AI acceptable use policy template
Last reviewed: 28 September 2026
Short answer
An AI acceptable use policy tells employees which AI tools they may use, what data must never go into them, and who approves new tools. A usable template covers scope, approved and prohibited tools, data and file-upload rules, human review, AI literacy training, incident reporting and a review date. Record who accepted each version.
Download the template (.docx) · Read the full template on this page
General information, not legal advice. This guide and template explain regulation and good practice as of 28 September 2026. Have your own legal counsel review your policy before you publish it.
What is an AI acceptable use policy?
An AI acceptable use policy (AUP) is the written rulebook for how people in your company use AI tools at work. It sits next to your information security and data protection policies and answers four practical questions: which tools, for what, with which data, and who decides.
A useful policy is short enough to read and specific enough to act on. "Use AI responsibly" is not a rule. "Customer personal data may only go into the company Copilot account, never into a personal ChatGPT account" is.
Does the EU AI Act require an AI acceptable use policy?
Not by name. No article of the EU AI Act (Regulation (EU) 2024/1689) says "write an AI policy". But several duties that already apply to ordinary companies are hard to meet without one:
| Duty | What it asks of a company that uses AI tools | Applies since | Where a policy helps |
|---|---|---|---|
| Article 4, AI literacy | Providers and deployers take measures to support the AI literacy of staff and others using AI on their behalf | 2 February 2025 (supervised by national authorities from 2 August 2026) | Training rule, training records, role-based modules |
| Article 5, prohibited practices | Certain practices are banned outright, including inferring emotions of people in the workplace (outside medical or safety reasons) | 2 February 2025 | Prohibited-uses clause |
| Article 50, transparency | Deployers disclose deep fakes, and AI-generated text published to inform the public on matters of public interest (unless human-reviewed under editorial responsibility) | August 2026 | Labelling clause |
| Article 26, deployers of high-risk systems | Use per instructions, human oversight by trained staff, log retention, informing workers before workplace use | Annex III uses from 2 December 2027 | Approval gate for HR, credit and similar uses |
| GDPR | Personal data put into AI tools is still processing of personal data | Since 2018 | Data rules, DPIA trigger, breach reporting |
A company whose staff use ChatGPT or Copilot at work is a deployer: the AI Act defines a deployer as a person or organisation "using an AI system under its authority" outside personal, non-professional use (Article 3(4)). The European Commission's AI literacy Q&A confirms that a company whose employees use ChatGPT for tasks like writing advertising text or translation falls under Article 4 and should inform staff about risks such as hallucination.
What changed in 2026. The Digital Omnibus on AI, Regulation (EU) 2026/1744, entered into force on 27 July 2026. It rewrote Article 4: providers and deployers must now "take measures to support the development of AI literacy", and the text states this "does not require providers or deployers to guarantee any specific level of AI literacy of any individual". The duty to act remains. The Omnibus also moved the high-risk rules for Annex III uses to 2 December 2027 and for AI embedded in regulated products to 2 August 2028, according to the Commission's AI Act page.
The Commission's Q&A also says there is no need for a certificate ("organisations can keep an internal record of trainings and/or other guiding initiatives") and that no specific governance structure, such as an AI officer or board, is mandated for Article 4. A policy plus training records is a proportionate way for an SMB to show what it did.
What should an AI acceptable use policy include?
Twelve sections cover what most SMBs need. The template below follows this order.
| Section | What it settles | Why it matters |
|---|---|---|
| Purpose and scope | Who is covered (including contractors) and which tools (chat assistants, AI features inside other software, extensions, agents) | Article 4 covers "other persons" acting on your behalf, not just employees |
| Definitions | Approved, restricted, prohibited; personal data; confidential; secrets | Rules are only enforceable if the terms are clear |
| Roles | Policy owner, tool approver, privacy contact, IT, managers, users | Someone must own the register and the review |
| AI tool register and approvals | Which tools, which account type, which data class, who approved, next review | The register turns "use approved tools" into something people can check |
| Acceptable uses | What people are encouraged to do | A policy that only forbids pushes use underground |
| Prohibited uses | Article 5 practices, decisions about people, impersonation, circumventing controls | Keeps you out of banned and high-risk territory by accident |
| Data rules | What never goes in; a data-class-by-tool table; file uploads; personal accounts | Data entered into the wrong tool is the risk staff can most directly prevent |
| Human review | Checking output; named accountability | AI output can be wrong or invented |
| Transparency | Chatbots, deep fakes, public-interest text | Article 50 deployer duties (deep fakes, public-interest text), plus good practice for chatbots |
| AI literacy training and records | Who trains, when, what is recorded | Your Article 4 evidence |
| Monitoring and privacy | What the company does and does not see | Trust, and GDPR and employment-law duties |
| Incidents, exceptions, review, acceptance | How to report, how to ask for exceptions, when the policy changes, who accepted which version | Makes the policy a living control rather than a PDF |
How do you roll it out in five working days?
You can have a first version live within a week if you keep the scope practical and put legal review on the calendar from day one.
- 1Day 1: find out what is already in use. Ask team leads, check expense reports and SaaS invoices for AI subscriptions, and review browser or network data if you have it. Surveys and firewall logs miss personal accounts and remote work; discovery in the company browser shows which AI sites people actually open (see how to see which AI tools employees use).
- 2Day 2: decide a status for each tool. Approved, restricted or prohibited, plus the account type and the highest data class allowed. Where you approve a tool, give people a company account so they are not pushed back to personal ones.
- 3Day 3: fill in the template. Replace every [bracketed] field. Delete clauses that do not apply. Write the monitoring clause to match what you really do.
- 4Day 4: review. Send the draft to legal counsel and your privacy contact or DPO. If you plan monitoring, check whether employee consultation is required where you operate.
- 5Day 5: publish, train and collect acceptance. Publish version 1.0, run the AI literacy training, and record who accepted which version. Put the review date in the calendar.
How do you classify tools as approved, restricted or prohibited?
Classify the account, not just the brand. The same assistant can be low-risk on a company plan and high-risk on a personal account, because data handling terms differ by plan.
| Account type (example) | What the vendor says about your data (checked 28 September 2026) | Typical status |
|---|---|---|
| ChatGPT Business or Enterprise (company workspace) | OpenAI: by default it does not use inputs or outputs from ChatGPT Enterprise or Business for training; admin roles and SSO are available, and Enterprise adds SCIM and user analytics | Approved, with a data-class limit you set |
| Personal ChatGPT account used for work | OpenAI's consumer privacy page says users "control whether your chats are used to improve our models"; the company has no admin control over the account | Prohibited for company information |
| Microsoft 365 Copilot Chat with enterprise data protection (work account) | Microsoft: prompts and responses are covered by the same contractual terms as Exchange and SharePoint data and are not used to train foundation models | Approved, often the natural choice for Microsoft 365 companies |
| Gemini in Google Workspace (work account) | Google: content is not human-reviewed or used for generative AI model training outside your domain without permission | Approved if you are on Workspace |
| Niche or new AI tools (transcription, image, extensions) | Varies; check terms, data location and a data processing agreement before approval | Restricted or prohibited until reviewed |
Vendor terms change. Record the date you checked them in the register and recheck at each review.
What data rules should the policy set?
Name the data, not just the principle. The rule people remember is a short list of things that never go into an AI tool unless the register allows that data class for that tool: personal data about customers, employees or candidates; special-category data such as health information; confidential information such as contracts, pricing and source code; and material received under an NDA. Secrets (passwords, API keys, tokens) never go in, whatever the tool.
File uploads deserve their own clause. One spreadsheet export can hold thousands of personal records, so the template allows uploads only to tools where the register permits them, and only when everything in the file is allowed for that tool. If you use a technical control to block uploads, say so, and say that getting around it is a breach.
Personal data in AI tools is processing under the GDPR. If a planned use is likely to result in a high risk to people's rights and freedoms, for example new technology applied to employee or customer data, you must carry out a data protection impact assessment before processing starts, as the Finnish Data Protection Ombudsman explains.
How do you prove people accepted the policy and were trained?
Keep two records per person: which policy version they accepted and when, and which AI literacy training they completed and when. That is the evidence Article 4 and the Commission's Q&A point to. No certificate is required.
A spreadsheet works for a small team. Record name, role, policy version, acceptance date, training module and version, completion date and, if you use one, the quiz result. Re-collect acceptance whenever you change the policy materially, and retrain when you add a significant tool.
What are the most common mistakes?
- Banning everything. If there is no approved option, people use personal accounts on their phones, and you lose all visibility. Approve at least one company tool.
- A policy with no register. "Use approved tools only" means nothing if nobody can see the list.
- Undefined data classes. "Don't enter confidential data" fails if staff do not know what counts as confidential. Link to your classification policy or give examples.
- Forgetting contractors. Article 4 covers others using AI on your behalf. The Commission's Q&A gives contractors, service providers and clients as examples.
- A monitoring clause that does not match reality. Say exactly what you do and do not see. Overstating or hiding monitoring damages trust and can breach employment and data protection law.
- No acceptance record. Emailing a PDF proves nothing. Record who accepted which version.
- Letting HR or finance use AI for decisions about people without review. Recruitment, performance evaluation and credit scoring appear in Annex III of the AI Act as high-risk areas. Put an approval gate in the policy.
- Never reviewing it. AI tools and the rules change quickly: the AI Act timeline itself changed in 2026. Set a review date and keep it.
Checklist before you publish
- Every [bracketed] field replaced; unused clauses deleted
- AI tool register filled in with account type, status, data class, owner and review date
- At least one approved company AI tool available to staff
- Data-class table matches your data classification policy
- File-upload and personal-account rules included
- Prohibited uses include Article 5 practices and an approval gate for decisions about people
- Monitoring clause matches what you really do; employee consultation checked
- AI literacy training ready, with a record of who completed what
- Incident contact named, with a 24-hour internal reporting window
- Legal counsel and privacy contact have reviewed the draft
- Version number, effective date and review date set
- Acceptance collected and stored per version
How does VAHTOR help apply the policy?
VAHTOR is an AI governance platform from Vahtor Oy (Helsinki, Finland). It can help you run the parts of this policy that need ongoing evidence, but it is not legal advice and does not by itself make a company compliant with the EU AI Act.
- Register: a Chrome and Edge extension brings the AI tools people use into one company registry, where you approve, restrict or block each one; devices pick up the decision on their next sync.
- Acceptance: publish a company AI policy from a template and track who accepted the current version; policy publishes and acceptances are logged in an audit trail.
- Training records: a workspace AI literacy course with modules and a quiz, where you set the pass mark and completions are recorded per person (Business and Enterprise plans).
- File-upload rule: a Files rule can cancel PDF, Excel and Office attachments to AI tools before they leave the tab, and credentials and secrets are flagged on the device (Business and Enterprise plans).
- Monitoring without reading chats: VAHTOR does not collect prompts or conversations. The workspace sees the tool, time, detection type and risk level, and reporting is aggregated by default, with individual names shown only if the workspace owner turns identifiers on.
Plans start at €199 per month + VAT for up to 25 employees (pricing). See EU AI Act records for companies that use AI for how the pieces fit together.
The template
How to use this template. Replace every [bracketed] field, delete clauses that do not apply, and delete this note. This template explains regulation and good practice as of 28 September 2026. It is not legal advice. Have your own legal counsel review the finished policy, in particular clauses 7, 8, 12 and 15, which interact with employment and data protection law in your country.
Document control
| Field | Value |
|---|---|
| Policy owner | [Name, role] |
| Approved by | [Name, role, e.g. CEO or management team] |
| Version | [1.0] |
| Effective date | [DD Month YYYY] |
| Next scheduled review | [DD Month YYYY, no later than 12 months after the effective date] |
| Related policies | [Information security policy; data classification policy; privacy notice for employees; acceptable use of IT policy] |
| Where to ask questions | [Email or channel, e.g. [email protected]] |
1. Purpose
1.1 This policy sets the rules for using artificial intelligence (AI) tools at [Company name] ("the Company"). It lets people use AI to work better while protecting customer, employee and company information.
1.2 The policy also records the measures the Company takes to support the AI literacy of its staff, as required by Article 4 of the EU Artificial Intelligence Act (Regulation (EU) 2024/1689, "AI Act"), and to meet its obligations under the General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR").
2. Scope
2.1 People. This policy applies to all employees, including part-time and temporary staff, and to contractors, consultants, trainees and anyone else who uses AI tools on the Company's behalf ("users").
2.2 Tools. This policy applies to every AI tool used for Company work, including:
(a) chat assistants such as ChatGPT, Microsoft Copilot, Claude and Gemini;
(b) AI features built into other software, such as writing, meeting-summary, transcription, translation, image or code assistants;
(c) browser extensions and plug-ins that send content to an AI service;
(d) AI agents and automations that act on the user's behalf.
2.3 Devices and accounts. This policy applies on any device, including personal devices, whenever a user works with Company information or acts for the Company. It applies to personal AI accounts used for Company work.
3. Definitions
3.1 AI tool: any software or service that generates content, predictions, recommendations or decisions from the input it receives. This includes "AI systems" as defined in Article 3(1) of the AI Act.
3.2 Approved tool: an AI tool listed in the AI Tool Register (clause 5) with status Approved, used through the account type named there.
3.3 Restricted tool: an AI tool listed with status Restricted. It may be used only for the purposes and data classes the register names.
3.4 Prohibited tool: any AI tool listed with status Prohibited, and any AI tool not listed in the register.
3.5 Personal data: any information relating to an identified or identifiable person, as defined in the GDPR. Examples: names, email addresses, customer records, HR files, CVs, call recordings.
3.6 Confidential information: information classified as [Confidential / Restricted] under the [Company data classification policy], including trade secrets, unreleased financials, contracts, source code, pricing and customer information.
3.7 Secrets: passwords, API keys, access tokens, private keys, recovery codes and similar credentials.
4. Roles and responsibilities
| Role | Holder | Responsibilities |
|---|---|---|
| Policy owner | [Name, role] | Maintains this policy and the AI Tool Register, runs the annual review, reports to management. |
| Tool approver | [Name, role, e.g. CTO or IT lead] | Decides on requests for new AI tools, with input from security and privacy. |
| Privacy contact / DPO | [Name, role] | Advises on personal data in AI tools, data protection impact assessments and data breaches. |
| IT / security | [Team] | Configures approved accounts, technical controls and logging; handles security incidents. |
| Managers | All people managers | Make sure their team has accepted this policy and completed AI literacy training before using AI tools. |
| Every user | Everyone in scope | Follows this policy, completes training, checks AI output, reports incidents. |
4.1 The Company remains responsible for how AI tools are used in its name. Each user remains responsible for the work they deliver, whether or not AI helped produce it.
5. AI Tool Register and approval of new tools
5.1 The Policy owner keeps an AI Tool Register. Only tools listed as Approved or Restricted may be used for Company work, and only through the account type named in the register.
5.2 AI Tool Register (current version kept at [location/link]):
| Tool and vendor | Account type | Status | Allowed uses | Highest data class allowed | Business owner | Approved on | Next review |
|---|---|---|---|---|---|---|---|
| [e.g. ChatGPT, OpenAI] | [Company workspace, e.g. ChatGPT Business or Enterprise] | [Approved] | [Drafting, summarising, translation, coding help] | [Internal] | [Name] | [Date] | [Date] |
| [e.g. Microsoft 365 Copilot Chat, Microsoft] | [Work account signed in with Entra ID] | [Approved] | [Work with Company documents] | [Confidential] | [Name] | [Date] | [Date] |
| [e.g. AI meeting transcription tool] | [Company licence] | [Restricted] | [Internal meetings only, with notice to participants] | [Internal] | [Name] | [Date] | [Date] |
| [e.g. Any chat assistant] | [Personal or free account] | [Prohibited] | [None for Company work] | [None] | [n/a] | [Date] | [Date] |
5.3 Statuses.
(a) Approved: may be used for the listed uses, up to the listed data class.
(b) Restricted: may be used only for the listed uses, by the listed teams, or with the listed extra safeguards.
(c) Prohibited: may not be used for Company work.
5.4 Requesting a new tool. Users request a new AI tool by [form/ticket/email to the Tool approver], stating the tool, the purpose, the data it would receive and the users who need it. The Tool approver decides within [10] working days after checking at least:
(a) the vendor's terms, including whether customer inputs are used to train the vendor's models and how long data is kept;
(b) where data is processed and whether a data processing agreement is in place;
(c) security features such as single sign-on, admin controls and audit logs;
(d) whether the intended use could be prohibited or high-risk under the AI Act (clause 7);
(e) whether a data protection impact assessment is needed under the GDPR.
5.5 Until a tool is approved, it is prohibited. Free trials and personal accounts are not a way around approval.
6. Acceptable uses
6.1 Users may use Approved and Restricted tools, within their listed limits, to:
(a) draft, edit, summarise and translate text;
(b) brainstorm, outline and structure ideas;
(c) write, explain and review code, following the [secure development policy];
(d) analyse information that is Public or Internal, or up to the data class allowed for that tool;
(e) learn about topics relevant to their work.
6.2 Users must check AI output before relying on it (clause 9).
7. Prohibited uses
7.1 Users must not use any AI tool to:
(a) carry out any practice prohibited by Article 5 of the AI Act, including inferring the emotions of people in the workplace (except for medical or safety reasons), manipulative or deceptive techniques, or social scoring;
(b) make or materially shape decisions about individuals, such as hiring, promotion, termination, performance ratings, task allocation or credit decisions, unless the use has been approved in writing by [Policy owner and legal counsel] and a human makes and documents the final decision. Such uses may be high-risk under Annex III of the AI Act and carry additional obligations;
(c) monitor or evaluate the behaviour or performance of colleagues, except through systems approved under clause 12;
(d) create content that impersonates a real person, or deep fakes of people, places or events, unless approved by [role] and labelled under clause 10;
(e) create or spread unlawful, discriminatory, harassing or misleading content;
(f) infringe copyright, licences or other people's rights, or enter third-party material the Company has no right to use;
(g) get around, disable or test the limits of the Company's security controls, including controls on AI tools;
(h) enter any data that clause 8 does not allow.
8. Data rules
8.1 Never enter the following into any AI tool unless the AI Tool Register expressly allows that data class for that tool:
(a) personal data about customers, employees, candidates or other people;
(b) special categories of personal data, such as health, trade union membership, ethnicity or biometric data;
(c) Confidential information;
(d) information the Company has received under a non-disclosure agreement or a customer contract that does not allow it.
8.2 Never enter Secrets into any AI tool, under any circumstances.
8.3 Data class by tool status:
| Data class | Approved tool | Restricted tool | Prohibited or unlisted tool |
|---|---|---|---|
| Public | Yes | Yes, within listed uses | No |
| Internal | Yes | If listed | No |
| Confidential | Only if the register allows it for that tool | Only if listed | No |
| Personal data | Only if the register allows it and the privacy contact has approved the use | Only if listed | No |
| Special categories of personal data | Only with written approval from [privacy contact] | No | No |
| Secrets (passwords, keys, tokens) | Never | Never | Never |
8.4 File uploads. Users may upload files to an AI tool only if the tool allows uploads in the register and every piece of information in the file is allowed for that tool. Spreadsheets, exports, contracts, CVs and customer files are high risk: check them before uploading. [Where the Company uses technical controls to block uploads, users must not try to get around them.]
8.5 Minimise. Give the AI tool only the information the task needs. Remove or replace names and identifiers where you can.
8.6 Personal accounts. Users must not use personal AI accounts for Company work or with Company information.
9. Human review and accountability
9.1 AI output can be wrong, out of date, biased or invented. Users must check facts, figures, citations, code and legal or financial statements before using or sharing AI output.
9.2 A named person is responsible for every piece of work the Company delivers. "The AI wrote it" is not an explanation for an error.
9.3 AI output that affects customers, legal positions, security or individuals must be reviewed by [a second person / the responsible manager] before use.
10. Transparency and labelling
10.1 Users must tell people when they are interacting with an AI system in the Company's name where this is not obvious, for example an AI chat assistant on the Company website.
10.2 Users must disclose that image, audio or video content is AI-generated or manipulated where it is a deep fake, and that text is AI-generated where it is published to inform the public on matters of public interest without human review and editorial responsibility, in line with Article 50 of the AI Act.
10.3 [Optional: Label AI-assisted content in [external marketing / customer deliverables] as follows: "[wording]".]
11. AI literacy training and records
11.1 Before using any AI tool for Company work, users must complete the Company's AI literacy training, [name of course], and accept this policy.
11.2 The training covers at least: what AI is and how the tools we use work; the Company's role under the AI Act (the Company is a [deployer / provider] of AI systems); the risks of the tools in use, such as incorrect output ("hallucinations"), data leaks and bias; and this policy's rules.
11.3 Training is adapted to people's role, technical knowledge and experience. [Teams that use AI for [e.g. customer communication, software development, HR] complete an additional module.]
11.4 Users repeat the training [every 12 months] and when the Company adds a significant new AI tool or changes this policy materially.
11.5 The Policy owner keeps a record of the measures taken, including for each person: name, role, training module and version, date completed, [quiz result], and the policy version accepted. Records are kept for [period].
12. Monitoring and privacy
12.1 The Company [does / does not] use technical tools to see which AI tools are used on Company devices and accounts and to enforce this policy.
12.2 [If monitoring is used:] The Company monitors [e.g. which AI tools are used, when, whether a policy rule was triggered and the risk level]. The Company [does not collect / collects] the text users type into AI tools. [Reports are aggregated by default; individual names are visible to [role] only when [condition].] Monitoring data is kept for [period].
12.3 The Company processes monitoring data in line with the GDPR, the [employee privacy notice] and applicable employment law, including any duty to consult employees or their representatives before introducing monitoring.
13. Incident reporting
13.1 Users must report the following to [contact/channel] as soon as possible and within [24 hours] of noticing it:
(a) personal data, Confidential information or Secrets entered into an AI tool in breach of clause 8;
(b) AI output that was used and turned out to be seriously wrong, harmful or discriminatory;
(c) a suspected compromise of an AI account or integration;
(d) any use of AI that may breach this policy or the law.
13.2 Reporting honestly and quickly is expected and will be treated as responsible behaviour. Speed matters: under the GDPR, the Company as controller must notify the Data Protection Ombudsman (Finland) [or: its lead supervisory authority] of a notifiable personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it.
13.3 If a Secret was entered, the user must also [rotate/revoke it immediately or ask IT to do so].
14. Exceptions
14.1 Exceptions to this policy must be requested in writing from the Policy owner, who records the reason, scope, safeguards and end date. No exception can permit a practice prohibited under clause 7.1(a) or the entry of Secrets.
15. Breaches of this policy
15.1 Breaches of this policy may lead to withdrawal of access to AI tools and to action under [the Company's disciplinary procedure / applicable employment law and contracts].
16. Review
16.1 The Policy owner reviews this policy and the AI Tool Register at least [every 12 months], and sooner when the Company adopts a significant new AI tool, when the law or regulator guidance changes, or after a significant incident.
16.2 Each new version gets a new version number. Users must accept material changes.
17. Acceptance
17.1 By accepting, I confirm that:
(a) I have read and understood the [Company name] AI Acceptable Use Policy, version [1.0];
(b) I have completed the Company's AI literacy training;
(c) I will use AI tools only as this policy allows and will report incidents under clause 13.
| Name | Role / team | Policy version | Date accepted | Signature or electronic acceptance record |
|---|---|---|---|---|
| [ ] | [ ] | [1.0] | [ ] | [ ] |
| [ ] | [ ] | [1.0] | [ ] | [ ] |
Template source: VAHTOR, https://vahtor.com/guides/ai-acceptable-use-policy-template (28 September 2026). Free to use and adapt within your organisation. Provided as is; not legal advice. © Vahtor Oy 2026. This template is not legal advice and does not by itself make an organisation compliant with the EU AI Act or the GDPR.
Frequently asked questions
What should an AI acceptable use policy include?
At minimum: purpose and scope, including contractors; a register of approved, restricted and prohibited tools; data rules that name what never goes into AI, including personal data, confidential information and credentials; file-upload rules; human review of AI output; AI literacy training with records; incident reporting; a named owner; a review date; and a recorded acceptance for each version.
Is there a free AI acceptable use policy template I can edit?
Yes. The template on this page is a complete, clause-numbered policy with bracketed fill-in fields, an AI tool register table, a data-class table and an acceptance table. Download it as a Word file, replace the fields, delete what does not apply and have your legal counsel review it before you publish it to staff.
Does the EU AI Act require an AI acceptable use policy?
Not by name. The AI Act requires providers and deployers to take measures supporting their staff's AI literacy (Article 4), bans certain practices (Article 5), sets transparency duties (Article 50) and adds duties for high-risk uses. A written policy is a practical way to show those measures. The Commission says an internal record of training is enough and no certificate is needed.
What does Article 4 of the EU AI Act require?
Since 2 February 2025, providers and deployers of AI systems must take measures to support the AI literacy of their staff and others using AI on their behalf, considering their knowledge, experience and the context of use. Since the Digital Omnibus entered into force on 27 July 2026, the text states that no specific literacy level must be guaranteed. National authorities supervise it from 2 August 2026.
Can my employer see what I search on ChatGPT?
It depends on the account and the tools your employer uses. Company plans such as ChatGPT Business and Enterprise give admins roles and usage analytics, and monitoring tools differ widely in what they record. A good AI policy states plainly what is monitored and what is not. With VAHTOR, admins see the tool, time, detection type and risk level, not the message text.
Do we need AI usage policy software, or is a document enough?
A document sets the rules; software helps you apply them and keep evidence. Small teams can start with this template, a spreadsheet register and recorded acceptance. As staff and tools multiply, keeping acceptance by version, training records and tool decisions current by hand gets harder, and that is where governance software helps. Neither a document nor software makes a company compliant on its own.
Is ChatGPT shadow AI?
ChatGPT is shadow AI when people use it for work without company approval, for example on personal accounts. The same tool used through an approved company workspace, listed in your AI tool register with clear data rules, is sanctioned AI. The register and the personal-account rule in your policy are what separate the two.
Related
- How can I see which AI tools my employees use?
- EU AI Act records for companies that use AI
- Pricing
- What does the EU AI Act require for AI literacy (Article 4)?
- How do I stop employees pasting company data into ChatGPT?
- How can I govern employee AI use without reading their chats?
- Browser DLP for ChatGPT and other AI tools
- How do you build an AI register for the EU AI Act?
- Tekoälypolitiikka – pohja yritykselle
- Guides: governing workplace AI