Why does every company need a written AI policy?
Because without one, every employee sets their own limits — and the decision gets made under deadline pressure. Pasting a client document into a Prompt is a disclosure to a third party, with real consequences under GDPR and confidentiality obligations.
Under GDPR, sending personal data to an external AI tool is processing that needs a legal basis and, typically, a data-processing agreement with the vendor. Fines reach up to 20 million euros or 4% of global annual turnover. A company that never regulated AI use struggles to show it meets its data-minimization and security duties — a gap covered in depth in our guide to safe AI adoption for business.
What must the policy include — and what fails?
A working policy answers three plain questions: what may I use, what must I never enter, and what do I do when I still need AI on a sensitive document. A blanket ban answers none of them — it just pushes usage to personal phones, outside all oversight.
- Readable by any employee — no legal jargon; a person should grasp the rules in a minute.
- Offers a permitted path — not just "don't", but "here is how to work on a sensitive document: anonymize first, then use AI".
- Names an owner — one role that approves new tools and answers questions.
- Stays alive — reviewed and updated, because both the tools and the regulation keep changing.
The ready outline: seven sections to adopt
Here is a skeleton you can adopt almost as-is and adapt to your organization — seven sections, from purpose to enforcement:
- Purpose — enable productive use of AI while protecting personal data, trade secrets and client information, and complying with data-protection law and contractual confidentiality.
- Approved tools — a closed list of vetted AI tools, including which tier (consumer/business). Anything not on the list is off-limits until the policy owner approves it.
- Prohibited data — never enter into an AI tool: identifiable personal data (names, ID numbers, phone numbers), health or financial data, trade secrets, proprietary code, client and supplier details, or anything classified confidential. Full breakdown in what not to paste into ChatGPT.
- Anonymization duty — a document containing prohibited data must be anonymized before entering any AI tool: remove or consistently replace every identifier, and clean the file's Metadata. If a replacement map is kept, it stays inside the organization only.
- Responsibility — each employee is accountable for what they enter; a named owner approves tools, maintains the policy and answers questions. Any exposure incident is reported to the owner immediately.
- Training — every employee gets a short onboarding session and periodic refreshers: what's allowed, what's not, and how to anonymize in practice.
- Enforcement — violations are handled proportionally, from refresher training to disciplinary process; exposure of personal data is also treated as a security incident under existing procedures.
How do you make the policy work day to day?
The section that turns a policy from a drawer document into a working tool is the anonymization duty — because it gives employees a green lane. Instead of wondering whether something is allowed, they know: a document with identifiers goes through anonymization first, then into any approved tool.
For that to actually happen, the tool must be available and effortless. If anonymizing takes ten minutes of manual work, it gets skipped. If it's a button in the browser, it becomes a habit.