AI policy in your company: how do you prepare for the EU AI Act?

Two men and a woman at AI policy meeting

The EU AI Act (Regulation (EU) 2024/1689) does not literally require a document called an “AI policy”. In practice you need one: without internal rules on which AI systems you use, how they are classified and who is responsible, you cannot show compliance with the AI Act, the GDPR or Dutch employment law.

Artificial intelligence has moved from the IT department into everyday business. Generative tools draft correspondence, recruitment software ranks candidates, service platforms answer customers and finance systems flag transactions. Much of this arrives through features quietly added to software you already license, or through public tools employees start using on their own. Below we explain what a workable AI policy contains, which obligations already apply, which have been postponed, and how to build a policy people actually use.

What is an AI policy, and why do you need one?

An AI policy is the set of internal rules that decides how, why and under what conditions your organisation may use artificial intelligence. It turns external legal duties into instructions an employee can follow on an ordinary working day.

The policy states which systems it covers, what may be entered into them, who decides that a new tool may be bought, when a person must review the outcome and what happens when something goes wrong. Management uses the same document to keep oversight while the technology changes faster than the purchasing cycle.

The risk of leaving this unregulated is concrete. Employees paste client data or draft contracts into consumer chatbots. A selection tool systematically filters out a group of applicants. A generated text is published as fact and turns out to be wrong. Each of these is a legal problem before it is a technical one. In each case the organisation that deployed the system carries the responsibility, not the supplier that built it.

Which rules apply: the AI Act, the GDPR and Dutch employment law?

Three sets of rules apply at the same time, and a policy that covers only one of them is incomplete. The AI Act regulates the system, the GDPR regulates the data, and Dutch employment law regulates what you may do to your own staff with it.

How does the AI Act classify AI systems?

The AI Act takes a risk-based approach. A small number of practices are banned outright, including social scoring and certain manipulative or exploitative techniques. Our article on prohibited AI practices explains them.

A defined group of uses counts as high-risk AI under Annex III of the Act. Examples are recruitment and selection, decisions on promotion and dismissal, creditworthiness assessments and access to essential public and private services. For those systems the Act requires:

  • a risk management system;
  • data governance;
  • technical documentation and logging;
  • transparency towards the deployer (the organisation using the system);
  • human oversight;
  • accuracy and robustness appropriate to the purpose.

Everything else is mainly subject to transparency duties, or to no specific AI Act obligation at all.

What does the GDPR add?

The GDPR applies in full wherever personal data is processed. In AI projects, purpose limitation, data minimisation and the need for a lawful basis, for training as well as for use, bite hardest.

Article 22 GDPR restricts decisions based solely on automated processing that have legal effects or similarly significantly affect a person. Where a system is likely to result in a high risk to individuals, Article 35 GDPR requires a data protection impact assessment (DPIA) before you start using it. Our article on using AI in your Dutch business works through these obligations in more detail.

What does Dutch employment law require?

The Dutch layer is the one most often overlooked. Under Article 27 of the Works Councils Act (Wet op de ondernemingsraden, WOR), the works council must consent to arrangements on the processing of employee personal data and on systems suitable for monitoring staff.

That right of consent covers any arrangement on the processing and protection of employees’ personal data. It also covers facilities intended or suitable for observing or monitoring the presence, behaviour or performance of staff. An AI policy that governs monitoring, productivity analytics or automated assessment of employees will often fall within this provision. The works council can challenge a decision taken without the required consent. Consultation is therefore a question of timing, not a formality.

Which AI Act deadlines apply now, and which have moved?

The bans, the rules for general-purpose AI models and the transparency duties already apply. The heavy obligations for high-risk systems have been postponed to December 2027 and August 2028.

The AI Act entered into force on 1 August 2024 and applies in stages:

  • 2 February 2025: the bans on unacceptable-risk practices and the AI literacy duty took effect.
  • 2 August 2025: the obligations for providers of general-purpose AI models took effect, together with the governance and penalty provisions.
  • 2 August 2026: the general date of application. From that date the transparency duties of Article 50 apply: people must be told when they interact with an AI system, and AI-generated or manipulated content must be marked as such.

One block of obligations has been postponed. Regulation (EU) 2026/1744, the AI part of the European Commission’s digital omnibus, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It changes the timetable as follows:

  • The high-risk regime for the stand-alone systems in Annex III, which include employment, education, credit and essential services, now applies from 2 December 2027.
  • For AI that is a safety component of products already covered by EU product legislation (Annex I), the date becomes 2 August 2028.
  • Generative systems placed on the market before 2 August 2026 have until 2 December 2026 to meet the machine-readable marking duty of Article 50.
  • The AI literacy duty is softened: providers and deployers must now take measures to support a sufficient level of AI literacy, rather than ensure it.

The practical reading is simple. The bans, the general-purpose AI rules and the transparency duties are enforceable today. The full compliance apparatus for high-risk systems arrives at the end of 2027. That is a preparation window, not a reprieve. If you select a recruitment or credit-scoring system now, you will still be running it in December 2027. The supplier contract you sign today decides whether the documentation, logging and human-oversight features exist by then.

What should the policy cover?

Start by defining the scope: which departments and which types of system the policy binds. A policy nobody can apply to their own situation is worse than none.

Name the departments it binds, typically HR, marketing, customer service, finance, operations, legal and research and development. Also name the categories of system: purchased AI software, AI features built into existing platforms, models developed in-house, generative assistants, chatbots, scoring and ranking tools and recommendation engines.

Two boundary questions need an explicit answer. First: may employees use public AI tools on their own account for work, and on what conditions? Second: what happens to AI features that appear in software you already use, without a purchase decision and often without notice? Both are routes by which AI enters an organisation unnoticed. Either the policy governs them, or nothing does.

How do you define AI and divide its use?

Use definitions that match the broad concept of an AI system in the AI Act, but write them in language employees recognise, with examples from their own department. Someone in HR should be able to tell, without asking the legal team, whether the tool in front of them falls under the policy.

Then divide use into three categories:

  • Prohibited use: the practices banned by the AI Act, plus any application your organisation has ruled out for its own reasons.
  • Conditional use: everything permitted subject to safeguards, such as a documented risk classification, a DPIA where the GDPR requires one, approval by a named role and agreed technical and organisational measures.
  • Permitted use: low-risk applications that need no more than the general rules on confidentiality and checking output.

The categories only work if the policy also says who moves an application from one category to another, and on what evidence.

Who is responsible?

Governance decides whether the rest of the policy is real. Assign final responsibility for AI compliance, usually at board level, and name the roles that select and approve new applications, keep the inventory and handle incidents.

Supplier management belongs here too. Where a system may become high-risk, the contract should oblige the provider to supply technical documentation, instructions for use, logging capability and the information you need for your own assessment. It should also allocate responsibility for changes that alter the intended purpose of the system.

How do you handle data, privacy, security and transparency?

The policy must state which information may be entered into which system. An AI system is only as lawful as the data it runs on.

Confidential business information, client files, special categories of personal data and anything covered by professional secrecy generally do not belong in a public tool. Set out where anonymisation or pseudonymisation is required, how long inputs and outputs are kept, and how training data is kept separate from production data. Where personal data is involved, carry out the GDPR assessment and the AI Act classification in one exercise. They ask different questions about the same system.

Security follows the ordinary rules. Grant access by role, log use, and route AI incidents into your existing incident and data breach procedure, not into a separate track nobody remembers. Under Article 33 GDPR, a personal data breach must be reported to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, AP) without undue delay and, where feasible, within 72 hours of becoming aware of it.

Transparency is now an operational duty, not a good intention. Since 2 August 2026, Article 50 of the AI Act requires that people are told when they interact with an AI system, unless that is obvious from the circumstances. Synthetic audio, images, video and text must be marked in a machine-readable way. Emotion recognition and biometric categorisation systems carry their own duty to inform the people exposed to them. Translate this into concrete instructions: what the chatbot says in its opening message, how AI-assisted content is labelled, and what candidates are told about the role of AI in a selection procedure.

How do you arrange human oversight, bias testing and AI literacy?

For every system that affects a person, the policy must say when a human decides and what that person can actually do. A sign-off box in a workflow is not oversight.

Meaningful oversight means the reviewer understands the limits of the system, can interpret its output, and has the authority and the time to set it aside. Under Article 22 GDPR, a decision with legal effects or a similarly significant effect on someone may not be based solely on automated processing, except in defined situations. Even then, the person keeps the right to human intervention, to give their point of view and to contest the decision.

Why test for bias?

Bias testing belongs in the policy as a recurring task with a named owner. Systems used in recruitment, performance assessment, onboarding and credit decisions should be tested periodically for differences in outcomes and error rates between groups, and the results recorded.

That record counts twice. It supports your AI Act documentation. And it is the evidence you need if a rejected candidate alleges discrimination under the Dutch Equal Treatment Act (Algemene wet gelijke behandeling, AWGB). Under that Act, facts that suggest discrimination shift the burden of proof to the employer.

What does AI literacy require?

The AI Act obliges providers and deployers to take measures to support a sufficient level of AI literacy among staff who work with these systems. The measures should take account of technical knowledge, experience and the context of use.

The standard is understanding, not expertise. Staff should be able to recognise an AI system, know what it is reliable for and what it is not, and know when to escalate. In practice this means a basic module for everyone and deeper training for the roles that carry the risk: HR, IT and data teams, procurement, compliance and management. Record who was trained and when. Repeat the training when a significant new system arrives or the legal framework changes, which in this field happens often.

Who supervises the AI Act in the Netherlands?

The Netherlands is organising supervision through existing regulators, not a new agency. The implementing bill is still a proposal, so the allocation of national powers is not yet final.

The government published the draft AI Regulation Implementation Act (Uitvoeringswet AI-verordening) for public consultation on 20 April 2026, with the consultation running until 1 June 2026. Under the draft, the Dutch Authority for Digital Infrastructure (Rijksinspectie Digitale Infrastructuur, RDI) and the Dutch Data Protection Authority share a coordinating role. The AP acts as supervisor where no sector regulator is designated, and existing sector supervisors keep their own domains. The bill has not yet been adopted, and a royal decree will set its date of entry into force.

The penalty ceilings come from the AI Act itself. The highest tier, for prohibited practices, is up to EUR 35 million or seven per cent of total worldwide annual turnover, whichever is higher.

How do you get from a first inventory to a working AI policy?

Start with an inventory of what is actually in use, and only then write the policy. A policy written before the inventory tends to ban things nobody does and allow things nobody checked.

Include AI features inside existing software and the tools employees adopted themselves. A short, confidential survey usually reveals more than a formal request to department heads. Then work through these steps:

  • Classify each application: prohibited, high-risk under Annex III, subject to transparency duties, or low-risk.
  • Assess the legal and organisational risk of the applications that matter. Combine the AI Act classification with the GDPR analysis and, where staff are affected, the employment law and works council questions.
  • Draft the policy and align it with your existing privacy, information security, procurement and HR frameworks, rather than writing a parallel set of rules.
  • Implement it where decisions are made: purchasing templates and supplier contracts, the intake process for new software, the recruitment procedure, the incident procedure and the training calendar.
  • Review it at least once a year, and always when a significant new system is introduced, the legal framework changes or an incident occurs.

Implementation is where most policies fail. A document on the intranet changes nothing if the procurement form does not ask whether a tool contains AI.

What should you do this quarter?

Three checks are worth doing now:

  • Check that no application in use falls under the prohibited practices. Those rules have been enforceable since February 2025.
  • Check that your customer-facing and content-producing systems meet the Article 50 transparency duties that took effect on 2 August 2026.
  • Check that any system heading for the Annex III high-risk category can contractually meet the requirements that apply from 2 December 2027. Renegotiating that in 2027 will cost considerably more than agreeing it now.

In summary

  • The AI Act does not require a document called an AI policy, but without one you can hardly show compliance with the AI Act, the GDPR and Dutch employment law.
  • The bans, the rules for general-purpose AI models and the Article 50 transparency duties already apply.
  • Regulation (EU) 2026/1744 postponed the high-risk regime to 2 December 2027 (Annex III) and 2 August 2028 (Annex I).
  • AI that monitors or assesses staff will often need the consent of the works council under Article 27 WOR.
  • Start with an inventory, then classify, assess, draft, implement and review.

Frequently asked questions

Is an AI policy mandatory under the EU AI Act?

The AI Act does not literally require a document called an “AI policy”. In practice you need one to show that you meet the duties under the AI Act and the GDPR, such as risk management, human oversight, transparency and AI literacy. Without written rules and a record of decisions, it is hard to prove any of this to a supervisor.

Which organisations are subject to the EU AI Act?

The AI Act applies to organisations that develop AI systems, place them on the EU market or use them in the EU. That includes not only technology companies but also employers, service providers and any organisation using AI in HR, marketing, customer contact, finance or decision-making. Most obligations depend on your role (provider or deployer) and on the risk category of the system.

Does the EU AI Act apply if we only use standard off-the-shelf software?

Yes. If AI features are built into third-party software, your organisation is still responsible for how it uses them, as the deployer. Relying on the vendor does not remove your own obligations under the AI Act and the GDPR. Your contract should make sure the vendor gives you the information you need.

What is the difference between low-, limited- and high-risk AI systems?

The AI Act classifies AI systems by the risk they pose to health, safety and fundamental rights. High-risk AI includes systems for recruitment and selection, employee assessment, creditworthiness and access to essential services, and these face strict requirements. Limited-risk systems, such as chatbots, mainly carry transparency duties; low-risk systems carry no specific AI Act obligations.

Do all AI applications need to be assessed in advance?

In practice, yes. Take stock of AI applications before you use them and classify them by risk. For high-risk AI a thorough assessment is needed, often combined with a data protection impact assessment (DPIA) under the GDPR.

How does an AI policy relate to the GDPR?

The two frameworks complement each other. The AI Act focuses on governance, risk management and how AI systems work; the GDPR regulates the processing of personal data. A good AI policy combines both, so that each system is assessed once for both sets of rules.

Is a data protection impact assessment always required when using AI?

Not always, but often. Under Article 35 GDPR a DPIA is mandatory if an AI system processes personal data and is likely to result in a high risk to individuals. For high-risk AI under the AI Act, a DPIA is usually unavoidable in practice.

May AI systems make autonomous decisions about employees or customers?

Only under strict conditions. Article 22 GDPR restricts decisions based solely on automated processing, and the AI Act requires meaningful human oversight for high-risk systems. In most cases a person must be able to intervene, review or override the outcome.

Can an AI policy restrict employees’ use of public AI tools?

Yes. One of the main purposes of an AI policy is to decide whether, and on what conditions, employees may use public AI tools. This usually includes rules on entering confidential information, personal data and sensitive business information. If the rules involve monitoring staff, check whether the works council must consent.

Who is responsible for compliance with the AI policy?

The policy itself should allocate responsibility. Final responsibility usually lies with senior management or the board, with important roles for legal, compliance, IT and HR. Without clear governance, effective oversight is unlikely.

What are the risks if an organisation does not have an AI policy?

Without a policy, the risk of breaching the AI Act and the GDPR increases. That can lead to fines, enforcement measures, reputational damage and civil liability. It also makes it harder to show a supervisor that you manage AI responsibly.

How often should an AI policy be reviewed?

An AI policy is not a static document. Review it at least once a year, and also when you introduce a significant new system, when the law or regulatory guidance changes, or after an incident.

Is AI literacy required for all employees?

The AI Act requires providers and deployers to take measures to support a sufficient level of AI literacy among staff who work with AI systems. Since the digital omnibus of July 2026 the duty is to support that level, not to guarantee it. Employees do not need to become technical experts, but they should understand what AI is, how it is used in your organisation and what the risks are.

When is it advisable to seek legal advice?

Legal advice is particularly useful before you deploy a high-risk AI system, when you are unsure whether a specific application is lawful, or when questions arise about enforcement, audits or liability. An early review is usually cheaper than correcting things later.

Law & More advises organisations on classifying AI systems, drafting and implementing AI policies, supplier and licence agreements for AI applications, and the privacy and employment law questions that come with them. Our IT lawyers can review your current position and show you where the gaps are. Unsure where you stand? Tell us about your situation. We will let you know your options within one working day.

Tom Meevis
Tom Meevis is an attorney-at-law at Law & More in Eindhoven and Amsterdam. He handles general practice and is the negotiator and litigator of the firm.

Need Legal Assistance?

Have you received a letter, a writ of summons or a judgment? Send us the documents. We will check which deadlines apply and what your options are.

This article provides general information and is not a substitute for advice on your specific situation.

Related articles

You can have a conservatory attachment (conservatoir beslag) lifted by starting summary proceedings (kort geding).

AI tools like ChatGPT and DALL-E can create text, images, and other content in seconds.

Whether you can enforce a judgment against a foreign business partner is largely decided when

A photo of you online without permission can be removed under Dutch law by two

Copyright on AI-generated content only exists under Dutch law if a human made creative choices

A suspect in the Netherlands is not obliged to answer questions. Article 29 of the

Stay Updated on Dutch Law

Subscribe to our newsletter for the latest legal insights, regulatory updates, and practical advice.