An AI policy does not need to be long. It needs to answer the questions that come up in practice, in language an employee can apply without calling legal.
Start from the obligation and the behaviour
The legal floor is Article 4 of the AI Act, applicable since 2 February 2025:
Providers and deployers of AI systems shall take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, education and training and the context the AI systems are to be used in, and considering the persons or groups of persons on whom the AI systems are to be used.
Regulation (EU) 2024/1689, Article 4
The behaviour being governed is already established. Microsoft and LinkedIn's 2024 Work Trend Index, published on 8 May 2024 from 31,000 knowledge workers across 31 markets, found that “75% of knowledge workers use AI at work today” and that “78% of AI users are bringing their own AI tools to work (BYOAI)”.
A policy written as though AI adoption is a future decision is a policy about a company that no longer exists.
The ten sections
1. Which tools are approved. Name them. If nobody can list the approved tools from memory, the rest of the policy is decorative.
2. What data may be entered. Use classes, not adjectives: public, internal, confidential, restricted, with one line each on what is allowed where.
3. Who may use what. Different roles, different permissions, and the permissions enforced by the system rather than by the document.
4. Which outputs need a human check. Be specific about what triggers review: anything sent to a client, anything that becomes a commitment, anything that touches a regulated process.
5. What the AI may decide alone. Usually the answer is nothing that affects a person's rights, employment, credit or care. Write it down anyway.
6. How usage is monitored. The organisation should be able to state which AI systems are in production. That is also the AI Act inventory question.
7. What happens when the model is wrong. A reporting route with no blame attached, because the alternative is silence.
8. What happens when the provider changes. Model retirement, price changes and terms changes are operational events, not surprises.
9. Who owns AI governance. One named role. Not "IT and legal".
10. What happens to company data. For each approved system: processing location, retention, whether inputs train anything, subprocessors, who may access, how deletion works, and the security controls.
The measure of an AI policy is not its length. It is whether the approved route is faster than the unapproved one.
Why a ban is the weakest option
A prohibition competes with a tool that saves an employee an hour a day, and it loses quietly. The usage does not stop; the visibility does. A policy that provides a route keeps both the productivity and the audit trail.
The strongest version is short: use this system for this class of work, with this class of data, and ask before you go outside it.
With Bastion
What Bastion changes
Bastion is a private AI system delivered as one sealed appliance that runs inside your building. One monthly fee covers the hardware, the model, the hardened operating system and support, and nothing your team types leaves the building.
An internal system makes sections 1, 2, 3, 6 and 10 easier to write, because they can describe one named tool with one processing location and one set of permissions instead of a shifting list of external services.
Sections 4, 5, 7, 8 and 9 stay the organisation's work. Technology supports governance and does not replace it.
Questions this article answers
- What should a company AI usage policy contain?
- Ten things: approved tools, permitted data classes, who may use what, which outputs need human review, what AI may decide alone, how usage is monitored, what happens when it is wrong, what happens when the provider changes, who owns governance, and what happens to company data.
- Is an AI policy a legal requirement?
- The policy itself is not named in the AI Act, but Article 4 requires providers and deployers to ensure a sufficient level of AI literacy among staff, and it has applied since 2 February 2025. A policy is how that duty becomes something an employee can follow.
- Should the policy ban AI tools that are not approved?
- A prohibition competes with a tool that saves an hour a day and loses quietly. The stronger version names one system for defined work and defined data classes, and asks people to check before going outside it.
On the record
- 1
EUR-Lex
Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligenceread 2026-09-22
- 2
Microsoft WorkLab
AI at Work Is Here. Now Comes the Hard Part. 2024 Work Trend Index Annual Reportread 2026-09-22
- 3
Read next
- Shadow AI: the tool arrives before the policy doesShadow AI is not an employee discipline problem. It is what happens when the demand for a tool arrives before the approved version of it. The measured scale, why a ban produces the worst version of the outcome, and what an approved path has to contain.Read the article
- AI literacy is already an obligation, and it is not a training courseWhat the Article actually says, what the Regulation's own recital says it is for, why the duty is role-based rather than uniform, and a five-module programme a thirty-person company can run without a consultant.Read the article