Most AI policies do not fail because they are legally unsound. They fail because nobody reads them. Here is what belongs in one — and how to write it so that it changes what people actually do on a Tuesday afternoon.
Three things at once. It has to make employees capable of acting, protect the company legally, and be comprehensible to an outsider — a customer's procurement team, an auditor, a regulator. Most drafts manage the second and third and fail at the first.
A working test: if a new colleague reads it in ten minutes and afterwards knows what she is allowed to do, it is a good policy. If she finds fifteen pages of legal prose, she will not read it, and you have a document rather than a rule.
The incident rule. What happens when somebody has accidentally pasted customer data into a public AI tool? Without a clear, blame-free procedure, nobody reports it — and you never find out.
Wording that works: "Anyone who has inadvertently entered confidential data must report it to the AI lead without delay. A prompt self-report carries no employment consequences. We will then assess together whether a notification duty arises under data protection law."
The second sentence is the load-bearing one. Without it you receive no reports — and without reports you cannot meet the 72-hour notification deadline in Article 33 GDPR, which runs from the moment the controller becomes aware, not from the moment somebody feels ready to mention it.
Under Directive (EU) 2016/943, information qualifies as a trade secret only where it is secret, has commercial value because it is secret, and has been subject to reasonable steps under the circumstances to keep it secret. That third limb is a test you either pass or fail, and it is assessed after the fact, in a dispute, by a court.
A written AI policy that names which categories of information must not be entered into AI tools is one of the cheapest "reasonable steps" available. Its absence works the other way: if staff routinely paste pricing models and customer lists into a public chatbot and no rule ever told them not to, the argument that you took reasonable steps becomes considerably harder to make. The UK regulations implementing the same directive apply the same test, and US trade secret law asks a materially similar question about reasonable measures.
This is worth spelling out because it converts the policy from a compliance cost into an asset-protection measure — which is usually the version that gets budget approved.
Whether formal consultation is required depends on where your people are, and the answer differs sharply across Europe. Some general points hold everywhere:
Practical advice that holds regardless of jurisdiction: involve employee representatives early and voluntarily, including where you are not obliged to. A policy developed jointly gets carried; one imposed from above gets worked around. For larger rollouts, a formal agreement with the representative body is the cleaner route.
A policy distributed by email is dead on arrival. What works:
Every change gets a version number and a date. Every version is archived rather than overwritten. Every material change is communicated, with acknowledgement recorded.
Because an auditor does not ask "do you have a policy?" They ask: "how do I know your people are working to the current version?" That is the question most organisations cannot answer, and it is answered entirely by process, not by drafting.
If you have people in more than one country, resist the temptation to write a separate policy per jurisdiction. The substance — approved tools, prohibited inputs, review duty, labelling, incidents — is the same everywhere. Put the differences in a short annex: which employee representation applies, which national data protection specifics bite, and which language versions are authoritative.
The same applies if you are outside the EU but your output reaches it. Under Article 2 the AI Act follows the output, so the labelling and literacy sections of your policy have to hold for anything that lands in the Union — even where the rest of the policy is drafted against domestic law.
The labelling section is the one most often out of date, because it is the one that touches the outside world. Our free AI labels cover the wording and the design for it, and the compliance kit includes the policy template with all nine components, the incident wording and the version log already in place.
Not expressly. It is, however, the most practical way to implement and evidence the duties under Articles 4 and 50 of the AI Act. It also counts as an organisational measure under Article 32 GDPR and as a reasonable step to keep information secret under the EU Trade Secrets Directive (EU) 2016/943.
It depends on where your people are. Where a works council or equivalent body exists, rules of this kind normally require consultation or co-determination, and in several member states the mere capability of a system to monitor performance or conduct is enough to trigger the right. In jurisdictions without works councils, information and consultation regulations and ordinary employment law still require proper communication before the policy can support any sanction.
Short enough to be read in ten minutes. Two to four pages is enough for most companies if the drafting is concrete.
Two. Abstract phrasing such as “sensitive data” with no examples from the business itself — and the absence of a blame-free incident report route. Without the latter you never hear about mistakes, and you cannot meet the 72-hour deadline in Article 33 GDPR.
No. Keep one policy with a short annex for national differences — which employee representation applies, which local data protection specifics bite, which language version is authoritative. The substance is the same everywhere.
The free quick check walks through ten points — AI inventory, training status, transparency duties, responsibilities. Two minutes, no sign-up, an honest result and your concrete gaps.
Start the quick check — free