AI policy template: what to include in 2026

    |7 min read
    Joachim Sahlin, CEO & AI Advisor

    Joachim Sahlin

    CEO & AI Advisor

    Pick a time for a call
    Painterly desk by a tall window with a policy checklist binder, a laptop, a reading lamp and a cup of tea, pine forest and a lake outside, illustrating an AI policy template for European businesses

    Your IT lead has made the call, and Claude goes out to the whole company next week with licences, single sign-on and a chat channel full of tips already in place. Then HR phones to ask what the rules are, and nobody on the call has an answer. An AI policy template is the bridge between the two, because IT wants to move quickly and HR wants the company covered, and both are right.

    The guide below gives you the eight sections a European company actually needs, from 20 to 500 staff, plus a finished template you can copy and adapt in one afternoon. It keeps to what a normal office does with Claude, ChatGPT and a meeting transcription tool, and leaves the high-risk cases to a lawyer.


    Why do European companies need an AI policy now?

    Two sets of rules meet in the same prompt window. The EU AI Act's transparency duties, including telling people when they talk to a chatbot, apply from 2 August 2026. That date survived the Digital Omnibus, which moved the high-risk rules to December 2027.12 Article 4 has required AI literacy measures for staff since February 2025, and the Omnibus softened the wording without removing the duty.23

    The GDPR sits underneath and gets far more visible once AI is involved, since every prompt that contains a customer name is a processing of personal data. Neither law demands a document called AI policy. A regulator who looks into a complaint will still ask for one first, and so will a customer's procurement team before it signs.

    What should an AI policy include?

    Eight sections cover what we see working at European companies, in four pages rather than forty.

    1. Purpose and scope

    Two sentences on why the policy exists and who it covers. Employees, contractors and interns belong inside, board members usually do, and partners who handle your data may need a separate clause in their contract.

    2. Definitions

    Say what you mean by AI tool, confidential information and personal data, with one example of each. A salesperson in Milan who knows that a client's price list counts as confidential will not paste it into a free chatbot, while one who only read the word "confidential" might.

    3. Principles

    Five short lines, covering data protection, purpose, quality, accountability and ethics. The quality line matters most in daily work, because it says the person who sends an AI draft is responsible for every sentence in it, exactly as if they had typed it.

    4. Risky versus safe prompts

    Concrete pairs teach faster than principles, so give people the difference in text:

    Risky: "Maria Rossi, born 12 March 1980, account IT-44 1234, has a problem with her order."

    Safe: "A customer has a problem with her order and the delivery is five days late."

    Add three pairs from your own work, such as a sales email, an HR case and a support ticket, since people copy what they recognise.

    5. Approved tools with their status

    List every tool with a status and a reason. The status matters more than the name, because "we allow ChatGPT" says nothing about the plan, the account type or whether training on your data is switched off.

    ToolStatusCondition
    Claude Team or EnterpriseApprovedCompany account, business data allowed, no model training on content by default4
    ChatGPT Business or EnterpriseApprovedCompany workspace, no training on business data by default5
    Free or private accounts of any AI toolNot approved for work dataFine for private use, never for customer or staff data
    Meeting transcription toolApproved with conditionsEveryone in the meeting is told before recording starts

    Claude Team and Enterprise store data in the US by default, so a company whose customers demand European storage should note that in the condition column and consider a route through an EU cloud region.6

    6. Incident handling

    Write down what someone does after pasting a customer list into a free tool by mistake. Stop, save the conversation, tell the data protection lead within two hours, and share the lesson without names in the next team update. Three lines are enough, as long as people know that reporting is safe and the routine is simple.

    7. AI meeting transcription

    Transcription tools have become standard in two years, which is useful and needs rules. Use approved tools only, tell everyone before recording, and never record meetings about health, disputes or individual staff matters.

    8. Ownership and review

    Name one owner, usually the data protection lead or the head of IT, and set a yearly review plus an extra one whenever the law changes. Breaches follow the normal employment terms, which is less dramatic than it sounds and avoids a separate disciplinary process.


    A ready AI policy template you can copy

    The complete template sits in our knowledge section and covers all eight sections above. It adds a licence request form, a quick checklist to read before sending a prompt and the approved tools table with status. Copy it into your intranet, swap in your company name and it is ready the same afternoon.

    Open the AI policy template

    Use it however you like. The template is free, and a company that already has a confident IT lead can run the whole rollout without us.


    Three traps that make an AI policy fail

    A policy nobody reads. Twenty pages on a shared drive die there, while four pages discussed at a team meeting get used. A useful test is to ask five people a week later which data never goes into an AI tool, and if fewer than four know, the policy is too long.

    Tools listed without status. "ChatGPT is allowed" leaves every reader to guess which plan and which account. Name the plan, the account type and the training setting, or people will fill the gap with their private login.

    Training left out. The literacy duty is softer after the Omnibus, still a policy without training is a document and not a practice.3 Budget half a day per role for the first round. Expect the first month to bring questions the policy did not foresee, which is normal and a reason to plan the first review after eight weeks.


    How to roll out the policy in three steps

    1. Copy the template from our knowledge section, fill in the approved tools and delete what does not apply to you.
    2. Run a one-hour session with management to check that the rules match how the company actually works.
    3. Roll it out with training, not with an email. People follow rules they have practised on a real task.

    Companies that want the rollout handled end to end can use satori-launch. It sets up the Claude accounts, the folder structure and the first five skills, then trains the team in a webinar and a full-day workshop for €560 per user from eight users. Your policy text itself stays yours, because nobody knows which data is sensitive in your business better than you do. All satori. prices are fixed and exclude VAT.

    Open the template, delete every tool your company does not use and write your own three risky prompts under section four. In thirty minutes you have a first draft that management can read before the next meeting.


    Sources

    Footnotes

    1. European Commission (2026). Timeline for the implementation of the EU AI Act. AI Act Service Desk. https://ai-act-service-desk.ec.europa.eu/en/ai-act/timeline/timeline-implementation-eu-ai-act ↩

    2. European Commission (2026). AI Omnibus enters into force. Shaping Europe's digital future. https://digital-strategy.ec.europa.eu/en/news/ai-omnibus-enters-force ↩ ↩2

    3. Lewis Silkin (2026). The Digital Omnibus on AI enters into force today. https://www.lewissilkin.com/insights/2026/07/27/the-digital-omnibus-on-ai-enters-into-force-today-102nedo ↩ ↩2

    4. Anthropic (2026). Plans and Pricing. https://claude.com/pricing ↩

    5. OpenAI (2026). Business data privacy, security, and compliance. https://openai.com/business-data/ ↩

    6. Anthropic (2026). Where are your servers located? Do you host your models on EU servers? Anthropic Privacy Center. https://privacy.claude.com/en/articles/7996890-where-are-your-servers-located-do-you-host-your-models-on-eu-servers ↩

    Cookies

    We use analytics cookies to see which pages people read, and marketing cookies stay off unless you tick them under Details.