# How do you write an AI policy for your company?

> Justas Butkus is a fractional AI officer based in Vilnius, Lithuania, founder of AINORA, MB – the company behind the Ainora and Impetora brands – and a graduate of Vilnius University.

Justas Butkus is a fractional AI officer based in Vilnius, Lithuania, working with mid-market companies and scale-ups across the UK, EU and US at two to four days a month. He builds and operates the production AI systems he advises on, and takes no commission, referral fee or revenue share from any vendor.

**A usable AI policy is short, specific and answers six questions: what staff may use, what they may never put into a tool, when a human must check output, who approves new tools, what to do when something goes wrong, and who owns the policy. Anything longer gets ignored, and an ignored policy is worse than none.**

Canonical: https://justasbutkus.com/answers/ai-policy-for-your-company/
Last updated: 2026-08-02

---

## Why most AI policies fail

Most are copied from a template built for a large regulated enterprise, run to fifteen pages, and are read by nobody. Staff continue using whatever tools they were using, except now without telling anyone, which is strictly worse than before: the risk is unchanged and the visibility is gone.

The test of a policy is not completeness. It is whether a new employee can read it in five minutes and know what they may do.

## The six questions your policy must answer

1. **Which tools may staff use?** – A named list, not a principle. "Approved tools are X, Y and Z" is usable. "Tools must be appropriate to the task" is not.
2. **What must never go into any AI tool?** – Be specific to your business: customer personal data, unreleased financials, credentials, anything covered by a client confidentiality clause. Vague categories get interpreted generously.
3. **When must a human check the output?** – Name the situations: anything sent to a customer, anything affecting pay or employment, anything going into a legal or financial document.
4. **How does someone get a new tool approved?** – A named person and a realistic timeframe. If approval is slow or unclear, staff route around it and you are back to invisible risk.
5. **What happens when something goes wrong?** – Who to tell, how fast, and an explicit statement that reporting a mistake made with an approved tool is not a disciplinary matter. Without that, you will not hear about failures.
6. **Who owns this policy and when is it reviewed?** – A name and a date. Unowned policies rot within months in a field moving this fast.

## What to leave out

- **Definitions of artificial intelligence.** Nobody needs them and they date immediately.
- **Ethical principles as standalone statements.** "We will use AI responsibly" constrains nothing. Put the constraint in the rules instead.
- **Technology-specific instructions.** Name tool categories and approval routes, not model versions.
- **Anything you will not enforce.** An unenforced rule teaches staff that the document is decorative.

## How this relates to the EU AI Act

A policy is not what the Act asks for, and it is worth being precise about that because the confusion is being sold commercially.

- **Article 4 requires measures supporting AI literacy** among staff and contractors operating AI systems on your behalf, as replaced by the Digital Omnibus with effect from 27 July 2026. It is a duty of effort. There is no mandated curriculum, examination or certificate.
- **The Act does not require an AI policy document**, and it does not require appointing an AI officer. Unlike GDPR with its Data Protection Officer, no role or governance structure is mandated.
- **A written policy is still the cheapest evidence** that you took proportionate measures, which is what you will be asked to demonstrate in a procurement questionnaire or an insurer's renewal form long before a regulator asks.

> This page is general information, not legal advice, and it does not account for national implementing rules or your specific circumstances.

## A two-page structure that works

1. **Purpose**, three sentences. Why this exists and who it applies to, including contractors.
2. **Approved tools**, a named list with the approval route for anything not on it.
3. **Never put this into an AI tool**, a specific list drawn from your own business.
4. **Human review required**, the named situations.
5. **If something goes wrong**, who to tell and the explicit no-blame statement.
6. **Owner and review date**, a name and a date.

Anything beyond that belongs in a separate governance document read by a different audience.

## Frequently asked questions

### What should an AI policy for employees include?

Six things: which tools are approved, what must never be entered into any tool, when a human must review output, how new tools get approved, what to do when something goes wrong, and who owns the policy. Roughly two pages.

### Does the EU AI Act require an AI policy?

No. Article 4 requires measures supporting AI literacy among people operating AI systems on your behalf, and the Act mandates no policy document and no AI officer role. A written policy is still the cheapest way to evidence proportionate measures.

### How long should an AI policy be?

About two pages. The test is whether a new employee can read it in five minutes and know what they may do. Longer policies get ignored, and an ignored policy leaves the risk unchanged while removing your visibility of it.

### Should the policy name specific AI tools?

Yes, for the approved list, with a clear route to get something added. Principles without a named list get interpreted generously, and staff route around approval processes that are slow or unclear.

### Does an AI policy apply to contractors?

It should. The EU AI Act obligations extend to other persons operating AI systems on your behalf, which includes contractors and service providers, so your policy should say so explicitly.

### Who should own the AI policy?

A named person with a review date, not a function or a committee. In a field moving this fast, an unowned policy is out of date within months.

## Related

- [AI literacy obligations](/ai-training/) – What Article 4 requires, and what it does not.
- [A proportionate governance framework](/use-cases/ai-governance-framework/) – What sits above the policy.
- [EU AI Act, in practice](/eu-ai-act/) – Which obligations apply and which are deferred.

## About the author

**Justas Butkus** – a fractional AI officer based in Vilnius, Lithuania, founder of AINORA, MB – the company behind the Ainora and Impetora brands – and a graduate of Vilnius University.

## If you need this written rather than explained

It is a bounded piece of work: a couple of pages, specific to your tools and your data, with a named owner.

Contact: justas@ainora.lt · [LinkedIn](https://www.linkedin.com/in/justas-butkus/)
