Key Takeaways
The EU AI Act's AI literacy duty (Article 4) has applied to every organization using AI since 2 February 2025: national authorities, including Germany's Bundesnetzagentur, are set to begin enforcing from 2 August 2026.
Most SMBs have no written AI policy: 63% of breached organizations lacked one (IBM, 2025), leaving GDPR and Shadow AI risks unmanaged.
A practical policy only needs to be 2–3 pages, built around a simple approved-tools register table.
The single most important rule: never enter customer or employee personal data, trade secrets, or confidential information into a public AI tool.
A policy only works if it's enforced, tie it to onboarding and device management (MDM), not just a shared folder.
Why your team needs an AI policy right now
The EU AI Act's AI literacy obligation (Article 4) has applied to every organization using AI since 2 February 2025, regardless of size. National market surveillance authorities, including Germany's Bundesnetzagentur, are set to begin enforcing these rules from 2 August 2026. Yet most small and mid-sized businesses still have nothing written down.
The gap between obligation and action is wide. According to IBM's 2025 Cost of a Data Breach Report, 63% of organizations have no AI governance policy in place (HubWise Tech). For SMBs without dedicated legal or compliance teams, that number is likely even higher.
The good news: a short, practical policy of two to three pages, built around a simple table, is enough to support your GDPR obligations, prevent Shadow AI risks, and protect sensitive company data. This guide walks you through building one, step by step.
What you'll need before you start
Gather three things before writing a single word of policy:
- A list of AI tools employees already use, both official and unofficial. Include browser extensions, free-tier accounts, and mobile apps.
- A basic understanding of which company data counts as personal data under GDPR: names, email addresses, customer records, employee files, and anything that can identify a living person.
- One named owner (IT lead, HR manager, or founder) who will maintain, enforce, and review the policy.
Step 1: Audit your current AI tool usage
Start by finding out what's actually happening across your team. Survey every department, ask direct questions, and check device inventories. The goal is discovery, not restriction.
You're looking for every AI tool in active use: ChatGPT, Copilot, image generators, transcription services, browser-based summariяers, and anything employees signed up for with a personal email. More than 80% of workers use unapproved AI tools in their jobs, with less than 20% saying they rely only on company-approved options (Cybersecurity Dive). If your team is typical, the list will be longer than expected.
This audit gives you the raw material for your approved-tools register and reveals where shadow AI is already creating risk.
Step 2: Set your approved-tools list, data rules, and prohibited uses
Sort every tool from your audit into one of three categories: approved, conditionally approved, or prohibited. For each approved tool, spell out exactly what data employees may enter.
The core rule should be plain and memorable: never paste customer or employee personal data, trade secrets, or confidential information into a public AI tool. The GDPR reason is straightforward: entering personal data into a tool without a data-processing agreement, a valid legal basis, or guarantees that data stays within the EU can amount to unlawful processing.
The stakes keep rising. A recent benchmark found that 27.4% of corporate data employees enter into AI tools is sensitive, up from 10.7% a year earlier, with top categories including customer support information, source code, and R&D material (Worklytics).
Beyond data rules, name specific prohibited actions:
- Fully automated decisions about people (hiring, firing, performance scoring) without human review
- Generating legal or medical advice without qualified oversight
- Using AI output in external communications, contracts, or reports without a human check
Require human oversight before any AI-generated output is used in a decision or shared outside the company. This single rule covers a surprising number of risk scenarios.
Step 3: Build the policy using the free template
Your AI policy is a short narrative document plus a register table. The narrative covers prohibited uses, the human-oversight rule, being transparent with staff about how AI is used, and incident reporting. The table is where the operational detail lives.
Here is the template. Fill one row per tool:
Keep the language plain. Two to three pages is the sweet spot for small teams. If it's longer, people skip it. If it's shorter, you miss critical rules around GDPR and AI usage.
Step 4: Roll out through onboarding and device management
A policy sitting in a shared folder doesn't protect anything. Tie it to your onboarding process so every new hire reads and acknowledges the AI rules on day one. Include it alongside your existing data protection and acceptable-use agreements.
Then move from documentation to enforcement. Use device management (MDM) to control which AI apps can be installed on company devices. This turns your approved-tools list from a suggestion into a technical control. Companies using an IT management platform like deeploi can automate this: new employees receive pre-configured devices with approved tools already installed and unapproved ones blocked, before they write their first email.
{{cta}}
Step 5: Handle incidents and schedule reviews
Give employees a clear, blame-free path when something goes wrong. For example: "If you accidentally paste personal data into a public tool, report it to [policy owner] immediately." Quick reporting lets you assess whether a GDPR breach notification is required within the 72-hour window.
Set a fixed review cycle. Every six months, revisit the approved-tools table, add new tools employees have requested, and remove deprecated ones. Pair the review with short, scenario-based awareness sessions: "A colleague asks you to summarize a contract using a free AI tool. What do you do?" This practical training style supports the Article 4 literacy obligation far better than abstract compliance lectures.
When someone leaves the company, secure AI-era offboarding means revoking access to all AI accounts and API keys, not just the usual SaaS seats.
Troubleshooting common failures
Employees bypass the approved list because it feels too restrictive. The fix is a fast-track request process. If someone can submit a new tool for review and get a yes-or-no within a week, they're far less likely to sign up with a personal email and skip IT entirely.
The policy exists but nobody enforces it. Connect compliance to device management and security controls so violations are visible, not just theoretical. If an unapproved app appears on a managed device, IT should see it immediately.
Unclear data classification causes inconsistent behavior. Give concrete examples for each sensitivity level. "Customer email addresses" is more useful than "personal data." "Revenue forecasts" is more useful than "confidential information." When people can picture the data, they make better decisions.
FAQ
Do we need a separate AI policy if we already have a data protection policy?
Yes. AI introduces risks that a general data protection policy doesn't cover, such as staff entering sensitive data into tools that may retain or train on it, and opaque outputs that are hard to verify. A dedicated AI policy addresses approved tools, human oversight, and prohibited uses in a way a broad privacy notice cannot.
How long should an AI policy be for a small team?
Two to three pages. Anything longer goes unread. Anything shorter misses critical rules around data handling, prohibited uses, and incident reporting. The register table does most of the heavy lifting.
Does the EU AI Act apply to companies that only use AI tools, not build them?
Yes. The Act calls them "deployers." Article 4 requires deployers to take measures to ensure, to their best extent, a sufficient level of AI literacy among staff who operate or interact with AI systems. You don't need to build models to be in scope.
We only use ChatGPT and Copilot. Do we have heavy compliance obligations?
Standard assistant use is generally not classified as a "high-risk" AI system, so the strictest obligations typically don't apply. Your practical duties are the AI literacy measures under Article 4 and your existing GDPR obligations around data handling. A short policy plus the register table covers both.
Conclusion
A written policy is the starting line, not the finish. Enforcement through device management, onboarding workflows, and regular training is what actually reduces risk and satisfies regulators. Review the template, fill in the table, and connect the rules to your IT compliance setup.
If maintaining tool governance and keeping enforcement current as regulations evolve sounds like more than your team can handle alone, a managed IT partner like deeploi can automate the process, from device configuration to approved-app enforcement, so your policy stays alive long after you've written it.
{{cta}}
.png)









