Loading
Please wait...
Please wait...
One set of rules for sharing, checking and escalating
The AI Act does not make a standalone AI Use Policy mandatory for every organisation, and the GPAI Code primarily addresses providers of general-purpose AI models. Teams still need clear decisions about approved tools, confidential data, output verification, human review and escalation. A practical policy connects those decisions to the organisation's actual systems and roles.
Not a universal formal duty
A practical governance control
A policy can support several duties and internal controls, but its legal relevance depends on your role, systems and use cases.
Fewer repeated decisions
Shared rules for every team
People know what they may share, what they must verify, when to escalate and which tools are approved.
Protect work and credibility
Data, IP and decision quality
Clear boundaries reduce avoidable exposure, inconsistent outputs and late-stage rework without claiming that a document alone ensures compliance.
Clarity for teams, reviewable controls for customers and a consistent basis for internal decisions. The policy is useful when it changes daily behaviour, not when it sits unread in a folder.
Boutique documents that align legal expectations with technical reality and evidence you can show.
We translate regulatory language into controls that match your architectures, data flows, and teams.
Clear scope, roles, transparency rules, human oversight, escalation paths, and evidence links you can show.
Tailored to sector, risk profile, stack, and contracts. A document that works in practice.
Guardrails speed adoption and remove regulatory anxiety for product and data teams.
Links to training logs, incident handling, and risk registers so audits are straightforward.
Applies to employees, contractors, and vendors. Defines GPAI and the systems in scope across products and internal use.
Accountability for providers, deployers, and users; RACI for approvals, monitoring, and incident handling.
Allowed tools, datasets, and tasks by team; prohibited uses; data handling rules for prompts and outputs.
User-facing disclosures, content attribution rules, and review steps before high-impact use.
Review cadence, policy change control, and links to training logs and risk registers.
Share one use case, data-sharing question or approval conflict. We will show how Governance School would translate it into a practical rule before you consider a company-wide policy project.
Bring one policy challengeShare your goals with us and discover how we can guide you through complex compliance requirements.