A company AI policy is the document that sets out which AI tools your teams may use, with which data and under what oversight. You write one for three reasons: to protect data, to keep control over quality, and to be able to prove a framework exists if there is an inspection or an incident. Allow four to six weeks, including consultation of the works council (CSE) in France.
Read the full guide
AI in Business 2026: Complete SME Guide (Strategy, ROI, Adoption)
Answer a few questions and get a personalized assessment with recommendations tailored to your industry.
Assess my AI maturityRelated articles
Dive deeper with these complementary articles.
AI in business means handing software systems the tasks that used to require skilled human time: writing, analysis, sorting, customer replies. In 2026, the question for an SME is no longer whether to experiment, but which two or three uses to pick, measure and sustain.
A company AI policy is the document that sets out which AI tools your teams may use, with which data and under what oversight. You write one for three reasons: to protect data, to keep control over quality, and to be able to prove a framework exists if there is an inspection or an incident. Allow four to six weeks, including consultation of the works council (CSE) in France.
Many SMEs approach the topic from the wrong end: they download a template, customise it in an afternoon and send it round by email. Three months later, nobody has read it and nothing has changed. The text itself matters less than how it was built: who was consulted, which decisions were made, and in what legal form it was issued. This article focuses on that process. If you want a ready-to-adapt text, our free AI policy template provides one in full. For the bigger picture, see our guide to AI in business for SMEs.
Because your employees already use AI, and without written rules, everyone follows their own. According to the INSEE ICT survey (Insee Première no. 2120, published in 2026), 18% of French companies with 10 or more employees reported using at least one AI technology in 2025, up from 10% a year earlier. That figure only covers usage declared by the company. It does not count the sales rep rewording follow-up emails in a free assistant, or the HR assistant pasting an interview summary into one.
That is where the real risk lies for an SME. Not in a science-fiction scenario, but in very ordinary situations:
On the regulatory side, three sets of rules overlap. The GDPR applies as soon as personal data goes into a tool. Regulation (EU) 2024/1689, the AI Act, imposes transparency obligations in certain cases (Article 50) and, in Article 4, provides for staff training efforts. And French labour law governs how you can impose rules on employees. We cover how the first two fit together in our article AI Act vs GDPR.
A recent development: Regulation (EU) 2026/1744, known as the "AI Omnibus", entered into force on 27 July 2026. According to the European Commission, it simplifies the AI literacy requirement that applied to companies and gives the Commission and Member States a stronger role in promoting it. That does not remove the case for an AI policy. Without a written document, you can neither sanction a dangerous practice nor show a customer or an insurer that you have put a framework in place.
The name of the document matters little; what counts is the procedure followed to make it binding on employees. An AI policy containing prohibitions backed by sanctions is, legally, a disciplinary rule. French labour law reserves such rules for the internal regulations (règlement intérieur) and the service notes that supplement them.
The official Service-Public page on internal regulations sets out three useful points:
The full procedure includes filing with the labour court registry, making the text available to staff, sending two copies to the labour inspectorate together with the CSE's opinion, and an entry into force at least one month after these formalities.
| Situation | Recommended format | Procedure | Enforceable for sanctions |
|---|---|---|---|
| Fewer than 11 employees, no CSE | Service note | Filing, publication, sending to the labour inspectorate, signed acknowledgement recommended | Yes if the procedure is followed, to be checked with an adviser |
| 11 to 49 employees | AI charter issued as a service note | CSE consultation, filing, publication, labour inspectorate | Yes if the procedure is followed |
| 50 employees or more | AI charter appended to the internal regulations | CSE consultation, filing, publication, labour inspectorate, one-month delay | Yes if the procedure is followed |
| Nonprofit with employees | Same rules as a company of the same size | Same | Same |
This table summarises the general framework under French law. Edge cases (multiple sites, a specific collective agreement) warrant advice from an employment lawyer before the document is issued.
A common trap: a purely "educational" policy sent by email is useful for guiding teams. But it will not allow you to sanction someone who copied the customer file into an unauthorised tool. If you want some rules to be binding, plan the procedure from the start, not after the first incident.
Finally, if you have a CSE in a company with at least 50 employees, Article L2312-8 of the French Labour Code requires it to be consulted on the introduction of new technologies. Rolling out AI tools across a department may fall within that scope, regardless of the policy itself.
An AI policy written by a single person is almost always unworkable: it misses either real-world usage or legal constraints. In an SME, the working group is four or five people:
The CSE is not part of the working group, but it pays to inform it early. Presenting the approach at a meeting before submitting the text avoids it discovering a finished document and seeing it as a surveillance tool.
An AI policy is built in four stages: inventory, decisions, drafting and testing, then consultation and rollout. Here is the timeline we see in SMEs of 20 to 150 employees.
Weeks 1 and 2: the inventory. An anonymous questionnaire to the whole team (tools used, frequency, types of data entered), three or four interviews with the most active users, and a list of subscriptions already paid for, including through expense claims. This overlaps with an AI audit; if you have already done one, start from its findings. Our article on the AI audit for SMEs details the method.
Week 3: the decisions. The working group settles the seven questions set out in the next section. This is the most important step, and the one most often rushed.
Week 4: drafting and testing. Draft from a template, then test the text against real cases (see below). Aim for four pages at most, with concrete examples of permitted and prohibited uses.
Weeks 5 and 6: consultation and rollout. CSE consultation if you have one, filing and publication formalities if the text contains disciplinary rules, then a presentation to teams. If the internal regulations procedure applies, add the one-month delay before entry into force.
For a micro-business without a CSE, the timeline shrinks to two or three weeks. The company's AI maturity also plays a part: the more scattered the usage, the longer the inventory takes.
Writing is not the hard part; deciding is. Each question below needs a clear answer, approved by management, before the first line of the document.
These decisions depend on your context. An accounting firm will not answer question 3 the way a communications agency does. That is why a template, however good, cannot replace this step.
Before publishing the policy, run it against ten situations drawn from your inventory and check it gives a clear answer to each. Online templates never include this step, and it is what separates a document people read from one they ignore.
Examples of situations to test:
For each situation, three members of the working group read the policy and answer separately: allowed, prohibited, or allowed with conditions. If the answers differ, the rule is badly written. Rephrase and try again. In practice, a first draft rarely passes more than six situations out of ten.
An AI policy that is neither explained nor reviewed goes out of date within six months, given how fast the tools change. Three actions make the difference at rollout:
Training is part of the rollout. A policy that bans entering personal data is useless if employees cannot recognise personal data in a spreadsheet. Our article on AI Act Article 4 covers expectations around staff training, to be read in light of the July 2026 AI Omnibus.
Then plan a review every six months, or whenever a major new tool arrives. Keep a short log of requests received and incidents: it is your best evidence that the policy is applied. The usage indicators you track to measure AI ROI in your SME can feed into this review.
Keep in mind that the policy sits within a wider approach. It corresponds to the "rules framework" step described in our article on AI adoption in SMEs: it comes after the inventory and before the pilot, not instead of either.
No law requires a document called an "AI policy". However, the GDPR requires processing of personal data to be documented, the AI Act imposes transparency obligations in certain cases, and French labour law requires a specific procedure for any disciplinary rule. An AI policy is the simplest way to meet all three in a single document.
In practice, both terms often refer to the same document. Some companies use "policy" for the strategic document approved by management and "charter" for the set of rules aimed at employees, appended to the internal regulations. What matters is the procedure followed, not the title.
Yes if the document contains general and permanent disciplinary obligations and you have a CSE: without consultation, these rules cannot be enforced against employees. In companies with at least 50 employees, rolling out AI tools may also require consultation on the introduction of new technologies.
Four to six weeks in an SME with a CSE, two to three weeks in a micro-business. Add one month before entry into force if the internal regulations procedure applies.
Only if the policy went through the internal regulations procedure (CSE consultation, filing, publication, sending to the labour inspectorate) and the sanction is provided for in the internal regulations. A policy simply sent by email guides practice but cannot ground a disciplinary sanction.
Not necessarily for every use. Many SMEs allow free tools for public data (rewording a text already published, brainstorming) and ban them as soon as internal or personal data is involved. The rule must be easy to apply without reading the terms of use of every tool.
Senior management approves and signs it. Day-to-day follow-up falls to the AI lead, who answers questions, handles requests for new tools and prepares the six-monthly review.
GrowthPerf is a Qualiopi-certified training provider that helps SMEs and nonprofits put a framework around their use of AI. We run the decision workshop (the seven questions above), help test the text against your real situations and train teams at rollout. Our AI for business training includes a module on usage rules, and our operational AI training puts the policy into practice on each department's tasks. We do not replace your lawyer on the employment law side: we prepare the substance, they secure the form.
For the full picture, see our complete guide to AI in business for SMEs. And to start from a base text, get our free AI policy template, then book a 30-minute call with us to adapt it to your context.