AI policy in companies: how to prepare your organisation for the EU AI Act

Two men and a woman at AI policy meeting

An AI policy is the set of internal rules that determines how, why and under what conditions your organisation may use artificial intelligence. Under the EU AI Act (Regulation (EU) 2024/1689) it is the most practical way to show a supervisory authority that you know which AI systems you run, how they are classified and who is accountable for them. It is not a legally prescribed document, but without one you cannot evidence compliance with the AI Act, the GDPR or Dutch employment law.

Artificial intelligence has moved from the IT department into ordinary business processes. Generative tools draft correspondence, recruitment software ranks candidates, service platforms answer customers and finance systems flag transactions. Much of this happens through features quietly added to software the organisation already licenses, and through public tools that employees start using on their own initiative. This article sets out what a workable AI policy contains, which obligations already apply and which have been postponed, and how to build the policy without turning it into a document nobody reads.

What an AI policy is and why it is necessary

An AI policy translates external legal duties into instructions an employee can follow on a Tuesday morning. It states which systems fall within its scope, what may be entered into them, who decides that a new tool may be bought, when a human must review the outcome, and what happens when something goes wrong. Management uses the same document to keep oversight as the technology changes faster than the procurement cycle.

The risk of leaving this unregulated is concrete rather than theoretical. Employees paste client data or draft contracts into consumer chatbots. A selection tool systematically filters out a group of applicants. A generated text is published as fact and turns out to be wrong. Each of these is a legal problem before it is a technical one, and in each case the organisation that deployed the system carries the responsibility, not the supplier that built it.

The legal framework: EU AI Act, GDPR and Dutch employment law

Three bodies of rules apply at the same time, and an AI policy that addresses only one of them is incomplete. The AI Act regulates the system: how it is built, documented, monitored and explained. The General Data Protection Regulation regulates the data that goes through it. Dutch employment law regulates what you may do to your own staff with it.

The AI Act follows a risk-based approach. A small number of practices are prohibited outright, including social scoring and certain manipulative or exploitative techniques; you can read more in our article on prohibited AI practices. A defined group of uses counts as high-risk AI, notably recruitment and selection, decisions on promotion and termination, creditworthiness assessment, and access to essential public and private services. For those systems the Act requires a risk management system, data governance, technical documentation, logging, transparency towards the deployer, human oversight and a level of accuracy and robustness appropriate to the purpose. Everything else is subject mainly to transparency duties or to no specific AI Act obligation at all.

The GDPR applies in full wherever personal data is processed. The principles that bite hardest in AI projects are purpose limitation and data minimisation, the requirement of a lawful basis for training as well as for use, and Article 22, which restricts decisions based solely on automated processing that produce legal effects or similarly significantly affect a person. Where a system is likely to result in a high risk to individuals, Article 35 requires a data protection impact assessment before deployment. Our article on using AI in your Dutch business works through those obligations in more detail.

The Dutch layer is the one most often overlooked. Under Article 27 of the Wet op de ondernemingsraden (Works Councils Act) the works council has a right of consent for any arrangement concerning the processing and protection of employees personal data, and for any arrangement on facilities intended or suitable for observing or monitoring the presence, behaviour or performance of staff. An AI policy that governs monitoring, productivity analytics or automated assessment of employees will regularly fall within that provision. A decision taken without the required consent can be invalidated by the works council, which makes the consultation a sequencing question rather than a formality.

Which AI Act deadlines apply now, and which have moved

The AI Act entered into force on 1 August 2024 and applies in stages. The prohibitions on unacceptable-risk practices and the AI literacy duty have applied since 2 February 2025. The obligations for providers of general-purpose AI models, together with the governance and penalty provisions, have applied since 2 August 2025. The general date of application was 2 August 2026, and from that date the transparency duties of Article 50 apply: people must be told when they are interacting with an AI system, and AI-generated or manipulated content must be marked as such.

One block of obligations has been postponed. Regulation (EU) 2026/1744, the AI part of the European Commission digital omnibus, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It moves the application of the high-risk regime for the stand-alone systems listed in Annex III, which include employment, education, credit and essential services, to 2 December 2027. For AI that functions as a safety component in products already regulated under Union harmonisation law, listed in Annex I, the date becomes 2 August 2028. The same regulation softens the AI literacy duty, which now requires providers and deployers to take measures to support a sufficient level of AI literacy rather than to guarantee it.

The practical reading is straightforward: the prohibitions, the general-purpose AI rules and the transparency duties are enforceable today, and the heavy compliance apparatus for high-risk systems arrives at the end of 2027. That is a preparation window, not a reprieve. Organisations that select a recruitment or credit-scoring system now will still be running it in December 2027, and the supplier contract signed today determines whether the documentation, logging and human-oversight features exist by then.

Scope and content: what the policy must cover

Define the scope before writing a single rule, because an AI policy that nobody can apply to their own situation is worse than none. The policy should name the departments it binds, typically HR, marketing, customer service, finance, operations, legal and research and development, and it should name the categories of system: purchased AI software, AI features embedded in existing platforms, models built in house, generative assistants, chatbots, scoring and ranking tools, and recommendation engines.

Two boundary questions deserve an explicit answer. The first is whether employees may use public AI tools on their own account for work, and on what conditions. The second is what happens to AI functionality that appears in software the organisation already uses, without a purchase decision and often without a notification. Both are the routes by which AI enters an organisation unnoticed, and both are governed by the policy or by nothing at all.

Start with definitions that match the broad concept of an AI system in the AI Act but are written in language an employee recognises, supported by examples from their own department. Someone in HR should be able to tell, without asking legal, whether the tool in front of them falls within the policy.

Then divide use into three categories. Prohibited use covers the practices banned by the AI Act and any application the organisation has decided against for its own reasons. Conditional use covers everything permitted subject to safeguards: a documented risk classification, a data protection impact assessment where the GDPR requires one, approval by a named role, and agreed technical and organisational measures. Permitted use covers low-risk applications that need no more than the general rules on confidentiality and verification. The categories only work if the policy also says who moves an application from one category to another, and on what evidence.

Governance is the part that determines whether the rest is real. Allocate final accountability for AI compliance, usually at board level, and name the roles that may select and approve new applications, that maintain the inventory, and that handle incidents. Supplier management belongs here too. Where a system may become high-risk, the contract should oblige the provider to supply technical documentation, instructions for use, logging capability and the information the deployer needs for its own assessment, and should allocate responsibility for changes that alter the intended purpose of the system.

Data, privacy, security and transparency

Because an AI system is only as lawful as the data it runs on, the policy should state what may and may not be entered into which system. Confidential business information, client files, special categories of personal data and anything covered by professional secrecy generally do not belong in a public tool. Set out where anonymisation or pseudonymisation is required, how long inputs and outputs are retained, and how training data is kept separate from production data. Where personal data is involved, the assessment under the GDPR and the classification under the AI Act are best carried out in a single exercise; they ask different questions about the same system.

Security follows the ordinary rules. Access rights are granted by role, use is logged, and AI incidents are routed into the existing incident and data breach procedure rather than into a separate track that nobody remembers. A personal data breach must be reported to the Autoriteit Persoonsgegevens (Dutch Data Protection Authority) without undue delay and, where feasible, within 72 hours of becoming aware of it.

Transparency is now an operational duty rather than a good intention. Since 2 August 2026, Article 50 of the AI Act requires that individuals are informed when they interact with an AI system unless that is obvious from the circumstances, and that synthetic audio, image, video and text content is marked in a machine-readable way. Emotion recognition and biometric categorisation systems trigger their own notification duty. Translate this into concrete instructions: what the chatbot says in its opening message, how AI-assisted content is labelled, and what candidates are told about the role of AI in a selection procedure.

Human oversight, bias and AI literacy

For any system that affects a person, the policy must say when a human decides and what that person is actually able to do. Meaningful oversight means the reviewer understands the limitations of the system, can interpret its output, and has the authority and the time to disregard it. A sign-off box in a workflow is not oversight. Under Article 22 GDPR, a decision that produces legal effects or similarly significantly affects someone may not be based solely on automated processing except in defined situations, and even then the person retains the right to obtain human intervention, to express their point of view and to contest the decision.

Bias testing belongs in the policy as a recurring obligation with a named owner. Systems used in recruitment, performance assessment, onboarding and credit decisions should be tested periodically for disparate outcomes and error rates across groups, and the results should be recorded. That record matters twice over: it supports the AI Act documentation, and it is the evidence an employer needs if a rejected candidate alleges discrimination under the Algemene wet gelijke behandeling (Equal Treatment Act), where an unexplained disparity can shift the burden of proof to the employer.

The AI Act obliges providers and deployers to take measures to support a sufficient level of AI literacy among the staff who work with these systems, taking account of their technical knowledge, experience and the context of use. The standard is understanding, not expertise. Staff should be able to recognise an AI system, know what it is reliable for, know what it is not reliable for, and know when to escalate.

In practice this means a baseline module for everyone and deeper training for the roles that carry the risk: HR, IT and data teams, procurement, compliance and management. Record who was trained and when. Repeat it when a significant new system is introduced or the legal framework shifts, which in this field is not a rare event.

Who supervises the AI Act in the Netherlands

Supervision is being organised through existing regulators rather than a single new agency. The government published the draft Uitvoeringswet AI-verordening (AI Regulation Implementation Act) for public consultation on 20 April 2026, with the consultation running until 1 June 2026. Under the draft, the Rijksinspectie Digitale Infrastructuur (Netherlands Authority for Digital Infrastructure) takes a coordinating role, the Autoriteit Persoonsgegevens acts as supervisor where no sector regulator is designated, and existing sector supervisors keep their own domains. The bill has not yet been adopted, and its entry into force will be determined by royal decree; until then the allocation of national enforcement powers is not final. The penalty ceilings, however, come from the AI Act itself, with the highest tier of up to seven per cent of total worldwide annual turnover reserved for the prohibited practices.

From first inventory to a working AI policy

A policy that arrives before the inventory tends to prohibit things nobody does and permit things nobody checked. Begin by finding out what is actually in use, including AI features inside existing software and the tools employees adopted themselves. A short, confidential survey usually produces more than a formal request to department heads.

Classify each application next: prohibited, high-risk under Annex III, subject to transparency duties, or low-risk. Then assess the legal and organisational risk of the applications that matter, combining the AI Act classification with the GDPR analysis and, where staff are affected, the employment law and works council questions. Only then draft the policy, and align it with the privacy, information security, procurement and HR frameworks that already exist rather than writing a parallel set of rules.

Implementation is where most policies fail. The rules have to reach the places where decisions are made: procurement templates and supplier contracts, the intake process for new software, the recruitment procedure, the incident procedure and the training calendar. Finally, set a review cycle. Review at least annually, and always when a significant new system is introduced, when the legal framework changes, or after an incident.

Three things are worth doing before the end of this quarter. Check that no application in use falls within the prohibited practices, because those rules have been enforceable since February 2025. Check that your customer-facing and content-producing systems meet the Article 50 transparency duties that took effect on 2 August 2026. And check that any system heading for the Annex III high-risk category is contractually capable of meeting the December 2027 requirements, because renegotiating that in 2027 will be considerably more expensive than agreeing it now.

Law & More advises organisations on the classification of AI systems, on drafting and implementing AI policies, on supplier and licence agreements for AI applications, and on the privacy and employment law questions that come with them. Our IT lawyers are happy to review your current position and tell you where the gaps are. Please contact us to discuss your situation.

FAQ

Is an AI policy mandatory under the EU AI Act?

The EU AI Act does not explicitly require organisations to have a document titled “AI policy”. In practice, however, an AI policy is essential to demonstrate compliance with the obligations imposed by the AI Act and the GDPR, such as risk management, human oversight, transparency and AI literacy.

Which organisations are subject to the EU AI Act?

The EU AI Act applies to virtually all organisations that develop, place on the market or use AI systems within the European Union. This includes not only technology companies, but also employers, service providers and organisations that use AI in HR, marketing, customer interaction, finance or decision-making processes.

Does the EU AI Act apply if we only use standard off-the-shelf software?

Yes. Even where AI functionalities are embedded in third-party software, the organisation using the system remains responsible for its use. Relying on a vendor does not remove the user’s obligations under the EU AI Act and the GDPR.

What is the difference between low-, limited- and high-risk AI systems?

The EU AI Act classifies AI systems based on the level of risk they pose to fundamental rights and interests of individuals. High-risk AI includes systems used for recruitment and selection, employee evaluation, creditworthiness assessments or access to essential services. These systems are subject to significantly stricter requirements.

Do all AI applications need to be assessed in advance?

In practice, yes. Organisations should inventory and assess AI applications before deployment and classify them according to risk. For high-risk AI, a thorough assessment is required, often combined with a Data Protection Impact Assessment under the GDPR.

How does an AI policy relate to the GDPR?

The EU AI Act and the GDPR complement each other. While the AI Act focuses on governance, risk management and the functioning of AI systems, the GDPR regulates the processing of personal data. An effective AI policy integrates both frameworks and ensures consistent compliance.

Is a data Protection impact assessment always required when using AI?

Not always, but frequently. If an AI system processes personal data and is likely to result in a high risk to individuals, a DPIA is mandatory under the GDPR. In the case of high-risk AI under the EU AI Act, a DPIA is often unavoidable in practice.

May AI systems make autonomous decisions about employees or customers?

Only under strict conditions. The GDPR restricts fully automated decision-making, and the EU AI Act requires meaningful human oversight for high-risk AI systems. In many cases, a human must be able to intervene, review or override AI-driven decisions.

Can an AI policy restrict employees’ use of public AI tools?

Yes. One of the key purposes of an AI policy is to define whether and under what conditions employees may use public AI tools. This typically includes rules on entering confidential information, personal data or sensitive business information.

Who is responsible for compliance with the AI policy?

The AI policy should clearly allocate responsibility for AI compliance. Ultimate responsibility usually lies with senior management or the board, with important roles for legal, compliance, IT and HR. Without clear governance, effective oversight is unlikely.

What are the risks if an organisation does not have an AI policy?

The absence of an AI policy increases the risk of non-compliance with the EU AI Act and the GDPR. This may result in substantial fines, enforcement measures, reputational damage and potential civil liability. It also makes it more difficult to demonstrate responsible AI governance to regulators.

How often should an AI policy be reviewed?

An AI policy should not be treated as a static document. Regular reviews are necessary, particularly when new AI systems are introduced, legislation or regulatory guidance changes, or incidents occur. Annual review is often considered a minimum.

Is AI literacy required for all employees?

The EU AI Act requires organisations to take measures to promote AI literacy. This does not mean every employee must become a technical expert, but they should understand what AI is, how it is used within the organisation and what risks are involved.

When is it advisable to seek legal advice?

Legal advice is particularly advisable when deploying high-risk AI systems, when there is uncertainty about the lawfulness of specific applications, or when questions arise regarding enforcement, audits or liability. Early legal review can prevent costly corrective action later.

Need Legal Assistance?

Contact Law & More for expert guidance on your legal matters. Our multilingual team is ready to help.

Related articles

Cyberattacks such as ransomware, phishing, DDoS attacks and computer intrusion rarely affect only the organisation

If your business depends on software you did not write, you depend on the company

Introduction Legal remedies against enforcement of a judgment offer crucial protection when a court ruling

Explore acquittal to understand its significance, how it works in law, and its implications for
Learn how to obtain a domestic violence restraining order in the Netherlands. Expert tips to

Sharing personal data under the GDPR is lawful only where the organisation that discloses the

Stay Updated on Dutch Law

Subscribe to our newsletter for the latest legal insights, regulatory updates, and practical advice.