AI Policy for Companies: What Needs to Be Included + Checklist 2026

Martin Bastius
10.06.2026
999
min.

Introduction

ChatGPT for customer service, Copilot on the development team, AI-powered recruiting tools — artificial intelligence has become a fixed part of everyday business life. What many overlook is that using AI tools carries significant legal and operational risks. Data protection violations, copyright infringement, or erroneous AI hallucinations can have serious consequences.

A clear AI policy creates certainty for your company and your employees. It defines in binding terms what's allowed, what isn't, and how to use AI responsibly. In this article, you'll learn what content belongs in a practical AI policy and how to introduce it successfully.

Why Does Your Company Need an AI Policy?

There's no explicit legal requirement in the GDPR titled "You must write an AI policy." Still, hard legal and practical reasons make a strong case for one:

  • Organizational Data Protection: The GDPR generally requires “appropriate technical and organizational measures" (TOMs)”, to protect personal data. If employees use arbitrary AI tools without any rules in place, confidential customer data, applicant data, or internal information can quickly end up in unvetted systems. An AI policy is the central organizational tool for minimizing these risks.
  • Management Liability: Management's general duty of care requires safeguarding against risks. Anyone who fails to regulate the use of AI systems risks unintentional copyright infringement, erroneous information becoming the basis for decisions, or discriminatory outcomes. In the event of damages, this can lead to direct liability.
  • The EU AI Act Is a Reality: Europe's regulatory framework for artificial intelligence is already taking effect in key stages. Companies must demonstrate that they're fostering AI competence (AI Literacy) within their workforce and minimizing risk. A well-thought-out AI policy also signals externally — to customers, partners, and regulators — that you take governance and compliance seriously.

What Belongs in Your AI Policy

A practical AI policy should be modular in structure and cover the following core areas:

Approved and Prohibited Tools

  • Whitelisting: A clear list of AI applications approved for use within the company (e.g., ChatGPT Enterprise, Microsoft Copilot with an active business license).
  • Shadow IT Ban: A strict prohibition on using personal accounts or unvetted tools for business purposes.
  • Approval Process: A defined process for how employees can submit new AI tools for review and approval.

Data Protection and Permitted Inputs (Input Rules)

  • Data Classification: Precise guidance on which data categories may be entered and which are absolutely off-limits (e.g., health data, source code for core products, passwords, sensitive customer files).
  • Anonymization Requirement: Instructions to anonymize or pseudonymize data before entering it, if context needs to be preserved.

Handling AI Output

  • Verification Requirement: A prohibition on adopting text, code, or decision recommendations without review.
  • Risk Awareness: A note on potential copyright infringement from uncontrolled further use of AI-generated output.

Transparency and Disclosure

  • Disclosure Requirements: Defining when the use of AI must be disclosed to customers or the public (e.g., for AI-generated marketing images or automated chatbots in customer service).

Implementing Data Protection Requirements in Practice (GDPR & DPF)

Data protection is the most critical point in any AI policy. Since many AI providers process data on external servers, you need to legally secure three pillars:

  1. Clarify the Legal Basis for Data Processing (Art. 6 GDPR): When personal data is processed, it must be clear whether this is covered by the company's "legitimate interest" or whether explicit consent (e.g., from customers or applicants) is required.
  2. Sign a Data Processing Agreement (DPA): If an AI tool processes personal data, a DPA under Art. 28 GDPR is mandatory. Your policy should state: No personal data may flow into the tool without a valid DPA.
  3. Secure Third-Country Data Transfers (EU-US Data Privacy Framework): Many AI services are based in the US. Preferably use providers certified under the current EU-US Data Privacy Framework (DPF), or ones where data transfer is legally watertight via Standard Contractual Clauses (SCCs) and additional security measures (such as data encryption).

Sample wording for your policy:

"Entering personal data into AI tools is only permitted if (a) a clear legal basis exists, (b) a DPA has been signed with the provider, and (c) the third-country transfer is legally secured (e.g., via the EU-US Data Privacy Framework). When in doubt, consult the Data Protection Officer before entering any data."

Practical tip: Reviewing new AI tools from a data protection standpoint and signing DPAs requires in-depth expertise. Companies without an internal legal department can rely on digital all-in-one solutions like heyData's External Data Protection Officer to automate compliance for software and internal policies efficiently and with legal certainty.

Handling Copyright and AI Output

The copyright situation surrounding AI systems is complex. Your policy should therefore be based on the following principles:

  • No Automatic Copyright Protection for AI Output: Under current case law, AI-generated works lack the required “personal intellectual creation” of a human being. This means purely AI-generated text, images, or code are generally in the public domain and can even be copied by your competitors. Independent copyright protection only arises through significant human refinement.
  • Risk of Copyright Infringement (Plagiarism Risk): Since AI models were trained on vast amounts of data, their output can sometimes closely resemble copyrighted works by third parties. Using this output commercially risks cease-and-desist letters.
  • Observe Tool Licensing Terms: Some providers reserve the right in their terms of service to use your inputs (prompts) to train their own models, or they restrict commercial use in free versions.

Sample wording for your policy:

"AI-generated content must be checked for potential copyright infringement before publication, distribution, or commercial use. Employees are responsible for carefully reviewing content before publishing it."

Quality Assurance and Responsibilities

AI systems can hallucinate (invent facts), output outdated data, or deliver biased results. Your policy must therefore define clear control mechanisms:

  • Human Final Responsibility (Human-in-the-Loop): AI is an assistant, not a final decision-maker. Every work product — whether a contract, customer email, or code snippet — must always be reviewed by a human.
  • Mandatory Plausibility Check: Cross-checking against primary sources is mandatory, especially for factual statements, statistical data, legal assessments, or decisions with external impact.
  • Responsibilities Within the Company: Assign fixed roles. Who maintains the list of approved tools? Who is the point of contact for errors or security incidents? Typically, this is a task force made up of IT, data protection, and legal.

How to Successfully Roll Out Your AI Policy

A policy only has an effect if it's actually put into practice within the company. Follow these six steps when rolling it out:

  1. Involve Stakeholders Early: Bring management, IT, data protection, HR, and the works council to the table early to build buy-in.
  2. Plain Language Instead of Legalese: Write the policy clearly, precisely, and accessibly. Use practical examples from your employees' everyday work.
  3. Offer Practical Training: Theory alone isn't enough. Run short workshops that show how to comply with the policy in day-to-day work with ChatGPT and similar tools.
  4. Ensure Central Availability: Store the policy on the intranet or in the employee handbook, and provide quick guides (e.g., as a one-pager) directly at the digital workplace.
  5. Embed It in Existing Processes: Integrate the AI policy into onboarding for new employees and make the "AI check" standard practice when procuring new software.
  6. Plan for Regular Updates: Technology and case law are evolving rapidly. Set a fixed schedule (at least once a year) to review and update the policy.

Checklist: Your AI Policy at a Glance

Use this checklist to make sure your AI policy covers all regulatory and practical requirements:

Fundamentals & Scope

  • The personal and material scope is precisely defined (who and which tools does the policy apply to?).
  • The goals and purpose of the policy are clearly stated.
  • Key terms (e.g., what does the company define as an “AI system”?) are clearly defined.

Data Protection & Compliance

  • Permitted and prohibited data categories for AI inputs are clearly defined.
  • Specific requirements for handling personal data (Art. 6 GDPR) are included.
  • The process for signing Data Processing Agreements (DPAs) is defined.
  • Compliance with third-country transfer requirements (e.g., EU-US Data Privacy Framework) is ensured.
  • A designated contact person for data protection questions regarding AI use is named.

Copyright & Output Control

  • Binding rules for manually reviewing AI-generated content before use are established.
  • Risk notices about potential copyright infringement and plagiarism are included.
  • The commercial usage and licensing rights of the tools used have been reviewed and documented.

Governance & Tool Management

  • A dynamic list (“whitelist”) of all approved AI applications exists or is linked.
  • A clear, auditable process for reviewing and approving new AI tools is established.
  • The prohibition of shadow IT (use of unapproved tools or personal accounts) is explicitly stated.
  • The principle of human final responsibility (human-in-the-loop) is established as a core principle.

Conclusion

A well-thought-out AI policy isn't a bureaucratic hurdle — it's a fundamental building block of a modern compliance and risk strategy. It effectively protects your company from data leaks, copyright issues, and liability risks. At the same time, it gives your employees the legal certainty they need to use innovative tools productively. Companies that establish clear guidelines today and properly incorporate the requirements of the EU AI Act and the GDPR are future-proofing their business.

FAQ

What's the most important point in an AI policy?

The protection of sensitive data (input control). The policy must make it absolutely clear which internal data, source code, or personal information must never be entered into a public or unsecured AI.

Do small companies or startups also need such a policy?

Yes, absolutely. As soon as even one person on the team uses ChatGPT or similar tools for business purposes, liability and data protection risks arise. For startups, whose company value is often based on intellectual property (IP), protection against careless data leakage via AI prompts is vital. In addition, investors now routinely demand proof of sound AI governance.

Is it enough to simply ban the use of AI in the company altogether?

A blanket AI ban is almost always counterproductive in practice. It leads to employees using the tools secretly (shadow IT) to keep up with the market's efficiency. As a result, the company loses all control. A controlled, legally secured framework is many times safer than a ban that gets ignored.

How does the EU AI Act affect internal company policies?

Among other things, the EU AI Act requires companies to promote and demonstrate the "AI literacy" of their workforce. Your policy should therefore not only contain prohibitions but also define how employees are trained to use AI safely and transparently. If you use systems classified as "high-risk AI," strict documentation and monitoring obligations apply as well.

How do I handle the use of AI by external service providers (e.g., agencies)?

Your AI policy should also include requirements for external partners and suppliers. If an agency creates copy, graphics, or program code for you, it must be contractually defined to what extent AI may be used and who is liable for reviewing the output under copyright and data protection law.

Published
10.06.2026
Martin Bastius
Co-Founder & CLO

More articles

View all articles
Data Protection & GDPR
4/3/24

Secure Handling of Ex-Employee Emails Under GDPR

Secure Handling of Ex-Employee Emails Under GDPR
AI & Data Governance
7/11/25

Balancing Trust and Control: How to Make AI-Recorded Online Meetings GDPR-Compliant

Balancing Trust and Control: How to Make AI-Recorded Online Meetings GDPR-Compliant
AI & Data Governance
6/12/26

Whistleblower System for SMBs: What You Need to Know About Whistleblower Protection

Whistleblower System for SMBs: What You Need to Know About Whistleblower Protection
Discover all stories