Company AI standard template under the GDPR and EU AI Act

    Everything we have learnt about rolling out AI safely at work, from a free AI policy template to hands-on guides for Claude, ChatGPT and Copilot.

    Company AI standard

    A complete standard for safe and lawful AI use, built on the GDPR and the EU AI Act

    About this standard

    This is the operational layer on top of our AI policy template, with concrete routines, roles and responsibilities for a European business that wants its team using AI under the GDPR and the EU AI Act without a legal department of its own. It is a starting point written by practitioners, not legal advice, so have your DPO or lawyer read it before you adopt it.

    Written for small and mid-sized businesses

    Few steps first: a one-page policy, business licences, a line in the privacy notice and a training log cover most of the everyday risk.

    Realistic scope: built for businesses with 10 to 250 employees, not for a group with its own compliance team.

    What is at stake: GDPR fines reach up to €20 million or 4% of worldwide annual turnover, whichever is higher (Article 83(5) GDPR).

    Legal basis under the GDPR

    Main rule: using AI to run the business more efficiently can rest on legitimate interest, Article 6(1)(f) GDPR.

    Requirement: a documented balancing test showing that the business interest outweighs the impact on the people whose data is processed.

    Special category data: health, religion, trade union membership and similar data need a separate condition under Article 9 GDPR.

    What the EU AI Act asks of you as a user

    AI literacy (Article 4): has applied since 2 February 2025. Take measures so staff who use AI understand the tools they use, and keep a record of the training.

    Transparency (Article 50): applies from 2 August 2026. Deepfake images, audio or video you publish must be disclosed as AI-generated.

    High-risk use (Annex III): AI in recruitment, staff evaluation or credit scoring carries extra duties from 2 December 2027.

    Data transfers outside the EU

    Anthropic: the data processing agreement incorporates the EU Standard Contractual Clauses. Claude.ai stores data in the US.

    EU-only processing for Claude: run it through EU cross-region inference on Amazon Bedrock (called from Frankfurt, eu-central-1) or the EU endpoint on Google Cloud Vertex AI.

    OpenAI: offers data residency in Europe for new ChatGPT Enterprise and Edu workspaces and for API projects.

    Recommendation: file a transfer risk assessment with your GDPR documentation, and tell customers in your privacy notice when personal data may leave the EU/EEA through AI services.

    Built on the GDPR, the EU AI Act and the satori. AI policy template • Adapt it to your own business • Not legal advice
    Cookies

    We use analytics cookies to see which pages people read, and marketing cookies stay off unless you tick them under Details.