Template · Articles 4, 5 and 50 (supporting governance) · Supports duties in force since 2 February 2025
Internal AI Use Policy Template (EU AI Act & GDPR)
An internal AI use policy is the company rulebook for how staff may use AI at work: which tools are approved, what data may go into them, which uses are off-limits, and what to do when something goes wrong. It supports obligations under the EU AI Act (Regulation (EU) 2024/1689) — the Article 5 prohibitions in force since 2 February 2025, the Article 4 literacy duty and the Article 50 transparency duties in force since 2 August 2026 — as well as the GDPR. No single article mandates such a policy; it is the governance layer that makes those duties operational.
Last reviewed: 26 August 2026 · Supports duties in force since 2 February 2025 · Included in the kit as 04_Internal_AI_Use_Policy.docx
What this document is
Document 04 of the RegShelf kit is a twelve-section Word policy whose centre of gravity is a fill-in approved-tools table: per tool, the approved uses, the data allowed and the data explicitly not allowed. Around it sit the rules that stop the two failure modes SMEs actually experience — confidential data pasted into unapproved tools, and unreviewed AI output reaching customers or decisions. The policy also restates the Article 5 prohibited practices in staff-facing language, so the legal red lines live in the same document as the everyday rules.
Who needs it
Any company whose staff touch AI tools — which by now is nearly all of them. The policy applies to employees, contractors, temporary staff and interns, on company or personal devices, in the office or remote, and its definition of "AI tools" deliberately includes AI features inside other software: office suites, design tools, CRMs, meeting transcribers, code assistants and image generators. If you have no written rules today, every one of those tools is being used on individual judgment — and your Article 4 literacy training has nothing to point at as "our rules".
What the law requires — precisely
The policy encodes several duties with dates and limits stated accurately:
- Article 5 prohibitions — most in force since 2 February 2025, with fines up to €35 million or 7% of worldwide turnover; for SMEs and small mid-caps the lower of the two applies (Article 99(6)). The CSAM/NCII prohibitions inserted by Regulation (EU) 2026/1744 apply from 2 December 2026, and for providers of generative systems they are conditional — intended purpose, or a reasonably foreseeable and reproducible outcome absent adequate safeguards. Creating such material may also constitute criminal offences under national law.
- GDPR Article 22 — solely automated decisions with legal or similarly significant effects are prohibited unless an Article 22(2) exception applies (contractual necessity, legal authorisation, explicit consent), each with Article 22(3) safeguards. The template's internal rule — a human reviews every such decision — is stricter than the law and labelled as such.
- DPIAs — required only where processing is likely to result in a high risk to individuals (Article 35(1) GDPR). Many, but not all, AI deployments meet that test; the policy tells staff to run the threshold test, not to assume.
- Article 50 transparency — since 2 August 2026; when you merely use a third-party generative tool, the machine-readable marking duty of Article 50(2) stays with the tool's provider, while deployer duties under Article 50(3)–(4) can be yours.
What's inside the RegShelf template
Twelve sections and four tables:
- Approved AI tools table — tool and account type, approved uses, data allowed, data not allowed;
- Prohibited uses — five company-level bans (confidential data into unapproved tools, unreviewed output in consequential decisions, unreviewed publication, misrepresenting AI work as human, circumvention) plus the Article 5 practices in plain language;
- New-tool request workflow — a three-step approval path with a [10]-working-day decision target, closing the shadow-AI loophole;
- GDPR section — data minimisation, DPAs, Article 22 and the DPIA threshold test;
- Output review table — minimum review by output type, from internal drafts to decisions about people;
- Incident reporting (report within [24 hours], honesty treated favourably), Article 50 day-to-day guidance, enforcement, a 12-month review cycle and a signature block.
How to use it
Complete the approved-tools table first — it is the heart of the policy — then fill the [bracketed] roles and deadlines, keep the Article 5 list intact (add to it, never trim it), and have management sign. Publish it to all staff and reference it in your AI literacy training. The tools table may be updated by the policy owner at any time; the rest is reviewed annually or when the law, your tools or an incident demands it.
Related reading
Frequently asked
Is an internal AI use policy legally required in the EU?+
No article of the AI Act says "adopt an AI use policy". But the Act bans certain practices outright (Article 5), requires AI literacy measures (Article 4) and imposes transparency duties (Article 50) — and a written policy with an approved-tools table is the standard way for an SME to operationalise and evidence those duties alongside the GDPR.
Can employees use free AI tools like ChatGPT for work?+
Under this template, only if the tool is listed in the approved-tools table for that use and data type. Unapproved tools — including free web tools and personal accounts — are not permitted until approved, because unvetted tools are the main route for confidential and personal data leaks.
Does using AI for decisions about people breach GDPR Article 22?+
Not automatically. Article 22 prohibits solely automated decisions with legal or similarly significant effects unless one of three exceptions applies — contractual necessity, Union or Member State law, or explicit consent — each with safeguards including the right to human intervention. The cautious SME practice, which this template adopts as an internal rule, is to have a qualified human review and own every such decision.
What AI uses are banned outright for companies?+
Article 5 prohibits, among others: emotion recognition in the workplace (outside narrow medical/safety exceptions), social scoring, manipulation exploiting vulnerabilities, untargeted facial-image scraping, biometric categorisation by sensitive traits, and crime prediction from profiling alone — most since 2 February 2025. Generating CSAM or non-consensual intimate imagery is prohibited from 2 December 2026 under the amendments made by Regulation (EU) 2026/1744.
Primary sources
- Regulation (EU) 2024/1689 (consolidated)
- Regulation (EU) 2026/1744 (Digital Omnibus on AI)
- Regulation (EU) 2016/679 (GDPR) — Articles 22 and 35
This template ships in the EU AI Act Kit
24 fill-in documents in Word and Excel — launch price €149, twelve months of updates included.
See the full kit