What should an AI use policy include?
An AI use policy is a short internal document that tells staff which AI tools they may use, for what, with which data, and whom to ask when they are unsure. It is useful only if people know it exists, understand it and follow it in their daily work.
Recommendation. Keep the policy to two or three pages of plain language. Staff should be able to answer “can I use this tool for this task?” in under a minute. Detailed procedures, such as how to approve a tool or handle an incident, can live in separate documents that the policy points to.
What an AI use policy should include
- What is allowed and what is not. Name the approved tools and typical permitted tasks, such as drafting text or summarising public documents. State clearly what is off-limits, for example making final decisions about people without human review.
- Data rules. Say which types of data may go into which tools. A simple traffic-light rule works well; see whether it is safe to share data with AI tools.
- Approval of new tools. Explain how staff request a new tool or a new use, and who decides. The steps are set out in how to approve a new AI use case.
- Human review. Specify which outputs a person must check before they are sent, published or acted on, and what that check involves.
- Transparency. State when customers or other people must be told that they are dealing with AI or with AI-generated content.
- Incidents. Tell staff what counts as a problem, such as a data leak, a harmful output or a tool behaving unexpectedly, and whom to contact straight away.
- Training. Describe what training people receive before and while using AI. As a legal requirement under the EU AI Act, providers and deployers have had to take measures to support AI literacy since 2 February 2025 (AI Act, Art. 4). The policy is a natural place to say how you do this. The full timeline is in what the EU AI Act requires.
- Who is responsible. Name the person who owns the policy and the owner of each approved use case; see who should be responsible for AI.
- Policy review. Set a review date, for example every six months, and triggers for an earlier review, such as a new tool or a change in the law.
The common mistake: a copied template nobody follows
Downloading a policy and circulating it for signature is quick, but it rarely changes behaviour. A copied template names tools the company does not use, ignores the ones it does, and sets rules nobody can apply. Staff sign it and carry on as before, while management assumes the matter is settled.
Hypothetical example: a small marketing agency adopts a ten-page template that bans “all generative AI unless approved”. No approval process exists, so designers keep using image generators through personal accounts. The ban does not stop the use; it only hides it.
To avoid this, start from your AI inventory: the tools people actually use and the tasks they use them for. Write rules for those cases, test the draft with two or three colleagues, and check that each rule answers a real question someone has asked.
What a policy does not do
A policy sets expectations; on its own, it does not make a company compliant. Legal obligations depend on each use case: the data involved, the people affected and the company’s role under the AI Act. Meeting them takes assessments, contracts, records and oversight, which the policy can point to but not replace.
Voluntary standards and frameworks. ISO/IEC 42001:2023, a certifiable AI management system standard, and the voluntary NIST AI Risk Management Framework both treat a policy as one part of a wider system of roles, processes and reviews. They are a useful reference once the basics are in place.
Next step: write down the five rules your staff need to know now, for example which tools are approved, which data never goes into them and whom to call when something goes wrong. Share them first, then build the full AI use policy around them.
Sources and further reading
AI Horizon Conference
The AI Horizon Conference returns to Lisbon, once again bringing together entrepreneurs, investors and industry leaders to discuss the future of AI.