Governance

AI policy for your organisation: template and essential rules

An AI use policy sets out what is allowed, what is not and who decides. Here are the rules that matter, the procedure that makes the policy genuinely enforceable, and a complete template to copy and adapt.

Published on Updated on 7 min readBy the Tacite-IA editorial team

Contents
  1. Why your organisation needs an AI policy
  2. The essential rules of an AI policy
  3. The heart of the policy: data
  4. Making the policy binding: the example of French law
  5. Keeping the policy alive
  6. AI policy template to copy
  7. Frequently asked questions
  8. Sources

Employees already use AI assistants to write, translate or summarise. The question is no longer whether a rule is needed, but which one. An AI policy sets a clear framework: which tools, for which uses, with which data. This guide presents the rules that matter, the procedure that makes the policy genuinely enforceable, and then a complete template to copy and adapt.

Why your organisation needs an AI policy

In France, the CNIL (the French data protection authority) explicitly recommends that every organisation govern the use of generative AI through internal policies or charters that clearly define permitted and prohibited uses.1 It points out that the user organisation is the one held responsible if its staff misuse AI.1

The GDPR points the same way: the organisation, as controller, must implement appropriate measures and be able to demonstrate that it complies with the regulation (Article 24).2 A written policy, shared and explained, is one of those measures. It also protects employees, who finally know what they are allowed to do.

The essential rules of an AI policy

An effective policy fits into a few pages and answers seven questions. The diagram below shows how it comes together, point by point.

  1. Purpose and scopeWho is covered, which tools, which uses.
  2. Approved toolsAn up-to-date list, work accounts only.
  3. Prohibited dataPersonal, sensitive, trade secrets, access credentials.
  4. Human reviewRead, check and take ownership of every output.
  5. TransparencyDisclose the use of AI when it is expected.
  6. IncidentsWho to alert, and how quickly.
  7. Training and oversightAwareness, updates, sanctions.
The seven building blocks of an AI policy, used in the template at the end of this article.
  1. Purpose and scope. Who is covered (employees, interns, contractors) and which tools (chat assistants, writing tools, coding assistants).
  2. Approved tools. An up-to-date list, used with work accounts. The French CNIL advises avoiding accounts created with personal addresses.1
  3. Prohibited data. The central point, detailed below.
  4. Human review. Outputs can be wrong: the person using them reads them and remains responsible for them.
  5. Transparency. Say when content has been produced with AI, if the recipient might expect otherwise.
  6. Incidents. Who to alert in case of a mistake. Personal data pasted by mistake may constitute a breach, requiring notification to the supervisory authority (the CNIL in France) within 72 hours if it presents a risk (GDPR, Article 33).2
  7. Training and oversight. A rule that is not explained is poorly applied. The CNIL recommends training users and making them accountable.1

The heart of the policy: data

Most risks come from what gets pasted into the tool. The policy must therefore name the prohibited categories precisely: identifying personal data, special categories of data under Article 9 of the GDPR (health, opinions, trade union membership and so on)2, confidential information and technical secrets.

Prohibiting is not enough: you also need to say what to do instead. The most useful rule is simple: replace the data with neutral placeholders before sending. The task can still be done, and the GDPR data minimisation principle is respected (Article 5).2

hr-review-notes.docxAnonymised version

Summarise this annual review:

Employee: Sarah Thompson[EMPLOYEE_1], staff number A-20417[ID_1]

Absences: sick leave (depression)[HEALTH] from March to May

Current salary: £3,850 gross[SALARY], pay rise requested

4 items replaced on the device
Applying section 3 of the template: identifying and sensitive data is replaced before sending. Fictitious example.

Making the policy binding: the example of French law

In France, a stand-alone policy has limited force. For its rules to support disciplinary action, it is generally annexed to the règlement intérieur, the company’s internal rules, which notably set out the general rules on discipline (Article L1321-1 of the French Labour Code).3 The règlement intérieur and its annexes can only be introduced after obtaining the opinion of the CSE (comité social et économique, the French staff representative body), and are then subject to publication formalities and must be sent to the labour inspectorate (Article L1321-4).4

The CSE is also consulted on the introduction of new technologies (Article L2312-8).6 Finally, any restriction on employees’ freedoms must be justified by the nature of the task and proportionate to the aim pursued (Article L1121-1).5 A policy that governs use is easier to justify than a blanket ban.

Keeping the policy alive

The European AI Act contains an AI literacy obligation (Article 4), applicable since 2 February 2025.7 In its version amended by Regulation (EU) 2026/1744, it requires organisations that use AI systems to take measures to support the development of AI literacy among their staff.8 An awareness session on the policy is a practical way of doing this.

France’s national cybersecurity agency (ANSSI), for its part, recommends adopting a cautious approach when deploying a generative AI system within an information system.9 Three habits help:

  • Choose business plans, which provide a contractual framework. OpenAI and Microsoft, for example, state that they do not train their models on their business customers’ data by default.10,11
  • Update the list of tools with each new request, rather than letting undeclared uses take hold.
  • Help at the right moment. A tool on the computer can remind employees of the rule when they are about to send sensitive data, and offer to anonymise it. Tacite-IA works this way in Chrome, Edge and coding assistants, with an audit mode to measure usage before enforcing any blocking.

AI policy template to copy

This template follows the seven building blocks presented above. Replace the text in square brackets, delete anything that does not apply to you and have the text reviewed before adopting it. France’s CNIL also offers practical guidance sheets for small and medium-sized businesses (in French).12

AI use policy template
POLICY ON THE USE OF ARTIFICIAL INTELLIGENCE TOOLS
[Company name], version [number], effective from [date]
1. Purpose and scope
This policy sets out the rules for using generative artificial intelligence tools (chat assistants, writing, translation and summarisation tools, coding assistants) in the course of professional activities. It applies to anyone using the resources or data of [Company name]: employees, interns, temporary staff and contractors.
2. Approved tools
2.1 Only the tools on the list maintained by [responsible department or function] may be used for work purposes. This list is available at [location].
2.2 These tools are used exclusively with the work accounts provided by [Company name]. Creating accounts with a personal email address for work purposes is prohibited.
2.3 Any request to add a tool is sent to [responsible department or function], which reviews it with the data protection officer.
3. Data that must not be entered
Unless authorised in writing by [responsible function], it is prohibited to enter, paste or attach into an AI tool:
a) personal data that could identify a customer, employee, job applicant or partner (name, contact details, national insurance or social security number, bank details, etc.);
b) sensitive data: health, opinions, trade union membership, biometric data, criminal convictions;
c) confidential information: contracts, unpublished financial data, strategy, trade secrets, intellectual property, non-public source code;
d) passwords, access keys, tokens and technical secrets.
Where a task involves a document containing such data, the user removes it or replaces it with neutral placeholders (for example [CUSTOMER_1]) before sending anything.
4. Permitted and prohibited uses
4.1 Permitted uses: brainstorming, help with drafting, rephrasing, translating and summarising non-confidential content, help with programming on non-sensitive code.
4.2 Prohibited uses: any decision affecting an individual (recruitment, appraisal, disciplinary action) taken solely on the basis of an AI output; producing unlawful or misleading content, or content that infringes the rights of others.
5. Review and responsibility
Content produced by AI may be inaccurate. Users read and check it before any use, and remain responsible for the output they share or pass on.
6. Transparency
The use of AI is disclosed when the recipient can reasonably expect content written entirely by a human, or when [Company name] requires it.
7. Incidents
Any accidental entry of the data listed in section 3 is reported without delay to [contact], so that [Company name] can assess the situation and, where applicable, meet its notification obligations.
8. Training and support
[Company name] provides awareness training on the use of AI tools, their limits and the rules of this policy. Technical tools may help detect sensitive data before it is sent.
9. Monitoring
Compliance with this policy may be subject to proportionate checks, in accordance with applicable regulations and after informing the people concerned.
10. Breaches
Failure to comply with this policy may lead to the disciplinary measures provided for in the internal rules of [Company name].
11. Updates
This policy is reviewed at least once a year and whenever there is a significant change in the tools or the regulations. Contact: [name, email address].

Frequently asked questions

Is an AI policy mandatory for businesses?

No text requires an “AI policy” as such. However, France’s data protection authority, the CNIL, explicitly recommends one, and the GDPR requires organisations to take appropriate measures to demonstrate their compliance. In practice, it is the simplest tool for governing use.

What should an AI policy contain?

At a minimum: the scope, the list of approved tools, the data that must not be entered, the obligation to check outputs, transparency rules, the incident procedure, training and sanctions.

Do you need to consult employee representatives about an AI policy?

In France, if the policy is annexed to the règlement intérieur (the company’s internal rules), Article L1321-4 of the French Labour Code requires the opinion of the CSE, the staff representative body. The CSE is also consulted on the introduction of new technologies (Article L2312-8). Other countries have their own rules on employee consultation; check the labour law that applies to you.

Can I copy this AI policy template?

Yes, it is freely available. Adapt it to your business and have it reviewed by your legal adviser before adopting it: it does not constitute legal advice.

Sources

  1. Les questions-réponses de la CNIL sur l’utilisation d’un système d’IA générative. CNIL (French data protection authority), 18 July 2024. In French. Accessed on 5 October 2026.
  2. Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data (General Data Protection Regulation). EUR-Lex. Accessed on 5 October 2026.
  3. French Labour Code (Code du travail), Article L1321-1 (content of the règlement intérieur, the internal rules). Légifrance (official French legal database). In French. Accessed on 5 October 2026.
  4. French Labour Code (Code du travail), Article L1321-4 (opinion of the CSE, publication, labour inspectorate). Légifrance (official French legal database). In French. Accessed on 5 October 2026.
  5. French Labour Code (Code du travail), Article L1121-1 (justified and proportionate restrictions). Légifrance (official French legal database). In French. Accessed on 5 October 2026.
  6. French Labour Code (Code du travail), Article L2312-8 (consultation of the CSE, new technologies). Légifrance (official French legal database). In French. Accessed on 5 October 2026.
  7. Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act). EUR-Lex. Accessed on 5 October 2026.
  8. Regulation (EU) 2026/1744 of 8 July 2026 (digital omnibus on AI). EUR-Lex. Accessed on 5 October 2026.
  9. Recommandations de sécurité pour un système d’IA générative. ANSSI (France’s national cybersecurity agency), 29 April 2024. In French. Accessed on 5 October 2026.
  10. Enterprise privacy at OpenAI. OpenAI, page updated on 8 January 2026. Accessed on 5 October 2026.
  11. Enterprise data protection in Microsoft Copilot and Microsoft Copilot Chat. Microsoft Learn. Accessed on 5 October 2026.
  12. Utiliser l’IA générative dans les TPE et PME. CNIL (French data protection authority). In French. Accessed on 5 October 2026.
One measure among others

Govern AI use without slowing your teams down

Tacite-IA detects sensitive data in messages and files before they are sent to AI assistants in Chrome and Edge, and in coding assistants (Claude Code, Cursor, Windsurf, Codex, Gemini CLI, Copilot CLI). Analysis runs 100% on the device, with no AI, and comes with an admin console and an audit mode. Desktop apps (the ChatGPT desktop app, the Chat tab in Claude Desktop, Copilot in Windows) are not covered.

€6 excl. VAT per user per month billed annually, €8 excl. VAT billed monthly. 3-month trial.

Further reading