By Rafael Luque Ocaña

An AI use policy for your company: what each clause must say, and why (downloadable template)

Eight clauses for a company AI use policy: what each one says, which law it rests on and sample wording, with a template to download.

This article is for whoever has to write, or review, their company's AI use policy: the person in HR, IT or management who has been asked for something in writing because the team already uses assistants, translators or text generators. The AI use policy template has eight clauses, each with sample wording; this piece goes through them one by one: what each clause must say, and why.

First, what it is not. No law requires a document called an AI use policy. What the law does require are things a policy puts in order: the AI literacy measures of Article 4 of the AI Act, the GDPR obligations when personal data are involved and, when the company provides digital devices to its staff, criteria for the use of those devices, which Article 87.3 of Spain's LOPDGDD requires employers to set. The policy is how you keep all of it in one place, with a date and someone responsible.

1. Scope and who it applies to

What it says. Who it applies to and which tools: all of them, whether the company's, a third party's or personal, when used for work.

Why. Article 4 of the AI Act is not limited to employees: it covers "their staff and other persons dealing with the operation and use of AI systems on their behalf". Collaborators and contractors who use AI on the company's behalf are in.

This policy applies to everyone who works for [ORGANISATION] — employees, collaborators and contractors — when they use an artificial intelligence system to carry out professional duties.

2. Authorised tools and inventory

What it says. Which tools may be used, who keeps the list and how to ask for a new one. And that none is used for one of the practices prohibited by Article 5.

Why. No law requires a list of authorised tools: it is an internal control. But without it nobody knows who uses what, and that is the first thing any Article 4 measure needs. It is the same inventory the rest of governance rests on, and the one that brings to light AI use nobody has declared.

Only the AI tools on the list of authorised tools kept by [RESPONSIBLE PERSON] are used. Anyone who needs a new one asks before using it, stating what for and with which data.

3. Data that never goes in

What it says. Which data are never entered into a tool that is not expressly authorised for it: personal data about customers, patients, candidates or employees, health data, credentials, confidential information.

Why. The GDPR requires personal data to be collected for specified purposes and to be "adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed". And pasting them into an unauthorised tool may be a personal data breach, whose definition includes "unauthorised disclosure of, or access to, personal data". It is the case we analyse in an employee pastes customer data into a chatbot.

Unless the tool is expressly authorised for it, no personal data about customers, patients, candidates or employees, no health data, no credentials and no confidential information are entered into any AI tool.

4. Personal accounts

What it says. That personal accounts, free or paid, are not used with company information.

Why. Where a vendor processes personal data on the company's behalf, Article 28 GDPR requires a contract with it, and a personal account falls outside that contract. What that contract has to say is covered in the article on Article 28.

Personal accounts of AI tools are not used with [ORGANISATION] information. Professional use goes through the business accounts of the authorised tools.

5. Human review of outputs

What it says. That no output affecting a person is used unless someone with the power to change it has reviewed it.

Why. Personal data must be "accurate and, where necessary, kept up to date", and generated text may not be. A decision based solely on automated processing with legal or similarly significant effects is subject to Article 22 GDPR. And if the system is high-risk, Article 26(2) of the AI Act requires human oversight to be assigned to persons with the necessary competence, training and authority. Article 26 applies from 2 December 2027 for Annex III high-risk systems and from 2 August 2028 for Annex I systems; it does not reach Annex I, Section B products.

No output of an AI tool that affects a person is used unless someone with the power to change it has reviewed it.

6. Vendors and the processor contract

What it says. What is checked about a vendor before its tool is authorised: its role, where it processes the data, which sub-processors it uses and whether it trains on the company's data.

Why. The controller may only use processors that meet the requirements of Article 28(1) GDPR, and processing by a processor is governed by a contract. The ten questions of a proper due diligence are there to check it before signing.

Before authorising a tool that processes personal data, [RESPONSIBLE PERSON] checks the vendor's role, where it processes the data, which sub-processors it uses and whether it uses the data for its own purposes.

7. Training

What it says. Which AI literacy measures are taken, for whom, and how they are recorded.

Why. Article 4, as amended by Regulation (EU) 2026/1744, requires measures to support the development of AI literacy, and it states that the obligation does not require any specific level of AI literacy to be reached by any individual. It is an obligation of means: you document what was done and for whom, not what each person knows. How the Article changed is explained in Article 4 after the Omnibus, and the Article 4 checklist is there to record the measures.

[ORGANISATION] takes AI literacy measures adapted to each person's knowledge, experience and training and to the context in which they use each tool, and records the measures, who they were for and when.

8. Worker representatives and review

What it says. Who it was drawn up with, who was informed and when it is reviewed.

Why. Where the policy sets criteria for the use of the digital devices the company provides to its staff, Article 87.3 LOPDGDD is explicit: workers' representatives must take part in drawing up those criteria, and workers must be informed of them. No law sets how often the policy must be reviewed.

This policy has been drawn up with the participation of [the workers' representatives] and everyone it applies to has been informed of it. [RESPONSIBLE PERSON] reviews it at least once a year and whenever the tools, the vendors or the law change.

From template to a policy in use

A policy works if people know it. Three steps after adapting the template: publish it with a date and version, collect read acknowledgements from those who have to apply it, and set a date for the first review. In Alethexis, the policy section of module M1 starts from an editable template and generates the PDF of each version published. All the templates are in resources.

Content in accordance with Articles 4 and 26 of Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744; Articles 4, 5, 22 and 28 of Regulation (EU) 2016/679; and Article 87 of Spain's Organic Law 3/2018.

This article is for informational purposes only and does not constitute legal advice.

Frequently asked questions

Is it required by law?

Not under that name: no law requires a document called an AI use policy, and as such it is an internal control. What is required are the Article 4 AI Act measures, the GDPR obligations when personal data are involved and, if the company provides digital devices to its staff, the criteria for their use that Article 87.3 LOPDGDD requires. The policy is the orderly way of setting them.

Does it have to be negotiated with the works council?

Article 87.3 LOPDGDD does not speak of negotiating: it requires workers' representatives to take part in drawing up the criteria for the use of digital devices, and workers to be informed of those criteria. If the policy sets them, the representatives must take part in drawing it up.

How often should it be reviewed?

No law sets a period. It is worth reviewing at least once a year and whenever the authorised tools, the vendors or the law change: Article 4 of the AI Act itself was reworded by Regulation (EU) 2026/1744.

Get analysis like this in your inbox

Alethexis regulatory and product news. No noise.

I agree to receive communications from Alethexis: content about AI and regulation, and product news. I can unsubscribe at any time.

Controller: ALETHEXIS, S.L. (NIF B88758057). Purpose: to send you the Alethexis newsletter (content about AI and regulation, and product news). Legal basis: your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time. Retention: until you unsubscribe or after 24 months of inactivity. Rights of access, rectification, erasure, objection, restriction and portability: [email protected]. You may lodge a complaint with the Spanish Data Protection Authority (AEPD, www.aepd.es) or with the supervisory authority of your Member State (Article 77 GDPR). More information in the privacy policy.