Use case

Creating an AI usage policy (ready-to-adapt example)

Your company uses generative AI but doesn't yet have a formalized usage policy? Here is a complete template with an allowed/forbidden table, ready to adapt to your SMB or mid-market context.

8 min read
AI PolicyGovernanceGDPREnterpriseCompliance
⚡ The essentials in 30 seconds

77% of SMBs use AI without a formalized policy — an avoidable risk

Your employees use ChatGPT, Copilot or Midjourney daily, but 77% of French SMBs have no written AI usage policy. Without a framework, risks accumulate: data leaks, erroneous content published, GDPR non-compliance. Yet an effective AI usage policy fits in 3 to 5 pages and can be drafted in one week. It is based on a clear table of what is authorized, supervised and forbidden, tailored to your business.

An AI usage policy is not a 50-page legal document: it's a practical guide that protects the company while encouraging innovation. Discover our AI governance support.

The problem

Generative AI was adopted in companies spontaneously, without waiting for directives. Employees discovered ChatGPT, found it useful, and integrated it into their daily work. This "bottom-up" adoption is healthy in its momentum, but dangerous without a framework.

The concrete problems we observe among our SMB clients:

  • Use of unsecured tools: 58% of employees use the free version of ChatGPT for professional tasks, without knowing that the data entered may be used to train the model.
  • No data classification: no one knows which data can or cannot be entered into an AI tool. An accountant copies and pastes a balance sheet into ChatGPT to generate a summary; a salesperson enters their customer list to prepare a campaign.
  • No validation process: AI-generated content is sent to customers or published without review. Hallucinations (false figures, non-existent sources) end up in sales proposals or reports.
  • Anxiety-inducing legal uncertainty: management knows it must "do something" but doesn't know where to start. The result: either a total ban (loss of competitiveness) or a hands-off approach (risk-taking).

The challenge is not to slow innovation but to channel it. A well-designed AI usage policy is an accelerator, not a brake: it gives employees the confidence to use AI more widely and better.

The AI solution

Our AI usage policy template rests on three essential components, tested and validated with more than 30 SMBs and mid-market companies.

🚦

Allowed / supervised / forbidden table

The heart of the policy: a simple table that classifies uses into three categories. Green (allowed): brainstorming, drafting, general information research, translation of public content. Orange (supervised): drafting customer documents (mandatory validation), aggregated data analysis, marketing visual generation. Red (forbidden): entering personal data, unpublished financial data, industrial secrets, automatic decision-making without supervision.

📋

Governance rules

Who validates what? The responsibilities table defines: the AI lead (tool management and monitoring), the process for requesting access to a new AI tool, the validation circuit for generated content according to its criticality, the incident reporting procedures, and the sanctions in case of non-compliance. These rules integrate into the existing internal regulations.

🔧

Approved tools kit

The list of AI tools authorized in the company, with for each: the required version (free vs. enterprise), the authorized uses, the limits, and the level of confidentiality guaranteed. Example: ChatGPT Enterprise (authorized for all supervised uses), Midjourney (authorized for marketing only), GitHub Copilot (authorized for the dev team with mandatory code review).

Implementation

Here is the three-step action plan to draft and deploy your AI usage policy in one week.

1

Flash usage audit (days 1-2)

Send an anonymous 5-minute survey to all employees: which AI tools do you use? how often? for what tasks? what data do you enter? Complement it with 3-4 interviews with key managers. The goal is to get a realistic snapshot of current practices, not an exhaustive inventory.

2

Collaborative drafting (days 3-4)

Bring together the working group (executive management, CIO, DPO, 1-2 business reps) for a 3-hour session. Start from our template and adapt it: classify your specific uses in the green/orange/red table, choose the approved tools, define the validation processes. The final document is 3 to 5 pages maximum — conciseness is the key to adoption.

3

Rollout and training (days 5-7)

Present the policy at a 30-minute plenary meeting. Distribute a one-page summary sheet (the allowed/forbidden table) that each employee can post at their workstation. Organize 1-hour training sessions per department to address specific cases. Create a dedicated channel (Slack, Teams) for questions. Schedule a first review at 3 months.

Results

Deployment time
5 to 7 business days for an SMB of 50-300 employees
Adoption rate
90% of employees informed within 2 weeks
Incidents avoided
75% reduction in risky uses in 1 month
Responsible AI use
+40% AI adoption thanks to the trust framework

Frequently asked questions

Is an AI usage policy mandatory for SMBs?

Not yet mandatory in the strict sense, but strongly recommended. The European AI Act has imposed AI literacy obligations since February 2025, which implies documenting usage and training employees. In addition, the GDPR requires documenting any processing of personal data, including via AI tools. A formalized policy protects you in the event of an audit.

Who should draft the AI usage policy?

Ideally, a working group bringing together executive management (strategic validation), the CIO or IT manager (technical feasibility and security), the DPO or legal manager (GDPR and AI Act compliance), and one or two business representatives (usability and acceptance). In SMBs, this often comes down to 3-4 people working in 2-3 sessions of 2 hours.

How often should the AI policy be updated?

At least once a year, or as soon as a significant event occurs: new regulatory text, security incident, adoption of a new AI tool, change of business activity. In practice, AI technologies evolve so fast that a semi-annual review is more prudent in the first year.

How do you enforce the AI usage policy?

Three complementary levers: training (raising awareness about the why, not just the what), technical controls (an enterprise proxy that blocks unauthorized tools, DLP to detect data leaks), and integration into existing processes (including AI rules in the internal regulations and annual reviews).

For technical profiles

Comparison of enterprise AI control and governance tools:

CriterionMicrosoft Purview + CopilotCustom AI proxy (LiteLLM / Helicone)Manual policy alone
Tool access controlNative (Azure AD)Via centralized proxyDeclarative only
DLP (data leak prevention)Integrated (auto detection)Custom (regex, NER)No
Request loggingComplete + complianceComplete + analyticsNo
Monthly cost (50 users)600 – 1,500 euros100 – 500 euros0 euros
Deployment complexityMedium (MS ecosystem)High (DevOps skills)Low
Multi-modelOpenAI + Azure onlyAll modelsAll models
Suitable forSMBs already on Microsoft 365Mid-market with a DevOps teamFirst step, any SMB

Recommendation: start with a manual policy deployed in 1 week (step 1), then add an AI proxy such as LiteLLM or Helicone as soon as you have 20+ active AI users (step 2). The Microsoft Purview suite is relevant if you are already in the Microsoft 365 E5 ecosystem.

Related articles