KlarComply
Language:DEENNL
HomeKnowledge › Writing an AI policy

The internal AI policy: nine components that belong in it

Most AI policies do not fail because they are legally unsound. They fail because nobody reads them. Here is what belongs in one — and how to write it so that it changes what people actually do on a Tuesday afternoon.

What a policy has to achieve

Three things at once. It has to make employees capable of acting, protect the company legally, and be comprehensible to an outsider — a customer's procurement team, an auditor, a regulator. Most drafts manage the second and third and fail at the first.

A working test: if a new colleague reads it in ten minutes and afterwards knows what she is allowed to do, it is a good policy. If she finds fifteen pages of legal prose, she will not read it, and you have a document rather than a rule.

The nine components

  1. Scope — who it applies to and which tools it covers. Say explicitly whether it binds contractors and agencies, because Article 4 of the AI Act extends to persons acting on your behalf.
  2. Approved tools — an exhaustive list, or a reference to the AI inventory. Do not maintain the same list twice.
  3. Prohibited inputs — personal data, trade secrets, third-party information held in confidence, security credentials, unpublished financial figures.
  4. Review duty — human checking before anything has an external effect. This is also the clause that carries the Article 50(4) editorial-responsibility exemption.
  5. Labelling rule — when and how AI content is disclosed under Article 50. Name the channels: website, social media, phone line, brochures.
  6. Approval process — how a new tool is requested and cleared, with a stated turnaround. Without a turnaround, people route around the process.
  7. Responsibilities — who decides, who is the point of contact, who holds editorial responsibility for published text.
  8. Incident procedure — what to do when something confidential went in anyway.
  9. Consequences of breach — the employment-law framework, proportionately drafted and consistent with your other policies.

Three techniques that make the difference

The section that is missing almost everywhere

The incident rule. What happens when somebody has accidentally pasted customer data into a public AI tool? Without a clear, blame-free procedure, nobody reports it — and you never find out.

Wording that works: "Anyone who has inadvertently entered confidential data must report it to the AI lead without delay. A prompt self-report carries no employment consequences. We will then assess together whether a notification duty arises under data protection law."

The second sentence is the load-bearing one. Without it you receive no reports — and without reports you cannot meet the 72-hour notification deadline in Article 33 GDPR, which runs from the moment the controller becomes aware, not from the moment somebody feels ready to mention it.

Trade secrets: the argument nobody makes

Under Directive (EU) 2016/943, information qualifies as a trade secret only where it is secret, has commercial value because it is secret, and has been subject to reasonable steps under the circumstances to keep it secret. That third limb is a test you either pass or fail, and it is assessed after the fact, in a dispute, by a court.

A written AI policy that names which categories of information must not be entered into AI tools is one of the cheapest "reasonable steps" available. Its absence works the other way: if staff routinely paste pricing models and customer lists into a public chatbot and no rule ever told them not to, the argument that you took reasonable steps becomes considerably harder to make. The UK regulations implementing the same directive apply the same test, and US trade secret law asks a materially similar question about reasonable measures.

This is worth spelling out because it converts the policy from a compliance cost into an asset-protection measure — which is usually the version that gets budget approved.

Consulting the workforce

Whether formal consultation is required depends on where your people are, and the answer differs sharply across Europe. Some general points hold everywhere:

Practical advice that holds regardless of jurisdiction: involve employee representatives early and voluntarily, including where you are not obliged to. A policy developed jointly gets carried; one imposed from above gets worked around. For larger rollouts, a formal agreement with the representative body is the cleaner route.

The first thirty days

A policy distributed by email is dead on arrival. What works:

Versioning: the question an auditor actually asks

Every change gets a version number and a date. Every version is archived rather than overwritten. Every material change is communicated, with acknowledgement recorded.

Because an auditor does not ask "do you have a policy?" They ask: "how do I know your people are working to the current version?" That is the question most organisations cannot answer, and it is answered entirely by process, not by drafting.

Cross-border teams: one policy, one annex

If you have people in more than one country, resist the temptation to write a separate policy per jurisdiction. The substance — approved tools, prohibited inputs, review duty, labelling, incidents — is the same everywhere. Put the differences in a short annex: which employee representation applies, which national data protection specifics bite, and which language versions are authoritative.

The same applies if you are outside the EU but your output reaches it. Under Article 2 the AI Act follows the output, so the labelling and literacy sections of your policy have to hold for anything that lands in the Union — even where the rest of the policy is drafted against domestic law.

When you have to touch the policy again

The labelling section is the one most often out of date, because it is the one that touches the outside world. Our free AI labels cover the wording and the design for it, and the compliance kit includes the policy template with all nine components, the incident wording and the version log already in place.

Frequently asked questions

Is an internal AI policy required by law?

Not expressly. It is, however, the most practical way to implement and evidence the duties under Articles 4 and 50 of the AI Act. It also counts as an organisational measure under Article 32 GDPR and as a reasonable step to keep information secret under the EU Trade Secrets Directive (EU) 2016/943.

Do employee representatives have to agree to the AI policy?

It depends on where your people are. Where a works council or equivalent body exists, rules of this kind normally require consultation or co-determination, and in several member states the mere capability of a system to monitor performance or conduct is enough to trigger the right. In jurisdictions without works councils, information and consultation regulations and ordinary employment law still require proper communication before the policy can support any sanction.

How long should an AI policy be?

Short enough to be read in ten minutes. Two to four pages is enough for most companies if the drafting is concrete.

What is the most common mistake?

Two. Abstract phrasing such as “sensitive data” with no examples from the business itself — and the absence of a blame-free incident report route. Without the latter you never hear about mistakes, and you cannot meet the 72-hour deadline in Article 33 GDPR.

We have staff in several countries. Do we need one policy per country?

No. Keep one policy with a short annex for national differences — which employee representation applies, which local data protection specifics bite, which language version is authoritative. The substance is the same everywhere.

Where does your company stand?

The free quick check walks through ten points — AI inventory, training status, transparency duties, responsibilities. Two minutes, no sign-up, an honest result and your concrete gaps.

Start the quick check — free
Read on AI literacy obligation → Building an AI inventory → Labelling AI content (Art. 50) → The AI Act for SMEs →
Sources:
Article 26 EU AI Act — obligations of deployers
Article 50 EU AI Act — transparency obligations
Article 32 GDPR — security of processing
Article 33 GDPR — notification of a personal data breach
Directive (EU) 2016/943 — protection of trade secrets (reasonable steps)
Regulation (EU) 2024/1689 — official consolidated text, EUR-Lex
Reviewed on 2 August 2026 · Reflects the Digital Omnibus · This article is general information and not legal advice.
Legal notice·Privacy·Terms·[email protected]