How to Write an AI Policy for Your Organization in 5 Steps
How to Write an AI Policy for Your Organization in 5 Steps
Your organization uses AI. Does it have a policy?
Somewhere in your company right now, someone is pasting confidential customer data into ChatGPT. Someone else is using an AI tool to screen resumes. A third person is generating marketing copy with Gemini without telling anyone. This isn't hypothetical. Research from Microsoft and LinkedIn shows that 78% of knowledge workers use AI at work, and more than half of them haven't told their managers.
This is the reality that makes an AI policy not just a compliance checkbox, but an operational necessity. Without clear guidelines, you're not just risking regulatory trouble under the EU AI Act. You're risking data leaks, biased decisions, reputational damage, and a workforce that's making it up as they go.
The good news: writing an effective AI policy doesn't require a team of lawyers and six months of committee meetings. It requires clarity about what you want, what you're willing to accept, and what your people need to know.
Step 1: Define your AI landscape
Before writing a single rule, you need to know what AI is actually being used in your organization. Not what you think is being used. What is actually being used.
This means conducting an AI inventory. Send a survey. Talk to department heads. Check procurement records. Look at browser extensions, SaaS subscriptions, and software integrations. You'll almost certainly find AI tools you didn't know about. Shadow AI, the organizational equivalent of shadow IT, is the norm in 2026, not the exception.
Your inventory should capture four things for each AI tool: what it does, who uses it, what data it processes, and whether it makes or supports decisions that affect people. That last point matters enormously under the EU AI Act, because AI systems that affect employment, creditworthiness, education access, or public services are classified as high-risk under Article 6 and Annex III.
Don't aim for perfection in this step. Aim for visibility. You can't govern what you can't see.
Step 2: Establish your risk framework
Not all AI use carries the same risk. A team using ChatGPT to brainstorm marketing slogans is fundamentally different from a team using an AI model to score credit applications. Your policy needs to reflect this difference.
The EU AI Act provides a useful starting framework with its four-tier risk classification: unacceptable risk (banned), high risk (heavily regulated), limited risk (transparency obligations), and minimal risk (essentially unregulated). But your internal policy should go further.
Editorial transparency
About the author and sources
Zahed Ashkara is a lawyer, AI governance specialist, and founder of LearnWize. Factual and legal references link to the sources below and in the article. Always check the official publication for the current legal position.
Published on April 15, 2026
Sources for this article
Related articles
Need AI literacy evidence for your team?
Start with the 5-minute scan and see where your AI literacy is not yet provable.