Policy on the Use of ChatGPT and Artificial Intelligence in the Company: What It Should Include and How to Implement It

Lawyers advising a company on its policy regarding the use of artificial intelligence, ChatGPT, and compliance with the AI Act

Your company may never have formally authorized the use of ChatGPT.

And yet, it’s very likely that someone is already using it.

An employee copies an email and asks an AI to improve it. The marketing team uses a tool to prepare a campaign. A sales rep enters information about a potential client to draft a proposal. Administration summarizes documents with Copilot. Human Resources experiments with AI to analyze resumes.

The problem isn’t necessarily that employees are using these tools.

The problem arises when each person decides on their own which artificial intelligence to use, what information to enter, and to what extent they can trust the result.

That’s why, by 2026, a corporate policy on the use of artificial intelligence will become, for many organizations, a compliance tool just as important as policies on data protection, information security, or the use of corporate devices.

But there’s one important point:

it’s not enough to simply download an AI policy template from the Internet and send it to employees.

The policy must address the actual uses of artificial intelligence within each company.

Is it mandatory for a company to have an artificial intelligence policy?

It’s best to start by clarifying this point because there is quite a bit of confusion.

The AI Act, or European Artificial Intelligence Regulation, does not generally require all companies to have a document titled exactly “Internal Artificial Intelligence Policy.”

Therefore, it would be incorrect to claim that any small or medium-sized enterprise (SME) that does not have this document is automatically in violation of the Regulation.

What does exist, however, are specific obligations related to the use of AI systems.

One of the most important areas for businesses is artificial intelligence literacy.

Article 4 of the AI Act requires providers and those responsible for deploying AI systems to take measures that support the development of AI knowledge and skills among the people who use these systems on their behalf, taking into account factors such as their knowledge, experience, training, and the context in which the technology is used. This obligation takes effect in February 2025, and oversight began in August 2026. Europe’s Digital Strategy

An internal policy can therefore serve as one of the tools that help a company organize, communicate, and demonstrate how it manages the responsible use of AI.

However, it does not replace training or other necessary measures.

So, what is the purpose of an AI policy?

A good policy answers very simple questions that, in many companies, no one currently knows how to answer with certainty:

Can we use ChatGPT?

Can I enter a customer’s information?

Can I upload a contract so it can summarize it?

Can I use Copilot to prepare an employee evaluation?

Can I generate an image using AI and use it for commercial purposes?

Do I have to check everything the tool generates?

What should I do if the AI gives me incorrect information?

Can I use my personal ChatGPT account for work?

If each employee answers these questions based on their own judgment, the company has a governance problem.

The purpose of the policy is to establish common and understandable rules.

What should an AI usage policy include in a company?

There is no one-size-fits-all template that works for every organization.

A tech startup that develops AI software does not face the same risks as a consulting firm, a clinic, an industrial company, or an e-commerce business.

However, there are a number of factors that should be analyzed in virtually any corporate policy.

1. Which AI tools are authorized

The first step seems obvious, but many companies have not taken it:

decide which tools employees can use.

It’s not enough to simply say:

“The use of artificial intelligence is permitted.”

The company should determine which solutions are authorized and, when necessary, under what conditions.

For example, it may decide to use certain corporate accounts for ChatGPT, Microsoft Copilot, or other tools, but not allow employees to use personal accounts to process business information.

The Spanish Data Protection Agency specifically recommends restricting the use of generative AI systems to authorized and trained users, as well as prohibiting systems that are not registered in the corporate inventory. AEPD

Why is this important?

Because privacy policies, information processing practices, data retention policies, and settings can vary between tools and even between different versions of the same service.

The company must know to whom it is providing its information.

2. What AI Can Be Used For

Authorizing a tool does not mean authorizing any and all uses.

We can imagine three simple levels.

Generally Permitted Uses

For example:

  • generate ideas;
  • prepare drafts;
  • summarize public information;
  • improve the writing of texts;
  • translate non-confidential content;
  • organize presentations;
  • help organize non-sensitive information.

Uses That Require Authorization or Additional Controls

For example:

  • review contracts;
  • process client documentation;
  • work with personal data;
  • analyze financial information;
  • use AI in Human Resources;
  • generate code to be incorporated into products;
  • prepare documents with legal implications.

Prohibited Uses

This section should clearly list the actions that the company has determined are unacceptable.

For example, entering trade secrets into public tools or allowing an AI to make certain decisions without human supervision.

The key is that an employee shouldn’t have to become a lawyer to know what they’re allowed to do.

3. What Information Should Never Be Entered Into an AI

This is probably one of the most important sections.

Let’s imagine a sales representative wants to prepare a proposal.

Instead of explaining the context in general terms, they copy it directly into ChatGPT:

  • the customer’s name;
  • their email address;
  • negotiated prices;
  • terms and conditions;
  • information about their needs;
  • and internal discussions.

You might receive an excellent proposal.

But the company must first ask itself whether that information could be entered into that tool under those conditions.

The AEPD recommends explicitly informing users that they should not share confidential information or enter private data, non-public information, or personal data into generative AI systems when the processing of such data is not authorized and controlled. AEPD

The policy should establish specific rules for:

Personal data.
Information about customers, employees, candidates, suppliers, or any identified or identifiable person.

Confidential information.
Contracts, strategies, prices, customer documentation, or internal communications.

Trade secrets.
Processes, formulas, code, business strategies, or information with competitive value.

Highly sensitive information.
Medical, financial, or biometric data, or other categories of information requiring greater safeguards.

A simple rule that can help employees is:

If you wouldn’t voluntarily send that information to an outside company you don’t know, don’t enter it into an AI tool without first verifying that it’s authorized.

4. The Need to Review AI-Generated Responses

Artificial intelligence can write something completely incorrect with great confidence.

It can make up data.

It can confuse concepts.

It can generate nonexistent references.

It can misinterpret a document.

It can provide outdated information.

Therefore, a corporate policy should make it clear that using AI does not eliminate the responsibility to review the results.

The AEPD expressly recommends manually reviewing and validating the generated results before using or publishing them and warns that information produced by AI should not be assumed to be correct without verification. AEPD

This is particularly important when the content may:

  • affect a customer;
  • be part of a contract;
  • be published externally;
  • be used to make a decision;
  • create an obligation;
  • affect an employee;
  • or have economic or legal consequences.

The rule should be simple:

AI can help prepare the work; the ultimate responsibility remains with humans.

5. Determine who is responsible for each use

One common mistake is that everyone uses artificial intelligence, but no one is accountable for how it’s used.

This doesn’t mean that all small and medium-sized businesses need to immediately hire a “Chief AI Officer.”

In fact, the European Commission clarifies that Article 4 of the AI Act does not require the appointment of an AI officer or the creation of a specific governance committee. Europe’s Digital Strategy

In an SME, it may be enough to assign clear roles.

For example:

Management approves the tools.

IT or the technology provider reviews security issues.

The data protection officer intervenes when necessary.

Human Resources manages training.

And each department head oversees how their team uses the tools.

What matters isn’t the job title.

What matters is that, when a question or an issue arises, it’s clear who should make a decision.

6. Specifically Regulate the Use of AI in Human Resources

This section deserves special attention.

The use of artificial intelligence for:

  • screen candidates;
  • review resumes;
  • evaluate employees;
  • assign tasks;
  • measure performance;
  • recommend promotions;
  • influence salaries;
  • or influence dismissals

It may have much more significant implications than using ChatGPT to draft a LinkedIn post.

The AI Act classifies certain systems used in the workplace as high-risk. According to the currently valid timeline, the rules applicable to certain high-risk systems listed in Annex III—including certain workplace uses—will take effect on December 2, 2027. Digital Strategy for Europe

But that doesn’t mean companies can ignore this issue until then.

Spain now recognizes information rights related to algorithms that affect employment decisions. Since 2021, workers’ legal representatives have had the right to be informed about certain parameters, rules, and instructions of algorithms or AI systems that affect working conditions, access to employment, or job retention. BOE

And there is one particularly significant development.

As of September 2026, Spanish regulations also require that employees be informed in writing of the existence of algorithmic or automated decision-making systems when such systems are used for certain decisions regarding their working conditions, including aspects such as working hours, task assignments, wages, career advancement, workplace, or termination of employment. BOE

Therefore, the AI policy should be aligned with the company’s labor obligations.

7. Regulate the use of chatbots and AI-generated content

AI does not always operate internally.

Many companies already have systems that interact directly with customers.

For example, a chatbot that answers questions on a website.

As of August 2, 2026, certain transparency obligations under Article 50 of the AI Act will apply. The Commission has also published specific guidelines to help providers and those responsible for deployment comply with these obligations. Europe’s Digital Strategy

Therefore, a company should review, among other issues, whether individuals interacting with certain systems should be informed that they are speaking with an artificial intelligence.

Internal policy should also specify who is allowed to use AI to generate external content and what kind of review such content requires before publication.

8. Intellectual Property: Be Careful About What Comes In and What Goes Out

The company must monitor both ends of the process.

What it inputs into the AI.

An employee should not provide protected content or third-party documentation without first verifying that they have the right to do so.

And what it obtains from the AI.

Generating text, an image, code, or a design using artificial intelligence does not mean it can automatically be used for any purpose without review.

The policy should require that the following types of content, in particular, be reviewed:

  • advertising campaigns;
  • websites;
  • commercial products;
  • software code;
  • external documentation;
  • designs;
  • trademarks;
  • customer materials.

This isn’t about banning creative AI.

It’s about avoiding the idea that:

“Since it was generated by a machine, we can do whatever we want with it.”

9. Establish an incident response procedure

What happens if an employee accidentally enters confidential information?

What if they discover that a tool has generated false information that has already been sent to a client?

What if personal data appears that should not have been processed?

What if an unauthorized tool is used?

The policy should specify who to notify immediately in the event of an incident.

The goal should not be to create a culture of fear.

If employees believe that reporting a mistake will only result in disciplinary action, there is a risk that they will try to cover it up.

From a compliance perspective, it’s usually much more helpful to learn about an incident quickly and be able to respond.

10. Train employees: simply sending out the policy isn’t enough

This is a crucial point.

A company can draft an excellent policy and still face the exact same problem if no one understands it.

The European Commission notes that training measures must be tailored to people’s knowledge, experience, and education, as well as to the context in which they use AI. No specific certification or uniform level of knowledge is required for all employees. Digital Strategy for Europe

Therefore, not everyone needs the same training.

The marketing department may need training on content creation and intellectual property.

Human Resources may need training on biases, employment decisions, and high-risk systems.

Management may need training on governance and accountability.

IT may need training on security and vendors.

Customer Service may need training on chatbots, personal data, and oversight.

The European Commission itself uses different training tracks for general staff, managers, and technical roles. This is a good example of why AI literacy must be tailored to each person’s actual job responsibilities. Europe’s Digital Strategy

Do I have to ban ChatGPT for my employees?

In most companies, this is probably the wrong question to ask.

An outright ban may seem like the safest option, but it can create another problem: employees may continue to use AI tools without informing the company.

The goal should be to ensure that employees know:

which tools they can use + what they can use them for + what information they can enter + what they should check before using the results.

A company can set much stricter restrictions in certain departments and allow broader use in others.

There doesn’t have to be a single rule for the entire organization.

Can we just copy an AI policy template?

Yes, we can.

Whether that’s enough is another matter.

Let’s imagine we download a template that says:

“It is prohibited to enter confidential information into artificial intelligence tools.”

That sounds reasonable.

But questions immediately arise:

What does the company consider confidential information?

Do employees know this?

Can they enter personal data?

What about an anonymized contract?

Can they use a business account but not a personal one?

Who authorizes a new tool?

What about Copilot integrated into programs the company already uses?

What are Human Resources’ policies?

Who reviews the results?

Where do you report an issue?

If the policy doesn’t address the company’s actual practices, it can become a document that exists but doesn’t govern anything.

Practical example of an AI policy for an SME

Let’s imagine a professional services firm with 30 employees.

After reviewing actual usage, they discover the following:

Marketing uses ChatGPT.

Administration uses Copilot.

The Sales department uses AI tools to draft proposals.

Some employees have personal accounts on various platforms.

Human Resources is considering purchasing a tool to screen resumes.

A reasonable policy could stipulate:

Authorized tools: only approved corporate accounts.

Permitted general uses: drafts, ideas, translations, and summaries of non-confidential information.

Prohibited data: personal data or confidential information unless authorization has been granted and the tool has been validated for such processing.

Moderation: No relevant external content may be published or automatically submitted without human review.

Human Resources: Any tool intended for the selection, evaluation, or management of employees requires prior review.

New Tools: Employees must request authorization before incorporating a new AI into their work.

Incidents: Any accidental disclosure of sensitive information must be reported immediately.

Training: Authorized users receive training tailored to their specific use of the tool.

That’s starting to look like a policy an employee can apply in their daily work.

How to implement an artificial intelligence policy step by step?

The order matters.

Step 1. Find out what AI the company is already using

Before drafting any guidelines, talk to the departments.

It’s very likely that tools will come to light that management wasn’t aware of.

Step 2. Create an inventory

For each tool, identify:

  • provider;
  • users;
  • department;
  • purpose;
  • information used;
  • decisions it may affect;
  • integrations with other systems.

Step 3. Classify uses according to their risk

Don’t allocate the same resources to a tool that helps proofread text as you would to one that evaluates candidates.

Step 4. Review providers and configurations

Analyze the contractual terms, privacy policies, data retention, subsequent uses of the data, and features available in the enterprise version.

The AEPD recommends evaluating aspects such as metadata, logs, telemetry, data reuse, localization, retention periods, and privacy settings before contracting generative AI systems. AEPD

Step 5. Draft the policy

The policy should be based on the findings from the previous steps.

Not the other way around.

Step 6. Communicate and Train

Explain the rules using examples.

An employee understands better:

“Don’t copy a customer database into ChatGPT”

than a whole page on abstract principles of data governance.

Step 7. Document

The Commission notes that it is not necessary to obtain a specific certificate to demonstrate AI literacy. Internal records of training sessions and other initiatives undertaken may be kept. Digital Europe Strategy

Keep evidence of:

  • policies adopted;
  • training conducted;
  • attendees;
  • authorized tools;
  • reviews;
  • incidents;
  • updates.

Step 8. Review it periodically

An AI policy drafted in 2026 will likely need to be updated.

Tools evolve rapidly, new use cases emerge, and the regulatory framework continues to develop.

The 10 Mistakes an AI Policy Should Avoid

1. Copying a template without analyzing the company.

2. Regulating only ChatGPT. In six months, there will likely be other tools.

3. Banning “sensitive data” without explaining what that means.

4. Forgetting about employees’ personal accounts.

5. Failing to differentiate between departments and risk levels.

6. Failing to regulate human review.

7. Ignoring Human Resources.

8. Failing to establish who authorizes new tools.

9. Distributing the document without training anyone.

10. Failing to update it.

The policy should not be written just so you can say:

“We have an AI policy.”

It should be drafted in such a way that artificial intelligence is used more effectively after its implementation than before.

Checklist: Does your company need an AI usage policy?

Ask yourself these questions:

  • Do employees use ChatGPT, Copilot, Gemini, Claude, or other tools?
  • Do we know exactly which ones?
  • Are there personal accounts being used for work purposes?
  • Do employees know what information they can enter?
  • Are there rules regarding customer data?
  • Are contracts or internal documents entered into these tools?
  • Is AI used in Human Resources?
  • Are there chatbots that serve customers?
  • Are the results reviewed before they are used?
  • Is there a procedure for authorizing new tools?
  • Have employees received training?
  • Do we know what to do if an incident occurs?

If you answered “I don’t know” to several questions, that is precisely the first problem the company should address.

Frequently Asked Questions About AI Policies in Companies

Will it be mandatory to have an AI policy by 2026?

There is no general requirement under the AI Act that mandates all companies to have a document by that name. However, there are obligations related to the use of AI—such as those regarding AI literacy—and a policy can be an important tool for properly implementing and documenting them. Europe’s Digital Strategy

Can I prohibit my employees from using ChatGPT?

A company may establish rules regarding the tools that may be used for work purposes, provided they fall within the applicable employment framework. However, from a practical standpoint, it may be more effective to specify authorized tools and uses rather than simply imposing a blanket ban.

Can employees use personal ChatGPT accounts for work?

It is recommended that the company evaluate this use and establish an explicit policy. Using personal accounts can make it difficult for the company to maintain control over information, settings, access, and the tools used.

Can an employee enter customer data into ChatGPT?

This should not be done automatically. It is necessary to analyze the tool, the type of contract, the purpose, the data being processed, the configuration, and the obligations arising from the GDPR and other regulations. The AEPD recommends preventing the entry of private, non-public, confidential, or personal data when its processing is not properly authorized and controlled. AEPD

Do we have to train all employees?

Digital literacy measures must be tailored to those who operate or use AI systems on behalf of the organization and to the relevant context. There is no one-size-fits-all course or mandatory certification for the entire workforce. Europe’s Digital Strategy

Do we need to appoint an AI officer?

Section 4 of the AI Act does not require the creation of a position called “AI Officer” or a specific committee. The company should, however, clearly define internal responsibilities. Europe’s Digital Strategy

Does an AI policy suffice to comply with the AI Act?

It can be part of compliance measures, but a policy alone does not guarantee compliance with the AI Act. It must align with the systems used, their risks, and the measures actually implemented.

From a Written Policy to the Responsible Use of AI

A good artificial intelligence policy shouldn’t start by imposing bans.

It should start with understanding.

What tools do employees use?

For what purpose.

With what information.

What decisions depend on them.

And what risks each use entails.

From there, the company can establish proportionate rules that allow it to take advantage of artificial intelligence without turning every new tool into an unknown risk.

Because the goal isn’t to fill a folder with compliance documents.

It’s to ensure that, when an employee thinks tomorrow:

“I’m going to use AI to do this faster,”

Know right away whether you can do it, which tool to use, what information you can use, and what you need to check before accepting the result.

And that’s what makes an AI policy a truly useful tool.

Does your company need an artificial intelligence policy?

At Martínez Caballero Abogados, we help companies, SMEs, startups, and entrepreneurs implement a legally sound approach to artificial intelligence.

Before drafting a policy, we analyze how AI is actually being used within the organization to avoid generic protocols that do not align with the company’s operations.

We can help you with AI tool audits, drafting or reviewing internal policies, data protection, vendor reviews, labor obligations, training, and compliance with the AI Act.

If your company already uses ChatGPT, Copilot, or other tools but doesn’t yet have clear guidelines in place, we can review your situation and develop a protocol tailored to your organization.

Request a consultation with our team to review the use of artificial intelligence in your company.

Diana Caballero
CEO – Founding Partner
Martínez Caballero Abogados

Want to learn about all the obligations your company may have when using artificial intelligence?
An internal policy is only one part of compliance. If your company uses ChatGPT, Microsoft Copilot, or other AI tools, we recommend reading our guide on the legal obligations under the AI Act for companies in 2026, where we explain what the regulations require, which uses may be considered high-risk, the training and transparency obligations, and how to prepare your company.

Share this article: