Does the AI Act require a document titled “AI use policy”? We do not present that as a legal duty. A short internal policy is a recommended measure: it writes down which tools the team may use, for what, with which information, and what to do when there is doubt. It is not a certificate. It is not an official EU document. It is not an AI Act obligation presented as if Legal Stones’ internal policy were the law.
In many SMEs the team already uses ChatGPT, Copilot or Gemini. Sometimes with client emails or contracts. The useful question is not “can we use AI?”. It is: for what, with which data, and under which rules?
What a company AI use policy is (and is not)
It is a written internal criterion. Two pages can be enough. At a minimum it should make clear:
- Which AI tools the team may use.
- Which uses are allowed.
- Which information may be entered and which may not.
- What happens with client data.
- Who may use which tools.
- What to do when there is doubt.
Do not enter personal data, trade secrets or unnecessary confidential information. That is a minimisation warning, not a legal classification.
A policy nobody understands does not help. Training can constitute an AI-literacy measure. It is not the only possible measure. Literacy measures must be adapted to context.
Link to Article 4 (without turning the policy into law)
Article 4 sets an obligation to adopt measures to support AI literacy. It applies to providers and deployers; determine first whether the organisation falls into those categories. Completing a course does not by itself guarantee compliance with Article 4.
A written policy can help organise and document measures. Legal Stones can generate a documentary file of the measures adopted. The file can serve as evidence of recorded actions. It does not automatically prove compliance. The Legal Stones file is not an official EU certification.
That does not turn Legal Stones’ template or internal policy into an AI Act obligation. It is methodology. The initial AI-use diagnosis is also not a mandatory AI Act procedure.
More on literacy: Article 4, no official certificate.
Client data and GDPR
The AI Act applies alongside other relevant EU rules, including data protection. AI Act compliance does not replace GDPR compliance. Pasting an email or a contract into ChatGPT may involve processing of personal data. There is no automatic yes or no for every company. It requires review.
If you are buying ChatGPT Enterprise, Copilot or Gemini, the next step is often the SaaS AI clause checklist.
What to do (recommended measures)
- See real use: personal accounts, Shadow AI, tools not inventoried. Start with the five questions.
- Write a short criterion: tools, uses, data, doubts.
- Train the team on your company’s real limits. Training oriented to Article 4, not “guarantees compliance”.
- Keep evidence of recorded actions (policy, inventory, training). It is not an official EU register.
- Review from time to time. Periodic review is a Legal Stones recommendation, not an annual duty imposed by Article 4.
Legal Stones does not guarantee that its programme avoids sanctions. Legal Stones does not by itself guarantee AI Act compliance. Legal Stones is not, by itself, an official certification and does not guarantee compliance with all legal obligations applicable to an organisation.
Frequently asked questions
Does the AI Act require an AI use policy?
We do not present an internal policy with that name as an AI Act obligation. There is a duty to adopt measures to support AI literacy (Article 4), for providers and deployers. A short policy is a recommended measure to document uses and data. Not a certificate.
Should we ban ChatGPT?
Not necessarily. A total ban sometimes pushes use onto personal accounts. The usual approach is to bound it: for what, with which information and with which tool.
Can the team paste client data?
They may already be doing it. It may involve processing of personal data. The AI Act does not replace the GDPR. The first step is to see real use: five questions at Legal Stones. Not a certificate.
Is Legal Stones’ policy the legal duty?
No. Legal Stones’ internal policy is methodology. It is not an AI Act obligation.
Does documenting the policy prove compliance?
The file can serve as evidence of recorded actions. It does not automatically prove compliance. It is not an official EU certification.