Vidimas is live – all leading AI models, securely hosted in the EU or Switzerland.Start free trial
Vidimas
All articles
PracticeUpdated on 26 July 20263 min readVidimas editorial team

Writing an AI policy: a guide for companies, with checklist

An AI policy sets out which AI tools are permitted in the company, which data may be entered and who is responsible for what. It is the central governance document for using AI – and in many industries effectively a precondition for using AI responsibly at all.

Good policies are short, concrete and accompanied by an official tool offering. This guide shows what belongs in one.

Why every company needs an AI policy

Employees will use AI anyway – the only question is whether it's governed or ungoverned. A policy creates legal certainty for both sides: the team knows what's allowed, and those responsible can demonstrate that they have met their organisational duties. That matters for liability too: GDPR fines are levied on the company, fines under the revFADP on responsible individuals.

What belongs in the policy

A workable AI policy answers seven questions:

  • Permitted tools: which AI applications are approved, and which are expressly not?
  • Data categories: which data may be entered – and which never (e.g. sensitive personal data, trade secrets)?
  • Check before use: AI output is reviewed professionally before it is used externally
  • Labelling: when does AI assistance have to be disclosed?
  • Responsibility: who approves new tools, who answers questions?
  • Training: how are employees enabled?
  • Consequences: what happens in the event of a breach?

The rollout decides the effect

Policies that are emailed round and never looked at again change nothing. A three-part approach has proved itself: short training with concrete examples from your own daily work, an official tool that makes the permitted use easy, and a named contact for borderline cases. The policy itself should run to no more than two or three pages – completeness doesn't beat comprehensibility here.

Policy and technology belong together

The best rule is the one enforced technically: a central AI platform with roles, permissions and audit logs turns a paper policy into lived practice. Providing assistants with fixed instructions also standardises quality and tone – the policy shifts from a list of prohibitions to an enablement tool.

Frequently asked questions

How long should an AI policy be?

Two to three pages are enough in most companies. What matters is that the data categories and permitted tools are crystal clear – details can be expanded in an FAQ or training session.

Who should draft the AI policy?

Ideally a small group made up of management, IT or the data protection lead, and representatives of the business units. The business units know which use cases actually occur – which keeps the rules grounded in practice.

How often does the policy need updating?

At least annually, plus whenever something relevant changes – new tools, new legal frameworks such as the EU AI Act, or changed provider terms.

Related reading

Bring AI into your company securely.

Try Vidimas with your team – and see how quickly secure AI becomes productive.

Start free trial
  • Try it with the whole team
  • Set up in minutes
  • Productive from day one