AI usage policy

What is an AI usage policy?

An AI usage policy is the internal document that says which AI tools your colleagues may use for work, which information may go into them, for which tasks, and who checks the output before it leaves the company. It is a set of rules somebody can follow on a Tuesday morning, not a statement of principles.

You write one because your staff are already using AI. That is the starting position in almost every company, including the ones that have never discussed it. So the choice is not whether AI comes into the business, it is whether it comes in with a written rule or without one. Without one you get shadow AI, and every colleague decides for themselves what may be pasted where.

What the AI Act asks of you

There is a legal hook, and it helps to know how far it reaches. Article 4 of the EU AI Act obliges providers and deployers of AI systems to take measures that support the development of AI literacy among their staff and anyone else operating an AI system on their behalf. It has applied since 2 February 2025.

The wording changed in 2026. The Digital Omnibus on AI, Regulation (EU) 2026/1744, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It rewrote Article 4 from a duty to ensure a sufficient level of AI literacy into a duty to take measures that support its development, and added a sentence saying you do not have to guarantee any specific level for any individual. The duty did not disappear. It became a duty of effort rather than of result.

The European Commission's questions and answers on AI literacy say no certificate is needed and that an internal record of trainings and other guiding initiatives is enough. They also warn that copying a practice out of the Commission's public repository grants no automatic presumption of compliance. For a company of twenty people, a written usage policy plus a note of who was walked through it and when is that record.

What actually goes in it

Six things. Most of what gets added beyond these is there to make the document look thorough.

  • The tools people may use, by name. Not a category such as approved AI assistants, but the product and the account: Copilot signed in with the company account, the ChatGPT workspace the company pays for, the AI features inside software you already licence.

  • The information that never goes in. Write it as a list of nouns, short enough to remember. This is where a light form of data classification earns its place: three levels are plenty, and the only line people need to hold in their head is which level may not leave the approved tools. An accountancy office lands on identity documents, salary data and anything out of a client file, with one named tool where those are still allowed.

  • What you say to colleagues and to customers. Internally, say when a draft came out of an AI tool and what you verified yourself. Towards customers, decide where you disclose before the awkward call rather than during it. If you run a chatbot on your site, the transparency rules in Article 50 of the AI Act, applicable since 2 August 2026, already require that the person knows they are talking to a machine.

  • Who checks before something leaves the company. The person who sends it. Say that explicitly, because it is the sentence most policies leave out and the one that decides whether the rest has any effect. Quotes, legal wording and anything with a customer name in it get read line by line by somebody who can defend them in a meeting.

  • AI-written code. Generated code goes through the same review as code a person typed, the developer who commits it answers for it, and credentials or production connection strings do not go into a prompt. Accept large blocks nobody read and you have moved a maintenance problem into your own repository under somebody else's name.

  • Who to ask. One name, for the case that is not on the list. Leave it out and the fallback is a guess, and the guess is almost always yes.

A one-page policy, section by section

The whole thing fits on one side of A4.

  1. Why this page exists. Two sentences. We use AI, here is how, ask when you are unsure.

  2. Approved tools. The list, with the account you log in with.

  3. Data that stays inside. Client files, personnel records, contracts, source code, anything under an NDA.

  4. What AI may be used for. First drafts, summaries, translations, brainstorming, code assistance.

  5. What it may not decide on its own. Hiring, dismissal, credit, the price towards one specific customer, anything that lands on a person unread.

  6. Checking and disclosure. The sender verifies. Say internally when AI helped, and tell customers where the law or ordinary honesty asks for it.

  7. Reporting. What to do when something went into a tool that should not have seen it, and a line saying the report carries no consequences.

  8. Owner and review date. A name and a date. This is the section that keeps the other seven alive.

Then put it where people already look. A file in a shared drive that nobody has ever opened is not a policy.

An AI usage policy versus a ban

Both are a management decision about AI at work. They differ in what you are holding a year later.

A year after a ban, you have a line in the staff handbook. No list of tools, no record of what was checked, and roughly the same usage as before, moved onto personal accounts and private phones where you can see none of it. The ban produced no information about your own company, which was the thing you needed most.

A year after a usage policy, you have a tool list somebody maintains, a short list of data that stays inside, a named owner who has been asked a dozen awkward questions, and a few incidents you know about because reporting them was safe. You also have a training record, which is the evidence Article 4 expects from you.

The ban is not weaker because it is stricter. It is weaker because it produces nothing you can inspect.

What to watch out for with an AI usage policy

No approved tool means no policy. A document that lists what is forbidden and offers nothing in return asks people to work slower than they know how to. There has to be one tool that covers the everyday case, on a company account, available the week the policy lands.

Ten pages is a decision not to be read. Length reads as legal cover. If the rules do not fit on a page, the ones that matter are competing for attention with the ones that do not.

Nobody owns it. A policy without a name on it belongs to everyone and therefore to no one. The owner is a person, not a committee, and the job is answering questions and keeping the tool list current. That list ages faster than you expect, because suppliers switch AI features on inside products you already pay for, so a list written in January is wrong by April. A quarter of an hour with the owner every quarter keeps it honest.

It arrives as a warning. A policy sent out as a stern email is read as a threat, and after that nobody tells you what they are really using. Walk the team through it with their own work as the examples, and ask what they use today before you tighten anything.

Last Updated: September 3, 2026 Back to Dictionary
Keywords
ai usage policy ai policy shadow ai ai literacy ai act data classification automation governance agent registry human-in-the-loop generative ai compliance ai governance