Artificial intelligence has become part of everyday operations in many organisations. Some companies are already implementing a consistent AI strategy, while others are still at the beginning of their journey. The reality, however, is that many organisations already use AI extensively across different functions, either through tools selected by the company or through applications adopted independently by employees.
Many companies find themselves in a situation where they have not yet had time to establish a consistent policy for the use of AI. In some cases, guidance already exists, but it was drafted before the requirements of the EU AI Act became relevant. Now, at the latest, is the right time to ensure that the company’s AI practices and expertise are up to date. This is also critical for ensuring that personnel have the level of AI literacy required under the AI Act.
Why is an AI policy needed?
An AI policy is not merely a formality. It is a practical tool that enables a company to use AI responsibly and safely. At the same time, it helps the organisation respond to new regulatory requirements and creates the conditions for effective innovation.
Ensuring AI literacy: First, an AI policy supports the obligation to ensure an adequate level of AI literacy under the AI Act. Since February 2025, every organisation using AI has been required, to the best of its ability, to ensure that its personnel have a sufficient understanding of the risks, opportunities and potential harm associated with AI. A well-drafted AI policy is a key part of meeting this organisational and training obligation. The European Commission has also indicated that fines and other penalties may be more likely in cases where an organisation has failed to comply with the AI literacy obligation.
Encouraging responsible use: Clear rules encourage employees to use AI. When employees understand what is permitted and what is not, the use of AI can develop from cautious experimentation into systematic business improvement. A clear policy creates a sense of security that encourages employees to explore new ways of making their work more efficient without fearing that the use of AI could inadvertently breach contractual or regulatory obligations or cause other risks to materialise. In this way, an AI policy serves not only as a risk management tool but also as a tool for innovation.
Managing hidden use: An AI policy helps an organisation identify and manage undisclosed use and shadow AI. In many organisations, AI tools have been introduced through applications selected independently by employees. Where the use of AI is not identified, the related risks cannot be managed either. A policy makes the use of AI visible and enables the organisation to provide guidance on tools that employees adopt independently without separate approval. A complete ban on AI may not necessarily reduce risks. On the contrary, it may make it more difficult to provide employees with practical guidance on appropriate ways of working.
Protecting trade secrets and personal data: One of the most important functions of an AI policy is to establish clear boundaries for the use of trade secrets and personal data in connection with AI. When an employee enters customer data, internal plans or personal data into an AI tool, the information may spread beyond the organisation’s control. The policy should establish practical rules on what information may be used, under what conditions and in which environments. In this way, it protects the interests of both the company and its stakeholders.
Implementing the requirements of the AI Act: An AI policy helps an organisation put into practice the operating models and restrictions required under AI regulation. The AI Act imposes obligations particularly in relation to high-risk use cases, including requirements concerning data governance, the retention of logs, and the monitoring and oversight of use. Merely being aware of these obligations is not enough. They must be implemented in a way that makes them visible in day-to-day processes and decision-making. The policy acts as a bridge between legal requirements and practical work.
Building trust among stakeholders: An AI policy also sends a message to external stakeholders. When a company can demonstrate that it uses AI in a considered and responsible manner, it builds trust among customers, business partners and authorities. Trust, in turn, strengthens the company’s reputation and distinguishes it positively from its competitors. An AI policy therefore serves simultaneously as a risk management tool, a training instrument and a strategic statement of responsible business conduct.
An AI policy is an investment in a sustainable future
The use of AI introduces new types of risk, but it also creates enormous opportunities. A clear AI policy helps turn AI into a genuine business strength by enabling new forms of innovation while ensuring that the associated risks are managed appropriately.
Whether AI is already an essential part of the company’s daily operations or still at the experimental stage, now is the right time to ensure that internal guidance and training are up to date.

Katri Aarnio
Counsel
050 306 2031
To receive our articles directly by email, subscribe to the Folks newsletter here.
