AI policy for employees: what to include, with a template
What belongs in an AI policy for employees: approved tools, which data may go in, human review, a named contact. With a template for teams of 5 to 50.
An AI policy for employees settles five things: which AI tools are approved, which data may go in and which never, that every output is checked before it is used, who decides when someone is unsure, and who gets trained. For a company of 5 to 50 people, that fits on one or two pages. There is a template below that you can adapt.
This is not legal advice. It is what European regulators recommend, translated into what a small company can actually run.
Does a small company need an AI policy at all?
No law asks for a document called "AI policy". The duties it covers do exist.
Article 29 GDPR says that anyone acting under your authority may process personal data only on your instructions. When a project manager pastes a client email with names and contract details into a chat window, that is processing. If nobody told them how to handle it, the gap is the company's, not theirs.
Germany's data protection authorities spell this out in their guidance on AI and data protection (DSK, May 2024). Section 2.2 recommends clear, documented internal instructions on whether, under which conditions and for which purposes each AI application may be used, ideally with concrete examples of allowed and forbidden uses.
Then there is the AI Act. Since February 2025, companies that use AI have to take measures for their staff's AI literacy. Your current policy is part of what you document for that. More in the article on AI literacy under Article 4.
What does a regulator tell its own staff?
Spain's data protection authority published its internal policy on generative AI in November 2025 and a summary of obligations in January 2026. It is written for a public body, and the AEPD says it is not a way of applying the AI Act. Still, the rules it states explicitly to its own people are a useful benchmark:
- no AI systems that are not in the organisation's inventory
- results are reviewed and validated by hand before use or publication
- no confidential information, personal data or non-public information goes in
- intellectual property is respected
If the regulator holds itself to that, a one-page policy for a twenty-person agency is not overkill.
What should an AI policy include?
Eight building blocks.
Scope. Who it covers: employees, temps and freelancers working for you. And which work: anything done in the company's name, on any device.
Approved tools. A list with product and plan, not a category. "ChatGPT" is too vague, because a free personal account and a business plan with a data processing agreement are different things. The DSK recommends that employers provide the accounts so nobody has to use a personal one (section 2.4). Why the plan matters is covered in Is ChatGPT GDPR compliant?.
Which data may go in. The core. It works best as a traffic light, see below. The DSK points out that removing names and addresses is often not enough, because people can be identified from context (section 3.1).
Human review. Every AI output is read before it is used. Figures, deadlines, names and quotes are checked against the source. Whoever sends a text owns it.
What AI does not decide. Hiring, dismissals, a customer's creditworthiness: a person decides. AI can prepare, it does not decide.
Other people's rights. No confidential client or partner documents in tools that are not approved. For anything published, check that no third-party content was copied.
A named contact. A person, not a department. Anyone unsure asks before uploading.
Training and review date. Everyone who gets the policy gets a walkthrough. And the policy carries a date for its next review, because tools change faster than any internal rule.
Which data belongs in which category?
Examples from a typical office:
| Light | Examples |
|---|---|
| Green: any approved tool | public texts, your own drafts without names, general professional questions, translating a product description |
| Amber: only the approved company tool | client emails, quotes, contracts, internal minutes, price calculations |
| Red: no AI tool, unless explicitly approved | health data, salaries, job applications, bank and ID details, anything under professional secrecy |
Amber is where the real work is, and where AI saves time. It needs a tool with a data processing agreement and company accounts. Without one, amber turns into red in practice, and your team drifts back to personal accounts.
What does a template look like?
Replace the square brackets with your details and delete what does not apply.
- Purpose. [Company] uses AI to get routine work done faster. This policy sets out how to do that safely.
- Scope. It applies to everyone working for [Company], including temps and freelancers, and to all work done in the company's name.
- Approved tools. Only [tool, plan] is allowed, always with the company account. Personal accounts and browser extensions are not used for work.
- Data. Green goes into any approved tool. Amber only into [tool]. Red into none. The list of examples is attached.
- Review. Every AI output is read and checked before use. Figures, deadlines, names and quotes are verified at the source. Whoever sends a text is responsible for it.
- Limits. AI makes no decisions about people. It prepares, a person decides.
- Questions and mistakes. The contact is [name]. Anyone who enters red data by mistake tells [name] straight away, so the company can react in time.
- Training. Everyone gets a walkthrough before first use. New starters in their first week.
- Validity. Version of [date]. Next review on [date].
Do employee representatives have a say?
It depends on the country and on the use.
In Germany, section 90 BetrVG requires the employer to inform the works council in good time when planning work processes "including the use of artificial intelligence". Rules on employee conduct and tools that can monitor behaviour or performance fall under section 87 BetrVG and need the council's agreement. A tool with a usage dashboard can qualify.
In Spain, article 64.4.d of the Workers' Statute gives the works council the right to be told the parameters and rules of AI systems that affect decisions on working conditions, hiring or profiling. AI that helps draft emails does not trigger it. AI involved in shifts, recruitment or appraisals does.
Without employee representatives, you issue the policy as a company instruction and keep a signed acknowledgement.
How do you roll it out so people actually follow it?
A PDF sent by email gets ignored. Three things make the difference.
Present it in a team meeting using the traffic light examples, and ask which cases are missing.
Pair it with training. The DSK recommends raising awareness through training, guidelines and conversations (section 2.7). That is the same measure you document for Article 4.
And have the approved tool ready on the same day. A rule that bans personal accounts without offering an alternative only moves the use out of sight. The article on shadow AI in the workplace walks through it.
Which parts of the policy can a tool take over?
Some points in the template are organisational, others can be secured technically. Verselo is an AI workspace for small and mid-sized companies and covers the technical ones:
- Company accounts, not personal ones. You invite your team as admin and assign roles. When someone leaves, access is revoked in one click.
- Allowed models and retention. Admins decide which models may be used and how long chats are kept: unlimited, 30, 90 or 365 days. An audit log records twelve months of activity. More under Admin & control.
- Amber has a home. The AI runs in EU data centres, and customer data trains no model. One exception: with web search, the search terms go to Google, and admins can switch web search off. Details on the security page.
- Good use built in. Reviewed prompts sit in the shared library, and recurring tasks run through assistants with fixed instructions.
The data processing agreement comes at launch. What no tool does for you: decide what counts as amber or red in your company, who reviews and whom people ask. That goes in your policy, and you write it.
Frequently asked questions
Is an AI policy for employees a legal requirement in the EU?
No law requires a document with that name. The duties behind it are real, though: under Article 29 GDPR, anyone working for you may process personal data only on your instructions, and Article 4 of the AI Act requires measures for AI literacy. Data protection authorities such as Germany's DSK recommend documented internal instructions with examples. A written policy is the simplest way to give them and to prove it.
What should never go into an AI tool at work?
Health data, salaries, job applications, bank and ID details, and anything under professional secrecy, unless explicitly approved and the tool is set up for it. Removing names is not enough, because people can often be identified from context. Spain's data protection authority, the AEPD, forbids its own staff from entering personal data or non-public information into unauthorised systems.
Do we need to involve employee representatives?
Often, yes. In Germany, the employer must inform the works council when planning the use of AI (section 90 BetrVG), and rules on conduct or tools that can monitor performance require its agreement. In Spain, the works council has a right to be informed about AI systems that affect decisions on working conditions or hiring (article 64.4.d of the Workers' Statute). Check the rules where your staff work.
How does Verselo help enforce an AI policy?
Verselo enforces the technical part of the policy inside the tool: company accounts instead of personal ones, allowed models set by the admin, a chosen retention period for chats, web search that can be switched off, and an audit log covering twelve months. The organisational part stays with you. No tool decides which data may go in or who reviews the output.