Why every company now needs an AI policy
In a short time, AI has gone from a question for the future to an everyday tool. Employees use generative AI services to write texts, summarise documents, analyse data, and write code, often without anyone in management really knowing which tools are used or what is being fed into them. This development is in many ways positive, but it also creates risks that most companies have yet to address.
An AI policy is the internal governing document that sets out how your company may, and may not, use AI. It translates abstract rules and risks into concrete ground rules for employees: which tools are approved, what information may be entered, who is responsible, and where the limits lie. Without such a policy the decisions are still made, but then by each individual employee, separately, with no overall view.
This article covers why an AI policy is needed, how it connects to the EU AI Act and the GDPR, the risks it should manage, and what a policy that actually holds up legally should contain.
What an AI policy is and why it is needed
An AI policy is not a technical document but a business and risk document. It addresses questions that are otherwise answered at random: may an employee paste a customer contract into an external AI tool? May AI be used to make decisions that affect individuals? Who owns what the AI tool produces?
The connection to the EU AI Act
The EU AI Act is the world’s first broad regulatory framework for artificial intelligence. It entered into force in August 2024 and is being introduced in stages. The ban on certain AI practices has applied since 2 February 2025, and obligations for providers of general-purpose AI models have applied since 2 August 2025. The requirements for high-risk AI are, as a main rule, set to apply from 2 August 2026, although a proposed so-called omnibus package may postpone certain high-risk requirements, something that is for now proposed and uncertain.
The regulation classifies AI use by risk, and the sanctions are significant: up to EUR 35 million or 7 percent of global turnover for prohibited AI, and up to EUR 15 million or 3 percent for other infringements. For most companies the issue is not developing AI but using it responsibly, and a policy is the natural way to ensure that use stays within what the framework allows.
The connection to the GDPR
As soon as personal data is entered into an AI tool, the GDPR is engaged. This applies to customer registers, employee data, job applications, or anything that can be linked to a natural person. The usual questions then arise: is there a legal basis, where is the data processed, is it transferred outside the EU, and how long is it stored?
The GDPR has applied since 2018, with sanctions of up to EUR 20 million or 4 percent of global turnover and an obligation to report serious incidents within 72 hours. An employee uploading a file of personal data to an unknown AI tool can, in the worst case, be exactly such an incident. An AI policy should therefore clearly regulate which personal data may be processed with AI at all, and in which tools.
Confidentiality, trade secrets, and intellectual property
Two risks tend to be overlooked. The first is confidentiality and trade secrets: information fed into an external AI tool can in some cases leave the company’s control, and in the worst case be used to train the provider’s models. Business plans, source code, and customer data do not belong in tools that are not approved for the purpose.
The second concerns intellectual property and ownership of what the AI tool produces. The question of who owns AI-generated material is legally far from settled, and there is also a risk that output resembles or reuses protected material. A policy should therefore regulate how AI-generated content may be used and reviewed before it is published or used as a basis for decisions.
A practical example: when the practical becomes a risk
Imagine a mid-sized company with no AI policy. A marketing manager uses a free AI tool to quickly produce campaign copy and pastes in parts of a not-yet-announced product strategy as input. At the same time, an HR employee uploads a number of CVs into another tool to get help ranking candidates. And a developer feeds in parts of the company’s source code to debug faster.
Each of these actions is well-meaning and aimed at working more efficiently. But together, in a single afternoon, the company has potentially leaked a trade secret, processed sensitive personal data in a tool no one has reviewed, risked a discriminatory screening of candidates, and exposed protected source code, all without management even knowing. This is the phenomenon usually called shadow AI: use that happens quietly, outside all governance.
With an AI policy, those same employees would have had clear answers. They would have known which tools are approved, that product strategies and source code must not be entered into external services, and that AI must not be used to screen candidates without human oversight. The efficiency would have been kept, but the risks managed.
Common mistakes companies make
The most common mistake is having no policy at all and hoping employees use common sense. The problem is that common sense around AI presupposes knowledge most people do not yet have, and the legal risks are not intuitive.
A second mistake is banning AI entirely. A blanket ban is almost always ignored in practice and instead drives use underground, where it becomes impossible to govern. The result is more shadow AI, not less.
A third mistake is writing a policy so general that it gives no guidance. Stating that AI should be used responsibly says nothing about which tools are approved or what information may be entered.
A fourth mistake is treating the policy as a one-off document. AI technology and the regulatory framework change quickly, and a policy that is not updated soon becomes outdated. The fourth mistake is often the most expensive, because it creates a false sense of control.
Legal risks without a considered AI policy
The first risk is data protection sanctions. Uncontrolled entry of personal data into AI tools can constitute a breach of the GDPR, with the sanction levels and reporting obligations that follow from the framework.
The second risk ties to the AI Act. Companies that use AI in ways falling under prohibited or high-risk practices, without having mapped this, risk both sanctions and being forced to quickly dismantle an already established use.
The third risk is the loss of trade secrets and unclear ownership of material. Information that has left the company’s control can rarely be recalled, and disputes over who owns AI-generated content can become both costly and hard to untangle. Added to this is the risk of discrimination when AI is used in decisions about, for example, recruitment or credit, where biased models can lead to systematically unfair outcomes and liability for the company.
Recommended actions
Start by mapping how AI is actually used today. Most companies underestimate the extent, and an honest picture of the current state is the precondition for governing use rather than banning it.
Introduce an AI policy that is concrete. It should state which tools are approved, what information may never be entered, how personal data may be handled, how AI-generated material must be reviewed, and where human oversight lies. The principle of human oversight is central: AI should support decisions, not make them alone in matters that affect people.
Assign clear responsibility. A policy with no owner is rarely followed. Appoint who is responsible for keeping the policy current, approving new tools, and answering employees’ questions, and anchor this with management so the governance carries weight.
Train employees and keep the policy alive. A policy no one knows about has no effect. Combine it with simple, practical training, and review it continuously as the technology and regulation develop.
Frequently asked questions about AI policy
Must our company have an AI policy?
There is no single requirement stating that every company must have a document called an AI policy. But because AI use engages the GDPR, the AI Act, and the protection of trade secrets, a policy is the most practical way to ensure that use stays within the framework and within your own risk limits.
What should an AI policy contain?
As a minimum, approved tools, rules on what information may be entered, handling of personal data, requirements to review AI-generated material, principles for human oversight, and a clear allocation of responsibility. It should be concrete enough that an employee can actually follow it.
How does the EU AI Act affect us if we only use AI?
The regulation classifies AI use by risk, and even those who only use AI need to know where their own use falls. Some practices are prohibited and some are high-risk with specific requirements. A policy helps you keep use within what is permitted.
May we enter personal data into AI tools?
It depends on the tool and the purpose. As soon as personal data is processed, the GDPR applies in full, requiring a legal basis, control over where the data is processed, and security in handling. A policy should clearly state which data may, and may not, be entered into which tools.
What is shadow AI and why is it a problem?
Shadow AI is AI use that happens without management’s knowledge or approval, often with free tools that employees choose themselves. The problem is that the risks around data, confidentiality, and compliance arise without anyone being able to govern or even detect them.
Who owns what an AI tool produces?
The question is legally complex and depends, among other things, on the tool’s terms and how the material was created. There is also a risk that output resembles protected material. A policy should therefore regulate how AI-generated content may be used and require human review before it is published.
Conclusion
An AI policy is not about slowing down but about being able to use AI with confidence. Properly designed, it turns scattered and invisible use into a governed asset: employees get clear frameworks, the risks around data and compliance are managed, and the company can benefit from AI without fumbling in uncertainty. As the AI Act comes fully into force, that difference becomes ever more important.
Lawgent specialises in AI, technology, and data protection law, and helps companies build AI policies that both hold up legally and work in practice. We map your use, tailor the policy to your specific business, and connect it to the AI Act and the GDPR. By combining deep specialist expertise with AI-driven efficiency, you get a well-crafted framework in place faster and more cost-effectively than at a traditional firm. Do you want to use AI with confidence rather than uncertainty? Contact Lawgent to build your AI policy.
Related reading
EU AI Act · GDPR · Business lawyer in Stockholm