Policy on the Use of Artificial Intelligence at [Company]
10 sections, free, no sign-up
AI policy template for companies A free acceptable use policy, ready to copy.
An AI policy is an internal set of rules that defines which AI tools employees may use, which data is off limits, who checks the output and how the company supports its staff's AI literacy. No law requires one as such. For companies in the EU, it's the simplest way to turn the duties from the GDPR and the EU AI Act into everyday practice.
Below is a complete template with 10 sections, from scope to review. Replace the placeholders in square brackets with your details, then copy each section on its own or the whole policy at once.
As of September 25, 2026 · GDPR and EU AI Act incl. Digital Omnibus · not legal advice
What should an AI policy include?
Ten sections cover what employees need to know day to day and what data protection, employee representatives and regulators will ask about. If you only use a few tools, a few sentences per section are enough. Don't skip any of them, though.
-
Purpose and scope
Who does the policy apply to, and which tools? Contractors too, AI features inside existing software too, and use in a web browser too.
-
Approved and prohibited AI tools
A list of approved tools with their purpose and permitted data, plus the route for getting a new tool approved. Without that route, people fall back on personal accounts and nobody in the company finds out.
-
Confidential and personal data
The most important section: which class of data may go into which tool. Personal data only with a legal basis and a data processing agreement under Art. 28 GDPR, credentials never.
-
Labeling AI-generated content
When a disclosure is legally required (Art. 50 EU AI Act, applicable since August 2, 2026) and where your company chooses to disclose more.
-
Responsibilities and approval
Who maintains the tool list, who answers questions, who signs off on output? Responsibility for a piece of work stays with a person, even if AI helped write it.
-
AI literacy and training
Art. 4 of the EU AI Act requires measures that support the AI literacy of staff. The policy sets out who gets trained, when, and how you record it.
-
Copyright and third-party rights
What may be entered, and why output generated purely by AI often isn't protected by copyright.
-
Errors and hallucinations
AI sounds convincing even when it's wrong. So: check facts, report errors, escalate data incidents immediately.
-
Violations
Clear consequences, written so that people ask first instead of using tools on the quiet.
-
Review and effective date
Tools and the law change quickly. A fixed review date and a named owner keep the policy current.
AI policy template: ten sections to copy
The template is written for companies in the EU and cites the legal basis wherever a rule rests on a legal duty. The EU AI Act can also apply outside the EU, for example when a company offers AI systems in the EU or their output is used there. Otherwise, adapt the legal references to your local law. Fill in tools, owners and data classes, and have the final version checked by your data protection officer.
This template is not legal advice. It reflects the legal status as of September 25, 2026. For your specific situation, talk to your data protection officer or a lawyer.
Is an AI policy mandatory? What the EU AI Act and GDPR require
No law requires an AI policy as such. Several rules do apply to every company in the EU that uses AI, and the policy is where you write them down for everyone. The overview shows which rule belongs in which section of the template.
-
AI literacy (Art. 4 EU AI Act)
The Digital Omnibus (Regulation (EU) 2026/1744) rewrote Article 4: companies that provide or use AI must take measures to support the AI literacy of their staff. They no longer have to guarantee a specific level of AI literacy for each individual. Germany's Federal Network Agency (Bundesnetzagentur) recommends documenting the measures in its guidance on Article 4.
-
Transparency (Art. 50 EU AI Act)
Anyone who uses deepfakes, or publishes AI-generated text on matters of public interest without human editorial review, must disclose that AI was involved. Chatbots and other systems that interact directly with people must make clear that they are AI; building that in is the provider's job. For machine-readable marking of AI-generated content, providers of systems already on the market before August 2, 2026 have until December 2, 2026.
-
Data protection (GDPR)
Personal data needs a legal basis, and an AI service that processes it on the company's behalf needs a data processing agreement under Art. 28. Decisions with significant effects on people must not be based solely on automated processing (Art. 22). Data incidents may have to be reported within 72 hours (Art. 33).
-
Employee representatives (national law)
In Germany, for example, employers must inform the works council in good time when they plan to use AI (Section 90(1) no. 3 Works Constitution Act), and the works council has co-determination rights over tools that can monitor employees' behavior or performance (Section 87(1) no. 6). Other countries have their own consultation rules. A works agreement often follows; the policy doesn't replace it.
-
Copyright (national law)
German law protects only personal intellectual creations by humans (Section 2(2) Copyright Act), and US courts also require human authorship. AI output without a substantial human contribution is therefore often not protected. For input, a sensible rule is to use only material you have the right to use.
Sources: EU AI Act, Regulation (EU) 2024/1689, Digital Omnibus, Regulation (EU) 2026/1744, Bundesnetzagentur on AI literacy (German). All EU AI Act deadlines after the Digital Omnibus are listed in our article on the EU AI Act.
How to write and roll out an AI policy
The template saves you the writing. The policy only works once it matches the tools people actually use and everyone knows it.
-
Take stock
Ask each department which AI tools are already in use, including personal accounts and browser tools. You'll get honest answers more easily if it's clear up front that this is about rules, not punishment.
-
Choose and approve tools
Check contract terms, the data processing agreement and whether the provider uses submitted data for training. Whatever fails goes on the prohibited list. The need behind it then needs an approved alternative, or people will keep using the tool on the quiet.
-
Adapt the template
Fill in tools, data classes and owners. Delete what doesn't apply to you and add rules your industry needs.
-
Review and adopt
Your data protection officer, information security and, where they exist, employee representatives see the draft before management adopts it.
-
Train, record, review
Introduce the policy in a training session instead of just emailing it, and record who attended. Set the next review date at the same time.
AI policy and training from one team.
A template is a start. The policy still has to fit the tools your people use and the data your company handles. titanspear.ai helps with that:
- AI policy: We define with you which data may go into which tool and who uses AI for what.
- Training: Your teams learn to use AI safely and effectively. This is also a measure that supports AI literacy under Art. 4 of the EU AI Act.
- The right tool: Working on confidential data with AI needs a tool that's fit for it. With a Corporate LLM, you run your own language model under your control. Your data is never used to train third-party models.
30 minutes by video, free and no obligation.
AI policy questions, answered.
What is an AI policy?
An AI policy is an internal set of rules that defines which AI tools employees may use for work, which data is off limits, who checks and approves AI output, and how the company supports its staff's AI literacy. It's also called an AI usage policy, an AI acceptable use policy or, in German, a KI-Richtlinie.
Is an AI policy mandatory?
No law requires an AI policy as such. Companies in the EU that use AI must, however, take measures to support AI literacy under Art. 4 of the EU AI Act, observe the transparency obligations of Art. 50 that apply since August 2, 2026, and comply with the GDPR when personal data is involved. A policy is the simplest way to make these rules binding for everyone and to show later what the company did.
What should an AI policy include?
Ten things: purpose and scope, approved and prohibited AI tools, handling of confidential and personal data, labeling of AI-generated content, responsibilities and approval, AI literacy and training, copyright, handling of errors and hallucinations, consequences of violations, and a fixed review date. The template on this page covers all ten sections with placeholders.
What is an AI acceptable use policy?
An AI acceptable use policy sets out what employees may and may not do with AI tools at work: which tools are approved, which data may go into them and how output must be checked. In practice, the term is mostly used for the same document as an AI policy. The template on this page can serve as either.
How long should an AI policy be?
Short enough to be read. For most companies a few pages are enough, and the template on this page is kept that short. Keep the list of approved tools as a separate appendix, so that approving a new tool doesn't mean changing the whole policy.
Can employees put customer data into ChatGPT?
Only under certain conditions. Under the GDPR, personal data may only go into an AI tool if the tool is approved for it, there is a legal basis and a data processing agreement under Art. 28 GDPR is in place with the provider. Personal accounts generally don't meet these conditions. The template handles this with data classes in section 3; whether a specific tool meets the conditions is for your data protection officer to check.
How often should an AI policy be reviewed?
At least once a year, ideally every six months, and also whenever a new tool is approved or the law changes. The EU AI Act shows how quickly that happens: in July 2026 the Digital Omnibus moved deadlines and rewrote Article 4.
Does titanspear.ai help with AI policies and training?
Yes. titanspear.ai, an AI agency based in Langenselbold, Germany, develops AI policies with companies and trains employees to use AI safely and effectively. For companies that want to work on confidential data with AI, we also offer a Corporate LLM: your own language model under your control. The first step is a free intro call, 30 minutes by video.
Last updated: September 25, 2026
Policy, training, tools: where do you stand?
Book a free intro call, 30 minutes by video. Together we'll look at which AI tools are in use at your company and what your policy needs to cover.
Prefer to write? Email info@titanspear.agency.