AI governance
Company AI policy: what to cover, with sample wording per section
An outline of a company AI policy with sample wording for each section, the difference between a policy and a control, and how to make it enforceable.
A company AI policy states which AI tools staff may use, with which data, under whose review, and what happens when the rules are broken. Cover nine areas: scope, approved tools, data classes per tool, human review, disclosure, procurement, incident reporting, training and enforcement. A policy only changes behaviour when controls back it. This page is an explainer, not legal advice.
Last verified 2026-10-07. Sources are listed at the end of the page.
What is a company AI policy, and what is it not?
It is a short document that tells staff and suppliers what is permitted, what is not and who decides in between. It is not a risk assessment, a technical standard or a legal opinion. It should be readable in ten minutes by someone who is not a lawyer.
NIST's AI RMF treats policy as part of its Govern function. GOVERN 1 is about policies, processes, procedures and practices for the mapping, measuring and managing of AI risks, and GOVERN 6.1 covers policies that address AI risks from third parties. The AI RMF is voluntary, and the sample wording below is a draft to adapt, not text taken from any regulator.
What should a company AI policy cover?
Nine sections, each with sample wording. Change every bracket to fit your organisation, and have counsel review the result.
1. Scope
Sample: "This policy applies to all staff, contractors and suppliers acting for [company] who build, buy or use AI systems, including chat tools, coding assistants, agents and AI features inside other software."
2. Approved tools
Sample: "Only tools on the approved list may be used for work. The list is held by [owner] and reviewed [monthly]. To request a tool, submit [form]." Link the list to the AI inventory.
3. Data classes allowed per tool
Sample: "Data classified [confidential] or above must not be entered into any tool not approved for that class. The approved list states the highest class allowed for each tool."
4. Human review
Sample: "A person is accountable for any AI-assisted output used in [customer communications, code released to production, or decisions about people]. The person must review the output before it is used."
5. Disclosure
Sample: "Staff must tell people when they are interacting with an AI system, or when content is AI-generated, where [law or our commitments] require it." Article 50 of the EU AI Act sets transparency duties for providers and deployers from 2 August 2026, with exceptions, so check whether it applies.
6. Procurement
Sample: "Before buying an AI product or enabling an AI feature, the requester completes [review], covering the models and providers used, the data sent, where it is processed and whether it is used for training." This is the third-party policy area of GOVERN 6.1.
7. Incident reporting
Sample: "Report suspected data exposure, harmful output or unexpected agent behaviour to [channel] within [time]. Reporting in good faith will not lead to discipline." Name who triages and who decides on notification.
8. Training
Sample: "All staff complete [training] before using approved AI tools, and annually after that." Article 4 of the EU AI Act, as amended, asks providers and deployers to take measures to support AI literacy of staff and others operating AI on their behalf. See AI literacy under Article 4.
9. Enforcement
Sample: "Breach of this policy may lead to access removal and disciplinary action under [process]. Exceptions are granted only by [owner] in writing and are recorded."
How do you write the data classes per tool section?
A matrix beats prose. This one is illustrative: the tool tiers and data classes are examples for you to replace.
| Data class | Approved tool with a contract and controls | Approved tool, limited use | Unapproved or personal tool |
|---|---|---|---|
| Public | Allowed | Allowed | Allowed for non-work use only |
| Internal | Allowed | Allowed with owner approval | Not allowed |
| Confidential | Allowed if the tool is approved for this class | Not allowed | Not allowed |
| Personal data or secrets | Only where a documented review allows it | Not allowed | Not allowed |
What is the difference between a policy and a control?
| Question | Policy | Control |
|---|---|---|
| What is it? | A statement of what should happen. | A mechanism that makes it happen or detects that it did not. |
| Where does it live? | A document, a wiki, a training module. | A gateway rule, an access setting, an approval step, a log alert. |
| What does it rely on? | People reading and following it. | A system that applies it every time. |
| What is the evidence? | Sign-offs and attestations. | Records such as events, decisions and approvals. |
| How does it fail? | Quietly: nobody reads it. | Visibly, if you log it: a block, an alert, a gap. |
How do you make an AI policy enforceable?
Turn each sentence of the policy into a check that runs without a person remembering to run it. Where that is not possible, say so and name the person who checks.
- Approved tools: route model calls through a gateway that allows only approved models and providers, and block the rest at the network where you can.
- Data classes: apply detectors and redaction to prompts and tool results, and keep sensitive data out of tools not approved for it. See DLP tools.
- Human review: make approval a step in the workflow that the agent cannot skip, bound to the exact action. See how to set up human approval.
- Procurement: gate new tools on an inventory entry with an owner and a tier.
- Incident reporting: collect runtime logs so a report can be checked against what happened.
- Review: compare the inventory to discovery results on a schedule, and treat gaps as findings.
What do the standards and the EU AI Act say about policy?
NIST GOVERN 1.2 asks that the characteristics of trustworthy AI are integrated into organisational policies, processes, procedures and practices, and GOVERN 2.2 asks that personnel and partners receive AI risk management training. These are voluntary outcomes.
ISO/IEC 42001 is a management system standard for AI. The ISO page could not be opened by our tooling on 2026-10-07, so this page states nothing about its policy clause and leaves that to the standard. The European Commission says its goals and definitions are not aligned with the quality management system the AI Act requires, so an AI policy written for ISO/IEC 42001 is not by itself an AI Act measure.
This page cites no sample policies from other bodies: none from a government or standards body were fetched and checked. Treat templates you find online as drafts.
Where Swfte fits
Swfte's policy engine can turn parts of a policy into runtime decisions. In the code it returns allow, redact, ask or deny at control points such as before a turn, at the model, at a tool and at egress, and a later guard cannot soften an earlier verdict. It is live only for runs that have a policy attached, and this page does not claim a self-serve policy editor. The verbs Allow, Deny, Warn, Filter, Escalate and Require human approval are the platform's design vocabulary. Warn is part of the design, and escalation exists in separate approval gates.
See platform governance and AI governance. You do not need Swfte to write a policy or to train staff. You need a gateway or runtime to enforce one. Swfte provides the technical controls, governance mechanisms and evidence you need to deploy AI within your applicable regulatory, security and policy requirements. The exact posture depends on your use case, jurisdiction, deployment and configuration.
Sources and last verified
Every dated or technical fact on this page was read from the pages below on 2026-10-07. Anything that could not be confirmed is left out or marked as not verified.
- NIST AI 100-1: AI Risk Management Framework (AI RMF 1.0). The Govern function and subcategories GOVERN 1, 1.2, 2.2 and 6.1.
- NIST AI Resource Centre: AI RMF Playbook. That the Playbook is voluntary and is neither a checklist nor a set of steps to follow in full.
- AI Act Service Desk: Article 4, AI literacy. The amended literacy wording.
- AI Act Service Desk: Article 50, transparency obligations. The four transparency duties.
- AI Act Service Desk: implementation timeline (European Commission). That Article 50 transparency applies from 2 August 2026.
- European Commission: understanding standardisation under the AI Act (FAQ). The statement on ISO/IEC 42001 and the AI Act quality management system. Dated 10 March 2026.
Frequently asked questions
What should a company AI policy include?
It should cover scope, approved tools, which data classes each tool may receive, human review, disclosure, procurement, incident reporting, training and enforcement. Keep it short and name an owner for each section. Add the checks that enforce it, so the policy is more than a statement.
Is a company AI policy legally required?
No general rule we read requires one by that name. The EU AI Act, as amended, asks providers and deployers to take measures to support AI literacy, and sets transparency duties from 2 August 2026. Whether a rule applies to you depends on your role and use case, so take legal advice.
What is the difference between an AI policy and an AI control?
A policy says what should happen. A control makes it happen or shows it did not. A policy that bans confidential data in unapproved tools is a statement. A gateway rule that redacts it, or blocks the call, is a control. You need both, and the control produces the evidence.
Should we ban public AI tools?
A ban often moves use out of sight. A clearer approach is to approve specific tools for specific data classes, make the approved route easy, and find the rest through discovery. If a tool cannot be approved for any class you use, block it and say why.
How does the NIST AI RMF treat policy?
It places policy in the Govern function. GOVERN 1 covers policies and procedures for mapping, measuring and managing AI risk, GOVERN 1.2 integrates trustworthiness into them, and GOVERN 6.1 covers third-party risk policies. The framework is voluntary and NIST says its Playbook is not a checklist.
Can Swfte enforce our AI policy?
In part. The policy engine returns allow, redact, ask or deny at control points, but it is live only for runs that have a policy attached, and a self-serve policy editor is not claimed here. Other parts of a policy, such as training and disclosure, are your processes.