Your staff use AI tools today, policy or no policy. A good AI usage policy is one page that makes that use safe — not a 40-page document nobody reads. Here is what belongs in it, what the law expects, and a practical outline you can adapt.
Last updated: 11 June 2026
An SME's AI usage policy needs five elements: which tools are approved (and which accounts), what data may and may not go in, where human review is mandatory, who owns the policy, and how staff get trained. The AI Act's Article 4 literacy duty already applies — a policy plus a short training is the practical way to meet it.
Two reasons, one legal, one practical. Legally, the EU AI Act's Article 4 requires organisations to ensure adequate AI literacy in staff who use AI systems — a duty that is already in force (unlike parts of the high-risk regime, which have shifted via the Digital Omnibus — disclosed honestly in our AI Act checklist). And under the GDPR, client or personnel data pasted into a free consumer chatbot account is a processing problem you cannot explain away.
Practically: without a policy, every employee invents their own rules. The result is the worst of both worlds — data risk from the enthusiasts and zero productivity gain from the cautious.
A usable SME policy fits on one page. The structure we implement with clients:
The failure modes are predictable: a policy that only forbids (staff route around it on their phones), a policy nobody trained on (legally worth little as literacy evidence), no named owner (it ages into fiction within a year), and copy-pasted corporate templates full of roles an SME does not have. Keep it short, name real tools, review it twice a year.
Want it done properly in one go? Our AI Act check (€950) delivers a gap analysis including a policy tailored to your tools and data, and our AI-literacy training (€12,500) makes the training-plus-sign-off part real — training costs are often partly SLIM-eligible, which we check for free.
An AI policy that works is not a legal treatise — it is a short, readable rulebook your staff can consult in two minutes. For a Dutch SME, the useful length is three to six pages. Anything longer gets skimmed once and forgotten. The goal is to make the safe choice the easy choice, not to build a compliance museum. Below is a section-by-section outline you can copy.
Acceptable use. State plainly what AI may and may not be used for. "You may use approved AI tools to draft, summarise and translate internal text; you may not use AI to make final decisions about people (hiring, credit, dismissal) without a human check." Ground it in concrete tasks your team actually does.
Approved tools. Keep a living list of sanctioned tools and the account tier that is allowed. Free consumer ChatGPT and the paid Enterprise/Team version have very different data terms — name the exact tier. If it is not on the list, it is not approved.
Data and AVG rules — what may go into which model. This is the heart of the policy. Classify data into tiers (public, internal, confidential, special-category personal data) and map each tier to what is permitted. As a rule: no client-identifiable data, personnel data, or special-category data (health, financials) into any tool that trains on your inputs or has no data-processing agreement. Under the AVG you need a lawful basis and a defined retention period for every processing activity — a chatbot log is a processing activity. Write down who signed a verwerkersovereenkomst (DPA) with which vendor.
Confidentiality and IP. Pasting a client contract into a public model can breach your NDA and leak trade secrets. State that source code, unpublished pricing and client documents are confidential by default.
Human oversight and accountability. Name a person, not a committee. Every AI-assisted output that leaves the building has a human owner who checked it.
You do not need to quote articles. You need two lenses. The first is the EU AI Act risk tier: most SME uses (drafting, summarising, marketing copy) are minimal-risk and carry light obligations, but two things bite. Any AI that interacts with customers or generates content must be transparently labelled as AI — a chatbot must tell people it is a bot, and AI-generated images or text aimed at the public should be disclosed. And anything touching hiring, credit-scoring or worker evaluation can fall into the high-risk tier with far heavier duties. Sort your use-cases into these buckets once.
The second lens is the AVG: for every place AI touches personal data, note the lawful basis and the retention period, and confirm a data-processing agreement exists. Our EU AI Act checklist for SMEs turns this into a one-page walkthrough. Keep the policy in plain Dutch and English; put the legal reasoning in a separate annex your DPO reads, not your marketeer.
Your staff are almost certainly already using AI. CBS reports that 29.8% of Dutch SMEs use AI, and even among the smallest firms 13.8% of micro-businesses do — with marketing and sales (32.7%) and administration (25.9%) the top uses. Where there is no policy, people quietly paste customer emails and spreadsheets into free public chatbots to get the work done. A policy that only says "no AI" does not stop this; it just drives it underground, out of sight and out of any audit trail.
The fix is to give people a sanctioned, better path. If there is an approved tool with a data-processing agreement that handles the same task safely, most staff will use it. Pair the rules with a lightweight approval path: anyone who wants a new tool submits a one-paragraph request, the named owner checks the data terms, and it is added to the approved list or rejected with a reason — turnaround measured in days, not months. CBS also found 74.6% of non-adopters cite lack of experience as the barrier; a policy that only forbids widens that gap instead of closing it.
Most first-draft SME policies forget the same handful of things. They name no owner, so nobody maintains the tool list. They skip transparency labelling, leaving the business exposed on the one EU AI Act duty that actually applies to it. They ignore retention — AI chat logs quietly accumulate personal data with no deletion schedule. They say nothing about training, so the rules are never explained and never followed. And they treat the policy as a one-time document rather than something reviewed each time a major model or feature ships.
Start small and ship a three-page version this month; refine it later. If you would rather have it drafted against your actual tools and data, our AI-for-SME guidance and a short AI scan get you a working policy without the legalese.
AI Act check for a fixed €950: gap analysis + a policy tailored to your tools. Training often partly SLIM-eligible.
Book a free consultation →