AI policy for employees: free template for SMBs (GDPR-compliant)

AI policy for employees: free template for SMBs (GDPR-compliant)

Create a GDPR-compliant AI policy for your team with our free template.

200+ companies already trust deeploi

Key Takeaways

  • The EU AI Act's AI literacy duty (Article 4) has applied to every organization using AI since 2 February 2025: national authorities, including Germany's Bundesnetzagentur, are set to begin enforcing from 2 August 2026.

  • Most SMBs have no written AI policy: 63% of breached organizations lacked one (IBM, 2025), leaving GDPR and Shadow AI risks unmanaged.

  • A practical policy only needs to be 2–3 pages, built around a simple approved-tools register table.

  • The single most important rule: never enter customer or employee personal data, trade secrets, or confidential information into a public AI tool.

  • A policy only works if it's enforced, tie it to onboarding and device management (MDM), not just a shared folder.

Why your team needs an AI policy right now

The EU AI Act's AI literacy obligation (Article 4) has applied to every organization using AI since 2 February 2025, regardless of size. National market surveillance authorities, including Germany's Bundesnetzagentur, are set to begin enforcing these rules from 2 August 2026. Yet most small and mid-sized businesses still have nothing written down.

The gap between obligation and action is wide. According to IBM's 2025 Cost of a Data Breach Report, 63% of organizations have no AI governance policy in place (HubWise Tech). For SMBs without dedicated legal or compliance teams, that number is likely even higher.

The good news: a short, practical policy of two to three pages, built around a simple table, is enough to support your GDPR obligations, prevent Shadow AI risks, and protect sensitive company data. This guide walks you through building one, step by step.

What you'll need before you start

Gather three things before writing a single word of policy:

  • A list of AI tools employees already use, both official and unofficial. Include browser extensions, free-tier accounts, and mobile apps.
  • A basic understanding of which company data counts as personal data under GDPR: names, email addresses, customer records, employee files, and anything that can identify a living person.
  • One named owner (IT lead, HR manager, or founder) who will maintain, enforce, and review the policy.

Step 1: Audit your current AI tool usage

Start by finding out what's actually happening across your team. Survey every department, ask direct questions, and check device inventories. The goal is discovery, not restriction.

You're looking for every AI tool in active use: ChatGPT, Copilot, image generators, transcription services, browser-based summariяers, and anything employees signed up for with a personal email. More than 80% of workers use unapproved AI tools in their jobs, with less than 20% saying they rely only on company-approved options (Cybersecurity Dive). If your team is typical, the list will be longer than expected.

This audit gives you the raw material for your approved-tools register and reveals where shadow AI is already creating risk.

Step 2: Set your approved-tools list, data rules, and prohibited uses

Sort every tool from your audit into one of three categories: approved, conditionally approved, or prohibited. For each approved tool, spell out exactly what data employees may enter.

The core rule should be plain and memorable: never paste customer or employee personal data, trade secrets, or confidential information into a public AI tool. The GDPR reason is straightforward: entering personal data into a tool without a data-processing agreement, a valid legal basis, or guarantees that data stays within the EU can amount to unlawful processing.

The stakes keep rising. A recent benchmark found that 27.4% of corporate data employees enter into AI tools is sensitive, up from 10.7% a year earlier, with top categories including customer support information, source code, and R&D material (Worklytics).

Beyond data rules, name specific prohibited actions:

  • Fully automated decisions about people (hiring, firing, performance scoring) without human review
  • Generating legal or medical advice without qualified oversight
  • Using AI output in external communications, contracts, or reports without a human check

Require human oversight before any AI-generated output is used in a decision or shared outside the company. This single rule covers a surprising number of risk scenarios.

Step 3: Build the policy using the free template

Your AI policy is a short narrative document plus a register table. The narrative covers prohibited uses, the human-oversight rule, being transparent with staff about how AI is used, and incident reporting. The table is where the operational detail lives.

Here is the template. Fill one row per tool:

deeploi AI Policy Template Table
AI tool Status Permitted data Approved use cases Prohibited uses Responsible owner Next review
ChatGPT (Team plan) Approved Non-personal, non-confidential only Drafting, brainstorming, code help Customer PII, contracts, HR decisions IT Lead [date]
Transcription tool (e.g. meeting notes) Conditional Internal meetings only, no client PII Internal meeting summaries Recording external client calls Ops Manager [date]
Free public LLM (personal account) Prohibited None All company data

Keep the language plain. Two to three pages is the sweet spot for small teams. If it's longer, people skip it. If it's shorter, you miss critical rules around GDPR and AI usage.

Step 4: Roll out through onboarding and device management

A policy sitting in a shared folder doesn't protect anything. Tie it to your onboarding process so every new hire reads and acknowledges the AI rules on day one. Include it alongside your existing data protection and acceptable-use agreements.

Then move from documentation to enforcement. Use device management (MDM) to control which AI apps can be installed on company devices. This turns your approved-tools list from a suggestion into a technical control. Companies using an IT management platform like deeploi can automate this: new employees receive pre-configured devices with approved tools already installed and unapproved ones blocked, before they write their first email.

{{cta}}

Step 5: Handle incidents and schedule reviews

Give employees a clear, blame-free path when something goes wrong. For example: "If you accidentally paste personal data into a public tool, report it to [policy owner] immediately." Quick reporting lets you assess whether a GDPR breach notification is required within the 72-hour window.

Set a fixed review cycle. Every six months, revisit the approved-tools table, add new tools employees have requested, and remove deprecated ones. Pair the review with short, scenario-based awareness sessions: "A colleague asks you to summarize a contract using a free AI tool. What do you do?" This practical training style supports the Article 4 literacy obligation far better than abstract compliance lectures.

When someone leaves the company, secure AI-era offboarding means revoking access to all AI accounts and API keys, not just the usual SaaS seats.

Troubleshooting common failures

Employees bypass the approved list because it feels too restrictive. The fix is a fast-track request process. If someone can submit a new tool for review and get a yes-or-no within a week, they're far less likely to sign up with a personal email and skip IT entirely.

The policy exists but nobody enforces it. Connect compliance to device management and security controls so violations are visible, not just theoretical. If an unapproved app appears on a managed device, IT should see it immediately.

Unclear data classification causes inconsistent behavior. Give concrete examples for each sensitivity level. "Customer email addresses" is more useful than "personal data." "Revenue forecasts" is more useful than "confidential information." When people can picture the data, they make better decisions.

FAQ

Do we need a separate AI policy if we already have a data protection policy?

Yes. AI introduces risks that a general data protection policy doesn't cover, such as staff entering sensitive data into tools that may retain or train on it, and opaque outputs that are hard to verify. A dedicated AI policy addresses approved tools, human oversight, and prohibited uses in a way a broad privacy notice cannot.

How long should an AI policy be for a small team?

Two to three pages. Anything longer goes unread. Anything shorter misses critical rules around data handling, prohibited uses, and incident reporting. The register table does most of the heavy lifting.

Does the EU AI Act apply to companies that only use AI tools, not build them?

Yes. The Act calls them "deployers." Article 4 requires deployers to take measures to ensure, to their best extent, a sufficient level of AI literacy among staff who operate or interact with AI systems. You don't need to build models to be in scope.

We only use ChatGPT and Copilot. Do we have heavy compliance obligations?

Standard assistant use is generally not classified as a "high-risk" AI system, so the strictest obligations typically don't apply. Your practical duties are the AI literacy measures under Article 4 and your existing GDPR obligations around data handling. A short policy plus the register table covers both.

Conclusion

A written policy is the starting line, not the finish. Enforcement through device management, onboarding workflows, and regular training is what actually reduces risk and satisfies regulators. Review the template, fill in the table, and connect the rules to your IT compliance setup.

If maintaining tool governance and keeping enforcement current as regulations evolve sounds like more than your team can handle alone, a managed IT partner like deeploi can automate the process, from device configuration to approved-app enforcement, so your policy stays alive long after you've written it.

{{cta}}

Founded
Customer Size
Headquarters
Industry
KEY RESULTS
CUSTOMER STORIES
This field is required
This field is required
This field is required
Choose
This field is required
This field is required
Thank you for your interest!

We’ll get back to you shortly.

Oops! Something went wrong while submitting the form.

From policy on paper to policy in practice

A written policy only helps if your tools match it. deeploi ships new hires pre-configured devices with the right apps already installed, manages software centrally across every device, and gives you clear visibility into which tools are actually in use, so approved-tool rules and GDPR obligations are built into your setup, not left to chance.
Download the professional onboarding checklist for free

Heading 1

Heading 2

Heading 3

Heading 4

Heading 5
Heading 6

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur.

Block quote

Ordered list

  1. Item 1
  2. Item 2
  3. Item 3

Unordered list

  • Item A
  • Item B
  • Item C

Text link

Bold text

Emphasis

Superscript

Subscript

Get the checklist