Skip to content
Back to blog
GovernanceCompany AI policy and employee rules in 2026

Company AI Policy: Seven Rules Employees Can Follow

A useful company AI policy names approved tools, data classes, review duties, incident reporting, training, and an owner. Build the rules around the tools and data your people actually use, then keep the document short enough to follow.

A usable policy makes approved AI work easier to follow. It names tools, data classes, review duties, incident contacts, training, and the owner who keeps the rules current.

Author

Syntalith

Published Updated 7 min read

A company AI policy is an operating document. It tells an employee which tool to open, which account to use, which data class is allowed, who reviews the result, and where to report a mistake. The best version fits the company's actual work and has an owner who updates it.

The EU AI Act places an AI literacy duty in Article 4. The European Data Protection Board's report on large language models discusses privacy risks and mitigations. Use those sources with your organisation's adviser when assigning duties.

What the policy must decide

Write one clear rule for each item:

  1. Approved tools and accounts. Name the service, plan, region, and company account. Record who approves a new tool.
  2. Data classes. State which material may enter each approved tool and which material requires a different route.
  3. Disclosure. Set the cases where a recipient is told that AI helped create text, audio, an image, or a decision support record.
  4. Human review. Name the work that requires a person to check facts, sources, tone, and any commitment before release.
  5. Incident reporting. Give employees one contact and one short form for an accidental upload, an incorrect result, or an account problem.
  6. Training. Link to the training record, examples, and instructions for each approved tool.
  7. Ownership. Name the policy owner, the security and process contacts, and the next review date.

Each rule should answer who acts, what record they keep, and what happens when a case falls outside the rule.

Data classes and account rules

Employees need a table they can consult during work:

Data classEveryday ruleRequired route
Public materialMay enter an approved toolCompany account and ordinary review
Internal working materialUse only with an approved company accountOwner confirms the tool's retention and access settings
Personal dataUse only for a documented purpose and approved data routePrivacy owner confirms the processing arrangement
Confidential commercial materialKeep within the approved environmentAccess is limited to the assigned team and recorded
Customer or partner materialFollow the contract and the agreed tool listProcess owner confirms permission before use

The table is a starting structure. Replace the labels with the classes the company already uses in its information policy. A private account belongs outside the approved route because the company cannot administer its access, retention, or deletion.

The approved-tool register

Keep a small register beside the policy. Each row should include:

  • service and plan,
  • business owner,
  • allowed data classes,
  • retention and deletion settings,
  • identity and access method,
  • connected systems,
  • review date and approval record.

The register turns a general rule into a choice an employee can make in seconds. It also gives the security owner a list to check when an account closes or a contract changes.

Review before an external result

The policy should name work that needs human acceptance. Examples include a customer message, a published document, a financial commitment, a change in a company record, or a recommendation that affects another person's rights or access.

The reviewer checks the source, required fields, tone, permissions, and destination. The record can be as small as an approval field, a link to the source, and the reviewer's name. The process owner decides which results need a second review.

A short incident route

Give employees a route they will use under pressure:

  1. Stop further sharing or automated sending.
  2. Preserve the prompt, output, source, account, and time when safe to do so.
  3. Contact the named policy owner or security contact.
  4. Record who received the data and which systems were affected.
  5. Let the owner decide the follow-up, notification, and rule change with the qualified privacy or security adviser.

Training should rehearse one harmless example so the route is familiar. The policy describes the action; the company's incident plan describes the investigation.

Training and review records

Keep a simple record of who received the instruction, which tools it covered, and when the next update is due. Article 4 of the EU AI Act is the primary source for the AI literacy requirement. The policy owner should review the tool register when a provider changes its plan, retention, or connected systems.

An annual calendar entry is useful, with an earlier review after a serious incident, a new high-impact use, or a material provider change.

When a one-page policy is enough

A small team with a short approved-tool list can begin with one page containing:

  • the approved accounts,
  • a red list of data,
  • the human-review rule,
  • the incident contact,
  • the training link,
  • the owner and review date.

Add a separate register when tools, departments, or data classes multiply. A longer document becomes useful when different teams have different permissions or when the company needs evidence of review.

Questions for management

Which tool should the policy approve? Start with the tools the team already needs. Security and process owners then check the plan, data route, access controls, and retention before adding it to the register.

Can the policy ban personal accounts? The company can set the account rule it can enforce. Pair an account restriction with an approved alternative, a clear data table, and a reporting route so employees have a workable path.

Who owns the policy? Choose one person with authority to maintain the register and convene security, privacy, HR, and process owners. Put the next review date in the document.

How much does a tailored policy cost? The effort depends on the tool list, data classes, and number of teams. A free process scan can identify the shortest useful document. Current Syntalith team training starts from €1,200 per day, and the pricing page contains the current offer.

Bring the existing tool list and one real use case to the scan. The output can be a one-page policy, a fuller register, or a training plan with named owners.

Frequently asked questions

Can employees use ChatGPT at work?
They can use an approved business account under the company's data and review rules. The policy should name the account, the allowed data classes, the required review, and the incident route.
What should an employee AI policy contain?
Set seven decisions: approved tools and accounts, data classes, disclosure, human review, incident reporting, training, and ownership with a review date. Map each decision to the company's real work.
Does the EU AI Act require one company policy document?
Article 4 requires providers and deployers to take measures for AI literacy. A single policy can organise the company's response, while the exact duties depend on the systems and roles involved. Confirm the application to your organisation with a qualified adviser.

Free process scan

Start with a free process scan.

  • A 30-minute call with the engineer who would lead the work.
  • A review of the processes that cost you the most time and money.
  • A written summary of what to automate first and the likely cost range.

The scan chooses one process to assess, and within 2 business days you receive a recommendation, including when a simpler route is the better fit.

€0

30 minutes · written takeaway within 2 business days

Book a free process scan (30 min)

Times are shown in your own time zone. We work with clients across time zones.

Describe the process in the form