Not sure where your AI use stands?
Run the free AI compliance checkup to get a practical readiness score, likely risk bucket, missing controls and next actions.
Core rules
- Use only approved AI tools for work.
- Do not enter personal, confidential, customer, security-sensitive, regulated or source-code data unless approved.
- Do not use AI as the sole decision-maker for hiring, credit, legal, medical, safety or high-impact decisions.
- Review AI outputs before using them externally or in important internal decisions.
- Disclose AI use where required by policy, law, customer contract or user expectation.
- Report suspected data exposure, harmful outputs, hallucinations or misuse.
How to make the policy usable
Policies fail when they are too vague. Give examples: “You may use AI to draft a first version of a blog post, but you must fact-check it before publication.” “You may not paste a customer contract into a public AI tool.” “You must not use AI to rank job applicants unless the use case is approved.”
Approval-required uses
Require approval for AI in hiring, employee monitoring, credit, insurance, legal, healthcare, safety, education, essential services, biometric systems, customer eligibility, automated decision-making, or any workflow involving sensitive data.
FAQ
Should we block all AI tools?
Usually a better approach is to approve safe tools and define restricted uses, so employees do not move into shadow AI.
Should contractors follow the same rules?
Yes, especially if they process company, customer or personal data.
How often should the policy be reviewed?
At least monthly during fast-changing periods and whenever tools or laws change materially.
Sources and review method
This page is written as general business guidance, not legal advice. It is maintained from official AI Act materials, European Commission / AI Office updates, the NIST AI Risk Management Framework and practical AI governance controls.