In this piece
The One-Page AI Policy for a 5 to 50 Person DACH Company
If staff use AI for company work, a short policy can establish a usable baseline: approved tools and a request path, data rules, role-based AI literacy, human review, applicable transparency duties, incident escalation, and an owner. The copy-ready template below is a starting point for a 5 to 50 person company in Austria, Germany, or Switzerland. It is not proof of compliance, and higher-risk uses need controls beyond one page.
This is a practical guide, not legal advice. The regulatory specifics were checked on 2 September 2026. Verify the applicable role, processing, use case, provider terms, and national requirements with qualified counsel.
Want this adapted to your tools and signed off in a week?
Book Free ConsultationWhy a small company actually needs one
Unapproved tools can create concrete confidentiality, personal-data, security, intellectual-property, and output-quality risks. First inventory actual use, then provide an approved path that staff can follow. A one-page baseline helps only when procurement, access controls, training, incident response, and higher-risk review processes support it.
The amended EU AI Act Article 4 requires providers and deployers to take measures supporting the development of AI literacy for relevant staff and others acting on their behalf, considering their knowledge, experience, education, training, context, and affected people. It does not require a guaranteed level for every individual. The duty has applied since 2 February 2025; the amendment entered into force on 27 July 2026. A policy can support that program, but does not satisfy the duty by itself.
What belongs in the policy
Eight short sections, each earning its place.
| Section | What it says |
|---|---|
| Scope and principles | Who and what it covers, plus a few plain principles: a human stays accountable, protect data, be transparent, verify before relying. |
| Approved tools | A named list of allowed tools per use case, and a one-line path to request a new one. This is what kills shadow AI: a yes path. |
| Data handling | What must never go into which tools. Consumer and free tiers are not for company data; a business tier with a signed DPA or AVV is the approved path. |
| AI literacy | A short, documented expectation that staff get basic training. This is your Article 4 hook. |
| Output rules | Mandatory human review; no unverified AI output in customer-facing, legal, or financial contexts. A four-eyes rule for critical outputs. |
| Disclosure | Tell people when they are talking to a bot; label AI content where required, with the human-editorial-control carve-out noted below. |
| Escalation and owner | One named owner and one contact. Without an owner, the policy and reality drift apart. |
| Review cadence | Revisit at least every six months. Tools and law move fast. |
The DACH data-protection part
GDPR roles follow the actual purposes and essential means of processing, not the label on a subscription. Where a provider processes personal data on the company's behalf, Article 28 processor terms are required; a provider using data for its own purposes may instead be a controller for that processing. Consumer and business products differ by provider, tier, settings, region, and contract, so verify retention, training, subprocessors, transfers, security, and deletion for the exact service. Switzerland's revised data-protection law can apply separately. We cover how these regimes stack in how GDPR and the AI Act stack for a DACH SaaS.
The copy-ready one-page template
Paste it, fill the brackets, delete what does not apply. It is built for a 5 to 50 person company, not an enterprise.
AI Usage Policy, [Company Name]
Version [1.0] · Owner: [name or role] · Last reviewed: [date] · Next review: [+6 months]
1. Scope and principles. This applies to all staff and contractors using AI tools for [Company] work. Our principles: a human stays accountable for every output; we protect customer, personal, and confidential data; we are transparent about AI use; we verify before we rely.
2. Approved tools. Use only: [for example ChatGPT Team or Enterprise, Microsoft 365 Copilot, Claude for Work]. Do not use personal or free accounts for company work. To request a new tool, ask [owner] before using it.
3. Data rules. Never enter into any non-approved tool: personal or customer data, confidential or contractual information, credentials, or source code. Approved business tools with a signed DPA or AVV, and no training on our data, may process work data per their tier. If unsure, ask [owner].
4. Training. Everyone using AI completes [short onboarding or link] and a refresher [annually]. Ask [owner] if you are unsure how a tool works or where its limits are.
5. Output rules. AI output is a draft, never a final answer. A qualified person reviews every output for accuracy and context before use. For customer-facing, legal, or financial content, apply the four-eyes principle. Never send unverified AI output to customers or authorities.
6. Disclosure. Apply Article 50 by role and content: providers of direct-interaction systems must inform people unless the AI interaction is obvious; providers of synthetic-content systems have machine-readable marking duties; deployers have separate disclosure duties for deepfakes and certain public-interest text. Record any exception you rely on.
7. Questions and escalation. Owner: [name, role, contact]. Report any data leak, wrong output that reached a customer, or "is this allowed" question immediately. No blame for asking.
8. Review. Reviewed at least every six months and whenever tools or law change materially. Acknowledged: [signature or sign-off].

"A one-page policy that people actually read and follow beats a 27-page document that sits in a folder. The job is not to look compliant. It is to give your team a safe yes instead of an invisible workaround."
What to leave out, on purpose
Avoid vague aspirations without operational rules. Whether ISO/IEC 42001, the NIST AI RMF, a longer risk register, or certification is proportionate depends on the use case, contractual commitments, sector, customer demands, and risk. A small company can start with a short policy, but should expand governance when the systems, obligations, or harms justify it.
Frequently Asked Questions
Does a small company need an AI policy?
What must an AI policy include under the EU AI Act?
Can employees use ChatGPT at work?
Is free ChatGPT GDPR-compliant for customer data?
What is the difference between consumer and business AI tiers?
Do we have to label AI-generated content?
Who should own the AI policy in a small company?
What is the EU AI Act AI-literacy obligation (Article 4)?
Is there a free German AI policy template (KI-Richtlinie Vorlage)?
Is a one-page policy really enough?
Final thoughts
A one-page AI policy can give a small DACH company a clear operating baseline. Name approved tools and use cases, define data and output rules, support role-based literacy, map Article 50 duties, name an owner, and set review triggers.
The page is not compliance by itself. Back it with product-specific contracts and settings, access controls, training, risk assessment, incident response, and additional governance wherever the use case or law requires it.