What to Include in a Workplace AI Policy: A Section-by-Section Checklist
Use this checklist to review an existing AI policy or plan a new one. Each section lists the questions your policy should answer clearly.
Short answer
A workplace AI policy should include: purpose and scope; approved tools and how to request new ones; data protection and confidentiality rules; acceptable uses with examples; prohibited uses; accuracy and human review responsibilities; transparency and disclosure; intellectual property; fairness and bias; how AI is used in decisions about employees; training and AI literacy measures; reporting and breaches; and ownership and review. Commonly missed items include AI built into existing software, AI agents that take actions, and employee rights when AI affects them.
Key takeaways
- Each section should answer practical questions employees actually ask.
- Cover AI embedded in everyday software, not only standalone chatbots.
- Address AI agents that can act, not just generate content.
- Include employee rights when AI is used on them.
Section-by-section checklist
| Section | Questions it must answer |
|---|---|
| Purpose and scope | Why does the policy exist? Who does it cover? Which tools and devices? |
| Approved tools | Which tools can I use? For what data? How do I request a new tool? |
| Data protection | What must I never enter? How do I anonymise? What about customer data? |
| Acceptable uses | What can I use AI for? Examples for my role? |
| Prohibited uses | What must I never do with AI? |
| Accuracy and review | Who is responsible for AI-assisted work? What must I check? |
| Transparency | When must I disclose AI use? To whom? |
| Intellectual property | What can I input? Who owns outputs? How do I avoid infringement? |
| Fairness | How do I avoid biased outputs? Who do I tell? |
| AI in people decisions | How does the organisation use AI on employees? What are my rights? |
| Training | What training must I complete? |
| Reporting and breaches | How do I report concerns? What happens if rules are broken? |
| Ownership and review | Who owns the policy? When is it reviewed? |
Commonly missed items
- Embedded AI: AI features inside email, documents, meeting and HR software.
- AI agents: tools that can send messages, update records or take actions, and the approvals they need. See agentic AI in HR.
- Meeting recording and transcription: consent and retention.
- Employee rights: notice, human review and challenge when AI affects them.
- Third parties: contractors and suppliers using AI on your data.
- Customer-facing AI: telling people when they interact with AI.
- Regulatory updates: a process for tracking changes such as the 2026 EU AI Act amendments.
Legal reference points
- EU AI Act: literacy measures (Article 4), prohibited practices including workplace emotion recognition (Article 5), human oversight and deployer duties for high-risk systems, transparency (Article 50). See the EU AI Act and HR.
- Data protection law such as the GDPR, including rules on automated decisions and impact assessments.
- Local AI employment rules such as New York City's Local Law 144.
- Employment law and consultation duties.
Use the AI acceptable use policy template for draft wording.
This is general information and a starting template, not legal advice. Adapt it to your organisation, jurisdictions, works council or union agreements and sector rules, and have it reviewed by qualified counsel.
Related guides
- AI Policy for Employees: Why You Need One and What It Should Cover
Why an employee AI policy is essential, what it covers and who owns it.
- Generative AI Acceptable Use Policy Template for Employees
A copy-ready 15-section AI acceptable use policy template to adapt for your organisation.
- The EU AI Act and HR: What Employers Need to Know in 2026
The AI Act for HR, updated for the 2026 Omnibus: what is high-risk, what is banned, and the timeline.
- Ethical AI in HR: A Framework for Responsible Use of AI with People
Principles, issues, governance and ethical review for using AI responsibly with people.
Frequently asked questions
What should a workplace AI policy include?
Purpose and scope, approved tools, data protection, acceptable and prohibited uses, accuracy and review, transparency, intellectual property, fairness, AI in people decisions, training, reporting and breaches, and ownership and review.
What do AI policies commonly miss?
AI embedded in everyday software, AI agents that take actions, meeting transcription, employee rights when AI affects them, third-party use of your data and processes for tracking regulatory changes.
Should an AI policy cover AI used on employees?
Yes. Employees should know how AI is used in HR decisions affecting them, and what notice, human review and challenge rights they have.
Which laws should an AI policy consider?
AI-specific laws such as the EU AI Act and New York City's Local Law 144, data protection law such as the GDPR, employment law and consultation requirements.
