Your team is already using AI.
Do they know the rules?
Someone in your company has pasted something into ChatGPT this week. Probably something a client would rather they hadn't. Answer five questions and we'll write you a one-page AI policy for your business — what staff may use AI for, what must never go into a public tool, and who signs off. Yours to send to your team as it is.
Five questions
No account, no sales call attached. The policy is yours whether we ever speak or not.
Questions people ask first
Does my company legally need an AI usage policy?
No law names an “AI policy” as a required document. But if your staff paste client data into a public AI tool, that is a personal data transfer you are accountable for under the GDPR. A written policy is how you show you took reasonable steps — and it is a great deal cheaper than finding out afterwards.
What should an AI usage policy actually cover?
Four things: what staff may use AI for, what must never be entered into a public tool, how a new tool gets approved, and who is responsible when something goes wrong. Anything longer than a page will not be read, which makes it worse than nothing.
Is the generated policy GDPR compliant?
It is written with GDPR practice in mind — data minimisation, keeping personal data out of systems you do not control — but no document makes you compliant on its own. Treat it as a solid starting point to adopt and have reviewed. It is not legal advice, and we say so on the PDF itself.
Can we edit it afterwards?
Yes. It is yours. Download the PDF, change anything that doesn't match how you actually work, and circulate it under your own name. We don't need to be mentioned.
What happens to the answers we give you?
They are used to write your policy and to reply if you want help implementing it. We don't sell them, and there is no newsletter. The privacy policy sets out the detail.
If something goes wrong
Keeping it current
A policy is the easy half.
The hard part is choosing tools people will actually use, and setting them up so the rules hold without anyone policing them. That's the conversation worth having.
This is a starting point, not legal advice. It reflects the answers you gave and general GDPR practice; have it reviewed before you rely on it for anything regulated. Smarter World e.U., Vienna · walker@smarterworld.ai