AI Tools

AI Policy for Employees: Contents and Structure

Schulung zur KI-Richtlinie am Arbeitsplatz

Images: created using AI

Short answer: An AI policy sets out which tools staff may use, which data they may enter and who signs off on results. Two to four pages are enough. What matters more than the wording is that every restriction comes with a permitted alternative, otherwise shadow AI fills the gap.

In most companies the situation in 2026 looks the same. Part of the workforce has been using AI for a while, often on personal accounts, and management roughly knows it. A ban does not solve this, it only moves the usage out of sight. A good policy permits more than it forbids and, in exchange, makes the boundary unmistakable. This article covers what belongs in it, how an approval model works and what the rollout realistically costs.

Why a written rule is necessary

Three reasons, in this order.

First, daily work. Without a rule, every individual decides for themselves whether a quote, a customer list or a draft contract may go into a chat window. That is not a question of loyalty but of missing guidance.

Second, quality. If nobody defines who checks results, someone eventually publishes an invented figure. One approval step costs minutes and prevents weeks of cleanup.

Third, the legal position. Article 4 of the AI Act requires providers and deployers to take measures supporting the AI literacy of their staff and of other people handling AI systems on their behalf. No particular level of literacy has to be guaranteed (Article 4 EU AI Act) [check legally]. A policy plus training is the simplest evidence that you have addressed it.

How far the obligations reach overall is set out in EU AI Act: what SMEs actually have to do.

The gap is measurable

Bitkom surveyed 604 German companies with 20 or more employees. Only 8 percent offer AI training to all staff, a further 21 percent to most and 25 percent to selected people. 43 percent offer nothing at all. At the same time, 53 percent name legal uncertainty as the biggest barrier to using AI (Bitkom press release, 15 September 2025). The two findings belong together: uncertainty grows wherever nobody has written the rules down.

A traffic-light model beats twenty special cases

The most workable structure assigns data types and tools to three levels. That saves you from deciding case by case.

Level Example content Permitted tools Sign-off
Green Public text, marketing drafts, research without personal data, coding help on sample data Approved services on a company account None, the output is read before use
Amber Internal documents without personal data, anonymised customer cases, price calculations Only services with a data processing agreement and training switched off Second pair of eyes before external use
Red HR data, health data, contracts under negotiation, credentials, source code containing trade secrets None, except explicitly assessed exceptions Management, in writing
As of September 2026. A template to adapt, not legal advice.

The trick sits in the tools column. Every red rule needs a green route that still solves the task. Otherwise someone works around it. Which providers qualify and what to look for in the contract is covered in our GDPR practice guide.

What belongs in the policy

  1. Scope. Who is covered, including working students, freelancers and service providers.
  2. Approved tools. A short list with names and account type, not the phrase suitable tools.
  3. Data traffic light. The table above, adapted.
  4. Duty to verify. Whoever uses an AI output owns the content. Figures, quotes and legal statements are checked before use.
  5. Disclosure. When AI involvement is flagged internally and externally [check legally].
  6. Reporting route. Where to report a mistake or request a new tool.
  7. Training. Who is trained when, and how that is documented.
  8. Review. The policy is revisited every six months, with a date and a named owner.

Four pages is plenty. A policy nobody finishes reading works worse than a short one everybody knows.

A worked example: what rollout and training cost

A company with 45 staff, 30 of them at a desk, wants to introduce a policy and basic training.

  • Writing and agreeing the policy: 12 internal hours at 60 euros, so 720 euros.
  • Legal review: 800 euros one-off.
  • Basic training of 90 minutes for 30 people: 45 working hours at 42 euros, so 1,890 euros, plus 900 euros for preparation and delivery.
  • First-year total: 4,310 euros, or roughly 96 euros per desk.

Set against that is the avoided rework. If training saves each person just 20 minutes a month, that is 10 hours across 30 people, or 420 euros. The investment is covered after about ten months, and that is before counting a single avoided data protection incident. How AI budgets break down in general is covered in What does AI cost a company.

Spotting and absorbing shadow AI

Shadow AI means staff using tools that IT knows nothing about, usually on a personal login. That is not misconduct, it is a response to a gap. Three approaches reveal the scale without putting anyone on the spot.

An anonymous survey. Three questions: which AI tools do you use, what for, and what would make your work easier. No name field. The answers are the best basis for the approved tool list.

A look at expenses. Personal subscriptions frequently appear in expense claims. If three different services show up there, the demand question is answered.

Conversation instead of blocking. Domain-level blocks only move the usage to a private phone. An approved company account with a proper contract works better, because it is more convenient than the workaround.

The order matters: first a usable offer, then the rule. Ban first and promise the alternative later, and you lose the workforce on this topic for months.

Pair the policy with a tool register

Alongside the policy, keep a simple table of every approved tool: name, purpose, provider, contract type, data level per the traffic light, responsible person, date of last review. In practice this list is worth more than any page of prose, because it answers the question people actually have: am I allowed to use this? It is also the starting point when you later need to map obligations under the AI Act.

Rollout in five steps

  1. Take stock. Ask anonymously which tools are in use today. The result nearly always surprises.
  2. Draft. Write the policy in the language of the business, not in legalese.
  3. Involve people. Bring in two or three colleagues from the departments. Where a works council exists, it has to be involved [check legally].
  4. Train. One session with real examples from your own company beats any generic video.
  5. Follow up. After three months, find the rule that does not work in practice and change exactly that one.

If you are planning a ChatGPT rollout anyway, combine the two. The sequence is in How to roll out ChatGPT in your company. For a structured starting point use the AI check, and for the data protection side the GDPR check. Questions go through the contact form.

Frequently asked questions

Is an email to everyone enough instead of a policy?

Better than nothing to start with, but it disappears into the inbox. A short, dated and versioned file in a fixed location can be trained on and evidenced.

Does the works council have to be involved?

As soon as tools are capable of monitoring behaviour or performance, co-determination rights come into play. That applies to many AI tools. Clarify it early rather than after rollout [check legally].

How strict should the policy be?

As strict as necessary and as permissive as possible. Every red rule without a green alternative invites a workaround. Measure success by how few personal accounts remain in use.

Does the policy apply to contractors?

Yes, where they work with your data on your behalf. Add a clause to contracts and reference the policy [check legally].

How often should it be revised?

Every six months as a fixed date, and additionally whenever a new tool is approved or the legal position changes.

Share
Newsletter

One real-world process, once a month

We only write when we have something substantial: a process we built ourselves, what it cost, what it saves — and where it got stuck. If nothing usable comes together in a given month, you get no email that month. You can unsubscribe from any email with one click.

  • Around once a month
  • Unsubscribe with one click
  • No sharing with third parties

Back to top

Get started

Ready to really put AI to work?

Tell us about your project in a few minutes — you’ll get an honest initial assessment, with no sales pressure.

  • Free & no obligation
  • Reply usually within 1 business day
  • GDPR-compliant