AI Policy for Companies: The 2026 Guide

TL;DR
- An AI policy defines which AI tools are approved and how they may be used.
- Article 4 now asks you to support AI literacy, not to guarantee it.
- Seven building blocks turn the policy into a real working document.
- Good policies enable AI use instead of merely banning it.
Article 4 of the EU AI Act has applied since 2 February 2025, and since 27 July 2026 in a new version: companies must support the development of AI literacy among their employees, but do not have to guarantee any particular level. At the same time, according to a Bitkom survey of 604 companies, one in three companies (36 percent) now uses artificial intelligence, almost double the share from a year earlier. In most businesses, employees have long been typing texts, customer data, and quotes into ChatGPT without anyone having set the rules for it. This is exactly the gap an AI policy closes.
This guide shows what an AI policy for companies needs to contain, how to build one in five steps, and which mistakes you should avoid. We look at the topic from the perspective of operators who use AI themselves in their daily work, not just from a legal distance.
What an AI policy is, and what it isn't
An AI policy (also called an AI usage policy or AI Policy) is an internal document that governs how your company handles artificial intelligence. It answers three core questions: Which AI tools are approved? Which data must never be entered? Who reviews and takes responsibility for the results?
More important is what a good AI policy is not. It is not a pure list of prohibitions that pushes employees toward secretly using private accounts. And it is not a template you download once, file away, and forget. An effective policy is a working document that enables use while clearly drawing the boundaries. That is the difference between AI governance that slows things down and AI governance that provides cover.
An example makes this concrete. Instead of writing "The use of AI is prohibited," a good policy states: "For text work, the company account for Tool X is approved. Personal data and contract content do not belong in the input. Results are checked before they go out." The first sentence creates resistance and secret use. The second gives employees a clear, permitted path. This exact translation of abstract rules into concrete work instructions decides whether a policy is actually followed or worked around.
Why no company can do without one in 2026
The pressure to act comes from two directions. Legally, Article 4 of Regulation (EU) 2024/1689 has applied since 2 February 2025. The Digital Omnibus Regulation on AI replaced it as of 27 July 2026: providers and deployers must take measures to support the development of AI literacy among their staff. They expressly do not have to guarantee any particular level. The regulation's general application follows on 2 August 2026. An AI policy is one of those measures, and the most practical one, because it covers data protection and due diligence duties at the same time. You can read how the regulation fits together as a whole in our article on the EU AI Act.
The second driver is daily practice. Legal uncertainty is, according to a further Bitkom survey of 602 companies, the most common obstacle: 68 percent name unclear rules as a brake, and 82 percent fear future legal restrictions. Without internal rules, shadow AI emerges: employees upload contracts, job applications, or customer lists to free tools whose servers sit outside the EU and whose providers are permitted to use the input for training. What is meant to save time turns into a data protection incident. A policy turns this diffuse uncertainty into clear, verifiable requirements, and gives employees the confidence to use AI openly in the first place.
The 7 building blocks of an AI policy
A solid AI policy covers seven areas. This structure follows proven templates, such as the GDD's model policy, translated into concrete decisions.
- Purpose and scope. Who does the policy apply to, and for which systems? Name all employees, working students, and external service providers explicitly.
- Approved tools and approval process. Keep a short list of permitted tools. Define who reviews and approves new tools, for example your IT or data protection officer.
- Data protection and confidentiality. Clearly define which data must never enter public AI models: personal data, trade secrets, source code, customer lists. We go deeper into the GDPR connection in our article on AI and data protection.
- Human in the loop. The final decision and the liability stay with a human. AI delivers drafts, not approvals.
- Labeling. Define when AI generated content must be disclosed internally or to customers.
- Training and AI literacy. Record how employees are briefed. This is one of the measures Article 4 calls for, and the easiest place to show that the support actually happened.
- Roles and violations. Name a responsible person and describe what happens in the event of a violation.
Not every one of these points needs to be perfectly worded from day one. What matters more than completeness is that the policy matches how AI is actually used. If your company currently only uses text tools, a lean document is enough. If systems for hiring decisions or customer data analysis are added later, expand the relevant building blocks specifically. These areas carry higher risk and deserve stricter rules, for example a mandatory human final check on any decision that affects people.
In 5 steps to your own AI policy
You do not need six months or a large external law firm to get started. A realistic path looks like this:
- Take stock. Ask each department which AI tools are already in use. This list is usually longer than expected.
- Set the framework. Decide the baseline: which tools are approved, and which data is off limits?
- Draft it. Use a template as a scaffold and adapt every point to your actual reality. An unmodified template will not help in a real incident.
- Align it. Involve IT, data protection, the works council, and at least one department. This increases acceptance.
- Roll it out and update it. Communicate the policy actively, provide a short training session, and review the document at least once a year.
The most common mistakes
In practice, policies rarely fail because of their content. They fail in the execution. Three patterns keep coming up.
First, the pure prohibition culture. Whoever bans AI across the board just pushes its use into the private sphere and loses all control. Second, the copy paste pattern. An AI usage policy adopted unchanged sounds good but does not fit your processes and creates a false sense of security. Third, the document in the drawer. A policy nobody knows about changes no behavior. Short training sessions and one fixed point of contact do more than twenty pages of text.
Use templates, but adapt them correctly
You do not have to start from zero. Besides the GDD, the IHK also provides an editable model AI policy that you can adapt to your company's structures. Templates like these save time on the scaffold. The decisive part, however, remains the adaptation: a trades business with fifteen employees needs different rules than a tax firm with sensitive client data. Treat the template as a checklist, not a finished solution. Remove what does not fit, and add the tools and types of data that actually come up in your daily work. Only then does a generic template become a policy that holds up in a real incident, one your employees actually understand.
The first step
Your first step on Monday morning: put together a table of which AI tools are already in use in your company and which data they process. This stocktaking takes about an hour and immediately shows you where the biggest risks lie. On this basis, you can draft a suitable policy within a few days.
If you are looking for a partner who does not just assess AI but also implements it: schedule an initial consultation. We combine strategy and execution under one roof, so your policy turns into lived practice.
Frequently asked questions
AI consulting for German SMEs. We don't just advise. We implement. With experience from 4 proprietary AI products and 50+ client projects.