Services Websites AI Agents AI Training AI Trust Layer Company Memory Portfolio Team About Process Contact PL Let's talk

Free template

AI policy template for your business

Eight sections, each tied to the rule it covers. Copy it, fill in the brackets, put it in front of your team. No email required.

Most free templates tell you what to write. This one also tells you which rule it satisfies.

Why this policy exists

An AI policy is an internal document that settles three things: which AI tools the company uses, what must never be typed into them, and who answers for the result. No law requires a document with that name. Laws do impose the obligations it organises.

There is a more practical reason, stronger than looking compliant. Regulation of the European Parliament and of the Council (EU) 2024/1689 (OJ L, 2024/1689, 12.7.2024), the AI Act, says in Article 99(7) that when an authority sets a fine it weighs mitigating circumstances. A documented tool register and a trained team are exactly that. A policy someone in the company has actually read works in both directions: it settles day-to-day questions, and it lowers exposure when something goes wrong.

Small and medium businesses get a second protection in Article 99(6): the fine cannot exceed the lower of the two figures, the percentage or the fixed amount. A large company pays the higher one, a smaller one pays the lower.

How to use this template

Replace anything in square brackets with your own: [company name], [full name], [date]. Delete sections that do not apply to you - a short policy people follow beats a long one nobody reads. Once it is filled in, give it to your team, and come back to it when a new tool arrives.

What this template does not replace

It is not legal advice and it is not a risk assessment for high-risk AI systems under the AI Act. It does not replace a data processing agreement with your tool vendor. If you handle special category data, make automated decisions about people, or work in a regulated sector, have a lawyer review it.

The template starts here

AI Usage Policy - [company name]

In force from
[date]
Document owner
[full name, role]
Last reviewed
[date]

This policy applies to everyone working at [company name], whatever the contract: employees, contractors and subcontractors with access to our data.

01 AI tool register

At [company name] we use only the tools listed below. Adding a new one needs approval from [full name / role].

ToolWhat we use it forWho has accessType of dataAccount
[e.g. ChatGPT][e.g. first drafts, summaries][e.g. marketing][e.g. public data only][company / personal]
[ ][ ][ ][ ][ ]

We review the register every [period, e.g. quarter]. A tool nobody uses comes off the list and its access is revoked.

02 Permitted and prohibited uses

AI may be used for:

  • [e.g. drafting text that a person then edits]
  • [e.g. summarising our own meeting notes]
  • [e.g. help with code that goes through review]

AI must not be used for:

  • making decisions about people without a human in the loop: hiring, performance reviews, dismissal, granting or refusing a benefit
  • [e.g. producing documents we sign as expert opinion]
  • [ ]

A decision that affects someone's situation always belongs to a person. AI can prepare the material; it cannot make the final call.

03 Data rules

Never enter into an AI tool:

  • personal data of clients, employees or candidates: names, addresses, phone numbers, ID numbers, anything copied from identity documents
  • anything covered by trade secret protection: contracts, quotes, financial figures
  • data our clients entrusted to us, unless our contract with them allows it
  • code or configuration containing keys, passwords or access credentials

Before you paste anything, ask one question: would I show this to a stranger outside the company? If not, do not paste it.

When you genuinely need to work on real data, use [e.g. a tool on a company account with training on our data switched off], or strip the identifying details first.

04 Human review of the output

Every piece of work produced with AI is checked by a person before it leaves the company or becomes the basis of a decision. Check three things: whether the facts and figures hold, whether anything was lifted from someone else's work, and whether it sounds like us.

The person who sends or publishes the material is responsible for that check. Not the tool vendor, and not whoever asked the tool for it.

Language models state wrong answers with exactly the same confidence as right ones. Fluency is not evidence that something is true.

05 Labelling AI-generated content

We tell people when they are dealing with an AI system or with machine-generated content, in the situations the law covers:

  • when a client is talking to a chatbot or a voice assistant rather than a person
  • when we publish image, audio or video that was generated or significantly altered by AI and shows real people, places or events

We do not label every task done with AI. The fact that a text was drafted with a tool and then edited by a person does not trigger a labelling duty.

06 Skills and training

Anyone using AI at [company name] gets an introduction covering the rules in this document, the limits of the tools they work with, and how to report a problem.

WhoScopeDeadlineRecord
[e.g. whole team][e.g. basics and data rules][date][attendance sheet]
[ ][ ][ ][ ]

Keep a record of training. When a materially different tool arrives, run the introduction again.

07 Reporting incidents

Report immediately to [full name / address] if:

  • data went into an AI tool that should not have
  • work produced with AI contained an error and reached a client
  • a tool behaved in a way you cannot explain
  • you suspect someone gained access to our account in a tool

No one gets in trouble for reporting. Hiding it is the problem. An incident flagged within the hour can usually be undone; the same incident found a month later usually cannot.

We log reports with the date, what happened and what we did about it. Where personal data is involved, [full name] decides whether it must be reported to the supervisory authority within 72 hours.

08 Responsibility and review

AreaWho is responsible
Tool register and approving new tools[full name]
Training and its records[full name]
Incidents and contact with the authority[full name]
Reviewing this document[full name]

We review this document every [period, e.g. six months] and whenever a new tool arrives or the law changes. Put the review date at the top.

Breaking these rules is treated as a breach of employment duties. Before that, we check whether the rule was clear and whether the person had the introduction - if not, we fix the document and the training, not the person.

Approved by: [full name, role, date]

Need more than a template?

The template settles the rules. If you want to work through the tool register, Article 4 training and the documentation with someone who has done it in a few companies already - get in touch.

See AI Trust Layer