Many organisations no longer need to introduce AI usage: use employees ChatGPT, Copilot, Gemini or AI features in existing software already. The first step is therefore to determine what is happening. After that you can make agreements that match the data, applications, activities and risks of your organisation.

What is AI policy?

AI policy describes the frameworks for the use of AI within an organisation. It answers practical questions about permitted applications, data, human control, decision-making, suppliers, incidents and responsibilities.

The impact varies from one organisation to another. A text suggestion within an approved business environment requires agreements other than AI that rank applicants, classifies clients or supports financial assessments.

A useful AI policy helps employees recognise what they can do independently, when control is needed and who decides on applications with more risk.

Is an AI policy mandatory?

A separate document entitled "Separate policy' shall not be automatically required by law for each organisation. The European AI Regulation does have obligations that depend on the role of the organisation, the application and the risk class of the AI system.

Al literacy has been applicable to providers and users since 2 February 2025. They take action to give employees and other stakeholders sufficient knowledge and understanding of AI use within their role. Since 2 August 2026, a larger proportion of the AI Regulation has been applicable. For specific high risk applications, different or later starting periods apply.

An AI policy is a logical way to bring together responsibilities, usage rules, privacy, security, supplier assessment and decision-making. The precise legal obligations that apply require an assessment of the practical application.

Editorial note: legislation and regulations around AI are developing rapidly. Check when updating this article whether the said deadlines and obligations are still up to date.

Why do you need AI policy?

AI policy provides staff with a hold on when they want to use a tool. Without clear agreements, each team chooses which type of account, supplier and data seem appropriate. Management then keeps a limited view of applications that have already become part of processes.

Good agreements make responsible use easier. Marketing can use AI for a first text version, HR knows when to review and IT or privacy can pre-check risky applications.

  • prevent confidential information from entering an inappropriate service
  • capture who checks AI output before it is used
  • differentiate low risk use from high impact applications
  • answer customer questions about AI usage and data processing supported
  • Al literacy to match functions and responsibilities

Start inventorying how AI is already used

First, map out which AI tools employees use, for what purpose and with what data. Also look at AI features that have enabled vendors in existing software. Free accounts, business accounts, pilots and built-in assistants can have any other settings and conditions.

Shadow AI is the use of AI applications without the organisation having sufficient visibility. An inventory is intended to improve that visibility and to involve employees early in workable arrangements.

  • tool, supplier and account type
  • department, owner and user group
  • supported process and intended outcome
  • input data and used links
  • role of AI output in advice or decision-making
  • ongoing pilots and planned functionality

What AI applications do we allow?

Work with identifiable categories. Employees will not have to carry out legal or technical research for each prompt. The organisation determines which tools, data and controls fit by category.

CategoryPractical arrangement
Freely permittedLow risk use within approved business tooling and without sensitive data.
Under conditionsUse is permitted with agreed data categories, business accounts and control of output.
First assessApplications concerning HR, care, legal or financial assessment, profiling and automated decisions are subject to prior review.
Not applicableThe organisation excludes applications that do not comply with legislation, risks, contracts or own standards.

What information can you enter in AI?

Connect the AI policy to the data classification and give examples by category. Also make clear which business AI environment a wider category is permitted.

Public texts can often be used within approved tools. Internal documents require a conscious choice. Confidential business information, source code, contract information, security reports, passwords, client data and special personal data require prior assessment and appropriate safeguards.

InformationExample of policy choice
PublicUse within approved applications is generally possible.
InternalOnly when account, supplier and purpose are appropriate.
ConfidentialPre-assessment; limit to explicitly approved environments and targets.
Personal dataReview purpose, basis, data minimize, supplier and possible DPIA.
Secrets and Security InformationTo exclude passwords, keys, pentest details and sensitive configurations from general AI usage.

AI and personal data

When an AI service processes personal data, the GDPR remains relevant. Review the purpose, the basis, necessity, data minimizement, retention periods, security and transparency towards stakeholders.

Also check what the supplier does with input and output, where data is processed, which subprocessors are involved and whether international transmission is involved. In applications with a likely high privacy risk, a DPIA may be required. The concrete assessment depends on the application and context.

Confidential information and business data

Financial reporting, contracts, strategy documents, personnel information, client files, security reports and source code can have high value or sensitivity. List these examples literally in the User Directive.

A staff member should be able to determine before entering whether the tool for that information has been approved. If in doubt, a clear call or notification route is needed.

Check AI Output

AI output may contain factual errors, outdated information, missing context, bias, incorrect calculations or non-existent sources. A convincing formulation does not say much about reliability.

Identify who checks the result, what sources are needed and when a second expert is watching. The employee or process owner remains responsible for the final use. Legal, medical or financial-sounding security requires extra attention.

When can Al decide?

Distinguish between support, advice, preparation, analysis and actual automated decision-making. The governance needed is growing with the influence on people and processes.

Rewriting a text or summing up a meeting usually has a different risk profile than ranking resumes, assessing an employee, classifying a client, estimating fraud or providing credit. Identify by application who will assess the outcome and what human decision remains.

Al literacy is part of good AI policy

AI literacy means that employees develop sufficient knowledge and understanding to use AI responsibly within their role and context. This includes the possibilities, limitations and risks of the application and the agreements of the organisation.

A general e-learning can lay the foundations. HR, marketing, IT, purchasing and management also have their own examples and responsibilities. Combine basic knowledge with privacy, security, control of output, escalation and practice with recognizable work situations. View Enhance security awareness.

Who's responsible for Al?

the board and executive management determine the frameworks and risk appetite. The process owner assesses the purpose and the consequences. IT, information security, privacy, HR, purchasing and legal provide expertise where necessary. Users follow the agreements and report errors or unwanted use.

A larger organisation can work with an AI governance group, AI coordinator or owner of the AI registry. For a smaller organisation, one clear decision-making route can be sufficient.

Keep track of which AI systems are used

A compact AI registry helps to periodically assess applications. Keep it workable and record information that supports decision-making and oversight.

  • application, supplier, owner and purpose
  • Users, data and personal data
  • links and role in decision-making
  • risk category and assessment carried out
  • contract, approval date and review time

Which supplier agreements are important?

Ask how input and output are used, whether data are used for training, where processing takes place and which subprocessors are involved. Review security measures, logging, management options, removal, changes and post-disclosure situation.

Capture responsibilities and evidence in the contractual relationship. Read more about supplier management and the selection of an IT service provider.

Microsoft Copilot, ChatGPT and other generative AI

Policy can distinguish between personal or free accounts, business accounts, integrated AI in existing software, external hosted services and own or private models. The name of the tool alone does not say enough about the device.

Account type, contract, configurations, links, data usage and management also determine the risks. Therefore, formulate product neutral and record how new functions are assessed.

What should be minimum in an AI policy?

Use these subjects as a compact table of contents and adjust the depth to the applications of your organisation.

Subject matterWhat are you laying down?
Purpose and scopeWho and which AI are the policy?
Allowed applicationsWhich tools and applications may be used?
DataWhat information may and may not be entered?
Human controlWhen and by whom is output assessed?
Decision-makingWhere can AI support and where do additional requirements apply?
Privacy and securityWhat requirements apply to personal data, access and security?
SuppliersHow are AI services and changes assessed?
RollWho decides, manages, uses and controls?
Al-LiteracyWhat knowledge do different users need?
IncidentsWhere are errors, data leaks and unwanted use reported?
RegistrationWhich applications and assessments are maintained?
ReviewWhat events lead to actualization?

What doesn't all belong in the main policy?

Keep the main policy readable. Use a User's Directive for daily examples, an assessment procedure for new applications, an AI registry for the overview and separate risk analyses such as a DPIA or FRIA when the application so requires.

Technical configurations are part of the tooling layout. The policy shall define the appropriate framework; helping management configurations enforce that framework.

How do you implement AI policies?

A practical introduction consists of a recognizable order with concrete owners.

  • inventory current use and planned applications
  • determine risks and classify tools and data
  • define policies and responsibilities
  • inform employees and organise role-oriented training
  • adapt technical configurations and suppliers' arrangements
  • review use, incidents and new applications periodically

How often do you update AI policies?

There is no universal term appropriate for each organisation. Plan a fixed review moment and reopen the policy with new tools, new AI features, sensitive data processing, incidents, changed supplier conditions, new processes or relevant legislation.

Record who collects these signals and who formally approves a change.

AI policy and works council

The content and application may raise questions of participation, especially when AI affects employees, personnel data, assessment, monitoring or work processes. The role of the works council is assessed by the proposed rules.

Any AI policy as a whole is too general to call consent. The concrete provisions and consequences are decisive.

AI policy and information security policy

AI policy affects data classification, access management, privacy, suppliers, incident management, awareness, logging, data governance and secure digital working. Connect the documents so that employees do not get conflicting rules.

Read what is in information security policy and watch Kynexis information security policy helps develop, implement and safeguard.

AI policy errors made in a variety of ways

The following learning points help to keep policy useful and up-to-date.

  • Focus on banning and explaining too little which can
  • name only ChatGPT and forget built-in AI functions
  • treat free and business tooling as equivalent
  • do not distinguish between public, internal and confidential data
  • Use AI output without owner or substantive control
  • Review privacy and security independently of the work process
  • Write policy without inventorying current usage
  • do not re-evaluate new applications and changed conditions

Checklist AI policy

Use the checklist to see which parts have already been arranged and where a decision is needed.

Use

  • AI applications inventoried
  • Allowed tooling determined
  • Risky applications identified

Data

  • Data categories defined
  • Personal data assessed
  • Confidential information regulated

Governance

  • Owner appointed
  • Decision-making process
  • AI registry present where appropriate

Suppliers

  • Conditions assessed
  • Security assessed
  • Data usage assessed

Employees

  • Rules of use clear
  • Al-Literacy organized
  • Report route known

Assurance

  • Review Moment Determined
  • Incidents are taken
  • New applications are being assessed

Sources and deepening

Based on official frameworks and practical implementation

The source pages provide the formal background. Kynexis Information Security translates this information into an executable approach for your organisation, sector and risk profile.

View European Commission - Navigating the AI ActView EUR-Lex - Regulation (EU) 2024/1689View Authority Personal Data - AI and algorithms