AI policy for companies – what should it include and when is it needed?
Share
By Mallbutiken · Facts verified September 30, 2026 · Approx. 8 minutes reading time
An AI policy is an internal governing document that sets practical rules for how an organization may use AI. The EU AI Act does not generally require every company to have a document with the specific title "AI Policy." However, a policy can be an effective way to translate obligations, data protection, information security, and internal risk decisions into rules that employees can actually follow.
When is an AI policy particularly useful?
The need increases when AI is no longer used sporadically by individuals but becomes part of workflows, systems, or decision-making. This applies, for example, when employees use generative AI for customer material, code, analyses, HR work, legal documentation, finance, or external communication.
A policy is also valuable when the organization needs to provide consistent instructions to many users. Without common rules, contradictions easily arise: one manager allows the uploading of customer material into a tool while another forbids it, or employees assume that a paid AI service may automatically be used with all types of data.
The policy does not replace risk assessment
A governing document can specify the process, but it does not automatically determine whether a specific AI system is permitted or appropriate. The role under the AI Act, the area of use, the type of data, the provider's terms, and other sector regulations must still be assessed for the specific system.
What should an AI policy contain?
| Area | Question the policy should answer |
|---|---|
| Scope | Which individuals, AI tools, systems, and tasks are covered? |
| Approved tools | Who decides which AI services may be used and how is that decision reviewed? |
| Data and confidentiality | What data may or may not be entered into external AI services? |
| Human oversight | When must facts, code, legal, financial, or personnel-related assessments be reviewed by a human? |
| Transparency | When do recipients need to be informed about AI usage or AI-generated content? |
| HR and individuals | What extra checks apply to recruitment, performance, selection, and other decisions that affect people? |
| Copyright and IP | How is protected material, customer material, code, trademarks, and licensing terms handled? |
| Security | What requirements apply to accounts, MFA, API keys, plugins, agents, and integrations? |
| AI literacy | What training and support do different roles need for their actual AI use? |
| Incidents | How are incorrect data exposure, inappropriate results, security issues, or changed provider terms reported? |
The policy should be concrete enough for a user to make an everyday decision without interpreting legal principles. The phrase "use AI responsibly," for example, provides significantly less guidance than a rule about which information classes may be provided to an external AI service.
Example: make the rules understandable with a traffic light model
A traffic light model can make the policy easier to use, but the levels must be adapted to the organization's data and risks.
- Green: low-risk tasks like idea generation with public or harmless information in an approved tool.
- Yellow: usage that requires review or approval, for example, customer material, external publishing, code, or tasks where errors can have clear consequences.
- Red: usage that the organization has prohibited, for example, uploading trade secrets or sensitive personal data into an unapproved service.
The important thing is not the colors, but that the boundaries are easy to understand. Therefore, provide examples from your own operations and specify who the user should contact in case of doubt.
AI literacy: what does Article 4 say after the 2026 amendment?
Article 4 of the AI Act applies to providers and user organizations that are "deployers" within the meaning of the regulation. Following the amendment by Regulation (EU) 2026/1744, they must take measures to support the development of AI literacy among staff and others dealing with the operation and use of AI systems on their behalf. Account should be taken of, among other things, technical knowledge, experience, education, the context of use, and the persons affected.
The amended provision also explicitly states that the obligation does not mean that the provider or user organization must guarantee a specific level of knowledge for every individual. This supports a proportional approach: a person using AI for linguistic assistance generally needs different training than a person implementing an AI system in HR or building an AI integration.
AI and GDPR: start with the data flow
If the AI service processes personal data, the organization must simultaneously comply with the GDPR. Start with simple questions: what data is sent to the service, for what purpose, who determines the processing, where is the data stored, is it used for model training, and which subcontractors have access?
If the provider processes personal data on your behalf, a Data Processing Agreement (DPA) may be needed. Read the guide on when a DPA is required and what the agreement should contain. However, a DPA does not make all AI processing legal in itself; legal basis, transparency, data minimization, and other relevant requirements must still be assessed.
Don't forget trade secrets
Information can be business-critical even when it is not personal data. The policy should therefore have separate rules for things like source code, quotes, customer contracts, product plans, security information, and other trade secrets. Also, assess the provider's contractual terms before inputting material.
How to implement an AI policy in six steps
- Map actual usage. What tools are already being used, by whom, and with what data?
- Classify use cases. Distinguish simple productivity from usage that affects people, security, or important decisions.
- Review providers. Check terms, data processing, security, storage, training, and subcontractors.
- Determine rules and responsibilities. Specify who owns the policy, approves tools, and receives incident reports.
- Train according to role. Connect the training to the AI that each group actually uses.
- Follow up. Review the tool list and the policy when operations, technology, or regulations change.
Common mistakes in AI policies
- Prohibiting or allowing "AI" as a single category. The risks differ greatly between tools and use cases.
- Writing legal texts without working rules. Employees need to know what can be done in practice.
- Focusing only on personal data. Confidentiality, trade secrets, IP, and security can be at least as important.
- Forgetting human oversight. AI output can be convincing but incorrect.
- Not owning the tool list. A policy quickly becomes outdated if no one is responsible for new AI functions and provider changes.
Do small businesses need an AI policy?
Size alone is not the deciding factor. A small business that uses AI with customer data or in central processes may have a greater need for clear rules than a larger company with limited AI use. Adapt the scope according to usage and risk; a short, clear policy that is actually used is better than a comprehensive document that is not embedded in the organization.

Do you need a ready-made structure for AI rules?
Mallbutiken's AI policy for companies contains an editable governing document in Word and PDF with rules for approved use cases, data, GDPR, security, human oversight, AI literacy, HR, transparency, and incidents. Price in store: 149 SEK.
See AI policy for companiesFrequently asked questions
Must all companies have an AI policy?
There is no general requirement in the AI Act that every company must have a document with that specific title. However, concrete obligations may apply depending on the organization's role and AI usage, and a governing document can help translate these into internal rules.
Is an AI policy enough to comply with the AI Act?
No. Compliance depends on the organization's role, the systems, and the use cases. A policy is a governing instrument, not a general certification of compliance.
Should ChatGPT, Copilot, and other tools be in the policy?
It is often better to combine technology-neutral main rules with a separate list of approved tools and conditions. This way, the tool list can be updated without needing to rewrite the entire policy.
Related guidance
See also Mallbutiken's document templates for AI and AI governance, the guide on data processing agreements, and the guide to SaaS agreements.
Sources and further reading
- EUR-Lex: Regulation (EU) 2026/1744, Digital Omnibus on AI
- EUR-Lex: Consolidated AI Act (EU) 2024/1689
- EU Commission's AI Act Service Desk: Article 4 on AI literacy
The guide provides general information and does not replace an assessment of a specific AI system, data protection setup, or high-risk use case.