Skip to content
All articles
AI regulation and governance

What an enterprise AI policy has to contain to be worth writing

Article 4 of the AI Act has required providers and deployers to ensure a sufficient level of AI literacy among their staff since 2 February 2025. A policy is how that duty becomes something an employee can actually follow.

By Bastion, Cluj-NapocaPublished 7 min read

An AI policy does not need to be long. It needs to answer the questions that come up in practice, in language an employee can apply without calling legal.

Start from the obligation and the behaviour

The legal floor is Article 4 of the AI Act, applicable since 2 February 2025:

Providers and deployers of AI systems shall take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, education and training and the context the AI systems are to be used in, and considering the persons or groups of persons on whom the AI systems are to be used.

Regulation (EU) 2024/1689, Article 4

The behaviour being governed is already established. Microsoft and LinkedIn's 2024 Work Trend Index, published on 8 May 2024 from 31,000 knowledge workers across 31 markets, found that “75% of knowledge workers use AI at work today” and that “78% of AI users are bringing their own AI tools to work (BYOAI)”.

A policy written as though AI adoption is a future decision is a policy about a company that no longer exists.

The ten sections

1. Which tools are approved. Name them. If nobody can list the approved tools from memory, the rest of the policy is decorative.

2. What data may be entered. Use classes, not adjectives: public, internal, confidential, restricted, with one line each on what is allowed where.

3. Who may use what. Different roles, different permissions, and the permissions enforced by the system rather than by the document.

4. Which outputs need a human check. Be specific about what triggers review: anything sent to a client, anything that becomes a commitment, anything that touches a regulated process.

5. What the AI may decide alone. Usually the answer is nothing that affects a person's rights, employment, credit or care. Write it down anyway.

6. How usage is monitored. The organisation should be able to state which AI systems are in production. That is also the AI Act inventory question.

7. What happens when the model is wrong. A reporting route with no blame attached, because the alternative is silence.

8. What happens when the provider changes. Model retirement, price changes and terms changes are operational events, not surprises.

9. Who owns AI governance. One named role. Not "IT and legal".

10. What happens to company data. For each approved system: processing location, retention, whether inputs train anything, subprocessors, who may access, how deletion works, and the security controls.

The measure of an AI policy is not its length. It is whether the approved route is faster than the unapproved one.

Why a ban is the weakest option

A prohibition competes with a tool that saves an employee an hour a day, and it loses quietly. The usage does not stop; the visibility does. A policy that provides a route keeps both the productivity and the audit trail.

The strongest version is short: use this system for this class of work, with this class of data, and ask before you go outside it.

With Bastion

What Bastion changes

Bastion is a private AI system delivered as one sealed appliance that runs inside your building. One monthly fee covers the hardware, the model, the hardened operating system and support, and nothing your team types leaves the building.

An internal system makes sections 1, 2, 3, 6 and 10 easier to write, because they can describe one named tool with one processing location and one set of permissions instead of a shifting list of external services.

Sections 4, 5, 7, 8 and 9 stay the organisation's work. Technology supports governance and does not replace it.

Questions this article answers

What should a company AI usage policy contain?
Ten things: approved tools, permitted data classes, who may use what, which outputs need human review, what AI may decide alone, how usage is monitored, what happens when it is wrong, what happens when the provider changes, who owns governance, and what happens to company data.
Is an AI policy a legal requirement?
The policy itself is not named in the AI Act, but Article 4 requires providers and deployers to ensure a sufficient level of AI literacy among staff, and it has applied since 2 February 2025. A policy is how that duty becomes something an employee can follow.
Should the policy ban AI tools that are not approved?
A prohibition competes with a tool that saves an hour a day and loses quietly. The stronger version names one system for defined work and defined data classes, and asks people to check before going outside it.

On the record

  1. 1
  2. 2
  3. 3

    European Commission

    AI Act. Regulatory framework for AI

    read 2026-09-22