"Do we really need an AI use policy?" If someone in your company uses ChatGPT, Copilot or a generative assistant — and today that happens almost everywhere — the answer is yes. Not because a single article of law imposes it, but because a written policy is the concrete way to govern a use that is already under way, often without rules (so-called shadow AI), and to demonstrate the compliance the AI Act and the GDPR require. Let's see what it must contain and how to build it.

Why an SME needs an AI policy

A policy is not bureaucracy: it is the document that turns "we use AI" into "we use AI safely, lawfully and verifiably". Four concrete drivers make it necessary.

  • AI literacy (Art. 4) — since 2 February 2025 Regulation (EU) 2024/1689 requires supporting an adequate level of competence in those who use AI. A policy is the natural complement to training: it defines how to use the tools.
  • Transparency (Art. 50) — from 2 August 2026 chatbots must be disclosed, generated content marked and deepfakes flagged. The policy sets who applies these rules and on which channels.
  • GDPR — entering personal data into an AI tool is a processing operation: it needs a legal basis, minimisation, and — in high-risk cases — an impact assessment. Without internal rules the risk of breaches is high.
  • Confidentiality and intellectual property — pasting a contract or source code into a public chatbot can expose trade secrets and customer data. This is the risk SMEs most underestimate.

On top of this sits an operational risk: without a policy, everyone uses the tool they prefer, the way they prefer. Shadow AI is already the norm; the policy surfaces it and makes it safe.

What it must contain: the checklist

A good SME policy is short and operational — a few pages anyone can read. It should cover at least these points:

  1. Purpose and scope — who it applies to (employees, collaborators, suppliers) and to which activities.
  2. Approved and prohibited tools — the list of allowed AI tools (with version/plan, e.g. corporate vs. free account) and those expressly forbidden.
  3. Data that must never be entered — the most important rule: never enter customer or employee personal data, trade secrets, credentials or confidential information into unapproved tools.
  4. Duty to verify outputs — whoever uses AI remains responsible for the result: outputs must always be checked before being used or published.
  5. Transparency — when to disclose AI use to customers, users and colleagues (chatbots, generated content, communications).
  6. High-risk and prohibited uses — a reference to the Art. 5 bans and to the precautions for high-risk uses (e.g. recruitment).
  7. Roles and reporting — who to turn to with doubts, how to report an incident or misuse.
  8. Training and updates — the commitment to train those who use AI and to review the policy.

Roles and responsibilities: who governs AI

A policy with no owner stays a dead letter. Even in an SME you need an AI point-person: the Italian Labour Ministry guidelines (DM No. 180 of 17 December 2025) recommend a Chief AI Officer role, coordinating technological, organisational and compliance aspects, working with the DPO where present. In a small company this can be an added responsibility for an existing role, not necessarily a new hire.

One principle must be stated plainly, because it is binding in the employment relationship: decisions affecting workers cannot be entirely automated. Both DM 180/2025 and the GDPR (Art. 22) reaffirm it: processes bearing on hiring, evaluation or personnel management always require qualified human oversight. The same guidelines coordinate the AI Act, the GDPR and the Workers' Statute, and insist on non-discrimination and human dignity.

Golden rules for generative AI

This is where the day-to-day risks concentrate. The policy should make at least four rules non-negotiable:

  • No confidential or personal data in public or unapproved tools. If a processing operation is needed, do it only on corporate tools with contractual safeguards.
  • Always verify the output. Generative models can produce wrong but plausible statements: no text, figure or citation should be used without human review.
  • Disclose AI use where required: a chatbot must state it is one, generated content must be marked (Art. 50).
  • Mind intellectual property and confidentiality: check licences and rights on what you generate, and never upload material covered by trade secrets or an NDA.

Adopting it and keeping it alive

Writing the policy is half the job. The other half is making it live.

  1. Approval and communication — management formally adopts it and communicates it to everyone, with an easy-to-consult short version.
  2. Documented training — link the policy to an AI literacy programme (Art. 4) and keep evidence of dates, participants and tools covered.
  3. Systems inventory — the policy rests on an up-to-date list of the AI systems in use and their risk classification.
  4. Periodic review — revise it at every new tool, regulatory change or incident. It is not a document to file away.

Where to start

An effective policy is not copied from a template: it starts from how AI is actually used in your company. The first step is an honest snapshot — which tools are already running, with what data, in which processes — followed by risk classification. An independent gap assessment turns that snapshot into a tailored policy, with applicable rules, clear owners and real priorities, avoiding both the generic document nobody reads and the regulatory vacuum that exposes the company.