AI · Internal governance
Internal policy on using AI tools
A total ban pushes AI use outside company control, while unrestricted use exposes data, secrets and important decisions. An effective policy classifies tools and use cases, establishes approvals and keeps responsibility with the people using the results.
The policy starts with actual use cases
The company must know which tools are used for drafting, coding, analysis, recruitment, marketing, support or decisions. The same chatbot may present low risk when rephrasing public text and major risk when assessing candidates or analysing client files.
The policy can list approved tools, uses permitted without approval, uses requiring validation and prohibited uses. Exceptions have an owner and minimum documentation.
Which data must not be entered
Rules must be easy for someone without legal training to apply. Abstract categories are accompanied by examples from company activities.
- Personal data: used only with a legal basis, minimisation and an approved tool.
- Special categories: health, biometrics, political opinions or other sensitive data require enhanced controls.
- Trade secrets: code, pricing, strategies, customer lists and contractually protected information.
- Client data: must not be entered into a public tool merely because an employee has internal access.
- Credentials: passwords, tokens, API keys and authentication details are prohibited.
- Privileged documents: professional obligations and confidentiality are checked separately.
Output verification and responsibility
The user remains responsible for the result’s accuracy, lawfulness and suitability. The policy requires source checking, code testing and competent review before output is sent to a client or used in a decision.
For public content, copyright, factual claims, discrimination and labelling generated content where necessary are checked. Decisions about people require analysis of profiling, impact and genuine human intervention.
AI literacy, incidents and updates
Article 4 of the AI Act on AI literacy measures applies from 2 February 2025, with relevant supervision and enforcement beginning in August 2026. Training levels are tailored to role, experience and use-case risk.
The policy includes prompt reporting of leaks, dangerous outputs, rights infringements and unapproved tools. It is reviewed when providers change terms, products integrate new features or the AI Act timetable changes.
How we work together
- 01Inventory and architecture
We clarify technology, actors, data flows, interface and the intended commercial outcome.
- 02Legal classification
We establish roles, applicable regimes, risks and information requiring completion.
- 03Drafting or audit
We prepare the internal policy and AI use-case matrix, coordinating the document with the product, technical processes and available evidence.
- 04Implementation and review
We deliver the final version, priority actions and reference points to monitor as products or legislation change.
Frequently asked questions
Should ChatGPT be completely banned at work?+
Not in every organisation. A proportionate approach approves low-risk tools and uses while introducing controls for sensitive data, decisions and functions.
Does an enterprise account eliminate every risk?+
No. Terms, retention and data use may be more favourable, but a legal basis, minimisation, security and output review remain necessary.
Is staff training mandatory?+
The AI Act requires providers and deployers to take measures ensuring appropriate AI literacy tailored to the people and context of use.
Need an internal AI use policy?
Send your documents for a legal assessment and a solution tailored to your commercial objective.
Aveți nevoie de asistență juridică urgentă sau de consultanță de specialitate?
Notă juridică și limitarea răspunderii
Informațiile și articolele publicate pe acest site web sunt puse la dispoziție de Avocatul „Basuc Cosmin Ștefan” exclusiv în scop informativ și educativ general. Materialele prezentate reprezintă analize teoretice și opinii de specialitate la data redactării lor, fără a constitui consultanță juridică, asistență legală sau o opinie aplicabilă unui caz concret. Lectura sau utilizarea acestui conținut nu creează o relație profesională avocat-client între cititor și Cabinet. Având în vedere dinamica legislativă și specificul fiecărei situații de fapt, interpretările conținute nu pot substitui analiza individuală a unei cauze. Pentru stabilirea cadrului juridic aplicabil problemei dumneavoastră și obținerea unei consultații profesionale dedicate, vă invităm să contactați Cabinetul prin mijloacele oficiale de comunicare afișate.
Linkuri utile și legislație
