# CORPORATE AI USE POLICY AND DATA-LEAKAGE PREVENTION PROTOCOL

**Document code:** AIA-POL-01 · **Version:** 1.0 · **Classification:** Internal
**Effective date:** ……/……/20……  ·  **Review cycle:** 12 months

> This is a blank framework. The bracketed `[…]` fields must be completed
> against your organisation's actual position. Adopted unfilled, it affords no
> legal protection whatsoever.

---

## ARTICLE 1 — PURPOSE AND SCOPE

**1.1** The purpose of this Policy is to set out the rules governing the use of
generative artificial intelligence and machine-learning tools ("AI Tools")
within [COMPANY NAME] (the "Company"), with respect to the protection of
personal data, trade secrets and client information.

**1.2** This Policy binds Company employees, interns, contractor personnel,
freelance service providers and all third parties with access to Company
systems.

**1.3** It covers AI use on all Company-owned or Company-accessed devices, as
well as on employees' personal devices (BYOD).

### 1.4 Legal basis

| Subject | Basis |
|---|---|
| Principles relating to processing | GDPR Art. 5 |
| Lawfulness of processing | GDPR Art. 6 |
| Processor obligations | GDPR Art. 28 |
| Security of processing | GDPR Art. 32 |
| Personal data breach notification | GDPR Art. 33, Art. 34 |
| Data protection impact assessment | GDPR Art. 35 |
| International transfers | GDPR Art. 44 et seq. |
| AI literacy obligation | Reg. (EU) 2024/1689 Art. 4 |
| Transparency obligations | Reg. (EU) 2024/1689 Art. 50 |
| Trade secret protection | Directive (EU) 2016/943 |

> **Verification note.** The provisions above reflect the text as at the date
> this template was prepared. Confirm against the current text before adoption.

---

## ARTICLE 2 — DEFINITIONS

**2.1 AI Tool:** Any software service that produces text, images, audio, code
or decision recommendations from input data.

**2.2 Publicly Available AI Tool:** A tool accessed under the provider's
standard terms without a corporate agreement (free or individual subscriptions).

**2.3 Enterprise AI Tool:** A tool governed by an agreement executed in the
Company's name that contains data-processing terms.

**2.4 Shadow AI:** Any AI Tool used without the knowledge and approval of the
information technology function.

**2.5 Sensitive Input:** Any data falling within the following categories:
- (a) Personal data and special categories of personal data;
- (b) Commercial information belonging to a client, supplier or partner;
- (c) Source code, architecture documents, security configurations;
- (d) Financial statements, pricing models, non-public information;
- (e) Any information covered by a non-disclosure agreement.

---

## ARTICLE 3 — APPROVED TOOL LIST AND ACCESS REGIME

**3.1** AI Tools are placed in three classes according to data-processing risk:

| Class | Definition | Sensitive Input | Approval |
|---|---|---|---|
| A | Enterprise agreement, excluded from model training | Permitted (with Art. 4 records) | IT + Legal |
| B | Enterprise agreement, restricted configuration | Partially permitted | IT |
| C | Publicly available | **Prohibited** | — |

**3.2** The **Approved Tool List** ([ANNEX 1]) is maintained by IT and reviewed
at least quarterly.

**3.3** Use of a tool absent from the List constitutes Shadow AI and is handled
under Article 9.

**3.4** A tool's class is determined by assessing the provider's retention
period, whether inputs are used for model training, server location and the
sub-processor list.

---

## ARTICLE 4 — PROHIBITED INPUT CATEGORIES

**4.1** Entering any Sensitive Input listed in Article 2.5 into a Class C tool
is **prohibited**.

**4.2** Even in Class A and B tools, the following may not be entered without
the approval of the relevant function:

- **4.2.A** Special categories of personal data (health, biometric, criminal
  convictions, trade union membership, religion, philosophical belief, sex
  life) — GDPR Art. 9.
- **4.2.B** Third-party personal data sets entrusted to the Company under a
  processor agreement (GDPR Art. 28).
- **4.2.C** Any data belonging to a client whose contract prohibits, or makes
  subject to prior consent, the use of sub-processors.
- **4.2.D** Production credentials, API keys, access tokens and encryption keys.
- **4.2.E** Correspondence and evidence relating to an ongoing legal dispute.

**4.3** Where there is doubt as to whether an input falls within this Article,
the input is not made and the opinion of [DATA CONTROLLER / LEGAL] is obtained.
Where doubt persists, the input is withheld.

---

## ARTICLE 5 — OUTPUT VERIFICATION AND EDITORIAL APPROVAL

**5.1** AI Tool output may not, without verification, be:
- (a) sent to a client;
- (b) deployed into a production environment;
- (c) published in a public channel;
- (d) relied upon for a legal or financial decision.

**5.2** Verification is performed by an informed employee other than the person
who generated the output and is entered in the [ANNEX 2] Output Verification Log.

**5.3 Copyright and intellectual property check.** Before commercial use of
image, text or code output, it is checked whether the output reproduces a
protected work belonging to a third party. Code output is scanned for licence
compatibility.

**5.4** For AI-generated content made available to the public, the disclosure
and marking obligations under Reg. (EU) 2024/1689 Art. 50 are reserved.

---

## ARTICLE 6 — TRANSPARENCY AND DISCLOSURE OBLIGATIONS

**6.1** Where the Company operates an AI system that interacts directly with
natural persons, the counterparty is informed that they are interacting with an
AI system at the time of the first interaction.

**6.2** Where synthetic audio, image, video or text is generated, the output is
marked in a machine-readable format.

**6.3** The scope of these obligations depends on whether the Company is a
provider or a deployer of the system in question. Role determination is made
using the [ANNEX 3] form.

---

## ARTICLE 7 — INCIDENT RESPONSE PROTOCOL

**7.1** Where it is discovered that Sensitive Input has been entered into an AI
Tool, the employee who made the entry notifies [INCIDENT RESPONSE FUNCTION]
**without delay and within one hour at the latest**.

**7.2** No disciplinary action is taken against a reporting employee on the
grounds of the report itself. Concealment does not benefit from this protection.

**7.3** Response sequence:
1. Terminate sessions on the affected account;
2. Submit a deletion request to the provider and record it in writing;
3. Identify the affected data categories and number of data subjects;
4. Assess the notification obligation (GDPR Art. 33 / Art. 34);
5. Assess contractual notification obligations towards the affected
   client or partner;
6. Enter the incident in the [ANNEX 4] Breach Register.

**7.4** Notification deadlines are mandatory. Time runs from the moment the
breach becomes known.

---

## ARTICLE 8 — RECORDS AND AUDITABILITY

**8.1** The following records are retained for at least [PERIOD]:
- (a) Version history of the Approved Tool List;
- (b) Per-tool risk assessments;
- (c) Output verification records;
- (d) Incident records and actions taken;
- (e) Employee training attendance records.

**8.2** These are the first documents requested in an audit or in an EU
corporate buyer's supplier assessment.

---

## ARTICLE 9 — NON-COMPLIANCE AND SANCTIONS

**9.1** Breach of this Policy is subject to disciplinary action proportionate to
its gravity.

**9.2** Where a trade secret or personal data is intentionally transferred to
third-party systems, rights of termination for cause together with claims for
damages and criminal liability are reserved.

---

## ARTICLE 10 — TRAINING AND ENTRY INTO FORCE

**10.1** The Company ensures a sufficient level of AI literacy among personnel
using AI Tools (Reg. (EU) 2024/1689 Art. 4).

**10.2** This Policy enters into force on [DATE] and is notified in writing to
all personnel.

---

### SIGNATURE BLOCK

| | Name | Title | Date | Signature |
|---|---|---|---|---|
| Prepared by | | | | |
| Reviewed by (Legal) | | | | |
| Approved by (Management) | | | | |

---

### ANNEXES

- **ANNEX 1** Approved Tool List
- **ANNEX 2** Output Verification Log
- **ANNEX 3** Provider / Deployer Role Determination Form
- **ANNEX 4** Breach Register

---

*This template is general in nature and does not constitute legal advice.
Before adoption it should be adapted to the company's actual system inventory
and reviewed by qualified legal counsel.*
