← Digital, E-Commerce & AI

AI · Internal governance

Internal policy on using AI tools

A total ban pushes AI use outside company control, while unrestricted use exposes data, secrets and important decisions. An effective policy classifies tools and use cases, establishes approvals and keeps responsibility with the people using the results.

ChatGPT and Copilot data and confidentiality AI literacy
Applies toEmployees, contractors and enterprise accounts
PrincipleNo important decision without appropriate human review
Current obligationAI literacy measures apply from 2 February 2025
01

The policy starts with actual use cases

The company must know which tools are used for drafting, coding, analysis, recruitment, marketing, support or decisions. The same chatbot may present low risk when rephrasing public text and major risk when assessing candidates or analysing client files.

The policy can list approved tools, uses permitted without approval, uses requiring validation and prohibited uses. Exceptions have an owner and minimum documentation.

02

Which data must not be entered

Rules must be easy for someone without legal training to apply. Abstract categories are accompanied by examples from company activities.

  • Personal data: used only with a legal basis, minimisation and an approved tool.
  • Special categories: health, biometrics, political opinions or other sensitive data require enhanced controls.
  • Trade secrets: code, pricing, strategies, customer lists and contractually protected information.
  • Client data: must not be entered into a public tool merely because an employee has internal access.
  • Credentials: passwords, tokens, API keys and authentication details are prohibited.
  • Privileged documents: professional obligations and confidentiality are checked separately.
03

Output verification and responsibility

The user remains responsible for the result’s accuracy, lawfulness and suitability. The policy requires source checking, code testing and competent review before output is sent to a client or used in a decision.

For public content, copyright, factual claims, discrimination and labelling generated content where necessary are checked. Decisions about people require analysis of profiling, impact and genuine human intervention.

04

AI literacy, incidents and updates

Article 4 of the AI Act on AI literacy measures applies from 2 February 2025, with relevant supervision and enforcement beginning in August 2026. Training levels are tailored to role, experience and use-case risk.

The policy includes prompt reporting of leaks, dangerous outputs, rights infringements and unapproved tools. It is reviewed when providers change terms, products integrate new features or the AI Act timetable changes.

05

How we work together

  1. 01
    Inventory and architecture

    We clarify technology, actors, data flows, interface and the intended commercial outcome.

  2. 02
    Legal classification

    We establish roles, applicable regimes, risks and information requiring completion.

  3. 03
    Drafting or audit

    We prepare the internal policy and AI use-case matrix, coordinating the document with the product, technical processes and available evidence.

  4. 04
    Implementation and review

    We deliver the final version, priority actions and reference points to monitor as products or legislation change.

QUESTIONS

Frequently asked questions

Should ChatGPT be completely banned at work?

Not in every organisation. A proportionate approach approves low-risk tools and uses while introducing controls for sensitive data, decisions and functions.

Does an enterprise account eliminate every risk?

No. Terms, retention and data use may be more favourable, but a legal basis, minimisation, security and output review remain necessary.

Is staff training mandatory?

The AI Act requires providers and deployers to take measures ensuring appropriate AI literacy tailored to the people and context of use.

Need an internal AI use policy?

Send your documents for a legal assessment and a solution tailored to your commercial objective.