AI Usage Policy Template for Companies: Ready to Adapt
An AI usage policy is a written document that sets out which AI tools your company allows, which data can never go into them, and who's responsible for training and enforcement. It's the practical starting point for meeting the AI literacy obligation in Article 4 of the EU AI Act. The template below is ready to adapt for your own company.
#Why you need a written AI policy, even without a dedicated IT team
In most companies, people are already using AI tools in daily work, usually without any official rule governing it. Marketing drafts copy with ChatGPT, customer service tests AI chatbots, individuals upload documents to Claude or Gemini to summarize them. Without a policy, every person decides for themselves what's acceptable, and that almost always causes problems: confidential customer data ends up in a public tool, or nobody knows whether an AI-drafted text still needs review.
A written policy doesn't solve this by banning things, it solves it through clarity. It answers the questions everyone would otherwise answer differently on their own: which tools are allowed, what data can go in, who checks the output. That clarity is also exactly what Article 4 of the AI Act is really asking for: a traceable, documented approach to how AI systems get used.
A written policy alone doesn't fully satisfy Article 4. The obligation also requires that staff actually know and understand the policy, not just that it exists on paper. See the article on the AI literacy obligation for more.
#What an AI usage policy needs to cover
A working policy covers seven areas:
| Section | Core question |
|---|---|
| Purpose and scope | Who does the policy apply to, and which tools does it cover? |
| Permitted and restricted use | Which tasks can be done with AI, and which can't? |
| Handling confidential data | What information should never go into an AI tool? |
| Disclosure of AI-generated content | When does AI involvement need to be disclosed? |
| Quality control | Who reviews AI output before it's used? |
| Training and records | How is AI literacy delivered and documented? |
| Violations and reporting | What happens when the policy is broken, and who do people report to? |
The template below fills each section with a starting point you can adapt directly for your company.
#Template: AI usage policy
1. Purpose and scope This policy governs the use of AI systems (e.g. ChatGPT, Copilot, Claude, Gemini) by all employees of [company name]. It applies to work purposes regardless of whether a tool is company-licensed or used on a personal account.
2. Permitted and restricted use Permitted: drafting text, research support, summarizing internal non-confidential documents, coding assistance within existing approvals. Not permitted without prior approval: automated decisions about individuals (for example, applicant screening), using unapproved AI tools for customer data.
3. Handling confidential and personal data Customer data, HR data, unpublished financial figures, and trade secrets may not be entered into public AI tools. Only company-approved, contractually secured tools are permitted for this kind of data.
4. Disclosure of AI-generated content Externally shared content with substantial AI involvement (for example marketing copy, reports) is documented internally accordingly. [Add here: your company's specific disclosure rule.]
5. Quality control AI-generated content is reviewed by a qualified person before use. Output affecting customers or legal matters requires a second review.
6. Training and records Everyone using AI systems completes an introductory training before first use and an annual refresher. Completions are logged and available on request.
7. Violations and reporting Violations of this policy are reported to [contact / department]. Repeated or serious violations are handled through existing HR processes.
Fill in only sections 2 and 3 first (permitted use, confidential data) and publish. An incomplete but clear draft creates more clarity than a perfect document stuck in review for three months. The remaining sections can be added in the first revision.
#How to make the policy actually stick
A document sitting on the intranet that nobody reads changes nothing. Three steps turn the policy into actual practice:
First, a short, mandatory introduction for everyone working with AI tools, not an hour-long presentation, but a focused micro-course that walks through the policy using real examples from daily work. Concrete prompting examples help make the abstract rules tangible.
Second, a clear point of contact for questions, because policies always run into edge cases the document doesn't cover. Answering those quickly is what stops people from just ignoring the policy.
Third, a documented refresher, at least annually, because both the tools in use and how teams actually use them change fast.
#Common mistakes in AI policies
Too vague to act on. "Use AI responsibly" isn't a rule, it's an intention. A good policy names specific tools, specific data types, and specific approval processes.
All restrictions, no permissions. Policies that only list what's banned push people toward using AI tools quietly instead of within the rules. A clear list of approved use cases matters just as much as the restrictions.
Written once, never updated. AI tools change faster than most other company policies. A policy from a year ago often already misses half the tools people actually use today.
#Frequently Asked Questions
#Does this template fully satisfy Article 4 of the AI Act?
The policy is a central building block, but not the only one. Article 4 also requires that staff can actually understand and apply it, which means pairing the document with training that has a documented completion record, not just the policy on its own.
#Does a works council need to approve the policy?
In countries with statutory works council co-determination rights, such as Germany's Betriebsverfassungsgesetz, AI tools that can track employee performance or behavior often trigger those rights. See the article on works councils and e-learning for how that plays out in practice, and check local requirements for your jurisdiction.
#How often should the policy be updated?
At least annually, ideally whenever a new tool gets rolled out company-wide. An outdated policy that doesn't mention current tools quickly loses credibility with the team.
#Do small companies need a written AI policy too?
Yes. Article 4 doesn't distinguish by company size, and in small teams without a dedicated IT or legal department, a short, clear document creates more certainty than informal agreements nobody can actually point to.
Once the policy exists, the next step is making sure it actually gets taught, not just emailed out. With Scibly, an AI policy turns into an interactive micro-course in minutes, complete with comprehension checks and a documented completion record per employee. See the AI training for your company use case for what that looks like in practice.