Guide · AI policy

A company AI policy: what goes in it, and a ready template.

An AI policy is two pages of house rules that tell employees what they may do with AI, what they may not, and who is responsible. This guide covers why every company needs one, what goes in it, how you know it is being followed, and how to roll it out in an hour. A ready template is at the end.

Updated 10 September 2026 · Reading time about 10 minutes · Jump to the template

What an AI policy is, and what it is not

It is a short, everyday document. Two or three pages that an employee reads once and returns to when unsure. It answers practical questions: which tools may I use, what may I enter into them, what must I check myself, what do we tell customers, and whom do I ask.

It is not a 40-page framework, a security standard or a legal contract. A document nobody reads governs nothing. A good policy is short enough to fit into onboarding and concrete enough to settle a single situation.

Why it is needed now

The absence of a policy does not mean there is no AI use. It means nobody knows how it is used. Five reasons management should take seriously:

The ten sections a good policy has

Below is the skeleton. Each section has two parts: what the company has to decide, and the most common mistake. The template at the end follows the same order.

1. Purpose and scope
Decide: whom the policy covers (all staff, including contractors and trainees) and what it covers (all AI tools, including assistants built into other software). Common mistake: applying it only to "ChatGPT", which leaves Copilot, Gemini and the email client's assistant outside.
2. Approved tools
Decide: a named list of tools and their business versions that may be used, and who manages the licences. Common mistake: no list, so "approved" means anything in practice, or a list so strict that use moves to personal phones.
3. Forbidden uses
Decide: a short list of absolute prohibitions: consumer versions without a business account, decisions about people without human judgement, presenting AI as a human to a customer, entering passwords or other secrets, entering confidential information without approval. Common mistake: a list of prohibitions longer than the list of what is allowed. Nobody remembers it.
4. What data may be entered
Decide: a traffic-light model. Green: public and general information. Yellow: internal information in approved business tools. Red: personal data, customers' confidential information and contracts, unless separately agreed. Passwords, API keys and other secrets belong to no class: they are never entered. Common mistake: an abstract "be careful", from which nobody can tell whether a customer's name may be mentioned.
5. Human review and responsibility
Decide: AI proposes, a person decides. Whoever sends or publishes is responsible for the content exactly as for their own writing. Define what is always checked: figures, prices, legal references, people's names. Common mistake: assuming "the AI" is responsible for errors.
6. Transparency
Decide: when the use of AI is disclosed to a customer and when it need not be. Rule of thumb: an aid need not be disclosed, but a bot that talks to a customer is introduced as a bot, always. Decide also what the company can see of staff AI use, and write it into the policy. Common mistake: no position at all, so everyone decides for themselves.
7. Training and skills
Decide: a short induction before access is granted, a refresher every year, and a record of who attended. This can form part of the measures required under Article 4 to support the development of AI literacy. Common mistake: the policy is emailed with no session, and half the staff never open it.
8. Incidents and reporting
Decide: what happens when someone enters sensitive data by mistake or notices that a wrong AI output went out: whom to tell, how fast, and that reporting is not punished. Common mistake: a reporting threshold so high that incidents stay hidden.
9. New tools and exceptions
Decide: who approves a new tool and what is checked first: where data is processed, whether it is used for training, whether there is a processing agreement, what it costs. Common mistake: approval takes months, so employees do not even ask.
10. Owner and updates
Decide: one named owner, a review every six months and a version number. Tools and rules change faster than most company documents. Common mistake: the policy is written once and forgotten.

Rolling it out in an hour

  1. Fill in the template (30 minutes). Decide the approved tools, the traffic lights and the owner. Do not polish the wording, polish the decisions.
  2. Get management sign-off (10 minutes). The policy is a management position, not an IT instruction.
  3. Hold a 20-minute session for staff. Walk through the traffic lights, three everyday examples, and what the company can and cannot see. Take questions. Record attendance.
  4. Ask for acknowledgement. An email reply or an entry in the HR system is enough.
  5. Make the tool settings match the policy. Business licences on, sign-in with company accounts, data visibility limited. This is where paper becomes practice, and it is usually the part where help is needed.
  6. Put the review in the calendar six months ahead.

The most common mistakes

How do you know it is being followed?

Not everything can be seen, and not everything should be. The aim is not to watch employees but to make the approved tools the easiest option, to catch the significant security risks, and to make sure the tools' settings support the agreed rules. What a company can see depends on its tools, licences and device management. And in Finland any technical visibility into what employees do is regulated: it is introduced openly and discussed with staff, never quietly. Visibility comes in layers:

What cannot be seen: a personal phone on mobile data. The company's network, DNS or device monitoring does not see what is done on an unmanaged personal phone on mobile data, and claiming otherwise would be dishonest. That is why the policy, the training and an easy approved path decide the outcome, and why reporting an incident is welcome and not punished.

What the law requires

In Finland, technical monitoring of employees is regulated. Under section 21 of the Act on the Protection of Privacy in Working Life (759/2004), the purpose, introduction and methods of technical monitoring, including email and network use, are handled with the staff before the decision. In companies with at least 50 employees this belongs to the dialogue under the Co-operation Act. Companies with 20 to 49 employees handle it in the Act's lightened dialogue (section 7a), whose form the company may decide itself. In companies with fewer than 20 employees, the employees or their representatives must be given an opportunity to be heard before the decision. In every case the employer then defines the purpose and methods of the monitoring and informs the staff. The headcount thresholds follow the amendment in force since 1 July 2025. The same applies to web and DNS filtering that logs per device. The data collected is personal data, and it is used only for the purpose it was collected for.

In practice: write into section 6 of the template what the company can see and what it cannot, go through it in the same session as the policy, and keep a record of the discussion.

The goal is not to monitor people. It is to make the approved path the easiest, to see the big leaks in time and to keep the settings in line with the policy. The visibility and blocking settings belong to configuring the tools, and checking them monthly is part of the reporting.

Template

AI use policy, fillable template

Items in square brackets are filled in with the company's own choices. The rest is ready to use as it is, and may be edited freely.

Download the Word template

[Company Ltd] · AI use policy

Version [1.0] · Approved [dd.mm.yyyy] · Owner [name, role] · Next review [dd.mm.yyyy]

1. Purpose and scope

This policy defines how AI tools are used at [Company Ltd]. It applies to all staff and to [contractors and trainees], and to all AI tools, including assistants built into other software. The aim is that AI is used boldly and safely.

2. Approved tools

Only the tools listed below may be used for work, with company accounts. Licences are managed by [name].

ToolLicencePermitted use
[Microsoft 365 Copilot][Business licence, company account][Email, documents, meeting notes, internal information]
[ChatGPT Business][Business licence, company account][Drafts, summaries, analysis, no personal data]
[Internal knowledge assistant][Company's own][Guidelines and internal documents]

Consumer versions without a business account (for example the free ChatGPT or Gemini on a personal account) are not permitted for work matters.

3. Forbidden uses

  • Personal data is not entered into tools that have not been approved. In approved tools, personal data is processed only in accordance with section 4 and when necessary for the task.
  • Decisions about people (recruitment, evaluation, a customer's creditworthiness) based on AI alone without human judgement.
  • Presenting AI as a human to a customer or partner.
  • Entering passwords, API keys, access tokens, private keys or other secrets into any AI tool. There are no exceptions.
  • Entering confidential information or contracts into tools, unless separately agreed under section 4.

4. What data may be entered

ClassExamplesRule
GreenPublic information, general texts, own drafts without identifying detailsMay be used in all approved tools.
YellowInternal information: guidelines, proposal templates, internal reportsOnly in approved business tools with company accounts.
RedPersonal data, customers' confidential information, contracts, [other defined by the company]Not entered unless [name] has approved the use and the tool for that purpose.

Passwords, API keys and other secrets belong to no class: they are never entered (section 3).

5. Responsibility and review

AI proposes, a person decides. Whoever sends, publishes or uses AI-generated content is responsible for it exactly as for their own work. Always checked: figures and prices, legal references, names of people and companies, and promises to customers.

6. Transparency

The use of AI as an aid need not be disclosed separately. If a customer or partner is talking to an AI, this is always disclosed. A customer's question about the use of AI is answered honestly.

Visibility within the company: the company can see the usage volumes of the approved tools and the apps connected to company accounts [and the web-filter logs of work computers]. The content of individual employees' conversations is not reviewed as a routine. If an incident requires handling of content, this is assessed separately on the basis of applicable law, access rights and the features of the service. Staff were informed of the technical monitoring on [dd.mm.yyyy] [and the matter was handled in the dialogue under the Co-operation Act / the staff were heard on dd.mm.yyyy]. The data is used only to ensure information security.

7. Training

Everyone completes a short induction before being given access to AI tools, and a refresher [every year]. Attendance is recorded. In this way the company supports the development of its staff's AI literacy in line with Article 4 of the EU AI Act.

8. Incidents and reporting

If sensitive data has been entered into a tool by mistake, or wrong AI-generated content has gone out, this is reported without delay to [name / address]. Reporting is welcome and carries no sanctions. [Name] assesses the situation and the necessary actions, if needed together with the data protection officer.

9. New tools and exceptions

A new tool or a new use is approved by [name]. Before approval it is checked where the data is processed, whether it is used to train models, whether a data processing agreement exists and what the use costs. An answer is given within [a week].

10. Owner and updates

The owner of the policy is [name, role]. The policy is reviewed [every six months] and whenever the list of approved tools changes. The current version is kept at [location].

I have read and understood this policy. Name: ____________________ Date: ____________

Työäly Start

Want us to do this for you?

In a Start project we assess the current state, tailor the policy, configure the tools to match it, train the staff and take the first automation into production. Three to four weeks, fixed price.

This guide and template are practical guidance, not legal advice. Check questions about the processing of personal data, the introduction of technical monitoring and customer contracts with a data protection officer or a lawyer where needed. Tool capabilities and licences were checked against the vendors' documentation on 10 September 2026, and they change.