An AI policy for business is an internal document that sets out which AI tools your company uses, what data must never go into them, and who is accountable for the output. No law forces you to have the document itself - but the obligations it organizes are real: AI literacy for staff (Article 4 of the EU AI Act) has applied since February 2025, transparency duties (Article 50) kick in on August 2, 2026, and GDPR applies the whole time.
The gap between usage and rules is wide. Microsoft's Work Trend Index found that 78% of AI users bring their own AI tools to work - in small and mid-sized companies it reaches 80%. Most of that happens on private accounts nobody at the company ever vetted.
That gap has a name: shadow AI. And it, not fines from Brussels, is the first reason to write your policy down.
Is an AI policy legally required?
No regulation orders you to keep a document called "AI policy". What the law does require are specific duties the document organizes: supporting AI literacy among staff (Article 4, EU AI Act, in force since February 2, 2025), transparency toward users (Article 50, from August 2, 2026), and GDPR rules whenever AI touches personal data.
The distinction matters in practice. Vendors and law firms often pitch the policy as "a legal requirement". Not quite. The requirements are the duties - the policy is the tool that proves you meet them. An auditor will not ask whether you own a document with the right title. They will ask how you ensured your team knows what it is doing with AI, and where your customers' data ends up. Without written rules, there is no good answer.
We took the obligations themselves apart - who they apply to, on what dates, with what penalties - in our guide to the EU AI Act for business. This article is about the document that holds it all together.
Why write an AI policy if no law demands it?
Because your team already uses AI, policy or not - Microsoft's Work Trend Index puts bring-your-own-AI at 78% of AI users. Banning AI does not close the gap - it hides it.
The ban route has been tested by one of the largest companies on the planet. In March 2023, Samsung's semiconductor division allowed staff to use ChatGPT. Within about three weeks it logged at least three data leaks: an engineer pasted proprietary source code, a colleague pasted code used to diagnose production equipment, and someone uploaded a recording of an internal meeting to get notes. In May 2023 Samsung banned generative AI outright - and then built its own models to be able to return to it at all. The ban turned out to be not a strategy but an expensive detour, one few companies can afford.
An AI policy is the third way between "everyone does what they want" and "nobody touches AI". It marks where AI helps and where risk starts - which lets a company use AI more boldly, not less.
What should an AI policy include?
Eight sections cover both the legal duties and daily practice: a register of AI tools, allowed and forbidden uses, data rules, human oversight, AI content disclosure, training, incident reporting, and ownership.
Here is each section mapped to the rule it serves:
| Policy section | What it settles | Which rule it serves |
|---|---|---|
| 1. Register of AI tools | What the company uses: tool, purpose, who, what data | basis of any audit; GDPR accountability |
| 2. Allowed and forbidden uses | What AI may and may not do (e.g. no HR decisions without a human) | GDPR Art. 22; prep for high-risk rules (from Dec 2027) |
| 3. Data rules | What must never be pasted in: personal data, financials, code, client secrets | GDPR (Art. 5, 32); trade secrets |
| 4. Human oversight | Who reviews AI output before it is used; AI assists, humans decide | GDPR Art. 22; hallucination control |
| 5. AI content disclosure | When AI involvement must be revealed (chatbots, synthetic media) - and when not | EU AI Act Art. 50 (from Aug 2, 2026) |
| 6. Training | Who gets trained, when, on what; keep records | EU AI Act Art. 4 (since Feb 2, 2025) |
| 7. Incidents | What to do after a leak, a hallucinated document, a wrong decision | GDPR (72-hour breach notification) |
| 8. Ownership | Who maintains the policy, who approves new tools | governance; proof of due diligence |
Two field notes. First: build the register (section 1) before anything else - without knowing what people actually use, the rest of the policy is fiction. Second: do not over-comply on disclosure (section 5). Article 50 does not make you label every email drafted with AI - the duty covers, among others, customer-facing chatbots and content people could mistake for authentic. A product description or a marketing post written with ChatGPT needs no label.
One more thing for the data rules (section 3): we went to the source and checked where your company's data goes when you use AI - which accounts train on pasted content and how to turn it off.
How much does an AI policy cost?
Anywhere from nothing to a bespoke law-firm quote. Template policies sell for a few hundred euros or dollars, SHRM publishes free member templates, a tailored legal draft is priced case by case - and the minimum version (tool register plus data rules) costs one afternoon of an owner's time.
For a small business the sane path starts free: survey the team about the tools they really use, write one page of data rules, and only then decide whether you need the full document. A bought template earns its price only if someone in the company reads and adapts it - filed away unread, it proves nothing in an audit. A law firm makes sense when you handle sensitive data (health, finance, HR) or when AI touches decisions about people.
There is also a fourth route: bundle the policy with implementation. We do this in our AI Trust Layer service - instead of a shelf document, you get rules written around the tools your team actually uses, plus the training that closes your Article 4 duty at the same time.
What happens if you have no AI policy?
For the missing document itself - nothing, because no such duty exists. The real risk sits in the obligations that are hard to keep without one: breaching Article 50 transparency carries fines up to EUR 15 million or 3% of global turnover, GDPR breaches run up to EUR 20 million or 4% under a separate regime, and a single data leak through a chatbot can cost more than either fine.
The full penalty ladder of the AI Act - including why the famous EUR 35 million tier almost never applies to a normal company, and how SMEs pay the lower of the two values - is in our EU AI Act guide. The one sentence you need here: fines hang over the duties, not over the missing document - but the document is the easiest proof that you take the duties seriously.
The policy angle adds a cost no regulation mentions: an incident without a procedure. A company with no written rules learns about a leak last, reacts in chaos, and cannot show due diligence - while the GDPR breach clock gives it 72 hours to notify.
Where to start - three steps for the first week
Step 1: build the register - ask the team which AI tools they really use (anonymously; more than half do it quietly). Step 2: set data rules - one page on what must never be pasted into AI. Step 3: turn both into a first version of the policy and announce it - a short policy people follow beats a long one in a drawer.
The order is deliberate. The register shows the scale (it usually surprises), data rules close the most painful risk immediately, and announcing the document turns it into practice. The remaining sections from the table - oversight, incidents, an approval path for new tools - can follow a week later, built on what the register revealed. Do not skip staff training (Article 4), but that is its own process - we covered the obligations with the EU AI Act guide, and what the training itself looks like in our article on AI training for business.
If you would rather not do this alone: at 30Elevate the tool audit, a policy written around your real usage, and team training are one process, not three separate projects. Get in touch and we will show you how it works.
Frequently asked questions
Is an AI policy required by law?
Not as such - no regulation names the document. What is mandatory: AI literacy for staff (EU AI Act Article 4, since February 2, 2025), transparency toward users (Article 50, from August 2, 2026), and GDPR whenever personal data is involved. A written policy is simply the most practical way to document all three.
What is shadow AI?
Employees using AI tools without the company's knowledge or approval. Microsoft's Work Trend Index puts bring-your-own-AI at 78% of AI users - 80% in small and mid-sized companies. The risk: company and client data flows into tools nobody vetted, on private accounts, leaving no trace.
How much does an AI policy cost?
Template policies: a few hundred euros or dollars, with free member templates at SHRM. A tailored legal draft: individual quote, noticeably above template prices. The minimum version - a tool register plus one page of data rules - costs nothing but an afternoon. Cost scales with data sensitivity, not headcount.
Do employees have to sign the AI policy?
Legally, effective communication is usually enough - like any internal workplace rule. In practice a signature (or an HR-system acknowledgment) changes your evidence position: after an incident, you can show the employee knew the rules. Collect it together with Article 4 training confirmation.
How often should an AI policy be updated?
At least yearly and after every significant change: a new tool in the company, a new legal duty (next up: Article 50 on August 2, 2026, then high-risk rules from December 2027), or an incident that exposed a gap. A policy dated two years ago tells an auditor more than having none.
Does the policy cover contractors and freelancers?
It should. Anyone working on your company's or your clients' data falls under the same data and oversight rules - add an AI clause to contractor agreements. Otherwise your register ends at the payroll, and the risk does not.
An AI policy that fits how your team works
As part of AI Trust Layer we audit your tools, write the rules around your team's day-to-day usage, and train them on safe AI use. Explore AI Trust Layer and AI Training
Let's talk AI policy