The internal AI policy
A policy nobody reads does not move the risk, it only records it. Short, concrete rules covering a few approved tools work better than a rulebook covering everything.
In most companies AI is already in use, merely unregulated. A policy brings that use into a frame where it stays traceable. It is not an end in itself but the instrument through which several duties can be met at once.
What belongs in it
- Which tools are approved, on which account and under which contract
- Which content must not be entered: personal data of certain categories, trade secrets, confidential third party material
- That results are checked before use, and against what
- When a result has to be labelled, towards customers and internally
- Who decides whether a new tool may be used, and how long that takes
- What to do after a mistake, who is told and how it is handled
- That breaches can have employment consequences
The most common mistake
Rarely works
- Twenty pages restating the legal framework
- Abstract appeals to care with no example
- A ban on everything not expressly permitted
- An approval process that takes months
Works
- Two pages saying what is allowed and what is not
- Concrete examples from your own working day
- A short list of approved tools that is kept current
- A route to have a further tool assessed within days
How we work
Step 1: Take stock
What is actually being used, on which accounts? This question regularly brings more to light than expected and shapes the rules that follow.
Step 2: Approve tools
For the tools in use we settle the contractual position, the data flow and the role under the AI Act, and we sort out what stays and what is replaced.
Step 3: Write the rules
Short, in the language of the business, with examples. What cannot be read in two minutes will not be read.
Step 4: Settle co-determination
Where a works agreement is the right route, we draft it and support the negotiation.
Step 5: Train
The duty of AI literacy is met by teaching, not by circulating a document.
What the AI literacy duty demands in detail is set out under AI literacy.
Rules that land in daily work?
We write the policy so that it gets read and followed.
Discuss the policyFrequently asked questions
Do we need a policy at all?
There is no statutory duty to produce such a document. Several duties can, however, only be met this way in practice: training for AI literacy, oversight of use, and the protection of trade secrets. Without a written rule there is also no basis on which to react to a breach.
Does the works council have to be involved?
As soon as the policy orders conduct in the workplace, or concerns a tool capable of monitoring conduct or performance, co-determination should be assumed. In practice it is usually better to aim for a works agreement than to issue a unilateral instruction that gets challenged later.
Should we ban tools?
A blanket ban generally leads to private accounts being used, and with that all visibility is lost. A short list of approved tools with clear limits on what may be entered works better, together with a simple route to have a further tool assessed.