 GDPR (such as health data): not as a rule. [Exceptions only with approval from the data protection officer.] Passwords, credentials and keys are never entered into an AI tool. When in doubt, employees ask [data protection contact] first.

4. Labeling AI-generated content

AI content is labeled where the law requires it: - Images, audio or video that realistically depict real people, places or events (deepfakes) are disclosed as artificially generated or manipulated (Art. 50(4) EU AI Act). - Text published to inform the public on matters of public interest is disclosed as AI-generated, unless a person has reviewed it editorially and [Company] holds editorial responsibility for it (Art. 50(4) EU AI Act). - If [Company] uses chatbots or other AI systems that talk or write directly with customers, they must make clear that the customer is dealing with an AI (Art. 50(1) EU AI Act). [Responsible function] checks this before launch. In addition, [Company] requires: [e.g. customer-facing texts and images created mostly with AI carry the note "Created with AI assistance".] Internally, employees disclose on request whether and how they used AI.

5. Responsibilities and approval

- Management: adopts this policy and provides the necessary resources. - AI lead [name, role]: maintains the list of approved tools, answers questions and receives reports. - IT and information security: review new tools technically. - Data protection officer [name]: reviews any processing of personal data. - Works council or employee representatives [if any]: involved as required by law, especially before new AI tools are introduced. - Managers: make sure their teams know and follow this policy. - All employees: check AI output before using it and remain responsible for their work, even when AI helped. Output that goes to customers, authorities or the public is approved by a person before it is sent. Decisions with legal or similarly significant effects on people, such as decisions on job applications, are never made by AI alone (Art. 22 GDPR).

6. AI literacy and training

Anyone who uses AI tools for work first takes part in an introductory session [format and length, e.g. 90 minutes online]. It covers at least: - how the approved tools work and where their limits are - which data may go into them (section 3) - how to check output (section 8) - what else this policy covers The content depends on role and prior knowledge: someone using AI for customer texts needs different skills from someone using it to analyze data. [Company] refreshes the training [annually and whenever a new tool is approved] and records the date, content, length and participants. With this, [Company] takes measures to support the AI literacy of its staff as required by Art. 4 of the EU AI Act.

7. Copyright and third-party rights

- Input: third-party texts, images or code are only entered if [Company] has the right to use them. Documents that customers or partners have shared in confidence count as confidential (section 3). - Output: depending on the jurisdiction, content generated by AI without a substantial human creative contribution may not be protected by copyright. That is the position in Germany and the US, for example. [Company] can therefore often not claim exclusive rights in such output. - Before publishing, employees check whether AI output recognizably imitates third-party works, trademarks or real people. If in doubt, it is not used. - [Optional: no prompts designed to imitate the style of specific living artists.]

8. Errors and hallucinations

AI tools sometimes produce statements that sound convincing but are wrong: invented sources, mixed-up figures, outdated law. Therefore: - Facts, figures, quotes, sources and legal statements from AI output are checked against a reliable source before use. - Code from AI tools is reviewed and tested like any other code before it goes into production systems. - Errors, problematic output (such as discriminatory statements) and data incidents are reported immediately to [reporting channel, e.g. AI lead or IT helpdesk]. - If personal data was entered without authorization, [AI lead] informs the data protection officer immediately, because the incident may have to be reported to the supervisory authority within 72 hours (Art. 33 GDPR). Anyone who reports a mistake will not be penalized for reporting it. Early reports limit the damage.

9. Violations

Violations of this policy may lead to disciplinary action, depending on their severity [up to and including termination]. For contractors, the contractual terms apply. The aim of this policy is safe use, not punishment. Anyone unsure whether a use is permitted asks [contact] first.

10. Review and effective date

[AI lead] reviews this policy at least [every six months], and also whenever a new tool is approved or the law changes, and proposes updates to management. The current version is kept at [location]. This policy takes effect on [date]. [Place, date], [signature, management] Acknowledgment: I have read and understood this policy. [Name, date, signature]

This template is not legal advice. It reflects the legal status as of September 25, 2026. For your specific situation, talk to your data protection officer or a lawyer.

Legal status: September 2026

Is an AI policy mandatory? What the EU AI Act and GDPR require

No law requires an AI policy as such. Several rules do apply to every company in the EU that uses AI, and the policy is where you write them down for everyone. The overview shows which rule belongs in which section of the template.

  1. AI literacy (Art. 4 EU AI Act)

    applies since February 2, 2025, rewritten as of July 27, 2026 · in the template: section 6

    The Digital Omnibus (Regulation (EU) 2026/1744) rewrote Article 4: companies that provide or use AI must take measures to support the AI literacy of their staff. They no longer have to guarantee a specific level of AI literacy for each individual. Germany's Federal Network Agency (Bundesnetzagentur) recommends documenting the measures in its guidance on Article 4.

  2. Transparency (Art. 50 EU AI Act)

    applies since August 2, 2026 · in the template: section 4

    Anyone who uses deepfakes, or publishes AI-generated text on matters of public interest without human editorial review, must disclose that AI was involved. Chatbots and other systems that interact directly with people must make clear that they are AI; building that in is the provider's job. For machine-readable marking of AI-generated content, providers of systems already on the market before August 2, 2026 have until December 2, 2026.

  3. Data protection (GDPR)

    applies since May 25, 2018 · in the template: sections 3, 5 and 8

    Personal data needs a legal basis, and an AI service that processes it on the company's behalf needs a data processing agreement under Art. 28. Decisions with significant effects on people must not be based solely on automated processing (Art. 22). Data incidents may have to be reported within 72 hours (Art. 33).

  4. Employee representatives (national law)

    where a works council exists · in the template: section 5

    In Germany, for example, employers must inform the works council in good time when they plan to use AI (Section 90(1) no. 3 Works Constitution Act), and the works council has co-determination rights over tools that can monitor employees' behavior or performance (Section 87(1) no. 6). Other countries have their own consultation rules. A works agreement often follows; the policy doesn't replace it.

  5. Copyright (national law)

    independent of the AI Act · in the template: section 7

    German law protects only personal intellectual creations by humans (Section 2(2) Copyright Act), and US courts also require human authorship. AI output without a substantial human contribution is therefore often not protected. For input, a sensible rule is to use only material you have the right to use.

In five steps

How to write and roll out an AI policy

The template saves you the writing. The policy only works once it matches the tools people actually use and everyone knows it.

  1. Take stock

    Ask each department which AI tools are already in use, including personal accounts and browser tools. You'll get honest answers more easily if it's clear up front that this is about rules, not punishment.

  2. Choose and approve tools

    Check contract terms, the data processing agreement and whether the provider uses submitted data for training. Whatever fails goes on the prohibited list. The need behind it then needs an approved alternative, or people will keep using the tool on the quiet.

  3. Adapt the template

    Fill in tools, data classes and owners. Delete what doesn't apply to you and add rules your industry needs.

  4. Review and adopt

    Your data protection officer, information security and, where they exist, employee representatives see the draft before management adopts it.

  5. Train, record, review

    Introduce the policy in a training session instead of just emailing it, and record who attended. Set the next review date at the same time.

If you'd rather move faster

AI policy and training from one team.

A template is a start. The policy still has to fit the tools your people use and the data your company handles. titanspear.ai helps with that:

  • AI policy: We define with you which data may go into which tool and who uses AI for what.
  • Training: Your teams learn to use AI safely and effectively. This is also a measure that supports AI literacy under Art. 4 of the EU AI Act.
  • The right tool: Working on confidential data with AI needs a tool that's fit for it. With a Corporate LLM, you run your own language model under your control. Your data is never used to train third-party models.

30 minutes by video, free and no obligation.

FAQ

AI policy questions, answered.

What is an AI policy?

An AI policy is an internal set of rules that defines which AI tools employees may use for work, which data is off limits, who checks and approves AI output, and how the company supports its staff's AI literacy. It's also called an AI usage policy, an AI acceptable use policy or, in German, a KI-Richtlinie.

Is an AI policy mandatory?

No law requires an AI policy as such. Companies in the EU that use AI must, however, take measures to support AI literacy under Art. 4 of the EU AI Act, observe the transparency obligations of Art. 50 that apply since August 2, 2026, and comply with the GDPR when personal data is involved. A policy is the simplest way to make these rules binding for everyone and to show later what the company did.

What should an AI policy include?

Ten things: purpose and scope, approved and prohibited AI tools, handling of confidential and personal data, labeling of AI-generated content, responsibilities and approval, AI literacy and training, copyright, handling of errors and hallucinations, consequences of violations, and a fixed review date. The template on this page covers all ten sections with placeholders.

What is an AI acceptable use policy?

An AI acceptable use policy sets out what employees may and may not do with AI tools at work: which tools are approved, which data may go into them and how output must be checked. In practice, the term is mostly used for the same document as an AI policy. The template on this page can serve as either.

How long should an AI policy be?

Short enough to be read. For most companies a few pages are enough, and the template on this page is kept that short. Keep the list of approved tools as a separate appendix, so that approving a new tool doesn't mean changing the whole policy.

Can employees put customer data into ChatGPT?

Only under certain conditions. Under the GDPR, personal data may only go into an AI tool if the tool is approved for it, there is a legal basis and a data processing agreement under Art. 28 GDPR is in place with the provider. Personal accounts generally don't meet these conditions. The template handles this with data classes in section 3; whether a specific tool meets the conditions is for your data protection officer to check.

How often should an AI policy be reviewed?

At least once a year, ideally every six months, and also whenever a new tool is approved or the law changes. The EU AI Act shows how quickly that happens: in July 2026 the Digital Omnibus moved deadlines and rewrote Article 4.

Does titanspear.ai help with AI policies and training?

Yes. titanspear.ai, an AI agency based in Langenselbold, Germany, develops AI policies with companies and trains employees to use AI safely and effectively. For companies that want to work on confidential data with AI, we also offer a Corporate LLM: your own language model under your control. The first step is a free intro call, 30 minutes by video.

Last updated: September 25, 2026

Intro call

Policy, training, tools: where do you stand?

Book a free intro call, 30 minutes by video. Together we'll look at which AI tools are in use at your company and what your policy needs to cover.

What happens in the intro call:

  1. We look at where time and work get stuck in your company.
  2. You see examples of what AI can take over there.
  3. You get an honest assessment of whether and where AI pays off for you.

30 minutes via video · free · no obligation

“The staff had more time to get their other tasks done.”
Alex · on his father's Mercedes dealership (translated from German)

Founder qualified by IHK & TÜV SÜD

Pick your slot right in the calendar. You get an instant email confirmation with a calendar invite and all the details.

The booking calendar comes from the external service cal.com and is covered in our privacy policy (German).

Prefer to write? Email info@titanspear.agency.