Back
Kevin Riedl

10 min read · 15 Jun 2026
Last reviewed

Next
Made on your device, with no Instagram connection. We copy the post link for Instagram’s Link sticker.

The One-Page AI Policy for a 5 to 50 Person DACH Company

If staff use AI for company work, a short policy can establish a usable baseline: approved tools and a request path, data rules, role-based AI literacy, human review, applicable transparency duties, incident escalation, and an owner. The copy-ready template below is a starting point for a 5 to 50 person company in Austria, Germany, or Switzerland. It is not proof of compliance, and higher-risk uses need controls beyond one page.

This is a practical guide, not legal advice. The regulatory specifics were checked on 2 September 2026. Verify the applicable role, processing, use case, provider terms, and national requirements with qualified counsel.

Want this adapted to your tools and signed off in a week?

 Book Free Consultation

Why a small company actually needs one

Unapproved tools can create concrete confidentiality, personal-data, security, intellectual-property, and output-quality risks. First inventory actual use, then provide an approved path that staff can follow. A one-page baseline helps only when procurement, access controls, training, incident response, and higher-risk review processes support it.

The amended EU AI Act Article 4 requires providers and deployers to take measures supporting the development of AI literacy for relevant staff and others acting on their behalf, considering their knowledge, experience, education, training, context, and affected people. It does not require a guaranteed level for every individual. The duty has applied since 2 February 2025; the amendment entered into force on 27 July 2026. A policy can support that program, but does not satisfy the duty by itself.

What belongs in the policy

Eight short sections, each earning its place.

SectionWhat it says
Scope and principlesWho and what it covers, plus a few plain principles: a human stays accountable, protect data, be transparent, verify before relying.
Approved toolsA named list of allowed tools per use case, and a one-line path to request a new one. This is what kills shadow AI: a yes path.
Data handlingWhat must never go into which tools. Consumer and free tiers are not for company data; a business tier with a signed DPA or AVV is the approved path.
AI literacyA short, documented expectation that staff get basic training. This is your Article 4 hook.
Output rulesMandatory human review; no unverified AI output in customer-facing, legal, or financial contexts. A four-eyes rule for critical outputs.
DisclosureTell people when they are talking to a bot; label AI content where required, with the human-editorial-control carve-out noted below.
Escalation and ownerOne named owner and one contact. Without an owner, the policy and reality drift apart.
Review cadenceRevisit at least every six months. Tools and law move fast.

The DACH data-protection part

GDPR roles follow the actual purposes and essential means of processing, not the label on a subscription. Where a provider processes personal data on the company's behalf, Article 28 processor terms are required; a provider using data for its own purposes may instead be a controller for that processing. Consumer and business products differ by provider, tier, settings, region, and contract, so verify retention, training, subprocessors, transfers, security, and deletion for the exact service. Switzerland's revised data-protection law can apply separately. We cover how these regimes stack in how GDPR and the AI Act stack for a DACH SaaS.

The copy-ready one-page template

Paste it, fill the brackets, delete what does not apply. It is built for a 5 to 50 person company, not an enterprise.

AI Usage Policy, [Company Name]
Version [1.0] · Owner: [name or role] · Last reviewed: [date] · Next review: [+6 months]

1. Scope and principles. This applies to all staff and contractors using AI tools for [Company] work. Our principles: a human stays accountable for every output; we protect customer, personal, and confidential data; we are transparent about AI use; we verify before we rely.

2. Approved tools. Use only: [for example ChatGPT Team or Enterprise, Microsoft 365 Copilot, Claude for Work]. Do not use personal or free accounts for company work. To request a new tool, ask [owner] before using it.

3. Data rules. Never enter into any non-approved tool: personal or customer data, confidential or contractual information, credentials, or source code. Approved business tools with a signed DPA or AVV, and no training on our data, may process work data per their tier. If unsure, ask [owner].

4. Training. Everyone using AI completes [short onboarding or link] and a refresher [annually]. Ask [owner] if you are unsure how a tool works or where its limits are.

5. Output rules. AI output is a draft, never a final answer. A qualified person reviews every output for accuracy and context before use. For customer-facing, legal, or financial content, apply the four-eyes principle. Never send unverified AI output to customers or authorities.

6. Disclosure. Apply Article 50 by role and content: providers of direct-interaction systems must inform people unless the AI interaction is obvious; providers of synthetic-content systems have machine-readable marking duties; deployers have separate disclosure duties for deepfakes and certain public-interest text. Record any exception you rely on.

7. Questions and escalation. Owner: [name, role, contact]. Report any data leak, wrong output that reached a customer, or "is this allowed" question immediately. No blame for asking.

8. Review. Reviewed at least every six months and whenever tools or law change materially. Acknowledged: [signature or sign-off].

Kevin Riedl

"A one-page policy that people actually read and follow beats a 27-page document that sits in a folder. The job is not to look compliant. It is to give your team a safe yes instead of an invisible workaround."

What to leave out, on purpose

Avoid vague aspirations without operational rules. Whether ISO/IEC 42001, the NIST AI RMF, a longer risk register, or certification is proportionate depends on the use case, contractual commitments, sector, customer demands, and risk. A small company can start with a short policy, but should expand governance when the systems, obligations, or harms justify it.

Frequently Asked Questions

Does a small company need an AI policy?
A short policy is a useful baseline when staff use AI, but whether it is enough depends on the systems, data, sector, contracts, and risk. Article 4 AI-literacy measures have applied since February 2025.
What must an AI policy include under the EU AI Act?
The Act does not prescribe a policy template. Article 4 requires contextual AI-literacy measures, while Article 50 assigns different transparency duties to providers and deployers. Training and disclosure rules are a starting point, not automatic compliance.
Can employees use ChatGPT at work?
Only under the company's approved use cases, configuration, contract, and data rules. Check the exact product's retention, training, processor terms, subprocessors, transfers, security, and deletion behavior.
Is free ChatGPT GDPR-compliant for customer data?
There is no product-wide yes or no without the processing context. A controller must establish a lawful basis, transparency, minimisation, security, retention, transfer safeguards, and the correct provider role and terms. A consumer account may not meet company requirements.
What is the difference between consumer and business AI tiers?
Terms and controls can differ in training defaults, retention, administration, security, subprocessors, transfer mechanisms, and processor contracts. A business label alone does not establish compliance; assess the exact service and configuration.
Do we have to label AI-generated content?
It depends on role and content. Article 50 separates direct-interaction notice, provider-side machine-readable marking, deepfake disclosure, and certain public-interest text. Human editorial review is an exception only to the specified public-interest text duty, not a universal exemption.
Who should own the AI policy in a small company?
One named person, often the owner, ops lead, or IT contact. A policy with no owner drifts from reality.
What is the EU AI Act AI-literacy obligation (Article 4)?
Since 2 February 2025, providers and deployers have had an AI-literacy duty. Following the Digital Omnibus that entered into force on 27 July 2026, they must take measures to support the development of staff AI literacy, considering knowledge, experience, education, training, context, and affected people. They do not have to guarantee a specific level for every individual.
Is there a free German AI policy template (KI-Richtlinie Vorlage)?
Yes. The WKO offers a free fill-in template for SMEs, and German bodies publish guidance too. The one-page template above is a ready DACH starting point you can adapt.
Is a one-page policy really enough?
It can be a useful baseline, not a universal compliance package. Expand it with procurement, risk assessment, data protection, security, incident response, worker consultation, and sector controls where the use case requires them.

Final thoughts

A one-page AI policy can give a small DACH company a clear operating baseline. Name approved tools and use cases, define data and output rules, support role-based literacy, map Article 50 duties, name an owner, and set review triggers.

The page is not compliance by itself. Back it with product-specific contracts and settings, access controls, training, risk assessment, incident response, and additional governance wherever the use case or law requires it.

Production AI help

Building an AI product and worried about inference cost, architecture, or production readiness? Wavect helps founders turn AI prototypes into reliable production systems.

Explore the service path:

Inbox, without the noise

Follow the work that matters to you

Get a short email when we publish something new. Follow the whole blog or only the problems you care about.

What would you like to receive?
Choose your topics

Free, double opt-in, no tracking pixels.

Back
Kevin Riedl

10 min read · 15 Jun 2026
Last reviewed

Next

Get the next Business and regulation field note

One concise email when we publish. No tracking pixels, and no inbox filler.

Free, double opt-in, no tracking pixels.