An AI policy is the internal document that sets out what your teams may do with artificial intelligence: which tools are approved, which data may go into them, who checks what before anything goes out. You will find a complete template below, published in full, ready to copy and adapt. No form, no email required.
Read the full guide
EU AI Act 2026: The Complete Compliance Guide for SMEs and Nonprofits
Answer a few questions and get a personalized assessment with recommendations tailored to your industry.
Assess my AI maturityRelated articles
Dive deeper with these complementary articles.
The EU AI Act (Regulation 2024/1689) applies to your SME or nonprofit as soon as you use an AI tool, even a simple ChatGPT subscription. Since February 2025 you must train your teams; on 2 August 2026 the transparency obligations and the penalty regime take effect.
An AI policy is the internal document that sets out what your teams may do with artificial intelligence: which tools are approved, which data may go into them, who checks what before anything goes out. You will find a complete template below, published in full, ready to copy and adapt. No form, no email required.
Most templates circulating online are three-page documents listing ethical principles and closing with a reminder about data protection. That is not what a 40-person company needs. It needs a short, concrete text that a salesperson understands in ten minutes, and that holds up legally the day an employee challenges a sanction. This article is part of our EU AI Act compliance guide for SMEs and nonprofits.
An AI policy is an internal organisational document: it turns legal obligations into everyday rules. On its own, it does not create compliance.
Three documents are often confused, and they serve different audiences:
| Document | Audience | What it does | Legal basis |
|---|---|---|---|
| AI policy (or AI charter) | Your employees | Approves, prohibits and frames internal usage | No direct obligation, but evidence of diligence |
| AI information notice | People whose data is processed | Explains the processing | GDPR, articles 13 and 14 |
| AI systems register | You, and the authority in case of inspection | Lists systems, purpose and risk level | Regulation EU 2024/1689 |
A common shortcut is to assume that a charter signed by everyone covers the company. It covers nothing by itself. It does two things: it reduces operational risk, meaning data leaks and false content published in the company's name, and it builds a body of evidence if someone asks one day what you actually put in place. On how the two European texts divide up, see our comparison of the AI Act and GDPR.
No text requires you to write an AI policy. Article 4 of Regulation EU 2024/1689, however, has required a sufficient level of AI literacy among the people operating these systems on your behalf since 2 February 2025.
That literacy obligation is demonstrated through a combination: training completed, documentation available, written rules. The AI policy is the cheapest building block in that set, and often the first one requested. We cover the obligation itself in AI Act Article 4: is AI training mandatory?.
Two calendar points matter, because they change what your policy needs to say:
That postponement covers neither Article 4 nor Article 5. If you use AI in recruitment or staff evaluation, you gain time on heavy documentation, not on internal rules. See AI Act Article 6: high-risk AI systems to check whether you fall within scope.
An effective AI policy runs four to six pages and covers ten points. Beyond that, nobody reads it, and an unread document protects nothing.
Here is the structure we use with our SME and nonprofit clients:
Point 3 is where policies succeed or fail. A policy stating "generative AI tools approved by management" is useless. A policy stating "ChatGPT Team, company account only, and Claude through the company subscription" is enforceable the next morning.
The text below is a baseline. Bracketed passages need completing. Budget two hours to adapt it, not two weeks.
Article 1. Purpose. This policy sets out the conditions for using artificial intelligence systems within [Company]. It applies to all employees, apprentices, interns and contractors acting on behalf of the company, on any device, whether company-issued or personal.
Article 2. Definitions. AI system: software producing content, predictions or recommendations from data. Generative AI: a system producing text, images, audio or code. Confidential data: any non-public information relating to clients, employees, pricing, contracts or ongoing projects.
Article 3. Approved tools. Only the following tools are approved: [named list, with version and account type]. Using free personal accounts for work purposes is prohibited, including for tasks involving no sensitive data.
Article 4. Requesting a new tool. Any request to use a tool not on the list is submitted to [AI lead] in writing, stating the intended use and the data involved. A decision follows within [10] working days. No use begins before approval.
Article 5. Data that must never be entered. The following must not be entered into an AI system: personal data of clients or employees, information covered by a confidentiality agreement, health data, credentials or passwords, non-anonymised contractual documents, proprietary code [adapt to your business].
Article 6. Verification before release. Any content produced with the help of an AI system and intended for external use is reviewed by a person competent on the subject before release. Figures, dates, quotations and legal references are checked against the source. The person releasing the content is accountable for it.
Article 7. Transparency. Where [Company] makes an AI system available in direct interaction with a person, that person is informed. Publicly released generated content discloses the use of AI where its nature could otherwise mislead.
Article 8. Prohibited uses. It is prohibited to use AI as the sole basis for a decision producing legal effects on a person, in particular in recruitment, evaluation, discipline or access to a service, as well as any use falling under the practices prohibited by Regulation EU 2024/1689.
Article 9. Incidents. Any accidental entry of confidential data, any release of faulty AI-generated content and any abnormal tool behaviour is reported to [AI lead] without delay. A good-faith report cannot lead to sanction.
Article 10. Training. Every employee using an AI system completes the internal training provided for that purpose. Attendance is recorded and the certificate retained.
Article 11. Governance and review. [AI lead] maintains the tool list and the AI systems register. This policy is reviewed at least once a year and whenever regulation changes materially.
Article 12. Sanctions. Failure to comply with these rules may lead to the sanctions set out in the internal rules of the company.
A three-colour grid is enough and will actually be used. Five-axis risk matrices end up in a drawer.
| Level | Type of use | Rule | Examples |
|---|---|---|---|
| Open | No confidential data, output not published as is | No review | Rewriting public text, generating ideas, explaining a concept |
| Framed | Internal non-personal data, or output sent externally | Mandatory review by a competent third party | Drafting a commercial proposal, summarising an internal report |
| Prohibited | Personal data, health data, trade secrets, or individual decisions | Prohibited, unless a specific approved procedure applies | Screening CVs, evaluating an employee, handling a named client file |
This grid goes on a wall. That is the only valid test: if your classification does not fit on one page, it will not be followed.
This is the point generic templates skip, and it decides the legal weight of the document.
An AI policy that provides for sanctions contains general and permanent requirements. Under French labour law, article R1321-1 of the Labour Code treats such service notes as additions to the company's internal rules, subject to the same formalities. In practice:
There is an alternative: write a purely informative policy with no disciplinary section, and leave sanctions to the existing internal rules. That is faster and less protective. The choice depends on what you want to be able to do the day an employee pastes a client file into a consumer tool.
This point belongs to labour law rather than to the AI Act. Have your final version reviewed by your usual counsel before release, especially if you keep the sanctions section. Requirements differ outside France, so check the equivalent employee consultation rules in your jurisdiction.
They show up in almost every document we review.
On that last point, the financial exposure is covered in our article on AI Act sanctions in 2026.
Three things turn a policy into evidence: a named lead, an up-to-date register, and a record of distribution.
The AI lead does not need to be a lawyer. In a company of 30 to 80 people it is usually the IT manager, the administrative director, or whoever pushed the topic internally. The role fits in three lines: approve new tools, maintain the register, trigger the annual review.
The AI systems register records, for each tool: name, vendor, purpose, categories of data processed, estimated risk level and go-live date. A spreadsheet is enough. It will also serve you the day you need to check whether a tool has moved into high-risk territory.
For distribution, keep the trail: send date, acknowledgement of receipt, attendance sheet from the briefing session. Those are the items that matter in an inspection, not the literary quality of the document. To place your company within the scope of the regulation, our article on who the AI Act applies to sets out the criteria.
Is an AI policy mandatory for an SME? No. No text requires one. Article 4 of Regulation EU 2024/1689 does require a sufficient level of AI literacy among users, and has done since 2 February 2025. A policy is the simplest way to give that requirement substance, alongside training.
AI policy or AI charter: what is the difference? None in substance. "Charter" suggests a statement of commitment, "policy" an organisational text. What matters is the content, and compliance with the formalities if the document provides for sanctions.
Should every employee sign the policy? Not required, but recommended. A dated acknowledgement of receipt proves distribution. It does not replace works council consultation or filing, which are what make the disciplinary section enforceable.
Can we ban generative AI outright? Legally yes, as an employer you set the rules for work tools. In practice a blanket ban pushes usage onto personal accounts and phones, outside any visibility. A narrow approved perimeter works better than a ban people work around.
What happens if an employee pastes client data into ChatGPT? You are facing a potential personal data breach under GDPR, requiring assessment and notification to the supervisory authority within 72 hours where the risk is established. That is precisely the scenario Article 5 of the template is meant to prevent, and Article 9 to surface quickly.
Do we need an AI policy separate from the IT acceptable use policy? Both approaches work. An AI annex to the existing IT policy avoids a further filing and a new consultation cycle. A standalone document is easier for teams to read. If your IT policy predates 2023, rewriting the whole thing is often simpler.
Does the Digital Omnibus postponement change my policy? Very little. Regulation EU 2026/1744 pushes Annex III high-risk obligations to 2 December 2027. Article 4 on AI literacy, Article 5 on prohibited practices and Article 50 on transparency are unaffected.
We work on three fronts, and rarely on just one.
The first is inventory. Before writing anything, you need to know what is actually in use. In most of the organisations we audit, the gap between official tools and tools in use is wide, and that gap is where the risk sits.
The second is drafting, starting from the template above and adapting it to your sector, your size and your existing tools. We do not deliver a twenty-page document, we deliver the one your teams will follow.
The third is training, because that is what Article 4 targets. Our programmes qualify for OPCO funding under our Qualiopi certification. See our AI training for business and the operational AI track.
If you want to take stock before starting, book a free 30-minute audit. We go through your tools, your real usage and what is missing for you to be compliant. You leave with the template adapted to your context, whether you work with us afterwards or not.