AI Acceptable Use Policy
Defines permitted and prohibited AI use across 28 scenarios. Supports deployer governance discipline.
Applies under Article 2 to EU providers, EU-based deployers, and third-country providers/deployers whose AI output is used in the Union — including UK · Ireland · EU
Eighteen article-referenced assets — sixteen compliance frameworks and a two-part Article 4 literacy programme — plus Sentinel, an optional runtime governance control. Pre-populated with practical content, designed for rapid customisation. Straightforward use cases can be adapted in hours; complex or high-risk deployments need deeper review. Not generic templates — a governance stack built to the regulation.
Under the EU AI Act, a deployer is any organisation that uses an AI system in its work — even one it didn't build. If your team uses Copilot, a customer chatbot, an AI-powered HR or recruitment tool, or marketing automation, you may be a deployer under the Act. At minimum, Article 4 AI-literacy duties may be relevant; further obligations depend on the system, use case, risk category and role. You don't have to be an "AI company" to be in scope — but what applies to you depends on how you use AI.
If your organisation uses AI in, sells into, operates in, or produces AI outputs used in the EU, you may already have EU AI Act obligations — across your HR tools, your Copilot subscription, your customer chatbot, your marketing automation.
Prohibited practices have applied since February 2025. Article 4 AI-literacy obligations also apply, with supervision and enforcement by national authorities beginning from August 2026; 2 August 2026 is the general application date for obligations not already applicable or subject to a specific transition period. AI Statute gives you a practitioner-built, article-referenced governance documentation base — professional-grade compliance documentation, not legal advice.
Organisations outside the EU may be in scope where they place AI systems or GPAI models on the EU market, operate as deployers in the EU, or produce AI-system outputs used in the Union (Article 2). This commonly catches UK and US businesses serving EU customers or operating EU subsidiaries — geography outside the EU does not remove exposure where those scope tests are met.
In a judgment promulgated in November 2025, the UK Upper Tribunal made serious observations about putting confidential and privileged material into public, consumer-tier AI tools — distinguishing closed or enterprise-configured tools with contractual, technical and data-handling controls designed to reduce exposure. The case arose in legal services, but its reasoning is a warning by analogy for any organisation whose staff paste personal, confidential or commercially sensitive material into public AI tools. Policy alone is rarely enough in practice — it needs training, controls and evidence where work actually happens.
Eighteen article-referenced assets: a documentation layer of sixteen frameworks, a two-part Article 4 literacy layer, and Sentinel — an optional runtime governance control. Pre-populated with real content — not empty templates. Every asset in the pack is below.
Articles marked * (26, 27, 14, 25, 73) apply where an organisation deploys a high-risk AI system or meets a provider / value-chain trigger. For everyday productivity-tool use, these frameworks provide governance discipline and evidence structure.
You don't work through eighteen documents. In substance, AI governance means being able to answer six practical questions — and the pack is organised around them. Most organisations start with two or three assets, not all eighteen.
Clear ground rules on what staff may and may not put into AI tools, and who approves new ones.
Governance Framework · Role Mapping Matrix · Acceptable Use Policy
A register of approved and prohibited tools, so shadow AI stops being invisible.
Tools Register · Vendor Due Diligence
Check where AI use touches personal data or people's rights — and evidence that you considered it.
Data Protection & AI Policy · DPIA · FRIA · Governance Checklist
The AI-literacy training and records the Act expects, plus notices where AI use must be disclosed.
Literacy Programme · Training Deck · Training Record · Art. 50 Notices
Plain guidance for staff, and a route to follow when an AI-related incident happens.
Incident Reporting Procedure · Usage Guidelines · Sentinel
Keep it current as tools change, without reopening the whole exercise each time.
Annual Review · Decommissioning · Adoption Pack
Every asset below sits under one of these six. Each ships with an implementation guide.
The Article 4 literacy duty has been live since February 2025, and your GDPR exposure from staff using public AI tools is live today. That's eight assets: Acceptable Use Policy · Employee Usage Guidelines · Tools Register · Role Mapping Matrix · Literacy Programme · Training Deck · Training Record · Data Protection & AI Policy.
Vendor due diligence when you procure. DPIA where GDPR high-risk processing arises. Article 50 notices if your AI use falls into the defined scenarios. FRIA and worker notification only where AI is used for Annex III employment purposes — recruitment, candidate selection, promotion, termination, task allocation, or performance monitoring. Under the Digital Omnibus timetable those apply from December 2027.
We'd rather tell you this than sell you urgency you don't have: most organisations will not use all eighteen assets on day one. You buy the library once, run the quick start now, and draw on the rest as procurement, HR, data-protection or higher-risk use cases arise — instead of buying a thin fix that's obsolete the moment a client asks the next question.
Defines permitted and prohibited AI use across 28 scenarios. Supports deployer governance discipline.
Function-specific guidance across six roles. Supports Article 4 literacy at the desk level.
18 common AI tools pre-populated with illustrative risk flags, data-flow prompts and Article 50 screening questions. Validate current vendor terms before approval — classification remains client-specific.
P1–P4 severity matrix with timelines. Supports the deployer escalation route and provider / authority notification where applicable.
Reconciles GDPR and AI Act data-protection touchpoints. Connects AI governance with controls often handled in separate documents.
70-point operational review with provider / high-risk / GPAI escalation flags. RAG scoring summary — board-facing.
AI risk mapped by role. Supports proportionate, role-calibrated literacy under Article 4.
Screening plus template. Helps determine whether a GDPR DPIA, an Article 27 FRIA, or both are required — and supports completion.
Workforce notification templates. Supports employer notification where high-risk AI is used in the workplace.
Provider assessment pack. Supports proportionate vendor review and flags where provider-style obligations may arise.
RACI, oversight committee structure, escalation routes. Supports human-oversight arrangements where high-risk systems require them.
Provider direct-interaction and synthetic-content marking templates; deployer disclosures for emotion recognition, biometrics, deepfakes and public-interest AI text.
Continuous-compliance review cycle. Supports proportionate, ongoing oversight beyond initial deployment.
Lifecycle exit controls. Supports deployer log retention and GDPR deletion duties at end-of-use.
Rollout playbook covering all frameworks. A sequenced 30/60/90-day implementation plan.
Structured FRIA template with Article 27 trigger test. Required only for specified deployers (public bodies, private providers of public services) and specified high-risk use cases; others may use it voluntarily as enhanced governance.
PowerPoint deck plus trainer's guide. Supports Article 4 AI literacy with role-appropriate materials and completion records.
Structured curriculum with assessment. Supports literacy at scale, with a completion register.
Step-by-step customisation and deployment guide for every framework in the pack. Delivered as a single companion document (AIS-IG-ALL).
Free hosted webform — 10 questions, indicative governance-readiness profile in under 3 minutes. No download required. Take the assessment →
Sentinel is a configurable governance control for sanctioned enterprise AI workspaces — Claude for Work, ChatGPT Enterprise, Microsoft Copilot and enterprise-configured Google Gemini. It flags inputs that appear to contain personal, confidential or potentially privileged material, requires conscious confirmation before proceeding, and records a governance event log — a control layer aligned with the risk pattern highlighted by Munir. Delivered as a configured control your workspace admin deploys — no software installation. An awareness and evidence control — not DLP; it does not prevent data submission.
Partner-Delivered: we run the scoping workshop, customisation, training delivery, optional Sentinel deployment and handover — scoped to the size of the business. For consultancies, chambers and firms, white-label licensing with commercial rebrand rights is available — terms negotiated on enquiry.
Enquire about Enterprise & White Label →The documentation base is in place within hours of download; adoption, training and evidence build from there. Designed for operational teams to implement — each document comes with a step-by-step guide, with counsel review recommended for complex, high-risk or regulated deployments.
Purchase and instantly download your pack — all eighteen assets: sixteen compliance frameworks, the two-part Article 4 literacy programme, implementation guides and the licence agreement. Everything opens in Microsoft Office.
Swap [ORGANISATION NAME] across all documents in one Find & Replace, then populate the fields each document requires — named individuals in governance and oversight roles, effective dates, and your specific tools and functions. Each implementation guide walks you through every field.
Each document has a natural internal owner. The AI Acceptable Use Policy and Incident Procedure go to Legal or Compliance. The Employee Guidelines go to HR. The Tools Register goes to IT. The Data Protection Policy goes to your DPO or equivalent.
Three documents go to your staff intranet or handbook. Where appropriate, publish a short AI transparency statement or privacy-notice insert on your public website — operational policies stay internal unless counsel or compliance decide otherwise. The Compliance Checklist goes to your Board or Audit Committee as evidence of an active governance programme.
Run the 70-item Compliance Checklist with your team. Each item has an Article reference, a priority rating and a RAG status. The scoring summary gives you an internal governance-readiness baseline you can present to investors, auditors or risk committees — structured evidence of an active governance process.
EU AI Act compliance is an ongoing obligation, not a one-time exercise. Review your documents when you onboard new AI tools, when your use of AI materially changes, and at minimum annually. Re-run the Compliance Checklist each cycle — an improving RAG score over time is evidence of a maturing governance programme, not just a point-in-time snapshot. AI Statute monitors implementation guidance and EDPB opinions; where material changes affect document content, updated versions are made available to licence holders.
The EU AI Act may apply where an organisation provides, deploys, imports, distributes or uses AI systems in ways covered by Article 2 — including where AI-system outputs are used in the Union. If that could describe your organisation, this documentation is for you.
You need documentation that holds up to regulatory scrutiny — not generic templates with no article references. Every framework in this pack cites the specific legal basis it addresses.
Your organisation uses Copilot, ChatGPT, AI recruitment tools or automated workflows. You need policies your employees can follow, an approved tools register you can point to, and an incident procedure that works.
You need to demonstrate to investors, auditors or regulators that your organisation takes AI governance seriously. The 70-item checklist is designed to be presented directly to a board or audit committee.
Portfolio companies face increasing AI governance scrutiny from investors and acquirers. AI Statute gives your portfolio the documentation infrastructure to evidence an active governance programme without expensive legal fees at every entity.
You advise organisations on governance and need credible AI documentation for client engagements. A White-Label Licence is available — contact us for commercial terms that allow you to rebrand and use with clients.
If your AI use falls within Article 2 scope — placing systems on the EU market, deploying from an EU establishment, or producing outputs used in the Union — the EU AI Act applies. This documentation gives you a structured starting point for building and maintaining your AI governance evidence base.
Not everything — and this is the most common, and most costly, misunderstanding. The 2026 Digital Omnibus delayed the high-risk obligations: stand-alone high-risk systems move to 2 December 2027, and high-risk systems embedded in products to 2 August 2028. But two things were never deferred. Article 4 AI-literacy obligations have applied since 2 February 2025 — that duty is live now, and from August 2026 national authorities move into an active supervision and enforcement phase. And Article 50's role-specific transparency duties apply from 2 August 2026 in their defined scenarios — emotion recognition, biometric categorisation, deepfakes, certain synthetic media, or AI-generated text published to inform the public on matters of public interest. Being honest about the rest: if you don't deploy high-risk AI, that heavy machinery was never your immediate problem — but the literacy duty, and your GDPR exposure from staff using public AI tools, are live today. August is a grace period ending, not a deadline starting.
A fair challenge, and worth answering honestly. Not every organisation is affected equally: a business using no AI has little to worry about today. And no EU inspector is going to knock on your door on 3 August — enforcement is national and largely complaint-driven, not proactive inspection of small firms. But organisations are less likely to be caught by a regulator than by the market. A client's procurement team asks how you govern AI and there is no answer, so a tender is lost. An investor's due diligence asks. An employee complains. Or an AI tool goes wrong and the absence of governance becomes the story. Governance is inexpensive insurance against the moment someone asks — and increasingly, they ask. The free readiness check will tell you whether you have obvious gaps.
No. There is no UK AI Act. The UK regulates AI through existing law — principally UK GDPR and sector regulators such as the ICO — rather than a single AI statute. Two things still make this relevant to UK and Northern Ireland businesses. First, the EU AI Act has extraterritorial reach: if you sell into the EU, have EU customers, or your AI outputs are used in the Union, it can apply to you directly. Second, much of what good AI governance requires — documented policies, impact assessments, human oversight, transparency, incident handling — maps onto what UK GDPR and the ICO already expect. This is EU AI Act governance that also strengthens your UK data-protection position; it is not, and does not claim to be, compliance with a UK AI statute that does not exist.
These frameworks are designed for use directly by your compliance, HR, legal or operations team. Each comes with an implementation guide walking you through every placeholder and customisation step. For complex or high-risk AI deployments, review by qualified legal counsel is recommended — the frameworks are scoped as deployer-focused templates, not bespoke legal advice.
No compliance documentation can guarantee immunity from enforcement — and any provider that claims otherwise should be treated with scepticism. Internal records of governance, staff training, incident procedures and a clear audit trail are likely to be important evidence if your AI governance is questioned. Having these frameworks implemented and reviewed is materially better — in any enforcement or due diligence scenario — than having nothing. The organisations most exposed are those who cannot produce anything when asked.
Microsoft Word (.docx), fully editable — with the AI literacy training deck supplied as Microsoft PowerPoint (.pptx). Customise with your organisation name, dates and named roles. A single Find & Replace handles the most frequent placeholder in seconds. Implementation guides walk you through every field.
Often, yes. Non-EU organisations — including UK and US businesses — may be in scope where they place AI systems or GPAI models on the EU market, operate as deployers in the EU, or produce AI-system outputs used in the Union (Article 2 scope tests). Serving EU customers or running an EU subsidiary may be enough to bring an organisation within scope, depending on whether the relevant Article 2 test is met. Being based outside the EU does not remove that exposure.
The standard licence covers a single legal entity. For group deployment across multiple subsidiaries or PE portfolio companies, contact us for a group licence. Volume pricing is available. The White-Label Licence includes commercial rights for client and portfolio company use.
AI Statute actively tracks the moving regulatory picture — including the 2026 Digital Omnibus amendments, EDPB opinions and national supervisory authority guidance. Where material changes affect framework content, updated versions are made available to licence holders.
There are two routes. Card: purchase through Payhip with instant download on completion — EU and UK VAT is calculated and handled at checkout. Bank transfer or purchase order: many finance teams cannot put a purchase like this on a card, so email info@aistatute.eu with your company details and any PO reference. We issue an invoice the same day, payable by bank transfer or card, and release the files on receipt of payment. Either way this is a business-to-business licence for a digital product, so sales are final once delivered. For partner-delivered and white-label arrangements, pricing is agreed on a call.
Article 4 AI-literacy obligations have applied since February 2025, with supervision and enforcement beginning from August 2026. Answer 10 questions for an indicative AI-literacy readiness profile in under 3 minutes — free, instant, no commitment.
10 questions · Under 3 minutes · Instant results
Get your compliance documentation in place now — before a regulator, auditor or acquirer asks how AI is governed and documented in your organisation.
Get the AI Governance Pack — €2,250 + VATNeed an invoice for bank transfer or a PO? Request one →
Issued same day. Files released on receipt of payment.