An AI acceptable use policy sets out which AI tools staff may use, what data must never go into them, who is accountable when something goes wrong, and when AI use must be disclosed. A policy covering these four domains, acceptable use, data, accountability and transparency, gives an Irish SME a defensible way to meet its GDPR and EU AI Act Article 4 obligations in one document.
Most AI acceptable use policy templates you will find online are short generic checklists with no reference to Irish or EU law at all. That matters, because Article 4 of the EU AI Act has applied to Irish businesses using AI tools since 2 February 2025, requiring measures to build staff AI literacy, and a written policy is the most direct way to show it's being done.[1] This piece breaks the task into four questions any Irish business can answer for itself: which tools, what data, who is accountable, and when to disclose.
Before writing one from scratch, most businesses benefit from knowing where AI use already stands across the team, which is what the AI Readiness Assessment maps.
What is an AI acceptable use policy, and why does Irish law already require one?
An AI acceptable use policy is the document that turns "we should probably have a policy" into something a new hire can actually follow on their first day. Article 4 of the EU AI Act has applied since 2 February 2025 to providers and deployers of AI systems, which includes almost any Irish SME whose staff use ChatGPT, Microsoft Copilot, or a similar tool. Until 27 July 2026, it required taking measures to ensure, to their best extent, a sufficient level of staff AI literacy. Since the Digital Omnibus amendment (Regulation (EU) 2026/1744) took effect on that date, the duty is to take measures that support the development of staff AI literacy, and the amendment states plainly that organisations are not required to guarantee any individual reaches a specific competence level.[1][2] AI Literacy Training: What Article 4 Requires of Irish SMEs covers what that obligation demands in full. The short version here: a written policy, backed by a recorded staff briefing, remains the most direct way most businesses show they have taken those measures under either version of the text.
A policy earns that status only by doing a specific job. Four domains cover it: which tools and tasks are approved, what data must never be entered, who is accountable when the policy is broken or the AI gets something wrong, and when the business needs to say out loud that AI was involved. Everything below works through each one in turn.
In summary
Answer four questions, one at a time: use, data, accountability, disclosure.
Which AI tools and tasks should the policy actually name?
Name the specific tools staff are allowed to use for work, specifically enough that anyone can check a decision against it before they act. If Microsoft Copilot and ChatGPT Business are the two tools your business has actually vetted, the policy should say so, alongside what each may be used for and what it must never be used for. A short table works better than a paragraph here: tool, permitted use, prohibited use.
Staff will find new tools regardless of what the policy says, so give people a clear way to ask for one instead of banning everything outright. Promise a maximum response time, one week is reasonable, and tell staff what decides how fast they hear back: does the tool's output affect a decision about someone's job, pay, credit, or access to a service, or does it use biometric data? A no to both usually means a same day yes. A yes to either means the tool likely falls into a higher risk category under the EU AI Act, which carries extra obligations, though most of those obligations for standalone high risk systems now phase in from December 2027 under the Digital Omnibus amendment. Either way, it goes to a closer review before anyone uses it. Before adding any tool to the approved list, also confirm a Data Processing Agreement is in place. Without one, the tool has no business handling client data.
Once a tool such as Microsoft Copilot, Zapier, or n8n is approved and running, AI Agent Governance: What Irish SMEs Need to Know covers a different, ongoing check: the specific settings inside each platform that control what the tool can access and who has to approve its actions.
In summary
Would you know, today, which AI tools are actually running across your team?
What data must the policy keep out of any AI tool?
List, by name, the categories of data that must never go into any AI tool, approved or not: client names combined with contact details or anything else that identifies a real person, commercially confidential material such as pricing and contract terms, staff records, financial detail that is not yet public, and anything covered by legal privilege. Naming these categories gives staff something concrete to check a piece of text against before they paste it anywhere.
This list protects three GDPR principles: lawfulness, fairness and transparency; purpose limitation, meaning data collected for one reason cannot be repurposed into an AI tool's training data without a fresh legal basis; and data minimisation.[4] Where that data is actually processed matters too, since an EU hosted tool with unclear onward data handling raises the same purpose limitation question as a US hosted one. Check both separately.
In summary
The prohibited list only works if staff check it before they paste.
Who is accountable when the policy is broken or AI gets something wrong?
Give the policy a named individual owner. A policy with no owner drifts. Someone specific needs to keep the approved tools list current, answer new tool requests inside the promised turnaround time, and update the document when a new AI feature turns up inside software the business already uses. In a team of ten this is often the MD. In a team of eighty it is usually whoever already owns the IT policy or data protection.
Accountability for output matters as much as accountability for the document. Any AI assisted work that reaches a client, a regulator, or a business decision needs a person to check it before it goes out. That person is responsible for what they send, regardless of whether they wrote the first draft themselves or an AI tool did. Owners often assume an AI error is nobody's fault because "the AI did it." It is not. GDPR does not recognise an AI tool as an accountable party, and neither should your policy.
The policy also needs a clear route for reporting a breach. Tie it to the disciplinary procedure the business already has rather than inventing a separate one for AI. Deliberately entering client data into an unapproved tool, after being told not to, is a conduct issue like any other breach of policy. It should be handled the same way. An honest mistake is different. Someone pastes something they should not have, notices straight away, and tells the policy owner the same day. State plainly in the policy that a quick, honest report is treated differently from a deliberate breach. Staff who catch their own mistake then have a real reason to raise it immediately instead of hoping nobody notices. A problem caught on day one is far easier to fix than one discovered months later.
In summary
Name a single person who owns a document, and check AI assisted work before it leaves the building.
When does the policy need to say AI was involved?
Decide, in writing, when the business needs to tell someone that AI helped produce a piece of work or a decision. Do not leave each staff member to work this out case by case. Internal disclosure and external disclosure are separate questions. Internally, keep a record of who has received AI guidance and when. That record is the evidence that the business took the measures Article 4 now asks for, if anyone ever asks.[1] Externally, decide plainly whether clients are told when AI was involved in producing work they receive, and write the answer into the policy so it does not depend on whoever happens to send the email that day.
A related but separate obligation sits alongside this. From 2 August 2026, Article 50 of the EU AI Act requires clear disclosure at the point someone interacts directly with an AI system, such as a chatbot on a website. The machine readable marking part of that obligation, for generative systems already on the market before 2 August 2026, is delayed until 2 December 2026.[1] What Do You Legally Need to Tell Customers When They Are Talking to an AI on Your Website? covers that specific rule in full.
In summary
Write down who gets told, and when, before the question comes up mid project.
How does an AI acceptable use policy actually get written and followed?
Draft it short enough that people will actually read it, then talk it through with the team before it goes anywhere near a shared drive. A page or two is enough for a team under fifty. Longer than that and staff stop reading it, which defeats the purpose regardless of how well it is written. Ten minutes in a team meeting explaining the reasoning, particularly the GDPR logic behind the data section, does more for compliance than a policy nobody has opened.
For a business that wants the fuller picture, an acceptable use policy is one part of a wider governance and workflow blueprint, which also covers risk classification and the accountability structure around AI use more broadly. A standalone policy is the right starting point for most SMEs. The wider blueprint becomes worth commissioning once AI use has spread past one or two tools or one or two people.
In summary
Two pages, read once by everyone, beats twenty pages read by nobody.
The AI Policy and Governance Pack covers this in full detail, built around the tools and data your business actually uses.
