Skip to main content

AI Policy Template for Businesses

This AI policy template sets clear rules for tools, data, reviews, and incidents. Copy it, then adapt it properly to your business, the EU AI Act, and GDPR.

FHFinn Hillebrandt
AI Application
AI Policy Template for Businesses
Links marked with * are affiliate links. If a purchase is made through such links, we receive a commission.

Employees use ChatGPT through personal accounts. Customer data appears in prompts. Nobody checks the factual claims in AI-written content.

Bad intent is rarely the problem. Missing rules are.

An AI policy turns abstract duties into everyday decisions. Which tools are approved? Which data can go into them? Who reviews the output? What happens after a mistake?

Below, you get a complete AI policy template to copy. I will also show you how to customize it, introduce it, and connect it with the EU AI Act.

TL;DRKey Takeaways
  • A useful AI policy covers approved systems, allowed data, prohibited uses, human review, disclosure, intellectual property, security, and incidents.
  • Do not copy the template blindly. Add the real tools, account types, purposes, owners, data classes, and approval routes used by your business.
  • A policy works only when people understand and follow it. Short rules with real examples beat a document that nobody opens.

What an AI policy should do

An AI policy is an internal rulebook for responsible professional use. It gives employees, managers, and contractors one shared framework.

It should achieve five things:

  1. separate permitted and prohibited use clearly,
  2. protect personal, confidential, and copyrighted data,
  3. assign human responsibility and approval,
  4. handle legal and platform-specific disclosure, and
  5. make errors, incidents, and emerging risks visible quickly.

The policy has to fit real work. “Use AI responsibly” sounds reassuring, but it does not tell an employee whether a customer list can go into a prompt.

Is an AI policy mandatory?

The EU AI Act does not tell every company to create a document with this exact title. It does contain duties that are difficult to implement without internal rules.

Examples include AI literacy measures, human oversight for certain systems, transparency duties, and role-specific risk and documentation requirements.

GDPR, trade secret protection, copyright, employment law, consumer protection, and information security also continue to apply. A policy turns that combination into instructions people can follow.

Read my EU AI Act guide for the wider legal framework.

Make three decisions before copying the template

1. Which systems are actually in use?

Include official contracts, AI features inside existing applications, browser extensions, and accounts created by individual workers.

2. Which data classes does your business have?

At minimum, distinguish public, internal, confidential, personal, and highly sensitive data. Add categories required by your sector.

3. Which uses have a high impact?

Flag systems that affect employment, health, credit, education, safety, access to services, or other consequential decisions. They need more scrutiny than internal brainstorming.

Copyable AI policy template

Replace every item in square brackets. Then read each sentence and confirm that it matches how your business really works.

AI Policy for [Company Name]
Version: [Version number]
Effective date: [Date]
Policy owner: [Name or role]

1. Purpose

This policy governs the professional use of artificial intelligence systems at [Company Name]. Its purpose is to enable useful, secure, lawful, and accountable use.

2. Scope

This policy applies to all employees, managers, and contractors who use, procure, develop, integrate, or review AI systems on behalf of [Company Name].

3. Principles

AI supports people. It does not replace human responsibility.
Outputs are reviewed according to their risk.
Personal and confidential data is protected.
People are informed when a law or platform policy requires disclosure.
AI is not used for unlawful, discriminatory, manipulative, or deceptive purposes.

4. Approved AI systems

Only the services, account types, and features listed in the Approved AI Systems Register may be used for company work.

Personal accounts, unreviewed browser extensions, and unapproved AI services must not process company data.

New systems and new purposes require approval from [Responsible Function] before use.

5. Minimum review before approval

The review covers at least:
intended purpose and users
provider and contractual terms
data processing and storage locations
use of inputs and outputs for model training
access controls, logging, retention, and deletion
security controls and known limitations
risks to affected people
duties under the EU AI Act, GDPR, and applicable sector rules

6. Permitted data

Public information may be used in approved systems for approved purposes.

Internal information may be used only where the approved service and account type permit it.

Confidential information, trade secrets, credentials, and unpublished financial, contractual, or product data require explicit prior approval.

Personal data may be processed only when the specific use is lawful and necessary, all applicable notice and safeguard requirements are met, and [Privacy Owner] has approved the use.

Special category personal data may be processed only when the specific use is lawful and necessary, all additional safeguards are in place, and [Privacy Owner] has approved the use in writing. Approval alone does not create a legal basis.

7. Data minimization

Inputs are limited to what the task requires. Names, contact details, customer numbers, and other identifiers are removed or replaced with neutral placeholders where possible.

8. Permitted uses

The following uses are permitted in the approved systems without separate case approval:
[Example: ideas and outlines for internal drafts]
[Example: language editing of non-confidential text]
[Example: summarizing public documents]
[Example: creating variants of previously approved content]

9. Uses requiring case approval

Prior approval from [Responsible Function] is required for:
decisions or recommendations with significant effects on people
processing personal or confidential data
automated communication with customers or applicants
publishing realistic synthetic people, voices, places, or events
developing or substantially modifying an AI system

10. Prohibited uses

The following uses are prohibited:
unlawful, discriminatory, or intentionally deceptive applications
bypassing security, privacy, or access controls
entering passwords, secret keys, or complete login credentials
using unreviewed AI output for consequential decisions
impersonating a real person without the required consent or legal basis
removing required provenance information or AI disclosures

11. Human review

The responsible person reviews AI output before use according to the risk.

Where relevant, the review covers:
facts and sources
completeness and currency
bias and inappropriate generalizations
privacy and confidentiality
copyright, trademarks, and personality rights
security and potentially harmful instructions
fit with brand, contract, and intended purpose

12. Approval

Content or decisions with [Defined Risk Level] may only be approved by [Role]. Approval is recorded in [System or Location].

13. Disclosure

AI interactions and AI-generated or AI-manipulated content are disclosed when the EU AI Act, another law, or a platform policy requires it.

Deepfakes and covered public-interest text are assessed before publication.

Existing Content Credentials, watermarks, and provenance metadata are not removed without a documented reason.

14. AI literacy

People receive measures suited to their tasks, existing knowledge, systems, and risks. [Responsible Function] documents delivery and review.

15. Incidents

Incorrect output, data exposure, security problems, discriminatory results, missing disclosures, and other significant concerns are reported immediately through [Reporting Route].

Affected content or automated processes are stopped when significant harm may occur.

16. Records

Approvals, risk reviews, AI literacy measures, and significant incidents are retained in [Location] for [Period], unless another legal period applies.

17. Breaches

Breaches of this policy are investigated and handled under applicable contractual and employment rules. A good-faith report of a possible problem will not result in retaliation.

18. Review

This policy is reviewed at least [Interval], and after new systems, new purposes, significant incidents, or legal changes.

Approved by: [Name and role]
Date: [Date]

Appendix 1 for approved AI systems

A policy without a concrete tool register leaves too much open. Keep a separate appendix that can change without rewriting the main policy.

FieldSystem and provider
What to recordProduct name, provider, and approved account type
FieldPurpose
What to recordSpecific approved tasks and departments
FieldPermitted data
What to recordAllowed data classes and excluded information
FieldOwnership
What to recordBusiness owner, approval owner, and subject-matter reviewer
FieldRisk
What to recordLow, medium, or high with a short reason
FieldReview
What to recordLast review, version, and next review trigger

Appendix 2 for risk levels and approval

LevelLow
ExampleInternal ideation without sensitive data
Minimum controlThe user reviews output before using it
LevelMedium
ExamplePublic expert content or customer communication
Minimum controlFact-check and approval by the responsible person
LevelHigh
ExampleConsequential decision or sensitive data
Minimum controlPrior review by legal, privacy, and the business owner
LevelProhibited
ExampleUse that conflicts with law or company principles
Minimum controlDo not start, or stop immediately

Appendix 3 for reviewing AI output

A short checklist makes human review specific and repeatable.

Checklist before use or publication

[ ] Purpose and audience are correct
[ ] Claims were checked against reliable sources
[ ] Numbers, names, quotations, and links are accurate
[ ] Confidential and personal data was removed
[ ] Rights in text, images, audio, and brands were checked
[ ] Discriminatory or inappropriate content was excluded
[ ] Required AI and platform disclosures are present
[ ] The responsible person approved the final version
[ ] Sources, original files, and approval are stored traceably

Appendix 4 for incident reports

People report problems faster when the process is clear and focused on containment, not blame.

AI incident report

Date and time:
Reporting person:
Affected system:
Intended purpose:
Short description:
Potentially affected people or data:
Immediate action already taken:
Location of relevant inputs and outputs:
Owner for the next review step:

How to introduce the policy

  1. Create a complete inventory of AI systems actually used.
  2. Agree on data classes, risks, and owners with the relevant teams.
  3. Adapt the template and appendices to real workflows.
  4. Have senior management approve the policy.
  5. Explain the rules with examples from each role's daily work.
  6. Document the briefing and access to the current version.
  7. Review early use and exceptions at short intervals.

The briefing can support your Article 4 AI literacy measures. A general policy does not replace specialist instruction for a high-risk task.

Build AI labeling into the policy

Do not write that every item involving AI requires a label. That rule is too broad legally and unhelpful in practice.

Create an assessment route for chatbots, deepfakes, AI-generated public-interest text, and platform rules. Assign a person to classify the case and approve any visible notice.

My guide to AI content labeling under the EU AI Act contains the legal tests and wording examples.

Common AI policy mistakes

  • The policy bans everything, so workers quietly ignore it.
  • It allows “common AI tools” without naming services and account types.
  • It mentions privacy without defining which data is permitted.
  • Human review has no owner and no review criteria.
  • Agencies and freelancers are missing.
  • Nobody owns updates or assesses new features.
  • Workers receive the file without role-specific examples.

A useful policy can stay short as long as it makes decisions before each worker is forced to invent an answer alone.

Frequently Asked Questions

FH

Finn Hillebrandt

AI Expert & Blogger

Finn Hillebrandt is the founder of Gradually AI, an SEO and AI expert. He helps online entrepreneurs simplify and automate their processes and marketing with AI. Finn shares his knowledge here on the blog in 50+ articles as well as through his ChatGPT Course and the AI Business Club.

Learn more about Finn and the team, follow Finn on LinkedIn, join his Facebook group for ChatGPT, OpenAI & AI Tools or do like 17,500+ others and subscribe to his AI Newsletter with tips, news and offers about AI tools and online business. Also visit his other blog, Blogmojo, which is about WordPress, blogging and SEO.