Websites, shops and web applications · post-launch care · Krakow, Poland · since 2016
+48 509 597 843 · info@invisio.digital
June 14, 2026

An AI policy for your company — where to start (a practical guide)

How to set up an AI usage policy from a practitioner's perspective, not a lawyer's: what to actually regulate, how to protect client data, and a ready checklist to start.

Artificial intelligence entered companies faster than the rules for using it. Employees paste fragments of contracts into ChatGPT, generate graphics, ask for email summaries — usually with no guidelines at all. An AI policy isn’t a bureaucratic document „for the drawer”, but a simple way for a company to use AI safely, consistently and without the risk of leaking data. This guide shows how to set one up from a practitioner’s perspective — a company that works with AI daily — not a purely legal one.

Why a company needs an AI policy

This isn’t about scaring people with regulations. Three concrete benefits:

  • Data security — so no one pastes confidential client data into a tool that trains on what it receives.
  • Consistency — so the team uses AI in a similar way and the results hold one standard.
  • Quality and accountability — so it’s clear that a human who approves the output is responsible for it.

An AI policy sorts this out in a few sentences, before an unpleasant surprise does it for the company.

What it should actually regulate

From the perspective of daily use, not theory. A good policy answers five questions:

  1. Which tools are allowed — a list of approved (and banned) ones, distinguishing free versions (which often train on your data) from company/paid ones with privacy guarantees.
  2. What data may and may not be entered — more on this below, because it’s the key point.
  3. Who verifies the result — AI is often confident and wrong; the output is always checked and approved by a human.
  4. Whether and how to label AI-generated content — internally and toward clients.
  5. Who is responsible — that the employee/company bears responsibility for the result, not „the algorithm”.

Client data and AI — the point that decides everything

This is where an AI policy truly protects the company — and exactly where most guides are vaguest. Practical rules to start with:

  • Don’t enter confidential or sensitive data into public models — clients’ personal data, passwords, access credentials, unpublished contracts, financial data.
  • Anonymise before asking AI for help — instead of pasting a real contract with party names, remove identifying data and work on the „skeleton”.
  • Distinguish between tools — free versions often use your input for training; company solutions (paid plans, „enterprise” versions) usually disable it. Know what you’re using.
  • When in doubt — don’t paste. A simpler rule than a list of exceptions.

In our own work we follow the same rule: AI helps us with research, content preparation and support while coding, but client data and access credentials never go into public models — that’s non-negotiable, no matter how convenient.

What it looks like in practice (the perspective of a company that uses AI)

This is the difference between theory and daily reality. At Invisio, AI is a real part of our toolkit — we use it for research, preparing and editing content, and support while working with code. But two rules are constant:

  • The human decides. AI speeds things up and suggests; the choice, verification and responsibility stay with people. No text, code or recommendation reaches a client without review.
  • The line on data is hard (see above). Convenience never beats the security of client data.

It’s this practice — not the document itself — that makes an AI policy work. The document only writes down what you already do.

An AI policy without an „AI Officer” — a version for a smaller company

Most guides are written for corporations: committees, audits, dedicated roles. In a small company that’s overkill. Here an AI policy can fit on one page and needs no new positions — it just has to be simple, known to the team and followed. A short rule everyone keeps beats a ten-page document no one reads.

What about the EU AI Act and GDPR?

Regulations are moving toward more accountability for how AI is used (the EU AI Act, and for personal data — GDPR). For most companies, though, the practice described above matters most to begin with — data security and clear rules. The legal details and risk classification are worth consulting with a lawyer; this guide deliberately stays on the practical side.

Checklist: an AI policy to start with

A minimal policy you can write down today (copy and adapt):

  1. Purpose — why we use AI and what we expect from it.
  2. Allowed tools — a list of approved ones (with versions), a list of banned ones.
  3. Data — what must not be entered; the duty to anonymise; the „when in doubt, don’t paste” rule.
  4. Verification — every output is checked and approved by a human before use.
  5. Labelling — when and how we mark AI-generated content.
  6. Accountability — who is responsible for the result; where to report doubts.
  7. Updates — who reviews the policy and how often (tools and rules change fast).

That’s enough to start. A policy can always be expanded — it’s worse when there’s none at all.


If you want to adopt AI in your company so it genuinely helps rather than creating risk — see how we work with AI. We help companies use artificial intelligence safely and sensibly, from tools to processes.

Next step

Want to discuss your case?

A free cost audit within 3 days or a 30-minute project call - whichever works better for you.

The simplest start is one conversation or a cost audit. If we are not the right fit, we will say it directly.

Free audit PDF