Research published in the Netherlands in August put a number on something I see in almost every first meeting. Among Dutch employees who use AI at work, 57 per cent now have it in their fixed work routine. Forty-two per cent of them say their organisation has rules for it. That gap is not a policy problem. It is a recall problem, and the two get fixed in completely different ways.
I have run an AI consultancy for Dutch and Flemish companies since 2022. When I ask a director whether there are rules for AI at work, the answer is almost always yes, and it is almost always true. Somewhere there is a document. Then I ask the same question of three people who actually do the work, and I get three different answers, one shrug, and a story about a supplier quote that went into a chatbot last month.
What does the Dutch data actually say about AI at work?
The AI Monitor 2026 from research agency Newcom, fielded in July 2026 among 3,122 people in the Netherlands aged 18 to 65, is the fifth wave since 2024, so it shows movement rather than a snapshot. Eight point six million people now use AI tools in daily life, up from 3.9 million in 2024. At work the figure is 5.2 million, up from 2.8 million over the same two years. Three point four million use these tools close to daily. ChatGPT is still the tool most people name at work, at 43 per cent.
The behavioural numbers are the ones I would put in front of a board. Sixty-four per cent of users at work feel ultimately responsible for what the tool produces. Fifty-nine per cent check the facts. Thirty-four per cent remove sensitive information before they paste. Read the last two together. Most people accept responsibility for the output, and two thirds of them still put text into a tool without taking out what should not leave the building.
Set that against how companies describe themselves. CBS counted 22.7 per cent of Dutch companies with ten or more staff using at least one AI technology in 2024. A year on, 29.8 per cent of firms with 10 to 249 staff and 66.2 per cent of firms with 250 or more were using AI technology in 2025. Those company figures are not directly comparable with the workforce survey: different years, different questions, and a company is not a person. That is exactly why the comparison is worth making. The organisation reports what it has adopted. The workforce reports what it is doing. Those two accounts have come apart, and the second one is where your risk actually lives.
Why do fewer people say the rules exist than at the start of this year?
Here is the finding that made me rewrite this piece. Forty-two per cent of workplace AI users say their organisation has rules for AI use. Six months earlier, in the monitor's previous wave at the start of 2026, that figure was 57 per cent. The researchers are careful about the drop and so am I: it does not automatically mean organisations abolished rules. It means fewer people report that clear rules exist. Awareness fell. Whether the documents fell with it, this data cannot say.
I find the awareness reading easy to believe, because I watch it happen. A policy gets written in one afternoon, usually after an incident or a board question. It is circulated once. Then the ground moves under it. Copilot appears inside the Office menu, a summarisation feature arrives in the ticketing tool, the bookkeeping package ships an assistant, and the accounts clerk is now using AI without ever opening a chatbot. The rule said do not paste company data into ChatGPT. Nobody pasted anything into ChatGPT. The rule did not change. Its address did.
That is the mechanism behind most of the shadow AI I meet. Not defiance. Drift. Only 29 per cent of people who use AI at work have had any training or instruction at all, and 47 per cent say none is available to them. A rule that is issued once and never restated is competing against a tool landscape that changes every quarter, and it loses on repetition alone. How to write the document itself is a separate question with a fairly settled answer. This essay is about the part that happens after you write it.
The law just got lighter, not heavier
If you were quietly hoping the regulator would force this conversation for you, the summer went the other way. Regulation (EU) 2026/1744, the Digital Omnibus on AI, was published in the Official Journal on 24 July 2026 and entered into force on 27 July. Among its amendments it replaces Article 4 of the AI Act in full: the provision on AI literacy.
The original wording asked providers and deployers to take measures to ensure, to their best extent, a sufficient level of AI literacy among their staff and among those operating systems on their behalf. The new wording asks them to take measures to support the development of AI literacy, and adds an explicit clarification that it does not require anyone to guarantee any specific level of AI literacy of any individual. A second paragraph asks the Commission and the member states to help, with particular regard to small and medium-sized enterprises.
In plain terms, an obligation of result became an obligation of means. Compliance teams will read that as relief, and for an organisation running a hundred AI systems it genuinely is. For a firm of thirty it removes the last external reason to do something you needed to do anyway. The rest of the AI Act still applies on its own timetable, and I am not arguing here for more regulation or less. I am pointing out that as of this summer, nobody is going to make you. What happens next in your company is a management decision, not a legal one.
Can your team repeat the rule at half past four on a Thursday?
This is the test I actually use, and it costs nothing. Pick three people who do different jobs. Ask each of them separately, without letting them look anything up: what are you allowed to put into an AI tool, and what are you not?
If the three answers agree, you have a rule. If they differ, you have a file. A rule only exists at the moment it is needed, and that is never a calm moment. It is half past four on a Thursday, the quote has to go out before five, and the fastest path is to paste the entire customer email in and ask for a summary. Whatever the person can recall in that second is your actual policy. Everything else is documentation about it.

Most policies fail this test for a structural reason. They are written to survive a lawyer rather than a Thursday. They are long, they are conditional, and they are organised by risk category instead of by moment of use. A document arranged around headings like personal data, intellectual property and confidentiality is correct and unusable, because the person at the keyboard is not thinking in categories. They are thinking about one email.
What I ask instead of “do you have an AI policy?”
Three questions. They take about ten minutes, and I have yet to sit in a first meeting where all three were already answered.
Which AI tools are actually in use here this month?
Not approved. In use. Almost nobody can answer this without asking around, and the asking around is the valuable part. The list is always longer than the director expects, and it nearly always includes something embedded in software the company already pays for, which nobody had filed mentally under AI at all.
What is the one thing that must never leave the building?
One category, named in the words your people already use. Anything with a client name on it. The price list. The patient record. Not “confidential information”, which means nothing at speed. One line, in your own vocabulary, that a new hire could repeat after hearing it once. If you cannot get it down to one line, the problem is not the writing. It is that the business has not yet decided.
Who do I ask when I am not sure?
A name, not a mailbox. The point is not governance. It is that uncertainty needs somewhere to go in under a minute, or it resolves itself as “probably fine”. In a firm of thirty that person already exists, and saying out loud that it is their job costs nothing. It is the same instinct behind keeping a small company’s AI plan down to one page: fewer moving parts, each of them owned by somebody with a name.
Answer those three in a sentence each and you have a working rule, whether or not it is written down anywhere. Fail them and a twelve-page document will not save you, because the document was never the thing doing the work.
Where the works council comes in, and where it does not
There is a specifically Dutch layer here that gets missed in both directions. Article 27 of the Wet op de ondernemingsraden gives a works council a consent right, the instemmingsrecht, over an employer’s decision to establish, change or withdraw certain arrangements. Two of them matter here. Sub k covers a regulation on the processing and protection of personal data of people working in the company. Sub l covers arrangements for facilities that are aimed at, or suitable for, observing or checking the presence, behaviour or performance of staff.
So the moment your AI rule includes logging who used which tool, or reviewing AI-assisted output as part of how people are assessed, you are inside article 27 rather than standing next to it. An employer who cannot obtain consent can ask the kantonrechter for permission to go ahead anyway. An employer who simply skips the step is exposed differently: the decision is void if the works council invokes that in writing within a month. None of this is obscure. It is the same provision that governed the arrival of email and internet monitoring in the early 2000s, which is a useful reminder that we have had a version of this conversation before.
Now the part that gets missed in the other direction. Most of the companies I work with have fewer than fifty employees, and the works council obligation starts at fifty. They have no works council at all. The WOR does provide a lighter participation route for companies with ten to fifty staff, in its chapter on small enterprises, and in my experience almost nobody reaches for it here. So no institution forces the conversation, and the rule ends up written by whoever is most worried, alone, in an afternoon, in language borrowed from a template. That is not a compliance failure. It is simply how a document gets made when nobody has to argue about it first.
None of the above is legal advice and I am not a lawyer. If your AI rules touch monitoring or personnel data, that is the moment to involve one. What the AVG asks of you is a related but separate question, and worth reading before you write anything down.
What changes when the rule is short enough to remember
The monitor reports an association I would not over-read: people who had received training or instruction were more likely to adjust AI output and to check facts. That is a correlation in survey data, not proof that the training caused the care. It is entirely possible that the kind of organisation which trains people is also the kind that hires and supervises carefully. Worth knowing. Not worth building a business case on.
My own reading, from the inside, is narrower. What changes after training is rarely the knowledge. It is that the rule acquired a face and a moment. Somebody said it out loud in a room, other people were there, and the whole thing became retrievable as the memory of a conversation instead of a document you would have to go and find. That is a low bar, and it is the bar most companies are failing.
So the practical move is smaller than a project. Take fifteen minutes on a meeting that already happens, once a quarter. Ask the three questions out loud, to the people who do the work, and write down what they actually say rather than what you were hoping to hear. Sometimes the honest answer is that a rule everybody agreed to is quietly impossible to follow, and the right response to that is to change the rule rather than the people. Do not start a committee. Add an item.
Your team already made this decision. They made it one paste at a time, on ordinary afternoons, under deadline, without malice and in most cases without incident. The open question was never whether AI is used in your company. It is whether the rule about it can be repeated, from memory, by the person holding the keyboard. If you would like a second opinion on where yours currently stands, that is a conversation I am glad to have, and it usually takes about half an hour.
Written on 8 September 2026. Figures checked against the Newcom AI Monitor 2026 (fieldwork July 2026, n=3,122), CBS business statistics for 2024 and 2025, and Regulation (EU) 2026/1744 as published in the Official Journal on 24 July 2026.