Does your company need an AI policy? What the law actually requires
Rasmus Kjaer Damgaard, Co-founder ·
Το παρόν άρθρο δημιουργήθηκε με τη βοήθεια AI και ελέγχθηκε από άτομο. Η Rasmus Kjaer Damgaard φέρει την εκδοτική ευθύνη για το περιεχόμενο.
TL;DR: No EU law mandates a document called an "AI policy". What the law does require, since 2 February 2025, is that companies promote AI literacy in the staff who operate AI (Art. 4, softened from "ensure" to "promote" by the Digital Omnibus in July 2026), and, since 2 August 2026, that they meet the Article 50 transparency duties that apply to their use. A written policy is the practical instrument for both, and the section that carries the real weight is the approved-tools register. You can assemble a complete, citation-grounded policy in ten minutes with our free AI policy generator.
What the law requires, precisely
Three legal anchors matter for an ordinary company using AI tools:
- Art. 4 AI literacy (in force since 2 Feb 2025): promote a sufficient level of AI literacy in staff operating AI systems, considering their technical knowledge and the context of use. The Digital Omnibus changed the operative verb from "ensure" to "promote" in July 2026; mandatory oversight training remains for high-risk deployers. There is no prescribed method: a policy plus training is the standard way to evidence it.
- Art. 50 transparency (since 2 Aug 2026): the four duties covered in our Article 50 guide, applying by role and use, not to everyone equally.
- GDPR, which never went away: pasting personal data into an AI tool is processing, processor agreements are required (Art. 28), and a breach can trigger the 72-hour notification duty (Art. 33).
Everything else commonly found in AI policies (ethics statements, review boards) is governance choice, not legal requirement. A good policy separates the two honestly.
What a policy that actually works contains
From our research across the European field of policy templates and generators, the sections that carry weight:
| Section | Why it matters |
|---|---|
| Approved-tools register | The operative control against shadow AI: which tools, what approval state, what data may enter each |
| Data classification + prohibited inputs | A traffic-light model people can apply in seconds, plus the never-list |
| Human review rules | AI output is a draft until a person has checked it; four-eyes for anything published |
| Transparency duties | The Art. 50 findings for your specific use, not boilerplate |
| Private accounts + reporting | A reporting path that is protective, not punitive, so shadow use surfaces instead of hiding |
| Training | The Art. 4 hook, with a cadence |
| Incidents | Who to tell, how fast, and why speed beats certainty (GDPR's 72 hours) |
| Owner + review triggers | A named owner and concrete triggers, not just an annual date |
The register is the section most templates fail. A policy that says "use AI responsibly" governs nothing; a register that says "these five tools, these data tiers, requests for new tools go here" governs everything, and it is also where the shadow-AI problem, the reason most companies write a policy at all, actually gets solved.
Generate one instead of starting from a blank page
Our AI policy generator assembles the policy above from structured answers: your role under the Act (including the white-label trap), your tools with per-tool data limits, your rules, your governance. Every section cites the specific obligation behind it, from the AI Act and GDPR to ISO/IEC 42001 control ids and NIST AI RMF GOVERN subcategories. It runs entirely in your browser, nothing you enter leaves your device, and no AI model writes any part of the document, which for a legal-adjacent artifact is a feature. We used it to generate our own AI policy.
Sources
- Regulation (EU) 2024/1689, Article 4
- Regulation (EU) 2024/1689, Article 50
- Commission FAQ on Article 50
- Digitaliseringsstyrelsen FAQ on the AI Regulation
Συχνές ερωτήσεις
Is an AI policy legally required in the EU?
No law names an 'AI policy' as a mandatory document. Article 4 of the AI Act requires promoting AI literacy in staff, and Article 50 imposes transparency duties; a written policy is the practical way to discharge both and to evidence accountability, which is why regulators and auditors expect to see one.
What should an AI policy contain at minimum?
Scope, an approved-tools register with data limits per tool, prohibited inputs, human-review rules, the transparency duties that apply to your use, private-account rules with a reporting path, training, incident handling, and a named owner with a review cadence.
Why is the approved-tools list the most important section?
Because shadow AI is the actual risk: employees pasting company data into unapproved tools. A policy without a concrete, maintained tool register with per-tool data limits governs nothing.
Can we generate a usable policy instead of writing one from scratch?
Yes. Our free generator assembles one deterministically from structured answers, with every section citing the legal obligation behind it, and no AI model writes any part of the document.