Guide · AI policy
A company AI policy: what goes in it, and a ready template.
An AI policy is two pages of house rules that tell employees what they may do with AI, what they may not, and who is responsible. This guide covers why every company needs one, what goes in it, how you know it is being followed, and how to roll it out in an hour. A ready template is at the end.
What an AI policy is, and what it is not
It is a short, everyday document. Two or three pages that an employee reads once and returns to when unsure. It answers practical questions: which tools may I use, what may I enter into them, what must I check myself, what do we tell customers, and whom do I ask.
It is not a 40-page framework, a security standard or a legal contract. A document nobody reads governs nothing. A good policy is short enough to fit into onboarding and concrete enough to settle a single situation.
Why it is needed now
The absence of a policy does not mean there is no AI use. It means nobody knows how it is used. Five reasons management should take seriously:
- Customer data ends up in consumer tools. When an employee pastes a customer's email into a personal ChatGPT account to summarise it, the content may be used to develop models unless the user has turned that off in the settings. Business versions such as ChatGPT Business, Microsoft 365 Copilot and Gemini for Google Workspace do not use the company's content to train models. The difference is the licence, not the tool.
- Data protection and customer contracts. Processing personal data in an AI service needs a legal basis and, where the provider acts as a processor, an appropriate data processing agreement. Many customer contracts contain a confidentiality clause that makes no exception for "I only summarised it".
- The EU AI Act. Article 4, as amended in July 2026, requires providers and deployers of AI systems to take measures to support the development of their staff's AI literacy. A policy and the short training that goes with it can be part of those measures and help document them.
- Confident-sounding errors. A language model writes convincingly even when it is wrong. Without an agreed checking practice, the error goes to the customer in the company's name.
- Unclear responsibility. Who is responsible for a proposal drafted by AI, and in whose name does it go out? The policy answers in one word: the sender.
The ten sections a good policy has
Below is the skeleton. Each section has two parts: what the company has to decide, and the most common mistake. The template at the end follows the same order.
Rolling it out in an hour
- Fill in the template (30 minutes). Decide the approved tools, the traffic lights and the owner. Do not polish the wording, polish the decisions.
- Get management sign-off (10 minutes). The policy is a management position, not an IT instruction.
- Hold a 20-minute session for staff. Walk through the traffic lights, three everyday examples, and what the company can and cannot see. Take questions. Record attendance.
- Ask for acknowledgement. An email reply or an entry in the HR system is enough.
- Make the tool settings match the policy. Business licences on, sign-in with company accounts, data visibility limited. This is where paper becomes practice, and it is usually the part where help is needed.
- Put the review in the calendar six months ahead.
The most common mistakes
- Banning everything. Use does not stop, it moves to personal devices and out of sight. A ban is the worst possible policy.
- Writing too much. If the document does not fit on two pages, it is not read.
- Not naming tools. "Approved tools" without a list is an empty phrase.
- Policy without settings. A rule the tool's settings do not support is forgotten on the first busy day.
- No training, no updates. Then the document exists but does not shape daily work.
How do you know it is being followed?
Not everything can be seen, and not everything should be. The aim is not to watch employees but to make the approved tools the easiest option, to catch the significant security risks, and to make sure the tools' settings support the agreed rules. What a company can see depends on its tools, licences and device management. And in Finland any technical visibility into what employees do is regulated: it is introduced openly and discussed with staff, never quietly. Visibility comes in layers:
- Use of the approved tools. The Copilot usage reports in the Microsoft 365 admin centre and the workspace analytics in ChatGPT Business show how many people use the tools and how much. Microsoft's reports hide user names by default, and that is a good default. Low adoption in one team is the first hint that something else is in use.
- Apps connected to company accounts. Both Microsoft Entra and Google Workspace list the apps someone has granted access to a company account or its data, and new connections can be limited to admin approval. These controls are basic settings in both environments, and the exact features depend on the licence or edition. They show only apps connected through sign-in, not websites anyone visits.
- Which AI services work computers talk to. Here the right tool depends on the licence. Defender for Business, included in Microsoft 365 Business Premium, protects the network traffic of work computers and can block and report website use. Wider visibility into which cloud services are used and by whom needs additional capabilities such as Defender for Cloud Apps, a separate add-on to Business Premium. Without Microsoft device management, a DNS or web filter with an agent on work computers can provide basic visibility into and control over access to certain services. All of these are technical monitoring, see the box below.
- What has been entered into the approved tools. Less is visible here than many assume. The Microsoft 365 audit log records metadata about Copilot interactions: the user, the time, the app used and the files referenced, not the content of prompts and responses. Access to the content requires separate Purview or eDiscovery features and is not part of normal usage reporting. In ChatGPT Business the admin cannot read workspace members' conversations; organisation-level conversation logs are Enterprise and Edu features. So "what has been entered" is secured through settings, for example by restricting who can see personal data and confidential files, so that Copilot cannot surface what a user should not see anyway.
- Blocking the paste. Microsoft Purview endpoint data loss prevention can detect customer data being pasted into consumer services, and Purview's AI reports show in aggregate whether sensitive data is entered into Copilot. Both need an E5-level licence or an equivalent add-on, so for most SMEs they are a later step, not the starting point.
What cannot be seen: a personal phone on mobile data. The company's network, DNS or device monitoring does not see what is done on an unmanaged personal phone on mobile data, and claiming otherwise would be dishonest. That is why the policy, the training and an easy approved path decide the outcome, and why reporting an incident is welcome and not punished.
What the law requires
In Finland, technical monitoring of employees is regulated. Under section 21 of the Act on the Protection of Privacy in Working Life (759/2004), the purpose, introduction and methods of technical monitoring, including email and network use, are handled with the staff before the decision. In companies with at least 50 employees this belongs to the dialogue under the Co-operation Act. Companies with 20 to 49 employees handle it in the Act's lightened dialogue (section 7a), whose form the company may decide itself. In companies with fewer than 20 employees, the employees or their representatives must be given an opportunity to be heard before the decision. In every case the employer then defines the purpose and methods of the monitoring and informs the staff. The headcount thresholds follow the amendment in force since 1 July 2025. The same applies to web and DNS filtering that logs per device. The data collected is personal data, and it is used only for the purpose it was collected for.
In practice: write into section 6 of the template what the company can see and what it cannot, go through it in the same session as the policy, and keep a record of the discussion.
The goal is not to monitor people. It is to make the approved path the easiest, to see the big leaks in time and to keep the settings in line with the policy. The visibility and blocking settings belong to configuring the tools, and checking them monthly is part of the reporting.
Template
AI use policy, fillable template
Items in square brackets are filled in with the company's own choices. The rest is ready to use as it is, and may be edited freely.
[Company Ltd] · AI use policy
1. Purpose and scope
This policy defines how AI tools are used at [Company Ltd]. It applies to all staff and to [contractors and trainees], and to all AI tools, including assistants built into other software. The aim is that AI is used boldly and safely.
2. Approved tools
Only the tools listed below may be used for work, with company accounts. Licences are managed by [name].
| Tool | Licence | Permitted use |
|---|---|---|
| [Microsoft 365 Copilot] | [Business licence, company account] | [Email, documents, meeting notes, internal information] |
| [ChatGPT Business] | [Business licence, company account] | [Drafts, summaries, analysis, no personal data] |
| [Internal knowledge assistant] | [Company's own] | [Guidelines and internal documents] |
Consumer versions without a business account (for example the free ChatGPT or Gemini on a personal account) are not permitted for work matters.
3. Forbidden uses
- Personal data is not entered into tools that have not been approved. In approved tools, personal data is processed only in accordance with section 4 and when necessary for the task.
- Decisions about people (recruitment, evaluation, a customer's creditworthiness) based on AI alone without human judgement.
- Presenting AI as a human to a customer or partner.
- Entering passwords, API keys, access tokens, private keys or other secrets into any AI tool. There are no exceptions.
- Entering confidential information or contracts into tools, unless separately agreed under section 4.
4. What data may be entered
| Class | Examples | Rule |
|---|---|---|
| Green | Public information, general texts, own drafts without identifying details | May be used in all approved tools. |
| Yellow | Internal information: guidelines, proposal templates, internal reports | Only in approved business tools with company accounts. |
| Red | Personal data, customers' confidential information, contracts, [other defined by the company] | Not entered unless [name] has approved the use and the tool for that purpose. |
Passwords, API keys and other secrets belong to no class: they are never entered (section 3).
5. Responsibility and review
AI proposes, a person decides. Whoever sends, publishes or uses AI-generated content is responsible for it exactly as for their own work. Always checked: figures and prices, legal references, names of people and companies, and promises to customers.
6. Transparency
The use of AI as an aid need not be disclosed separately. If a customer or partner is talking to an AI, this is always disclosed. A customer's question about the use of AI is answered honestly.
Visibility within the company: the company can see the usage volumes of the approved tools and the apps connected to company accounts [and the web-filter logs of work computers]. The content of individual employees' conversations is not reviewed as a routine. If an incident requires handling of content, this is assessed separately on the basis of applicable law, access rights and the features of the service. Staff were informed of the technical monitoring on [dd.mm.yyyy] [and the matter was handled in the dialogue under the Co-operation Act / the staff were heard on dd.mm.yyyy]. The data is used only to ensure information security.
7. Training
Everyone completes a short induction before being given access to AI tools, and a refresher [every year]. Attendance is recorded. In this way the company supports the development of its staff's AI literacy in line with Article 4 of the EU AI Act.
8. Incidents and reporting
If sensitive data has been entered into a tool by mistake, or wrong AI-generated content has gone out, this is reported without delay to [name / address]. Reporting is welcome and carries no sanctions. [Name] assesses the situation and the necessary actions, if needed together with the data protection officer.
9. New tools and exceptions
A new tool or a new use is approved by [name]. Before approval it is checked where the data is processed, whether it is used to train models, whether a data processing agreement exists and what the use costs. An answer is given within [a week].
10. Owner and updates
The owner of the policy is [name, role]. The policy is reviewed [every six months] and whenever the list of approved tools changes. The current version is kept at [location].
I have read and understood this policy. Name: ____________________ Date: ____________
Työäly Start
Want us to do this for you?
In a Start project we assess the current state, tailor the policy, configure the tools to match it, train the staff and take the first automation into production. Three to four weeks, fixed price.
This guide and template are practical guidance, not legal advice. Check questions about the processing of personal data, the introduction of technical monitoring and customer contracts with a data protection officer or a lawyer where needed. Tool capabilities and licences were checked against the vendors' documentation on 10 September 2026, and they change.