Short answer: an AI policy is a simple set of rules for how employees can use AI tools at work. It should at least address which tools are approved, which information must never be entered, that a person always reviews the results, and who to ask in case of doubt. It should be short enough to actually be read.

Why do we need an AI policy?

Most employees are already using AI – with or without their manager's knowledge. Without rules, risks arise: someone pastes customer data into a tool that saves everything, someone publishes an AI text with wrong facts, someone uploads a contract with trade secrets. An AI policy is not meant to prohibit. It's there to let everyone know where the line is, so you can use AI with confidence.

Think of it as traffic rules. The rules do not stop the car – they enable everyone to drive safely in the same direction.

What should an AI policy contain?

Keep it short. A policy that no one can bear to read protects no one. These parts should be included.

1. Which tools are approved

List which AI services are okay to use at work, and how. Example:"Approved tools are ChatGPT (paid version with data sharing turned off) and our internal AI support. Other tools must be approved by immediate supervisor before being used with work materials."

2. What information must never be entered

This is the heart of the policy. Example:"Never enter personal data, customer data, passwords, logins, unpublished trade secrets or sensitive financial information into external AI tools."

3. That a person always reviews

AI can be wrong without being noticed. Example:"AI-generated content should always be read and approved by a responsible person before it is sent, published or used in decisions. AI is an aid, not a final source."

4. Transparency and responsibility

Clarify who owns the result. Example:"You are responsible for what you deliver, even if AI helped produce it. If in doubt about copyright or facts, check with your boss."

5. Who to ask

There must be a way when in doubt. Example:"Not sure if something is okay? Ask [name/role] before doing it."

A good AI policy fits on one page and answers a single question for the employee: "Is this okay to do?"

Do small businesses really need a policy?

Yes. It's even more important for small businesses, since you rarely have a legal department to catch mistakes. A simple page goes a long way. It doesn't have to be perfect from the start – the important thing is that it exists and that everyone knows about it.

Consider data protection (GDPR)

GDPR is the EU's regulatory framework for how personal data may be handled. If an employee enters customers' names, email addresses or other personal data into an AI tool, it can be considered that personal data is passed on - and then the rules apply. Therefore, the line about "never enter personal data" is not only a good idea, but connected to the law. The Swedish Privacy Agency (IMY) is the Swedish authority that provides guidance in this regard.

Don't forget the new AI legislation

The EU has also decided on a special AI regulation (often calledAI Act) which comes into effect gradually. For most smaller companies, it means common sense in practice: be open about the use of AI, keep track of which tools you run, and hold humans accountable. A policy is a simple way to be right now.

Then you get started

  1. Write a one-page draft using the five parts above.
  2. Adapt the example formulations to your business.
  3. Go through it with the team – verbally, not just via email.
  4. Put it somewhere everyone will find it.
  5. Review it a couple of times a year, or when new tools appear.

Writing a policy is a good start - but it should also match how you actually work and which tools you use.ZORChelps companies introduce AI in a safe and responsible way, from policy to secure deployment of the tools. Do you want help developing an AI policy that suits you? Get in touch and we'll make it easy.