Skip to main content

← All articles

AI policy for companies: a template with an agent annex

What a company AI policy should cover, whether it is mandatory, and why AI agents need their own annex with a register and permission levels.

Sebastian LangSebastian LangOctober 5, 202616 min read
AI policy for companies: a template with an agent annex

A company AI policy should first settle which tools are allowed, which data may go into them and who checks the output. That is still right, but with agents it is no longer enough. AI agents read mailboxes, change files and send messages without a human triggering every step. And they appear faster than many IT departments can keep up with: in a survey of 685 CIOs from eight countries, including Germany, 84 percent agree that employees build AI agents and AI applications faster than IT can govern them (Dataiku, September 2026).

A good company AI policy therefore has two parts: basic rules for all AI tools and an annex just for agents. Here you can read what belongs in both parts, whether an AI policy is mandatory and how to roll it out. The article works as a checklist even without a template. If you do not want to start from zero: our free AI policy template follows exactly this structure.

TL;DR

  • For Art. 4 AI Act, the policy as a document is not mandatory. Art. 4 requires measures to build AI literacy, but no particular level, no prescribed training, no certificate and no fixed format. A policy is still the simplest place to record rules and measures.
  • The core fits on a few pages: scope, roles, approved-tools list, data classes, basic rules, AI literacy, incidents, review.
  • Agents need rules of their own: a register, graded permissions with human confirmation for risky actions, rules for connectors, logs and protection against prompt injection. According to Gartner, uniform rules for all agents can lead agent projects to fail.

Is an AI policy mandatory?

In short: for Art. 4 of the AI Act, the rule this is usually about, it is not required as a separate document. The obligation behind it is real, though, and a policy is the obvious place to put it into practice.

The starting point is Art. 4 of the AI Act (Regulation (EU) 2024/1689, "KI-Verordnung" in German). It has applied since 2 February 2025 and was amended by the Digital Omnibus, which entered into force on 27 July 2026. In the new version, Art. 4 requires providers and deployers of AI systems to take measures that promote the AI literacy of their staff and of other persons operating or using AI systems on their behalf. This is not only about companies that develop AI themselves: asked whether a company whose employees use ChatGPT has to comply with the rule, the European Commission answers yes.

What matters just as much is what Art. 4 does not require. The Commission writes in its AI literacy questions and answers (as of 27 July 2026): no specific level of literacy is mandated, there are no strict requirements and no mandatory training, and no certificate is needed. Companies can keep an internal record of their training activities and other measures. Art. 4 does not prescribe a particular governance structure either. The Federal Network Agency (Bundesnetzagentur) puts it similarly: the AI Act does not specify how the support is to be provided and does not set standardised training measures. More on the new version is in our article on AI literacy under Art. 4 and the Digital Omnibus.

On supervision: since 2 August 2026, the national market surveillance authorities monitor compliance. In Germany, under the KI-MIG this is in principle the Bundesnetzagentur. For Art. 4, neither Art. 99 AI Act nor the German KI-MIG names a separate fine range. According to the European Commission, however, the authorities can impose penalties and other enforcement measures.

Why have a policy at all, then? Because it brings three things together in one place: what is allowed, who is responsible and which measures you have taken for AI literacy. The Bundesnetzagentur recommends documenting these measures well. It also points out that a lack of AI literacy can be regarded as a breach of the duty of care, particularly if damage results from it. A policy with a sheet for the documentation is a practical place for that. This format is not prescribed.

What belongs in an AI policy

A usable policy answers the same three questions for everyone in the company: may I use this tool, with which data, and whom do I turn to? Our template divides this into nine sections and two appendices (durations and intervals in it appear in brackets as suggestions to adapt, not statutory requirements). The structure also works as a checklist for a policy you already have.

SectionWhat it contains
1 Purpose and scopeApplies to employees, external persons with access to company systems and all AI systems, including AI functions in office, CRM or ERP software, on company and private devices
2 DefinitionsAI system, AI tool, AI agent, connector and MCP server, personal data
3 Roles and responsibilityManagement, AI lead, IT, data protection officer, managers, employees
4 Approved AI toolsApproved list with account type and permitted data classes, company accounts only, request process for new tools
5 Data classesPublic, Internal, Confidential, Strictly confidential, plus additional rules for personal data
6 Basic rulesHuman review, check facts, copyright, disclosure under Art. 50, chatbot notice, no prohibited practices, no AI-only decisions about people
7 AI literacyMeasures under Art. 4 by role: all users, power users and agent builders, managers
8 Reporting incidentsWhat counts as an incident, reporting route, stopping the agent, checking whether a notification duty under Art. 33 GDPR applies
9 ReviewAt least once a year and when there are new tools, agents or material legal changes
Appendix AAI agents: register, permission levels, connectors, oversight, logs, own agents, prompt injection
Appendix BRecord sheet for the AI literacy measures

Three parts of this decide whether the policy works in everyday use.

An approved list instead of a ban list

The most important sentence: for company tasks, only tools from the approved list are used, and only with company accounts. Private accounts, even paid ones, are not allowed for company data. For each tool, the list names the account type and the data classes with which it may be used. New tools and new AI functions in software already in use go through a fixed request process with review by IT and data protection.

Data classes everyone understands

Four classes are enough: public, internal, confidential and strictly confidential. When in doubt, the higher class applies. For personal data, conditions are added, such as data minimisation and, where the provider processes personal data as a processor, a corresponding contract (Art. 28 GDPR). Important with a view to agents: input is not only what someone types into the chat window, but also every uploaded file and everything a tool accesses through connectors. How you secure data protection for agents in operation is described in our article on GDPR and agentic AI.

Basic rules linked to the AI Act

Some rules follow directly from the AI Act and therefore belong in every policy:

  • Transparency (Art. 50): Since 2 August 2026, chatbots and other interactive AI systems must tell people that they are communicating with an AI. Deepfakes are labelled. Published AI-generated texts intended to inform the public on matters of public interest are disclosed, unless a human has reviewed them editorially and someone holds editorial responsibility.
  • Prohibited practices (Art. 5): AI is not used for prohibited practices, such as manipulative influence or social scoring.
  • Decisions about people: Annex III lists AI systems for selecting applicants or evaluating performance and behaviour as a high-risk area. After the Omnibus, these rules apply from 2 December 2027. The template already stipulates today: such decisions are never made by an AI alone, and such uses require prior approval.

Section 7 regulates AI literacy by role. The formats in the template, such as a 60-minute introduction for all users, appear as placeholders in brackets to adapt and are not a requirement of the law. Appendix B records who received which measure and when. Instead of the table, an export from the learning system will also do.

Template

AI policy with an agent annex

Request the template

Why AI agents need an annex of their own

In addition to answers, AI agents can carry out actions in other systems. The template defines an AI agent as an AI system that carries out tasks in several steps on its own: it reads and changes files, sends messages and operates other systems without a human triggering every step individually. The basic rule "a human checks the result before it is used" then comes too late. The email is already out.

Gartner sees a central mistake here. In a press release of 26 May 2026, the analyst firm warns that uniform rules for all AI agents, regardless of autonomy and access rights, can lead agent projects to fail. Gartner analyst Shiva Varma says that enterprises are treating AI agent governance as binary, "either locked down or fully trusted", and that this is the root cause of the failure (our rendering of the German wording). Gartner's forecast: by 2027, 40 percent of enterprises will demote or decommission autonomous AI agents because governance gaps are only noticed after incidents in production. The recommendation: classify agents by autonomy level, from "Observe" (read only) through "Advise" (drafts, the human acts) and "Act with Approval" (action only after approval) to "Act Autonomously" (acting within fixed guardrails), and define separate controls for each level.

The Dataiku survey shows how big the gap is. For the "Global AI Confessions Report: CIO Edition 2026", The Harris Poll surveyed exactly 685 CIOs in the USA, the United Kingdom, France, Germany, the United Arab Emirates, Japan, South Korea and Singapore between 9 and 29 July 2026:

  • 81 percent lack complete oversight of agents created outside approved systems or formal channels.
  • 83 percent have no uniform lifecycle management for agents.
  • 47 percent have already decommissioned more than 20 agents this year.

Appendix A of the template therefore answers seven questions that a pure tool policy leaves out:

  • A1 Agent register: Every agent that works with company data or company systems is entered before its first use, with purpose, responsible person, platform, connectors, data classes, permission level and the date of the next review.
  • A2 Permission levels: six levels from reading to payments, more on this in a moment.
  • A3 Connectors and MCP servers: only connections approved by IT, read-only access wherever possible, credentials never in prompts or shared files. Our article on the Model Context Protocol explains what MCP is.
  • A4 Human oversight: fixed checkpoints, a known way to stop the agent at any time, no blanket confirmations.
  • A5 Logging and review: actions are logged as far as the platform can do so, samples are checked, unused agents are deactivated and their connectors and credentials removed.
  • A6 Employees' own agents: allowed in approved tools. Registration and approval are required before an agent works with company data beyond its creator's own files or with other people's data. Agents that only use their creator's own files still follow the other rules.
  • A7 Prompt injection: External content is treated as untrusted, because hidden instructions in emails, web pages or documents can redirect an agent. The risk cannot currently be fully ruled out technically. Background is in our article on protection against prompt injection.

Permission levels for agents

The permission levels are the part of the annex that most directly takes up Gartner's criticism of uniform rules. Instead of "agents allowed" or "agents forbidden", each agent gets exactly the level its purpose requires.

LevelWhat the agent may doHuman confirmation
1 ReadRead and analyse files, records or mailboxesNot required
2 Create draftsCreate drafts in a workspace of its own, nothing leaves the workspaceNot required, drafts are reviewed before use
3 Edit and fileModify or store files and records in internal systemsAs set in the register, at least samples
4 DeleteDelete files, records or messagesYes, case by case
5 Send externallyEmails, messages or publications to external partiesYes, case by case
6 Payments and legally binding declarationsTrigger payments, place orders, enter into contracts or give notices of terminationYes, case by case, and only with the express permission of management

Three rules hold the system together. First: an agent performs actions of levels 4 to 6 only if a human has confirmed them case by case. The agent prepares, the human reviews and approves. Second: the lowest level that is sufficient for the purpose always applies. Third: agents that read external content get no rights of levels 4 to 6 without human confirmation.

Levels 1 and 2 roughly correspond to Gartner's "Observe" and "Advise", levels 4 to 6 to "Act with Approval". Gartner warns of a trap precisely at this level: approvals work only as long as they remain real control. Under time pressure or through approval fatigue they can become a formality and create false security. That is why the template states explicitly that no blanket approvals are given and actions are reviewed before approval. How you set the checkpoints in practice is shown in our guide to human-in-the-loop for AI agents.

Shadow AI and shadow agents

Shadow AI means: employees use AI tools that are not approved, often with private accounts. We analysed Bitkom data on how widespread this is in Germany in our article Shadow AI in the Mittelstand. With agents, a second layer is added: shadow agents, which someone clicks together in a tool, connects to a mailbox or a file store and then forgets. Dataiku reports more generally: 81 percent of the CIOs surveyed lack complete oversight of agents created entirely outside approved systems or formal channels.

A ban alone does not create an approved route. Gartner describes the consequence of overly strict rules for simple agents like this: they slow down implementation and drive shadow development. The template therefore goes the opposite way. Employees' own agents are allowed in approved tools. Before an agent works with company data beyond its creator's own files or with other people's data, it is registered and approved. The data classes and the confirmation from level 4 apply to all agents.

Technology helps with enforcement but does not replace the rules. Two examples from recent months:

  • Microsoft Agent 365 has been generally available since 1 May 2026. Microsoft describes it as a control plane to observe, govern and secure agents, with a register of the agents in the company. The standalone price is 15 US dollars per user per month. Alternatively, it is included in Microsoft 365 E7 (as of October 2026).
  • Claude Code received new settings for administrators at the end of September. Since version 2.1.283 (25 September 2026), a model approval can be pinned to exactly the version named, so that new model versions stay blocked until an admin adds them to the list. Individual models can also be blocked specifically. Since version 2.1.285 (29 September 2026), a setting limits which API providers a machine may use for Claude Code.

This way, parts of the approved list can also be enforced technically, for example which models and providers are allowed.

How to roll out the policy

A policy only works when people know it and everyday work fits it. A possible work plan in six steps, which you adapt to your size:

  1. Take stock. Which AI tools and agents are already running today, with which accounts and connectors? Tip: ask without blame, so that privately used tools also come to light.
  2. Set the approved list and data classes. IT and data protection review the tools you really need. Offer a good company account for the most important tasks, otherwise the private account remains the more convenient choice.
  3. Create the agent register. Enter existing agents, assign permission levels, switch off unused agents.
  4. Involve the works council early. If there is a works council, it must be informed in good time about the planning of work procedures and workflows, including the use of artificial intelligence, and the measures must be discussed with it (§ 90 BetrVG, Works Constitution Act). It has co-determination rights, among other things, on matters relating to workplace rules and the conduct of employees and on technical devices intended to monitor behaviour or performance (§ 87(1) nos. 1 and 6 BetrVG). Rules of conduct for AI use and logs of agent actions can touch on such points. Where the works council has to assess the use of AI, calling in an expert is deemed necessary (§ 80(3) BetrVG).
  5. Train and document. The template provides that everyone receives an introduction suited to their role before first use, and that you record who received what. If you do not want to build courses yourself: our training costs €599 per licence, one-off, with the Cowork course and the Claude Code course (pricing).
  6. Review regularly. The policy at least annually and when there are new tools, agents or legal changes, the register considerably more often.

A word on evaluations: providers draw lines here too. Anthropic states that Smart Reports for Claude Enterprise, available in beta since 10 September 2026 to analyse team usage, are not intended for assessing individual performance or making personnel decisions and should not be used for those purposes. We recommend recording this stance in your policy as well: logs serve the safety of the agents, not the performance monitoring of people.

For questions on classification, the Bundesnetzagentur offers an AI Service Desk with information, an online tool for initial risk classification, guidelines and material for building competence.

The template itself is not legal advice. Agree the adapted version with your data protection officer and have it legally reviewed where needed.

If you want to start small: take a single agent, enter it in the register and give it the lowest permission level that is sufficient for its purpose. It gets more rights only once the checkpoints work in everyday use. Prefer to talk directly? Book a 30-minute call.

FAQ

Is an AI policy mandatory for companies?

For Art. 4, the AI Act rule that affects practically every company using AI tools, no such document is prescribed. Art. 4 requires measures to build AI literacy, but no particular level, no prescribed training and no certificate. The Bundesnetzagentur recommends documenting the measures well, and a policy with a record sheet is a practical place for that.

What must an AI policy contain?

Our recommendation: scope, roles, an approved list of tools, data classes, basic rules for use, AI literacy measures, a reporting route for incidents and a fixed review rhythm. Anyone using AI agents adds an annex with a register, permission levels, rules for connectors, human oversight, logging and prompt injection.

Does the works council have to approve an AI policy?

That depends on the content. The works council must be informed in good time about the planning of AI use (§ 90 BetrVG) and, among other things, has co-determination rights on rules of conduct in the establishment and on technical devices for monitoring behaviour or performance (§ 87(1) nos. 1 and 6 BetrVG). So involve it from the start and have doubtful cases reviewed under employment law.

Do we need an AI officer?

Not for Art. 4. The European Commission prescribes no particular governance structure for it, and the Bundesnetzagentur expressly counts the introduction of an AI officer among the things that are not required. In practice, a named person who maintains the approved list and the agent register still helps. In our template, this role is called AI lead.

Does a ban help against shadow AI?

A ban alone does not create an approved route. Gartner warns that overly strict rules for simple agents slow down implementation and drive shadow development. Our template therefore relies on an approved route: company accounts for good tools, clear data classes and a rule under which employees may build and register their own agents.

How often should the policy be reviewed?

Our template provides for a review at least once a year, in addition when there are new tools or agents and when there are material legal changes. You look at the agent register more often; the template suggests quarterly as an adaptable placeholder, plus monthly samples of the agent logs. These are suggestions, not statutory requirements. The Bundesnetzagentur also advises refreshing AI literacy regularly.

Sources

Template

AI policy with an agent annex

An editable Word template for approvals, data classes, roles, AI literacy and AI agents. Free by email.

Sebastian Lang

About the author

Sebastian Lang

Co-Founder · Business & Content Lead

Co-Founder of Sentient Dynamics. 15+ years of business strategy (incl. SAP), MBA. Writes about EU AI Act compliance, ROI measurement and how Mittelstand CTOs actually adopt agentic AI.

Keep reading

Once a month. Only substance.

No motivational fluff. No tool lists. Only what CTOs, COOs and MDs in DACH really need to know about AI adoption.