Witness
Get Started
Free ToolsPricing
Sign In
Back to Blog
July 22, 2026

The Company AI Policy: A Practical Guide + What Article 4 Actually Requires

Your employees already use ChatGPT. What belongs in a company AI policy, what Article 4 of the EU AI Act actually requires, and how to prove compliance.

Kevin Miller·7 min read·company AI policyAI policy templateArticle 4 EU AI ActAI literacy Article 4ChatGPT workplace policy

In most companies the situation is identical: sales writes proposals with ChatGPT, marketing generates images, the developers use Copilot. Nobody asked, nothing is regulated. That is not an accusation; it is the normal state of affairs. It becomes a problem for three reasons: the EU AI Act has required AI literacy measures since February 2025 (Article 4), the transparency obligations kick in on 2 August 2026 (Article 50), and enterprise customers increasingly open their supplier audits with one question: "Do you have an AI policy?"

The good news: a usable AI policy is not a 40-page project. This guide shows what Article 4 actually requires and which six building blocks belong in the policy.

What Article 4 actually requires

Article 4 of the EU AI Act has applied since 2 February 2025 and concerns every company that provides or deploys AI systems, regardless of risk class.

Until the Omnibus takes effect, the wording in force requires companies to ensure, to their best extent, a "sufficient level of AI literacy" of their staff. The Digital Omnibus adopted in June 2026 softens that wording: once it enters into force after publication in the Official Journal, Article 4 will only require measures that support the development of employees' AI literacy. The duty remains in place; the bar will be lower.

Three things are worth stating soberly:

  1. There is no certification requirement. The Regulation does not prescribe a specific training format. Measures must fit the context: a team that only uses a text assistant needs different training than a team operating applicant screening.
  2. There is no dedicated fine line-item for Article 4. The penalty catalogue in Article 99 does not name Article 4 explicitly. But concluding "so we can ignore Article 4" misses the practical point: AI literacy is a standard question in audits and questionnaires, and documented measures are the answer.
  3. A measure without proof does not exist. "We ran a webinar once" convinces neither auditors nor procurement teams. What counts: named measures, attendance records, a date.

The AI policy is the foundation for all of this. It sets the rules, and it is at the same time the document you can show.

The six building blocks of an AI policy

1. Scope

Who does the policy apply to, and which tools does it cover? The honest answer must include private accounts used for work. That is exactly where shadow AI is born: the employee copying customer data into a personal ChatGPT account is the scenario the policy exists to prevent.

2. Approved tools and an approval process

An allowlist beats a total ban. Bans without alternatives produce workarounds, not safety. List the approved tools (with account type: business account, not personal) and define a lightweight approval process for new tools: who decides, on what criteria, and how fast. If approval takes six weeks, people will use the tool before it arrives.

3. Prohibited inputs

The most important and shortest section: what must never be entered into an AI tool? A typical list: personal data of customers and employees, trade secrets, contracts and proposals covered by confidentiality, source code under NDA, credentials. If you train only one paragraph of the policy, train this one.

4. Output control and labelling

Two rules. First: AI output leaves the building only after human review. The person who sends or publishes the text is responsible for it. Second: wherever AI content is published, the Article 50 transparency obligations apply from 2 August 2026, from chatbot disclosure to the labelling of AI-generated content. The policy should name who in the company is responsible for that labelling. Whether your systems are affected is something the free Article 50 checker clarifies in three minutes.

5. Roles and training

Name a person responsible for AI questions (realistically in an SME: a role next to other roles, not a new full-time job) and set the training cadence. This is where the policy pays directly into Article 4: define the measure, run it, document attendance. The Witness Academy offers free training modules with a completion record, built for exactly this purpose.

6. Violations and review

What happens when the policy is breached, and when is the policy reviewed? AI tools change on a monthly cycle. A policy without a fixed review date (recommended: every six months, at least annually) is decoration after a year. A short change log with dates additionally makes the document audit-ready: you can see that it is alive.

What the policy does not have to do

The boundaries matter as much as the content. An AI policy for the use of generative tools is not high-risk documentation. Anyone deploying an AI system for applicant screening, credit decisions, or similar Annex III purposes needs considerably more from December 2027: risk management, technical documentation, human oversight. That belongs in a project of its own, not in the one-page company policy.

The policy also does not have to contain detailed tool assessments or replace a data protection assessment. It regulates behaviour. Everything else it merely references. If you are unsure which category your own systems fall into, clarify that first with the free classifier: ten questions, risk class and role as the result.

Implementation: one page beats zero pages

The most common mistake is perfectionism. A one-page policy that is adopted, communicated, and trained today is worth more than a 30-page draft that has been "in alignment" for months. The pragmatic route:

  1. Get the six building blocks onto one page (an afternoon).
  2. Have management adopt it, with a date.
  3. Present it to the team, 30 minutes, document attendance.
  4. Add training records, for example via the Academy modules.
  5. Put the review date in the calendar.

That gives you three things at once: a lived rule for daily work, an Article 4 record, and a document for the next supplier questionnaire. Provable compliance is built in exactly this order: first the rule, then the evidence, then the competitive edge.

Check if the EU AI Act applies to you

Free classification in 3 minutes. No signup required.

Get Started