PRACTICAL GUIDE · UPDATED 27 JULY 2026

Write an AI use policy your team can actually follow.

A useful policy does more than say “use AI responsibly.” It tells people which tools they may use, what must never be entered, when a human must check the output and who to ask when the answer is unclear.

The nine decisions your policy should settle

  1. Purpose. Say why the team uses AI and what the policy is meant to prevent or improve.
  2. Scope. Name the people, contractors, tools and work covered by the policy.
  3. Approved tools. Explain who can approve a tool and where the current approved list lives.
  4. Data boundaries. State whether personal, client, confidential, copyrighted or security-sensitive information may be entered.
  5. Human review. Define which outputs need checking and who remains accountable for the final work.
  6. Disclosure. Explain when customers, colleagues or the public should be told that AI was used.
  7. High-impact uses. Require escalation before AI affects hiring, performance, access, safety, credit, health or other consequential decisions.
  8. Incidents and uncertainty. Give people a named contact and a simple route for mistakes, leaks, bias or unclear cases.
  9. Ownership and review. Name the policy owner, an effective date and a realistic review cycle.

Why this matters now in the EU

The European Commission says the AI Act’s transparency rules apply from 2 August 2026. Those rules concern specific situations, including people interacting with AI and certain AI-generated or manipulated content. The exact obligation depends on whether an organisation is a provider or deployer and on the use case.

That does not mean every small business suddenly needs the same disclosure label. It does mean teams should be able to answer basic operational questions: Where do we use AI? Who checks it? When do we disclose it? What information is off limits? The Commission’s current AI Act overview and Article 50 transparency facts are sensible starting points for legal review.

A short rule is better than a vague principle

TOO VAGUE

“Employees should use AI safely and responsibly.”

MORE USEFUL

“Do not enter client data into a public AI tool. Use only tools on the approved list. A named employee must check factual claims before work reaches a client.”

Questions to ask before adoption

BUILD THE WORKING DRAFT FIRST

Turn your answers into an editable AI use policy.

Create and review the complete draft for free. Pay once only if you decide to export it.

Create my free draft → No account · No card required to draft · Practical guidance, not legal advice

Frequently asked questions

Is an AI use policy legally required?

Requirements depend on the organisation, role and use case. The EU AI Act contains obligations for particular providers and deployers; other laws, contracts or regulated activities may also matter. Get qualified advice for a legal conclusion.

How long should a small-team AI policy be?

Long enough to settle real decisions, short enough to use. A concise policy with named owners, concrete examples and a review date is usually more useful than a long document copied from another organisation.

Can we use a template unchanged?

No template knows your approved tools, contracts, data, customers or escalation routes. Use a template as a structured first draft, then edit and approve it internally.