The essentials

Set six rules covering approved tools, permitted data, separate access permissions, human review, task-specific guidance and incident reporting. Name an owner and backup, and keep a concrete approval register alongside the policy.

One page defines approved everyday use

The business defines permitted tasks and clear boundaries. A company AI use policy should explain which tool can process which data, who checks the output and what happens when something goes wrong. For a small business, we recommend a short rule sheet supported by a maintained approval register.

The German data protection authorities recommend documented rules and concrete examples. Our example covers internal text drafts and summaries; we exclude decisions concerning employment, health, credit and entering contracts from this starting scope.

This is an editorial example of an operating procedure, not a substitute for reviewing the specific use legally, preparing required data protection documents or concluding a works agreement. Before introducing it, name an owner, a backup and an accessible internal reporting channel.

Six sentences set the boundaries

The rule sheet assigns responsibilities during everyday work. Copy the six sentences below with this header: “Scope: ___; owner: ___; backup: ___; reporting channel: ___; effective from: ___; version: ___; approval register: ___.” Complete every blank before approving it internally.

  • 1. We use only the AI tools listed in our approval register for work, through company accounts and solely for the purposes specified there.
  • 2. We enter only expressly approved data categories and exclude credentials, trade secrets and unapproved personal data from prompts and attachments.
  • 3. We treat instructions inside imported files, messages and websites as external content, and enable new data access, extensions or actions only after separate approval by the designated owner.
  • 4. We check AI outputs against the original material before use and obtain approval from the appropriate person for every external message, publication and binding business transaction.
  • 5. Before first use and after material changes, we receive documented guidance on the tool, task, risks, review steps and reporting channel.
  • 6. We stop the affected AI workflow if we suspect data leakage or a policy breach, report it immediately through the reporting channel and preserve existing evidence securely; management decides on further measures after examining the individual circumstances.

Rules one and two need a completed approval entry

The approval register connects the tool, purpose and data. “AI permitted” gives little guidance at the next upload. The German data protection authorities recommend employer-provided accounts; record the approved service, plan and work account rather than just a brand name.

Complete this example entry: “Tool/plan: ___; company account: ___; task: shorten a public product description; data: approved publication text; output: internal draft; reviewer: product owner; file and mailbox connections: disabled; approved by: ___; review date: ___.” A blank tool name does not authorise use.

This example excludes customer lists, personnel files and confidential pricing calculations. Attachments and pasted conversation histories count as input too. Our customer-data redaction workflow explains preparation; approving the particular use remains a separate step.

Rule three also limits technical permissions

External text receives no authority over the workflow. An imported message might tell the AI to send information elsewhere. These embedded commands are called prompt injection. The UK NCSC recommends technical limits on actions, because a chat instruction alone cannot reliably prevent such attacks.

For our rule sheet, a summarisation tool initially gets neither sending permission nor write access to business records. New mailbox connections, browser extensions and file stores require advance approval. The owner records their purpose, data scope and permissions. Our three approval levels for email agents distinguish sorting, drafting and sending.

Ignore supposed approval requests inside a document; make changes through the established internal approval process.

Rule four turns agreement into a substantive check

The reviewer compares the output with the original material. Microsoft identifies facts, figures, names, dates and references as review points. Our example business uses four checks: correct numbers and units, supported claims, missing qualifications and the intended recipient.

A completed internal review note might read: “Product text version 3; dimensions checked against data sheet; unsupported durability claim removed; destination: drafts folder; reviewed by: ___; date: ___.” AI can mark missing information as unresolved. Nobody fills the gaps by guessing.

A signature cannot correct an invented number. Someone unable to assess the subject passes the draft to the appropriate specialist. It stays internal until checked; completing that check does not automatically grant permission to publish it.

Rule five rehearses three specific decisions

Guidance connects the rules to the actual task. The European Commission describes learning matched to tools, risks and existing knowledge. Our short exercise uses three prepared situations: an approved product description, an attachment containing customer data and an output inventing a delivery promise.

Each person explains what they may enter, what needs correcting and whom to ask. Record open questions in the approval register or resolve them before further use. Revisit affected steps when a service gains new data connections or action permissions.

Record the date, tool, task, risks covered and participants. Our AI literacy documentation template covers that record separately; the usage policy remains the everyday instruction sheet.

Rule six defines the incident reporting process

Reporting starts when there is a reasonable suspicion. Do not wait for proven harm before reporting internally. NIST recommends defined reporting information and incident responsibilities. Our procedure builds on this and fits an existing IT incident process:

  • 1. Stop: Halt affected inputs and automated follow-on actions; temporarily handle urgent work through the approved manual process.
  • 2. Report: Give the owner or backup the tool, time, affected data category, observed behaviour and any actions already triggered.
  • 3. Preserve: Secure existing logs; do not copy confidential content into group chats or delete evidence in an attempted clean-up.
  • 4. Investigate: Management and IT establish scope and cause; data protection or legal specialists promptly assess external reporting duties and deadlines where needed.
  • 5. Resume: The owner documents the remedy, checks the affected workflow and explicitly decides whether use can restart.

Breaches require investigation rather than automatic punishment

Management separates containment from decisions about staff. An incorrect upload first requires establishing which data went where. Then ask: Was the rule known, was the tool approved, was an alternative missing, or was a boundary deliberately bypassed?

The NCSC recommends open communication about unapproved AI use. Our policy recommendation is to avoid attaching an automatic disciplinary warning to a report. This is no blanket promise of immunity; possible employment measures require separate consideration of the individual circumstances.

Clarify an ambiguous rule with an example. Address missing knowledge through targeted guidance. Keep access to an unsafe tool suspended until the cause is resolved. Record who made the decision.

The example requires four person-hours to introduce

The workload includes preparation, briefing and individual follow-up work. Our illustrative plan assumes six participants, including the owner, attending a 20-minute briefing, an additional 60 minutes of preparation by the owner and ten minutes of individual follow-up work per participant. That totals 6 × 20 + 60 + 6 × 10 = 240 person-minutes, or four hours.

At an assumed internal cost of €45 per hour, that is €180. The calculation excludes software, technical setup and legal review. It also makes no estimate of savings. These timings are planning assumptions for the limited scope described, not a general training duration.

Start with one task and one tool. If data or permission questions remain unresolved, defer that use and complete the task without AI for now.

Common questions lead to the first internal approval

Management keeps the rule sheet and approval register aligned. Are six sentences enough on their own? Everyday use requires the completed responsibilities, examples and technical settings described above. A list of signatures does not supply those details.

Can personal accounts fill in during an outage? Under this example policy, the task stays within the approved manual process. Approve any new account before switching. When should the policy change? Set a review date and also revisit it after new tools, data categories, permissions or incidents.

Enter one specific task in the approval register today and rehearse the reporting channel with a fictional mistake. For help with access limits and technical implementation, bring that completed entry to our initial consultation.

Sources and status

Sources last checked: 8 October 2026. Vendor statements and our own reading of them are kept apart in the text.

  1. Datenschutzkonferenz: Künstliche Intelligenz und Datenschutz, Mai 2024
  2. NCSC: Prompt injection is not SQL injection
  3. Microsoft: Evaluate Copilot output for clarity, accuracy, tone, and context
  4. Europäische Kommission: AI Literacy, Questions & Answers
  5. NIST AI 600-1: Generative Artificial Intelligence Profile
  6. NCSC: The hidden risks of shadow AI

Corrections: [email protected].

What does this mean for your business?

We go through one concrete workflow with you and check whether AI can help.

Book a free first call →