This article is for whoever has to write, or review, their company's AI use policy: the person in HR, IT or management who has been asked for something in writing because the team already uses assistants, translators or text generators. The AI use policy template has eight clauses, each with sample wording; this piece goes through them one by one: what each clause must say, and why.
First, what it is not. No law requires a document called an AI use policy. What the law does require are things a policy puts in order: the AI literacy measures of Article 4 of the AI Act, the GDPR obligations when personal data are involved and, when the company provides digital devices to its staff, criteria for the use of those devices, which Article 87.3 of Spain's LOPDGDD requires employers to set. The policy is how you keep all of it in one place, with a date and someone responsible.
1. Scope and who it applies to
What it says. Who it applies to and which tools: all of them, whether the company's, a third party's or personal, when used for work.
Why. Article 4 of the AI Act is not limited to employees: it covers "their staff and other persons dealing with the operation and use of AI systems on their behalf". Collaborators and contractors who use AI on the company's behalf are in.
This policy applies to everyone who works for [ORGANISATION] — employees, collaborators and contractors — when they use an artificial intelligence system to carry out professional duties.
2. Authorised tools and inventory
What it says. Which tools may be used, who keeps the list and how to ask for a new one. And that none is used for one of the practices prohibited by Article 5.
Why. No law requires a list of authorised tools: it is an internal control. But without it nobody knows who uses what, and that is the first thing any Article 4 measure needs. It is the same inventory the rest of governance rests on, and the one that brings to light AI use nobody has declared.
Only the AI tools on the list of authorised tools kept by [RESPONSIBLE PERSON] are used. Anyone who needs a new one asks before using it, stating what for and with which data.
3. Data that never goes in
What it says. Which data are never entered into a tool that is not expressly authorised for it: personal data about customers, patients, candidates or employees, health data, credentials, confidential information.
Why. The GDPR requires personal data to be collected for specified purposes and to be "adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed". And pasting them into an unauthorised tool may be a personal data breach, whose definition includes "unauthorised disclosure of, or access to, personal data". It is the case we analyse in an employee pastes customer data into a chatbot.
Unless the tool is expressly authorised for it, no personal data about customers, patients, candidates or employees, no health data, no credentials and no confidential information are entered into any AI tool.
4. Personal accounts
What it says. That personal accounts, free or paid, are not used with company information.
Why. Where a vendor processes personal data on the company's behalf, Article 28 GDPR requires a contract with it, and a personal account falls outside that contract. What that contract has to say is covered in the article on Article 28.
Personal accounts of AI tools are not used with [ORGANISATION] information. Professional use goes through the business accounts of the authorised tools.
5. Human review of outputs
What it says. That no output affecting a person is used unless someone with the power to change it has reviewed it.
Why. Personal data must be "accurate and, where necessary, kept up to date", and generated text may not be. A decision based solely on automated processing with legal or similarly significant effects is subject to Article 22 GDPR. And if the system is high-risk, Article 26(2) of the AI Act requires human oversight to be assigned to persons with the necessary competence, training and authority. Article 26 applies from 2 December 2027 for Annex III high-risk systems and from 2 August 2028 for Annex I systems; it does not reach Annex I, Section B products.
No output of an AI tool that affects a person is used unless someone with the power to change it has reviewed it.
6. Vendors and the processor contract
What it says. What is checked about a vendor before its tool is authorised: its role, where it processes the data, which sub-processors it uses and whether it trains on the company's data.
Why. The controller may only use processors that meet the requirements of Article 28(1) GDPR, and processing by a processor is governed by a contract. The ten questions of a proper due diligence are there to check it before signing.
Before authorising a tool that processes personal data, [RESPONSIBLE PERSON] checks the vendor's role, where it processes the data, which sub-processors it uses and whether it uses the data for its own purposes.
7. Training
What it says. Which AI literacy measures are taken, for whom, and how they are recorded.
Why. Article 4, as amended by Regulation (EU) 2026/1744, requires measures to support the development of AI literacy, and it states that the obligation does not require any specific level of AI literacy to be reached by any individual. It is an obligation of means: you document what was done and for whom, not what each person knows. How the Article changed is explained in Article 4 after the Omnibus, and the Article 4 checklist is there to record the measures.
[ORGANISATION] takes AI literacy measures adapted to each person's knowledge, experience and training and to the context in which they use each tool, and records the measures, who they were for and when.
8. Worker representatives and review
What it says. Who it was drawn up with, who was informed and when it is reviewed.
Why. Where the policy sets criteria for the use of the digital devices the company provides to its staff, Article 87.3 LOPDGDD is explicit: workers' representatives must take part in drawing up those criteria, and workers must be informed of them. No law sets how often the policy must be reviewed.
This policy has been drawn up with the participation of [the workers' representatives] and everyone it applies to has been informed of it. [RESPONSIBLE PERSON] reviews it at least once a year and whenever the tools, the vendors or the law change.
From template to a policy in use
A policy works if people know it. Three steps after adapting the template: publish it with a date and version, collect read acknowledgements from those who have to apply it, and set a date for the first review. In Alethexis, the policy section of module M1 starts from an editable template and generates the PDF of each version published. All the templates are in resources.
Content in accordance with Articles 4 and 26 of Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744; Articles 4, 5, 22 and 28 of Regulation (EU) 2016/679; and Article 87 of Spain's Organic Law 3/2018.
This article is for informational purposes only and does not constitute legal advice.