allclouds.pl
Knowledge

AI use policy for companies — template and guide

An AI use policy is an internal document that sets out which AI tools staff may use, which data must not be entered into them and who is responsible for the result. It is the basis for demonstrating compliance with the EU AI Act, GDPR and ISO/IEC 42001 — provided it is backed by tools and technical controls. The template also fits public offices and local government units

11template sections
3annexes
PDFby email
3.10.2026legal status
01 / 08

What an AI use policy is

A policy is a decision of the organisation, not a statement by an employee. Under the AI Act, the employer is the deployer of an AI system used at work — regardless of whose account it is and who pays the subscription. That is why the policy sets rules for the organisation: which tools are approved, how they are approved, who oversees them and how to prove it to an inspector

OFTEN CONFUSED

A policy is an organisational decision, not an employee statement

Employee statement

“I use AI at my own risk” transfers nothing. The employer is liable towards clients (Art. 120 of the Polish Labour Code); the organisation is the deployer and the employer remains the data controller

vs
AI use policy

The organisation decides which tools are approved, how they are approved, what data must not be entered and who is responsible for the result — backed by a company tool

02 / 08

What it must cover

11 sekcji wzoru — każda z odniesieniem do przepisu lub normy

Template map · 11 sections + 3 annexesEvery section with a legal basis or standard
ANNEXES1 Tool register · 2 Data list · 3 Acknowledgement form
§ 4
Data that must not be entered

List of data and exceptions — The template includes a list to tailor (annex 2): personal data, trade secrets, client data, information protected by law — plus exceptions for tools with a data processing agreement

GDPR Art. 28 and 32
Click a section to see what it sets out and where it comes from — the full text is in the PDFTemplate · as at 3.10.2026
03 / 08

What cannot be shifted to employees

An employee’s statement that they use private AI “at their own risk” transfers nothing: towards clients the employer is liable (Art. 120 of the Polish Labour Code), the organisation is the deployer under the AI Act, and the employer remains the data controller under GDPR. An employee’s signature can confirm that they know the rules. It cannot replace a tool, controls or training. More in the article “How much can a lax AI policy cost”

Towards clients

the employer is liable — Art. 120 of the Polish Labour Code

Under the AI Act

the organisation is the deployer, not the employee

Under GDPR

the employer remains the data controller

Towards an ISO auditor

a service outside the management system is an organisational nonconformity

1

One employee signature confirms that they know the policy. It cannot replace a tool, controls or training — or transfer the liability that stays with the organisation by law

04 / 08

How to roll out the policy

1List tools

List the AI tools your staff already use — including private ones

2Decide

For each use case decide: approve, replace with a company tool or prohibit

3Adopt the policy

Adopt the policy based on the template and tailor the data list to your sector

4Provide a tool

Provide a company tool and a data control layer before the policy takes effect — a ban with no alternative pushes the problem into shadow AI

5Train staff

Train staff by role and collect acknowledgements of the policy

6Review

Review the policy at least once a year and after every change in the law

05 / 08

Check your policy

Which of the 11 template sections do you already have? An instant result: what is missing and what to add first

Tool · checklist

What your policy already covers

Instant result · no e-mail
Tick the sections your policy already contains
0sections in place

Tick the sections your policy already contains — the result appears immediately, nothing is sent anywhere. If there is no policy yet, the shortest route is the template: Download the template →

A checklist, not an audit — compliance depends on the content of a section, not its presence
06 / 08

Download the template

The template has 11 sections and 3 annexes: a tool register, a list of protected data and an acknowledgement form. It is a starting point — before adopting it, agree it with your DPO and legal counsel

AI use policy template (PDF)

11 sections · 3 annexes: tool register, data catalogue, acknowledgement

Enter your email address — we will send a download link

07 / 08

Sources

For information only, not legal advice. As of 3.10.2026

FAQ

Questions about AI use policies

Is an AI use policy mandatory?

The AI Act does not name such a document, but it requires deployers to ensure, among other things, staff AI literacy (Art. 4) and transparency (Art. 50). ISO/IEC 42001 requires an AI policy. Whether it is called a policy or AI usage rules does not matter; what counts is the content and the tools behind it. Without written rules these obligations are hard to prove during an inspection

Is it enough to ban staff from using ChatGPT?

A ban with no company alternative usually moves usage to private phones and accounts, i.e. into shadow AI. It is more effective to approve a safe tool with data controls and logging

Does the policy apply to B2B contractors?

It should. Labour law does not cover them, but the AI Act, GDPR and ISO standards apply to the organisation in the same way, whatever the form of engagement. The rules are worth including in contracts

What data must not be entered into AI tools?

It depends on the tool and the contract with the provider. Tools without a data processing agreement and control over data location should not receive personal data, trade secrets, client data or information protected by law. The template includes a list to tailor

Who should approve the policy?

The management board or head of the organisation, after consulting the DPO, information security and — where one exists — employee representatives

Does a public office need an AI use policy?

Yes, if officials use AI tools — including private ones — with the office’s documents. As a deployer, the office is responsible for citizens’ data (GDPR) and for staff training (Art. 4 of the AI Act). The same template only needs adapting: the office’s document types, the approved tools and the person who approves the output

All questions →

https://www.allclouds.pl/en/wiedza/polityka-korzystania-z-ai-w-firmie-wzor/