AI Policy in the Company: What It Must Contain to Work
This article was created with AI
The text and images in this article were generated with the help of AI systems. Labelled in accordance with Art. 50(4) of the EU AI Act. Responsible for publication: ArkeonTech.
The question tends to arrive late in projects, sometimes only once the system is already running: are our people actually allowed to use it like this? A clerk has pasted the contact list into a chat window to draft invitation emails. The head of sales has contract drafts pre-reviewed - in a private account, because there simply is no company account. Nobody forbade it, nobody allowed it. That is exactly the state most mid-sized companies operate in this September.
In October 2025 the industry association Bitkom surveyed 604 German companies with at least 20 employees. In 8 percent, the use of private AI tools is widespread; 17 percent report isolated cases; another 17 percent suspect it without knowing for sure. Together that is 42 percent of companies observing or assuming shadow AI. Only 23 percent, meanwhile, have set binding rules - the year before it was 15. The gap between usage and rules is the normal state.
This article answers the questions that actually come up when writing such a policy: which obligations sit behind it, how data maps to systems, which sections it needs, who may adopt it and why most templates found online fail at the same point. It is written from the perspective of someone who sets up these rulebooks with companies, not from a lawyer's; where individual interpretation decides, we say so.
In brief: An AI usage policy is not a statutory document in its own right, but without one, three obligations become hard to meet: AI competence under Article 4 of the AI Act, data protection when third-party services are used, and secrecy under the Trade Secrets Act, which requires reasonable measures. What makes a policy effective is three contents: a positive list of approved systems, a matrix assigning data classes to systems, and a review duty before results are used. A total ban without an alternative counts as proven failure: in the 2025 WalkMe survey, 46 percent of employees said they would keep using unapproved AI despite an explicit ban.
Is an AI usage policy legally required?
No. No statute demands a document by that name, and anyone selling you an "AI policy obligation" is selling a term that appears in no regulation. Four obligations do, however, converge on the same result, because they can neither be met cleanly nor evidenced without written rules.
The first is AI competence under Article 4 of the AI Act: since February 2025, deployers must ensure that staff dealing with the systems understand them sufficiently. The policy is the evidence that the company has defined who may do what at all - only from that follows who needs training.
The second is data protection. As soon as employees enter personal data into a third-party service, processing on behalf or a transfer takes place. Without a decision on which service is approved for which data, that decision effectively does not exist - each person then makes it alone, on the private account of their choice.
The third is the Trade Secrets Act. A trade secret is only protected if it is subject to reasonable secrecy measures (§ 2 no. 1 lit. b GeschGehG). A company that has never ruled that internal matters do not belong in public chat services has one argument less when it needs that protection. What exactly is at stake is worked through in our article on ChatGPT and trade secrets.
The fourth concerns only certain deployments: for high-risk systems under the AI Act, employees must be informed before the system is put into service (Art. 26 para. 7), and that includes a rule on who uses the system and how. On top comes commercial pressure: tenders and audits now regularly ask how AI is handled, and a policy is the shortest honest answer.
How large is shadow usage really?
Larger than most boards assume, and it is growing faster than the rulebooks. Four independent surveys draw the same picture:
| Survey | Sample | Central finding |
|---|---|---|
| Bitkom (October 2025) | 604 German companies with 20+ employees | 42 % observe or suspect private AI use; only 23 % have rules, 26 % provide accounts |
| Work Trend Index (Microsoft/LinkedIn 2024) | 31,000 people in 31 countries | 78 % of AI users bring their own tools, 80 % in small and mid-sized companies |
| YouGov for SThree (November 2025) | 5,391 STEM professionals in six countries | In Germany 77 % use AI at work; a similarly large share reaches for non-approved applications at least monthly |
| WalkMe State of Digital Adoption (2025) | over 3,500 knowledge workers worldwide | 78 % use unapproved AI tools; 46 % would continue despite an explicit ban |
The most important sentence in this table sits in the last row. A ban does not change behaviour; it changes the visibility of behaviour. KPMG and the University of Melbourne measured the same point in their global Trust in AI study 2025: 57 percent of employees use AI without the employer's knowledge, 63 percent do not label AI output as such. Whoever only prohibits produces not safety but blindness - nobody knows which data went where.
Which data may go into which system?
The heart of every usable policy is not a list of permitted tools but a matrix: data classes on one side, system tiers on the other. Four classes and four tiers are enough for a mid-sized company.
| Data class | Consumer account (private) | Company account with DPA | EU-hosted service | In-house solution |
|---|---|---|---|---|
| Public: published texts, trade-fair material, website content | Yes | Yes | Yes | Yes |
| Internal: work in progress, concepts, internal figures without personal reference | No | Yes | Yes | Yes |
| Confidential: customer, contract and applicant data, unpublished pricing | No | Yes, if the DPA excludes training use and onward transfer | Yes | Yes |
| Protected: professional secrets under § 203 StGB, health data, R&D secrets | No | No | Only under the assurances of the respective professional code | Yes |
The reading is simple: one cell fully answers the question "May this information go into this system?" What sits on the website may go anywhere. What carries a name, a price or a contract clause does not belong in a consumer account - full stop. The last row follows its own rules that have nothing to do with data protection in general but with criminal and professional law; the details are in the article on LLM hosting for secrecy-bound professions.
Two additions make the matrix workable. First: "company account" means an account held by the company with a data processing agreement and training use switched off - not the paid tier of the same consumer account that stays tied to the person. Second, the matrix belongs in the policy as an annex, not in the running text. New systems enter the annex without the document having to be renegotiated.
What goes in? Nine mandatory sections
A policy meant to carry weight in operations needs nine sections. Fewer leaves gaps; more does not get read.
- Scope and purpose. Who it covers (employees, freelancers, contractors with access) and what it governs: the use of generative AI for work purposes, regardless of who owns the account.
- Approved systems as an annex. A positive list rather than a ban list: what is listed is allowed, everything else is unevaluated. New systems are reviewed as annex amendments, not improvised at the desk.
- The data matrix. The table from the previous section, adapted to your own classes. It is the only place where the document becomes concrete.
- Absolute prohibitions. Professional secrets, unanonymised applicant data and health data go into no external system - health and professional data not even into every in-house one. This is where the short, unambiguous list sits.
- Labelling duties. AI-generated content that leaves the company must be labelled under the conditions of Article 50 of the AI Act - mandatory for deepfakes and synthetic content, a matter of honesty towards customers for text.
- The review duty. AI results are working hypotheses, not results. Whatever goes to customers, authorities or into code unchecked is personally co-carried by the responsible person. This single line prevents more damage than any tool list.
- Ownership and reporting channel. A named owner of the policy and a low-threshold point to report when something wrong entered a system - without blame, otherwise nobody reports.
- Training. Who is trained, how often and on what. This doubles as the evidence for Article 4; details on tiered training are in the article on the AI competence duty.
- Review and amendment. One fixed date per year, one responsible name, and the rule that the annex is updated with every new system.
Who adopts the policy - and when does the works council enter?
The usage rule itself is a management instruction: it governs work conduct - how work is to be done - which management may in principle issue alone. The Hamburg Labour Court made that clear on 16 January 2024 (24 BVGa 1/24): the ChatGPT policy in dispute concerned work conduct and was therefore not subject to co-determination.
It is different for the system through which the rule is enforced. A company account on a chat service whose usage logs the employer can inspect is a technical device within the meaning of § 87 para. 1 no. 6 BetrVG: it can monitor behaviour and performance, and that capability suffices under settled case law. Introducing that access is subject to co-determination, no matter how the usage policy is worded. The cleanest solution is therefore usually a two-layer structure: the policy governs work conduct, a works agreement governs the system and its logs. What belongs in that agreement and how short the procedure stays is covered in the article on works councils and AI adoption.
In practice: even where no co-determination right exists, early involvement is the faster route. A policy written against the workforce is read as a surveillance measure and fought accordingly. One written with it gets followed.
Why do most policies fail?
Five recurring patterns, all traceable to a document without an operation behind it.
Total ban without alternative. Prohibiting AI while providing no approved tool produces shadow usage. The 46 percent from the WalkMe survey are the empirical answer to every policy that only says no.
Template without company reference. A downloaded model policy governs data classes the company does not have and omits the ones it does - professional secrets in a law firm, design data in mechanical engineering.
One rule for all data. Treating everything the same protects nothing. The blanket ban on public texts gets ignored just like the one on contract clauses, and in the end effectively neither applies.
No owner, no date. Vendors change models, processing locations and training terms every quarter. A policy dated 2024 lists systems that no longer exist in 2026 and fails to mention the ones everyone uses.
No answer to the one question. "Which tool for which task?" If an employee cannot answer that in two sentences, the policy is a compliance file, not a working rule.
How does the rule reach operations?
The document is the smaller part. Three steps create the effect.
The first is access: instead of banning usage, procure company accounts for the approved services. This is where the real governance gap sits - 26 percent of companies provide accounts per Bitkom, 42 percent see shadow usage. The difference between those numbers is the sum of private accounts.
The second is technical reinforcement: central sign-on and administration of company accounts, blocking of private AI accounts on company devices via filtering, a short review step in procurement for every new tool. What is not enforced organisationally leaves you with an appeal, not a rule.
The third is repetition: one training at launch, one refresher per year, documented - which doubles as the Article 4 evidence - plus a review date in the owner's calendar. A realistic timeline for the first version is two to four weeks including the works council: half a day for the data matrix, one day for the draft, the rest is alignment.
Frequently asked questions
Is an AI usage policy legally required? No, but in practice it is hard to avoid. No statute demands a document by that name; yet the obligations under Article 4 of the AI Act, the GDPR and the Trade Secrets Act can hardly be met - or evidenced in a dispute - without written rules. The policy is the proof, not the duty.
Do I need the works council to introduce an AI policy? For the rule itself usually not, because it governs work conduct, i.e. how work is to be done (Hamburg Labour Court, 16.01.2024, 24 BVGa 1/24). What is subject to co-determination is the system used for oversight: a company account with inspectable usage logs falls under § 87 para. 1 no. 6 BetrVG and needs a works agreement.
May employees use ChatGPT privately for work? It is not forbidden as such, but it is effectively uncontrolled. Without a data processing agreement no personal data may go in, and trade secrets can lose their statutory protection. The policy therefore has to state which account type may carry which data, not just whether the service is allowed.
What does it cost to create an AI policy? Internally one to two days for the data matrix and the alignment, plus a legal review. Externally drafted policies range from a few hundred to a few thousand euros depending on depth. The larger cost is not the document but the implementation: licences for the approved accounts, training and technical enforcement.
How often does an AI policy need updating? The list of approved tools quarterly, the document itself annually, and event-driven whenever a new system, a new risk class or a new vendor contract arrives. Providers change training terms and processing locations without much notice; the annex is the part that ages fastest.
Is a template downloaded from the internet enough? As an outline yes, as a rule no. Templates fail exactly where things are company-specific: your own data classes, the industry-typical protected assets such as professional secrets, and the interface with an existing works agreement. Anyone who adopts a template unchanged mainly documents that nobody read it.
Conclusion
The real finding is the gap: 42 percent of companies see or suspect shadow AI, 23 percent have rules. A policy does not close that gap by length but by three short answers: which systems, which data, which review. Everything else is decoration.
The test of whether it works is one sentence long: can every employee say which data may go into which tool - without looking it up? If yes, the document is a working rule. If not, it is a file.
This article reflects the state as of 15 September 2026.
Sources
- Bitkom Research, press release "Employees increasingly use shadow AI" (21 October 2025): representative survey of 604 companies with 20+ employees
- Bitkom, study report "Artificial Intelligence in Germany" (2025)
- Microsoft and LinkedIn, Work Trend Index Annual Report (2024): 78 % BYOAI, 80 % in small and mid-sized companies
- YouGov survey commissioned by SThree (November 2025): 5,391 STEM professionals in six countries
- WalkMe/Software AG, State of Digital Adoption Survey (2025): over 3,500 knowledge workers
- KPMG International and University of Melbourne, "Trust, Attitudes and Use of Artificial Intelligence: A Global Study" (2025)
- Hamburg Labour Court, decision of 16 January 2024 - 24 BVGa 1/24
- Regulation (EU) 2024/1689 (AI Act): Art. 4, Art. 26 para. 7, Art. 50
AI process automation with a legal framework
One bounded process first, with a data processing agreement, EU hosting and the technical documentation the works council and the data protection officer want to see.
More Articles
AI Automation for SMEs: A Guide to Boosting Efficiency in 2025
36 percent of German firms cannot fully fill open positions, according to the DIHK. Which processes can be automated first, how to recognise them, and why most projects fail.
WhatsApp Business API & AI: How Companies Generate More Revenue
WhatsApp reaches customers more reliably than email. But without documented consent under Section 7 UWG, every promotional message is a legal risk. What has to be settled first.