the employer is liable — Art. 120 of the Polish Labour Code
AI use policy for companies — template and guide
An AI use policy is an internal document that sets out which AI tools staff may use, which data must not be entered into them and who is responsible for the result. It is the basis for demonstrating compliance with the EU AI Act, GDPR and ISO/IEC 42001 — provided it is backed by tools and technical controls. The template also fits public offices and local government units
What an AI use policy is
A policy is a decision of the organisation, not a statement by an employee. Under the AI Act, the employer is the deployer of an AI system used at work — regardless of whose account it is and who pays the subscription. That is why the policy sets rules for the organisation: which tools are approved, how they are approved, who oversees them and how to prove it to an inspector
A policy is an organisational decision, not an employee statement
“I use AI at my own risk” transfers nothing. The employer is liable towards clients (Art. 120 of the Polish Labour Code); the organisation is the deployer and the employer remains the data controller
The organisation decides which tools are approved, how they are approved, what data must not be entered and who is responsible for the result — backed by a company tool
What it must cover
11 sekcji wzoru — każda z odniesieniem do przepisu lub normy
List of data and exceptions — The template includes a list to tailor (annex 2): personal data, trade secrets, client data, information protected by law — plus exceptions for tools with a data processing agreement
What cannot be shifted to employees
An employee’s statement that they use private AI “at their own risk” transfers nothing: towards clients the employer is liable (Art. 120 of the Polish Labour Code), the organisation is the deployer under the AI Act, and the employer remains the data controller under GDPR. An employee’s signature can confirm that they know the rules. It cannot replace a tool, controls or training. More in the article “How much can a lax AI policy cost”
the organisation is the deployer, not the employee
the employer remains the data controller
a service outside the management system is an organisational nonconformity
One employee signature confirms that they know the policy. It cannot replace a tool, controls or training — or transfer the liability that stays with the organisation by law
How to roll out the policy
List the AI tools your staff already use — including private ones
For each use case decide: approve, replace with a company tool or prohibit
Adopt the policy based on the template and tailor the data list to your sector
Provide a company tool and a data control layer before the policy takes effect — a ban with no alternative pushes the problem into shadow AI
Train staff by role and collect acknowledgements of the policy
Review the policy at least once a year and after every change in the law
Check your policy
Which of the 11 template sections do you already have? An instant result: what is missing and what to add first
What your policy already covers
Tick the sections your policy already contains — the result appears immediately, nothing is sent anywhere. If there is no policy yet, the shortest route is the template: Download the template →
Download the template
The template has 11 sections and 3 annexes: a tool register, a list of protected data and an acknowledgement form. It is a starting point — before adopting it, agree it with your DPO and legal counsel
AI use policy template (PDF)
11 sections · 3 annexes: tool register, data catalogue, acknowledgement
Enter your email address — we will send a download link
Sources
- Regulation (EU) 2024/1689 (AI Act), Art. 3, 4, 5, 50
- Regulation (EU) 2016/679 (GDPR), Art. 28, 32, 33
- Polish Labour Code (Act of 26 June 1974), Art. 120
- ISO/IEC 42001:2023 · ISO/IEC 27001:2022
For information only, not legal advice. As of 3.10.2026
Questions about AI use policies
Is an AI use policy mandatory?
The AI Act does not name such a document, but it requires deployers to ensure, among other things, staff AI literacy (Art. 4) and transparency (Art. 50). ISO/IEC 42001 requires an AI policy. Whether it is called a policy or AI usage rules does not matter; what counts is the content and the tools behind it. Without written rules these obligations are hard to prove during an inspection
Is it enough to ban staff from using ChatGPT?
A ban with no company alternative usually moves usage to private phones and accounts, i.e. into shadow AI. It is more effective to approve a safe tool with data controls and logging
Does the policy apply to B2B contractors?
It should. Labour law does not cover them, but the AI Act, GDPR and ISO standards apply to the organisation in the same way, whatever the form of engagement. The rules are worth including in contracts
What data must not be entered into AI tools?
It depends on the tool and the contract with the provider. Tools without a data processing agreement and control over data location should not receive personal data, trade secrets, client data or information protected by law. The template includes a list to tailor
Who should approve the policy?
The management board or head of the organisation, after consulting the DPO, information security and — where one exists — employee representatives
Does a public office need an AI use policy?
Yes, if officials use AI tools — including private ones — with the office’s documents. As a deployer, the office is responsible for citizens’ data (GDPR) and for staff training (Art. 4 of the AI Act). The same template only needs adapting: the office’s document types, the approved tools and the person who approves the output