AI Policy Generator
Create a complete AI policy for your company in 5 minutes, free, without sign-up, as a PDF. With a training section under Art. 4 of the EU AI Act.
AI policy
Policy on the use of artificial intelligence: our company
As of: 15/09/2026
§ 1 Scope
This policy governs how our company uses artificial intelligence (AI) in daily work. It applies to all employees, regardless of department, role, or type of employment, as well as to all persons who work with AI tools on behalf of the company.
This policy covers all AI applications used for work purposes: text assistants, translation services, image generators, and comparable tools. It also applies when a tool is not explicitly named here.
§ 2 Approved AI tools
For work with company data, only the following AI tools are approved: ChatGPT (Team/Enterprise) and Claude.
Additional AI tools may only be used after explicit approval. Approval is granted by the management. This keeps it traceable which data flows into which systems, and prevents shadow AI from arising through unvetted tools.
§ 3 Prohibited inputs
The following data categories may not be entered into AI tools unless explicit, documented approval has been granted for the individual case: personal customer data, health data, trade secrets and contract content, access credentials and source code containing secrets and financial data.
Regardless of this, the following always applies: personal or confidential data must never be entered into public or private AI tools without a company contract (for example, free web versions). When in doubt: anonymize or ask first, then enter the data.
§ 4 Review obligation and responsibility
AI output can contain errors, ranging from outdated facts to entirely fabricated information. Therefore: every AI output is reviewed by a human before use. Responsibility for content that you use further lies with you, not with the AI tool.
For content that is published or leaves the company (website, proposals, customer communication, contracts), the four-eyes principle also applies: a second person reviews the content before it is released.
§ 5 Labeling AI-generated content
Content that was predominantly created by AI and goes to external parties (for example texts, images, or responses in customer communication) is labeled as AI-generated. This builds trust and meets the transparency requirements of the EU AI Act.
A brief note is sufficient, for example: “This content was created with the assistance of AI.” Internal working documents do not need to be labeled.
§ 6 Training and evidence (Art. 4 EU AI Act)
Required under Art. 4 EU AI ActSince 2 February 2025, Article 4 of the EU AI Act has applied: companies must ensure that all employees who use AI systems have a sufficient level of AI literacy. This obligation applies regardless of company size.
Therefore: all employees who use AI tools complete a foundational AI training before using AI tools with company data. Participation is documented, for example through a certificate; in the event of an audit, this evidence counts. New employees complete the training as part of onboarding.
§ 7 Private AI accounts
Private AI accounts (for example a personal, free ChatGPT access) may not be used for company data. With private and free accounts, it is not guaranteed that inputs remain confidential; many providers use them to train their models.
The approved company accounts are available for work. If you lack access, contact the responsible department (see § 8).
§ 8 Responsibility and violations
Responsibility for this policy and its interpretation lies with the management. Contact this department with questions about AI use, uncertainties in individual cases, and suggestions for new tools.
If you make a mistake (for example, the accidental entry of confidential data), please report it immediately. Prompt reporting protects the company: under certain circumstances, data breaches must be reported to the supervisory authority within 72 hours (Art. 33 GDPR). Being open about mistakes takes priority over sanctions; intentional or repeated violations may have consequences under employment law.
§ 9 Entry into force
This policy takes effect on 15/09/2026 and remains in force until further notice. It is reviewed regularly and adjusted as needed, in particular when new tools are approved or the legal situation changes.
By using AI tools, employees confirm that they have read and understood this policy.
Why every company needs an AI policy
An AI policy has 9 elements: scope, approved AI tools, prohibited inputs, review duty, labelling of AI-generated content, training under Art. 4 of the EU AI Act, rules for private accounts, responsibility and the effective date. With the generator above you turn these into a finished document in 5 minutes, free and without sign-up.
Without a policy, shadow AI quietly emerges in most companies: employees use ChatGPT, Copilot or other tools on their own initiative because nobody has defined what is allowed and which alternatives exist. In the process, customer data, contract contents or access credentials end up unnoticed in systems without a data processing agreement. If a data breach then occurs, you lack the proof that you fulfilled your duty of care, and supervisory authorities ask exactly that. The good news: one page is enough to start. More important than length is that everyone in the team knows the same rules.
The 9 elements of an AI policy explained
The scope defines who the policy applies to: all employees or certain departments. The approved AI tools name specifically which applications may be used with company data. The prohibited inputs define which data categories, such as customer data, health data or access credentials, do not belong in AI tools. The review duty makes clear that AI output can be wrong, so a person always checks before content is reused. For labelling: the EU AI Act requires AI-generated content that is shared externally to be labelled, for example in customer communication or in chatbots. Training under Art. 4 of the EU AI Act builds AI literacy in the team and provides the documented proof of it. The rules for private accounts clarify whether and how private AI accounts may be used. The responsibility names a contact point for questions and violations. And the effective date dates the policy and thereby makes it binding.
AI policy and Art. 4 of the EU AI Act
Article 4 of the EU AI Act has applied since 2 February 2025: companies of every size must promote the AI literacy of employees who use AI systems; since the Digital Omnibus Regulation of 27 July 2026 the obligation expressly reads “promote” rather than “ensure”. From 2 August 2026, supervisory authorities can demand proof of these measures. A documented policy combined with verified training is the most practical way to demonstrate them when in doubt.
How to introduce the policy in your team
Do not just distribute the policy, but present it briefly to the team; only then does it become lived practice rather than a filed document. Actually provide the approved tools, because that is exactly what removes the reason for shadow AI. Document training attendance, make the contact point for questions visible, and review the policy once a year, especially when new tools are approved or the legal situation changes.
Frequently asked questions
What belongs in an AI policy?
An AI policy has 9 elements: scope, approved AI tools, prohibited inputs, review duty and responsibility, labelling of AI-generated content, training and proof under Art. 4 of the EU AI Act, rules for private AI accounts, responsibility for questions and violations, and the effective date. One page is enough to start; more important than length is that everyone in the team knows the rules.
Is an AI policy mandatory for companies?
An AI policy itself is not explicitly required by law. What has been mandatory since 2 February 2025 is the AI literacy of employees (Art. 4 EU AI Act), and a documented policy plus training is the most practical proof of this duty of care. In the event of a data breach, supervisory authorities examine whether the company had internal rules and training.
Does AI-generated content have to be labelled?
Yes. The EU AI Act requires AI-generated content that is shared externally to be labelled, from texts and images in customer communication to chatbots where people interact directly with an AI, and deceptively realistic media (deepfakes). A short note such as ‘This content was created with the support of AI.’ is sufficient. Internal drafts that are reviewed and revised by a person are not covered.
May employees use private ChatGPT accounts for work?
This is not advisable: private and free AI accounts have no data processing agreement, and many providers use the inputs to train their models. Company data belongs only in approved business accounts with training opt-out. That is exactly why the item “private accounts” is a fixed part of the generated policy.
Does the generated AI policy replace legal advice?
No. The generator creates a practical template that covers the common key points for small and medium-sized companies. For special industries (such as healthcare or finance), works agreements or the use of high-risk AI, you should have the document reviewed by a lawyer. Your inputs, by the way, are neither stored nor evaluated.
AI literacy certificate
Get your team ready for the EU AI Act
The EU AI Act requires transparency for certain AI content and sufficient AI literacy in your team. Train your team in under two hours.
More free tools
AI Training Obligation Check
Are your employees required to receive AI training under the EU AI Act? 8 questions to find out.
AI Knowledge Test for Teams
10 questions, 3 minutes: how safely does your team use AI? With instant results and a level rating.
LLM API Cost Calculator
What do GPT-5, Claude or Gemini cost per month? Enter requests and tokens and compare the API costs of all models.