Itjoe
ENNL

AI policy

An AI policy that fits one sheet and that people actually read.

Seven rules, each with the reason it is there. You can copy and adapt them below. No form, and no download that costs you an email address first.

What an AI policy is and isn't

01 · The scope

It is a working agreement, not a legal document. It describes what people do and don't do on a Monday morning, in language they understand without explanation.

It does not replace your processing agreements and it is not a risk assessment. Those two already exist or need to, but they are separate from this. This document is about behaviour, and you don't change behaviour with a reference to a regulation.

The policy is step four of the four Article 4 implies: inventory, level assessment, training, recording. The other three are worked out on the checklist. Start here without those three and you have a document with nothing underneath it.

Not legal advice

This is how we read it from the training side, in plain language. For a legal assessment of your situation you need a lawyer; we supply the material such an assessment rests on.

The template, seven rules

02 · Copy it

Copy them, drop what does not fit and fill in what belongs to you. The rule is on the left, the reason it is there on the right. That second part is what you have to be able to explain.

  1. 01

    Which tools are allowed, and which are not

    Without this rule everyone uses whatever they find. Name them, and name one that is not allowed, otherwise the list reads as a recommendation.

  2. 02

    What never gets entered

    Personal data, medical data, source code, third-party quotes. Be concrete: 'be careful with sensitive information' is not a rule but a feeling.

  3. 03

    Where a human belongs in between

    Name the decisions that never leave unchecked. Usually that is anything affecting a customer, a patient or a citizen.

  4. 04

    How you check the output

    Figures, quotes, names and sources are the four places it goes wrong. List those four and you have a check rather than an appeal to be alert.

  5. 05

    What you disclose and what you don't

    Does a text need to say AI helped write it? Pick one line and write it down. Disclosing halfway is more confusing than not disclosing at all.

  6. 06

    Who to go to

    One name, not a mailbox. Without a contact point, doubtful cases are not reported but resolved by guessing.

  7. 07

    When this document gets reviewed

    Put a date on it. An AI policy without a review date is demonstrably out of date within a year, and that is exactly what a regulator sees.

Writing it down is the easy part

03 · Enforcing it

A policy nobody has read is worth as much in an audit as no policy at all. The difference is in what you can show.

Three things make the difference. That you can show who read it and when. That there is one name on it people can turn to. And that it carries a date on which it gets reviewed again.

The first is where most organisations fall short. An attendance list from a training proves attendance, not understanding. What you need for that is a measurement before and after, and that difference is the only figure showing something changed. How that works is on AI literacy.

Questions about AI policy

04 · Short answer

Is an AI policy legally required?

The word policy does not appear in the law. Article 4 of the AI Act asks for a sufficient level of AI literacy, and you have to be able to justify that. A written agreement is the cheapest way to do so, but the form is free and there is no prescribed template.

How long should such a document be?

One sheet. The standard is proportionality, not completeness. Seven rules that hold up and that people have actually read are stronger than forty pages nobody checked, and they can be produced in an afternoon.

Who draws it up?

In practice it works best when IT and the business write it together and legal reviews it. If legal writes it alone you get a document nobody on the floor uses. If IT writes it alone it misses the cases that actually matter.

What if someone doesn't follow it?

Then the first question is whether the rule was clear and whether the person knew it. Which is why recording who was trained belongs with the policy: without it, enforcement cannot be explained. The sanctions side belongs in your existing code of conduct, not in this document.

Read it yourself

05 · Sources

The template above is our interpretation, not legal text. At the bodies themselves you can read what is actually required.

Read on

  • The plan

    The four steps from inventory to file, of which this policy is the last.

  • What Article 4 asks

    The legal text in plain language, with the timeline and what enforcement means.

  • The course underneath

    A policy only works once people understand why those rules exist.

The policy is written, now what?

Recording who has read it is the part most organisations skip. In half an hour we show how the measurement and reporting solve that, using sample data.