The Unlearning School

What should an internal AI use policy contain?

A practical template for an internal AI use policy - the eight sections every company policy needs, with guidance for each and common mistakes to avoid.

For companies that already have access to AI, but need rules, real tasks, verification and adoption evidence.

An internal AI use policy needs eight sections: scope, approved tools, data rules, verification standards, role-specific guidance, responsibilities, training and evidence, and a review cycle. It should fit on two to four pages. A policy nobody reads because it is written like a contract protects nobody; the test of a good AI policy is whether an employee can answer "may I paste this into ChatGPT?" in under ten seconds.

The eight-section template

Use this structure and adapt the content to your company:

  1. Scope and purpose. Who the policy applies to, which tools count as AI, and why the policy exists: enabling safe use, not banning use. A policy that only forbids drives usage underground.
  2. Approved and unapproved tools. Name the tools the company provides or approves, the conditions for each, and the process for requesting a new one. Distinguish company accounts from personal free accounts.
  3. Data rules. The core of the policy. State plainly what must never enter an external AI tool: personal data of clients or employees, financial records, credentials, unreleased commercial terms, anything under NDA. Give examples in your company's language.
  4. Verification standard. AI output is a draft until a human checks it. Define what checking means: facts and figures verified, sources confirmed, tone reviewed, and a named person responsible before anything leaves the company.
  5. Role-specific guidance. HR, sales, finance and operations face different risks. Two or three concrete rules per role beat one abstract paragraph for everyone.
  6. Responsibilities. Who approves tools, who answers questions, who handles incidents, who owns the policy. Name functions, not just "management".
  7. Training and evidence. How people learn the policy, how new joiners are covered, and what records are kept. The European Commission says organisations can keep these internal records, but Article 4 does not prescribe a certificate or a specific documentation format.
  8. Review cycle. AI tools change quarterly; a policy dated two years ago signals nobody owns it. Commit to a review rhythm and a version history.

Common mistakes

Frequently asked questions

Do we legally need an AI use policy?

No law mandates a specific document. EU AI Act Article 4 requires providers and deployers to take context-specific AI literacy measures. A written policy and internal training records are practical ways to organise those measures, but they are not prescribed proof of compliance. A client may request them separately under its own contract, security or supplier-review process.

Should we ban free ChatGPT accounts?

Ban is the wrong frame. Decide which tasks and data classes are acceptable on which tools. Many companies allow public tools for non-sensitive work while routing sensitive tasks to approved enterprise tools with data protection agreements.

Who should write the policy?

A small group: someone who knows the work (operations or team leads), someone who knows the data risks (IT or legal), and someone who owns training (HR or L&D). A policy written by legal alone tends to be safe, unread and ignored.

How does the policy connect to training?

The policy defines rules; training makes them usable on real tasks. Rolling both out together, on the tasks each team actually does, is what produces observable practice. That is the approach behind our AI literacy work.

Next step

Measure how your team uses AI today with the free AI Adoption Score, or see how a policy rollout fits a training program on the workshops page.

Next step

Take the free 7-minute AI Adoption Gap Score to see exactly where adoption is stuck in your company before any sales conversation.

Get your AI Adoption Gap Score →