PLBook a call
Menu

Insights

AI use policy for a small business: what to include and how to roll it out

If staff use personal accounts and nobody knows what data reaches the tools, write down short rules. This is a template you can copy. Fill in the square brackets, name the policy owner and check the rules against real tasks before signing.

Daniel Siwek, Founder of SyncGrowth

Found an error in this guide? kontakt@syncgrowth.pl. We correct the text and publish a new review date.

01

What this template covers and the legal context

The rules below cover everyday tool use by staff and contractors. They do not decide whether a particular use carries additional obligations. The template cannot replace contracts, information-security rules or legal assessment.

Article 4 of the AI Act covers measures to support AI literacy among people acting on behalf of providers or deployers. The Commission explains that the appropriate measures depend on the tool, roles, staff experience and risks; it does not mandate one training format. Source: Commission questions and answers on Article 4

Article 50 contains separate transparency duties for certain systems and content. It does not automatically require a label on every text helped by an assistant. Read: Article 50 on the European Commission service desk

02

Template 1. Purpose, scope and owner

[Company name] applies these rules to generative tools used at work. They apply to [covered teams and contractors] from [date]. [Name and role] owns this policy and the tool register. Send questions and proposed uses to [contact].

Before publishing the policy, name the people who can grant access and approve new tools. Staff should know whom to ask without waiting for the owner to decide every detail.

03

Template 2. Approved tools and accounts

Only tools in the register at [register location] may be used for company work. Each entry names the tool, allowed tasks, owner, account type, permitted data, provider, available privacy settings, review date and approver. A new tool or connection to a company system needs approval from [role].

Personal accounts must not be used for company material. If staff have already used them, first record those uses and check what data was shared. Grant access only to people who need it for a defined task.

04

Template 3. Data we do not paste

You may enter [list of permitted data categories and examples]. Do not paste passwords, keys, confidential agreements, customer and staff data or other personal data without a separately approved processing arrangement. Limit inputs to what the task needs; remove identifiers and confidential detail from trial examples.

Company rules do not replace obligations governing personal-data processing. Before using such data, establish the purpose, legal basis and conditions for sharing it with a provider. The Commission explains individual rights under the GDPR: personal data protection

05

Template 4. Output checks and accountability

The person preparing material checks facts against sources, dates, numbers, quotes, rights to use source material and compliance with company rules. [Role] approves outputs about offers, customers, staff or money before they are sent or published. If an answer has no sound basis, stop the task and hand it to a person.

The decision record stores [what and where: use case, review result, approver, date]. Do not copy entire chats or unnecessary personal data. Name who corrects published mistakes.

06

Template 5. Rights in content and disclosure

Before publication, [role] checks the origins of inputs, licence terms and whether AI use needs disclosure. When rights to an image, voice or third-party text are uncertain, pause publication and seek appropriate advice. Record the company's labelling rules at [procedure location].

Article 50 obligations depend on the system, content and the company's role. Separate rules cover deep fakes and text on matters of public interest, with an exception tied to substantive editorial control for some text. The Commission explains: Article 50 transparency FAQ

Our guide walks through publication decisions: labelling AI content under Article 50

07

Template 6. Incidents, reporting and review

If someone sends data to an unapproved tool, finds a consequential error or detects unauthorised access, they immediately notify [contact and channel]. The incident owner [role] preserves relevant information, disables access where needed, assesses impact and follows the company's security or data-protection process.

The policy owner reviews the tool register when a provider, data category or workflow changes, and reviews the policy every [suggested: 6 months]. Your company chooses this interval. Record updates with a date and approver.

08

Rollout, dry run and sign-off

Walk the team through 10 real, appropriately prepared tasks: routine, incomplete and cases where tool use must be declined. Check that everyone can find the register, spot forbidden data, verify an output and report an error. Improve unclear rules before granting access.

Adoption record: [company name], [policy version], [effective date], [policy owner], [approver and signature], [location of team acknowledgements]. Keep a version history. If actual tool use needs sorting out or the rules need putting into a working process, a review or implementation service can help.

Support for a first process: AI implementation for small businesses

Sources

Let’s identify the right starting point.

Reply within 1 business day, scope and price proposal within 2 business days after the call, with the option to end the engagement after accepting the first stage.

Book a call ↗