All insights

AI policy for companies: a practical guide and checklist

Practical guidance for tools, data, accountability and human oversight as AI becomes part of everyday work. Includes a ten-point checklist to start from.

Van Gogh-style oil painting: a winding path lined with pale marker posts through wind-swept meadow grass toward a glowing sun on the horizon.

AI has already taken a seat in the working day – in research, in email replies, in code review. The question is rarely whether employees use AI, but whether they do it in a way that is safe for the company. An AI policy sets the frame: which tools are approved, which data may be entered and who is accountable for the result.

Why you need an AI policy

Without shared rules, "shadow AI" appears: employees paste customer contracts, personal data or code into consumer tools without knowing how the data is handled. At the same time, those who are unsure freeze and avoid it entirely. A policy does both jobs at once – it lowers risk and gives clear room to use AI where it helps.

What an AI policy should contain

Keep it short enough to actually be read. These parts go a long way:

  • Purpose and scope – what the policy covers and who it applies to.
  • Approved tools – a list of reviewed services, and how new tools are proposed.
  • Data classification – which information may be used in which tools.
  • Accountability and roles – who owns the policy, who answers questions, who reviews tools.
  • Human oversight – a requirement that a person reviews before AI-generated material is used for real.
  • Transparency – when customers and colleagues should be told AI was used.
  • Review – how often the policy is revisited and how deviations are handled.

Approved tools and shadow AI

Start from a short list of tools given the green light after a review of terms, data retention and the ability to opt out of training on your data. Make it easy to propose new tools – a block list with no way forward only pushes usage under the radar.

Which data may be used – and which may not

Classify information into a few levels and tie each level to what is allowed:

  • Public – marketing material, public documentation. May be used freely in approved tools.
  • Internal – processes, meeting notes, non-public figures. Only in tools with a business agreement and no model training.
  • Sensitive – personal data, customer data, trade secrets. Only in specifically approved solutions, often in your own environment.

Accountability, roles and human oversight

The core principle is that responsibility for a result stays with the person who uses it. The AI proposes, an employee reviews and approves. Name an owner for the policy and a route for questions, so it does not become a document without an owner.

An AI policy should make it clear what is allowed – not scare employees into abandoning AI entirely.

Transparency with customers and employees

Decide when AI use should be mentioned: in deliverables to customers, in published content, in recruitment. Be open internally too about how AI is used in the business. Transparency builds trust and makes it easier to talk about what works and what does not.

Compliance: GDPR and the EU AI Act

This is not legal advice, but two things are worth including. GDPR applies the moment personal data is entered into an AI tool – lawful basis, a data processing agreement and third-country transfers must be in order. The EU AI Act introduces obligations that scale up over time, especially for uses classed as high risk. Have a lawyer read the policy before it is adopted.

Checklist: ten points to start from

  1. The policy fits on two pages and is written for employees, not lawyers.
  2. There is a list of approved tools and a way to propose new ones.
  3. Information is classified into levels with clear rules for each level.
  4. Entering sensitive data into tools without a business agreement is prohibited.
  5. Model training on your data is turned off in the tools you use.
  6. A named person owns the policy and answers questions.
  7. The requirement for human review before AI material is used for real is documented.
  8. There is guidance on when AI use should be disclosed to customers.
  9. GDPR questions – lawful basis, processing agreement, third-country transfer – have been worked through.
  10. The policy has a date for its next review, at least once a year.

How to embed the policy in everyday work

A policy that is only emailed out gets forgotten. Run a short training session, show concrete examples of allowed and disallowed use, and make it easy to ask questions. When you then build a shared AI knowledge base, the policy becomes even more concrete: knowledge lives in one place, with rules and traceability built in. To see what that can look like, book a demo.

AI policy for companies: guide + checklist