Skip to Content
People Stack Now
Home
About
Shop
Services
FAQ
Contact
Blog
Login Account
(0)
Cart (0)
People Stack Now
Home
About
Shop
Services
FAQ
Contact
Blog
Login Account
(0)
Cart (0)
Home
About
Shop
Services
FAQ
Contact
Blog
Login Account
Shop › AI Usage Policy Template — EU AI Act & GDPR Compliant | People Stack Now
Untitled - June 05, 2026 at 20.05.46-58.png Image 1 of 1
Untitled - June 05, 2026 at 20.05.46-58.png
Untitled - June 05, 2026 at 20.05.46-58.png

AI Usage Policy Template — EU AI Act & GDPR Compliant | People Stack Now

$39.00

Most AI policies are either too restrictive to be followed or too vague to be useful. This one is built around practical tools — traffic-light use tables, a named tool register with approval status, and concrete verification standards — so employees can make real decisions about real situations.

Twelve parts covering: scope and definitions (AI tool, approved tool, consumer/public tool, high-risk AI use), the core accountability principle with a Do/Don't behaviour table, approved uses (10 categories), conditional uses (8 categories), prohibited uses (10 categories), data protection and confidentiality (GDPR/UK GDPR, HIPAA, PIPEDA/Law 25, Australian APPs), quality and verification standards by output type, IP and copyright (five-jurisdiction flag), disclosure standards, AI in employment decisions (EU AI Act Annex III high-risk classification, GDPR Article 22, US EEOC guidance, NYC Local Law 144, Australian general protections), the AI tool register with named examples, and governance. Regulatory context flag covers EU AI Act (in force August 2024), UK pro-innovation approach, US state AI legislation, Canada's AIDA, and Australian Voluntary AI Safety Standard.

FAQS

Q  Does my business need an AI policy in addition to an Acceptable Use Policy?

If your employees are using AI tools — and they almost certainly are — then yes. A general AUP does not address the specific risks of generative AI: data leakage through public tools, quality and verification obligations, IP ownership of AI-generated outputs, or the EU AI Act's high-risk classification for HR AI systems. The AI Usage Policy provides the specific, practical framework that fills this gap.

Q  What is the EU AI Act and does it affect HR?

The EU AI Act (in force August 2024) is the world's first comprehensive AI regulation. Critically for HR: AI systems used for recruitment, CV screening, interview assessment, performance monitoring, and employee evaluation are classified as high-risk under Annex III of the Act. From August 2026, employers using such systems must comply with conformity assessment, transparency, human oversight, and data governance requirements. This is a material compliance obligation for any organization using AI-assisted hiring or performance tools in the EU.

Q  What is the traffic-light use table?

The policy includes three colour-coded tables: approved uses (10 categories in green), conditional uses requiring care or approval (8 categories in amber or blue), and prohibited uses (10 categories in red). Each row names a specific use case, the status, and the conditions or notes. An employee can find the answer to a real question — 'can I use this tool for this task?' — in under a minute without reading the whole policy.

Q  What data must never be entered into a public AI tool?

Personal data about any individual, clinical or patient data, confidential business information (financial data, product roadmaps, customer lists), intellectual property (source code, algorithms), legal advice or privileged communications, and third-party NDA-protected information. Any of these categories entered into a public AI tool constitutes a confidentiality breach and, where personal data is involved, a potential data protection violation in all five jurisdictions.

Most AI policies are either too restrictive to be followed or too vague to be useful. This one is built around practical tools — traffic-light use tables, a named tool register with approval status, and concrete verification standards — so employees can make real decisions about real situations.

Twelve parts covering: scope and definitions (AI tool, approved tool, consumer/public tool, high-risk AI use), the core accountability principle with a Do/Don't behaviour table, approved uses (10 categories), conditional uses (8 categories), prohibited uses (10 categories), data protection and confidentiality (GDPR/UK GDPR, HIPAA, PIPEDA/Law 25, Australian APPs), quality and verification standards by output type, IP and copyright (five-jurisdiction flag), disclosure standards, AI in employment decisions (EU AI Act Annex III high-risk classification, GDPR Article 22, US EEOC guidance, NYC Local Law 144, Australian general protections), the AI tool register with named examples, and governance. Regulatory context flag covers EU AI Act (in force August 2024), UK pro-innovation approach, US state AI legislation, Canada's AIDA, and Australian Voluntary AI Safety Standard.

FAQS

Q  Does my business need an AI policy in addition to an Acceptable Use Policy?

If your employees are using AI tools — and they almost certainly are — then yes. A general AUP does not address the specific risks of generative AI: data leakage through public tools, quality and verification obligations, IP ownership of AI-generated outputs, or the EU AI Act's high-risk classification for HR AI systems. The AI Usage Policy provides the specific, practical framework that fills this gap.

Q  What is the EU AI Act and does it affect HR?

The EU AI Act (in force August 2024) is the world's first comprehensive AI regulation. Critically for HR: AI systems used for recruitment, CV screening, interview assessment, performance monitoring, and employee evaluation are classified as high-risk under Annex III of the Act. From August 2026, employers using such systems must comply with conformity assessment, transparency, human oversight, and data governance requirements. This is a material compliance obligation for any organization using AI-assisted hiring or performance tools in the EU.

Q  What is the traffic-light use table?

The policy includes three colour-coded tables: approved uses (10 categories in green), conditional uses requiring care or approval (8 categories in amber or blue), and prohibited uses (10 categories in red). Each row names a specific use case, the status, and the conditions or notes. An employee can find the answer to a real question — 'can I use this tool for this task?' — in under a minute without reading the whole policy.

Q  What data must never be entered into a public AI tool?

Personal data about any individual, clinical or patient data, confidential business information (financial data, product roadmaps, customer lists), intellectual property (source code, algorithms), legal advice or privileged communications, and third-party NDA-protected information. Any of these categories entered into a public AI tool constitutes a confidentiality breach and, where personal data is involved, a potential data protection violation in all five jurisdictions.

You Might Also Like

Confidentiality Policy & NDA Template — Multi-Jurisdiction | People Stack Now Untitled - June 05, 2026 at 20.05.46-41.png
Confidentiality Policy & NDA Template — Multi-Jurisdiction | People Stack Now
$29.00
Expenses & Reimbursement Policy Template | Multi-Jurisdiction | People Stack Now Untitled - June 05, 2026 at 20.05.46-46.png
Expenses & Reimbursement Policy Template | Multi-Jurisdiction | People Stack Now
$19.00
Equal Opportunities Policy Template — Multi-Jurisdiction | People Stack Now Untitled - June 05, 2026 at 20.05.46-45.png
Equal Opportunities Policy Template — Multi-Jurisdiction | People Stack Now
$19.00
Share Option & Equity Policy Template — EMI, KEEP, ISO | People Stack Now Untitled - June 05, 2026 at 20.05.46-55.png
Share Option & Equity Policy Template — EMI, KEEP, ISO | People Stack Now
$19.00
Health & Safety Policy Template — Multi-Jurisdiction | People Stack Now Untitled - June 05, 2026 at 20.05.46-44.png
Health & Safety Policy Template — Multi-Jurisdiction | People Stack Now
$19.00

sales@people-stack-now.com