bettersorted Logo
eu ai act compliance
General

Drawing up an AI policy: A 5-step guide to data protection and the EU AI Act

AuthorMuhamed Alahmed
Published on
Reading time17 min
In short

Uncontrolled use of AI in the workplace — also known as ‘shadow AI’ — poses risks to data protection and compliance under the GDPR and the EU AI Act. A clear AI policy establishes rules that reduce these risks and boost acceptance within the team.

You must monitor the use of AI in your Company Regulate? Uncontrolled use of AI, also known as ‘shadow AI’, is dangerous. It can jeopardise data security and compliance.

Without a clear AI Directive you risk breaching the EU AI Act and the GDPR. This could also have a negative financial impact. A clear AI strategy helps to mitigate these risks.

One GDPR-compliant The use of AI is important for compliance and staff acceptance. A clear AI policy ensures that your AI applications are compliant with the law and operate efficiently.

Key findings

The uncontrolled use of AI poses significant risks to data security.

A clear AI policy minimises compliance risks.

GDPR-compliant AI-Usability is crucial to staff acceptance.

A structured AI strategy reduces business risks.

Compliance with the EU AI Act is essential for businesses.

The risk of uncontrolled AI proliferation in companies

Without clear rules, the use of AI in companies can quickly get out of hand. This leads to major risks, ranging from data protection issues to financial losses.

What is ‘shadow AI’ and why is it problematic?

‘Shadow AI’ refers to AI applications that are deployed without the knowledge of the IT department or senior management. This hidden use can major security risks mean. It often fails to meet the company’s safety standards.

Problems caused by Shadow AI include:

Inadequate security measures

Data breaches

Uncoordinated data processing

Risks to data security and compliance

The uncontrolled use of AI poses a threat to the Data security and Compliance in companies. Without clear rules, AI systems can leave sensitive data unprotected. They may even breach laws such as the GDPR.

The risks include:

Unauthorised access to data

Data breaches

Non-compliance with statutory requirements

Economic consequences of the uncoordinated use of AI

The economic consequences of uncoordinated AI use are significant. Companies risk financial losses due to security issues. You also risk Damage to reputation, if sensitive data is lost.

Some of the economic consequences are:

Direct costs arising from security incidents

Indirect costs resulting from damage to reputation

Loss of customer trust

The legal framework for AI in businesses

Companies face a major challenge when it comes to AI. There are many laws and regulations they must comply with. These rules apply both within the EU and in individual countries.

Overview of the EU AI Act

The EU AI Act is very important for AI in business. It aims to ensure that AI is used fairly and ethically. The Act classifies AI systems into risk categories and sets out requirements.

Risk categories under the EU AI Act:

Unacceptable Risk (unreasonable risk)

High Risk

Limited Risk

Minimal Risk (minimal risk)

GDPR requirements for AI applications

The GDPR is very important for AI, particularly when it comes to data processing. Companies must ensure that their AI applications comply with the GDPR.

Key aspects of the GDPR relating to AI:

Transparency in data processing

Purpose limitation of data

Data minimisation

Rights of data subjects

National characteristics in Germany

In Germany, there are additional rules on top of EU regulations. Companies must familiarise themselves with the German requirements.

Regulation

Description

Impact on AI applications

EU AI Act

Regulation of AI at EU level

Risk assessment and classification

GDPR

EU General Data Protection Regulation

Data protection in AI applications

BDSG

The Federal Data Protection Act in Germany

National data protection regulations

Companies must adapt their AI strategy to the EU AI Act, the GDPR and national specificities. Through local AI models they can improve their compliance and make AI applications more efficient.

Why every business needs an AI policy

An AI policy is important for ensuring responsible use of AI within companies. It ensures that AI technologies are used correctly and lawfully.

Legal protection through clear rules

A clear AI policy protects companies from legal problems. It helps companies to comply with the law.

Legal advantages:

Minimising legal risks

Compliance with regulatory requirements

Protection against legal consequences

Improving efficiency through the structured use of AI

AI can make companies much more efficient. An AI policy ensures that AI technologies are used effectively.

One example is the automation of routine tasks. This significantly boosts productivity.

Improving efficiency

Description

Advantages

Automation

Use of AI to automate routine tasks

Increased productivity, cost reduction

Optimisation

Optimising business processes using AI

Increased efficiency, better decision-making

Competitive advantages through a responsible AI strategy

A responsible AI strategy helps companies hold their own. By using AI ethically, they build trust with their customers.

Trust through transparency: Companies that are open about AI build trust.




You are currently viewing placeholder content from YouTube. To access the actual content, click on the button below. Please note that this will result in data being shared with third parties.

Further information

Unlock content: Accept the required service and unlock content


In summary, an AI policy is very important for companies. It provides legal certainty, boosts efficiency and creates competitive advantages.

The 5-step guide to creating an AI policy

A company needs a clear AI policy to use AI applications safely. This guide will help you draw up and implement this policy.

An overview of the 5 steps

There are five key steps to creating an AI policy:

A review of current AI usage

Risk analysis and classification under the EU AI Act

Defining the key elements of your AI policy

Technical measures for implementation

Change management and staff acceptance

Every step is important in developing a comprehensive AI policy. This must ensure data protection and Automation and Compliance Please note.

Prerequisites for successful implementation

Before you start, there are a few things you need to check:

A clear Understanding current AI usage within the company

One defined responsibility for the AI Directive

One adequate training the employee

The use of local AI models and Open-source LLMs helps with data protection. It also reduces reliance on external services.

Timeframe for implementation

The time taken to implement the solution depends on the size and complexity of your business. Generally speaking, you will need 3 to 6 months.

Regular Reviews and adjustments These aspects of your AI policy are important. This ensures that it remains legally valid and relevant to your organisation.

Step 1: Assessing current AI usage

To develop effective AI governance, it is important to carry out a detailed analysis of your AI usage. This step helps you to understand all aspects of your AI strategy. In this way, you can lay a solid foundation for your AI policy.

Inventory of all AI tools used within the company

Start by drawing up a list of all AI tools and applications used within your organisation. This includes both official tools and those used without authorisation.

Identification of shadow AI applications

Shadow AI refers to AI applications used without the IT department’s authorisation. It is important to identify this ‘shadow AI’. This will help you avoid security risks and compliance issues.

Assessment of the risks associated with existing AI solutions

Once you have identified and documented the AI tools, you should assess the risks. When doing so, bear in mind data protection, security and compliance with legislation such as the EU AI Act.

Checklist for the stock-take

Which AI tools are used in your company?

Who is responsible for approving and monitoring these tools?

Is there Shadow AI-Applications within your organisation?

What risks are associated with the AI solutions being used?

How is data processed and protected in AI systems?

The assessment will provide you with a comprehensive overview of your use of AI. This will enable you to develop an effective AI policy that complies with legal requirements and meets your organisation’s needs.

Step 2: Risk analysis and classification under the EU AI Act

To ensure your AI applications comply with the EU AI Act, you must assess risks. This step helps you to meet legal requirements and improve efficiency.

Understanding the risk categories under the EU AI Act

The EU AI Act classifies AI applications into risk categories. These categories determine which compliance measures are required. There are four categories:

Unacceptable Risk (unacceptable risk)

High Risk

Limited Risk

Minimal Risk (minimal risk)

Each category has specific requirements.

Classifying your AI applications into risk categories

To classify your AI applications, analyse their functionality and impact. Ask yourself:

What data is processed by the AI application?

How is this data used?

What potential risks arise from its use?

Implications of the classification for your AI policy

The classification of your AI applications has a significant impact on your AI policy. Stricter controls are required for high-risk applications.

Practical example: Risk analysis of a chatbot

A chatbot that processes sensitive data could be classified as high-risk. In that case, specific data protection and security measures must be put in place.

Risk category

Requirements

Unacceptable Risk

Prohibition on use

High Risk

Strict controls and monitoring

Limited Risk

Transparency requirements

Minimal Risk

No specific requirements

EU AI Act Risikokategorien

Step 3: Key elements of an effective corporate AI policy

Once you have assessed your use of AI, you need to identify the key elements of your AI Policy for Businesses set out. A good policy sets out how AI technologies may be used within the organisation.

Definition of the scope and objectives

The first step is to define the scope. You need to identify which areas and processes are affected. The objective must be clear so that everyone knows what is to be achieved.

Identification of the business areas affected by the AI Directive

Definition of the objectives to be achieved through the implementation of the AI Directive

Defining permitted and prohibited uses of AI

A key aspect is the clear distinction between permitted and prohibited uses of AI. This prevents misuse and ensures that AI technologies are used correctly.

Clear guidelines give us the assurance that we are using AI technologies responsibly.

Data Protection Policy for AI Systems

A strong Data Protection Policy is essential for the success of AI systems. It ensures that all AI applications comply with data protection regulations.

Responsibilities and approval processes

Clear lines of responsibility and approval processes are important for the implementation of the AI policy. It is important to appoint those responsible for oversight and approval.

Template for an AI policy

There are template documents available to help organisations draw up their AI policy. These templates contain the key elements and can be customised.

Scope and Objectives

Permitted and prohibited uses of AI

Data Protection Policy

Responsibilities and approval processes

By incorporating these elements into your AI policy, you can use AI technologies effectively and responsibly.

Step 4: Technical measures for implementation

Technical measures are very important when implementing your AI policy. You must ensure that your AI applications are secure and efficient.

Use of on-premises AI models versus cloud solutions

When choosing between on-premises AI models and cloud-based solutions, a decision must be made. On-premises models offer greater data security, as sensitive data does not need to be transferred to the cloud. Cloud solutions are scalable and flexible, but they pose greater security risks.

When making your decision, you should consider your requirements and the nature of your data. For organisations handling sensitive data, on-premises models are often the better choice.

Open-source LLMs as a privacy-friendly alternative

Open-source LLMs (Large Language Models) are a privacy-friendly alternative compared to commercial solutions. They enable you to retain control over your data and increase transparency.

Some of the advantages of open-source LLMs are:

Flexibility in tailoring the solution to your specific needs

Enhanced security through open code review

Cost-effectiveness through the avoidance of licence fees

Automated compliance testing for AI applications

An automated compliance check is important to ensure that your AI applications comply with regulations. Automation tools help to continuously monitor data protection and security standards.

These tools help to identify and rectify compliance breaches at an early stage.

Technical checklist for IT managers

IT managers should consider the following points to support the technical implementation of their AI policy:

Data storage and transmission

Security measures for AI applications

Regular updates and maintenance of AI systems

Training of IT staff on AI-specific security risks

Step 5: Change management and staff acceptance

It is crucial that your staff accept the AI policy. This ensures long-term success and compliance with the Compliance with the EU AI Act. Comprehensive change management is therefore necessary.

Communication strategies for the AI Directive

Clear and transparent communication is key. You should keep your staff informed about the objectives, benefits and implications. These include:

Regular information sessions

Intranet articles and newsletters

FAQ lists covering frequently asked questions

Training programmes for different groups of staff

To train all staff, develop bespoke programmes. These could include the following:

Basic training on AI and data protection for everyone

Specialised training courses for AI applications

Workshops on conflict resolution

Dealing with resistance and concerns

It is normal for staff to have concerns. It is important to take these seriously and to communicate openly. Some strategies include:

Establishment of a feedback mechanism

Face-to-face discussions where concerns are raised

Amendment of the directive in response to objections

Successful implementation: dos and don’ts

When implementing the AI Directive, please bear the following key points in mind:

DOS

DON’TS

Communicate transparently and regularly

Avoid surprises and unexpected changes

Do you offer comprehensive training courses?

Don’t overestimate your staff’s abilities without proper training

Listen to your staff’s feedback

Ignore any concerns or resistance

By following these steps, you will ensure the success of the AI policy. You will promote the Staff training on AI.

Best practices for implementing AI policies

To integrate AI into your business, you need a clear policy. This policy ensures security, efficiency and legal compliance when using AI technologies.

Success stories from German companies

German companies have already successfully implemented AI policies. For example, the Siemens AG has developed a comprehensive AI strategy. This takes both technical and ethical aspects into account.

The Deutsche Telekom has established an AI governance framework. This supports the development and use of AI applications.

Common pitfalls and how to avoid them

There are challenges involved in introducing AI guidelines. One major problem is Shadow AI, i.e. AI operating without the knowledge or authorisation of senior management.

To prevent this, you should:

Draw up a detailed list of all AI applications.

Establish clear rules and approval processes.

Provide regular training and raise awareness amongst staff.

Timetable and resource planning for the roll-out

Introducing an AI policy requires careful planning and resources. A detailed timetable helps to coordinate all the steps.

Don’t forget to consider the necessary resources, such as staff, budget and technology. A local AI model-The solution helps to manage data and meet requirements.

Follow these best practices to implement an effective AI policy. This will help your organisation on its journey towards a digital future.

AI governance: Long-term monitoring and adaptation

Effective AI governance is essential for monitoring and adapting your AI strategy. A sound governance structure ensures that AI applications are regularly reviewed and adapted.

Establishment of an AI Governance Committee

An important step is the establishment of an AI governance committee. It should comprise experts from the fields of IT, legal affairs and compliance. Its aim is to oversee the AI strategy and ensure that all applications comply with the guidelines.

The committee meets regularly. It assesses new AI applications, checks compliance with the guidelines and amends them where necessary.

Regular audits and compliance checks

Regular audits and compliance checks are important. They ensure that AI applications comply with laws and guidelines. These audits are carried out both internally and externally.

The audits examine key areas. These include compliance with the GDPR, compliance with the EU AI Act and the security of AI systems.

Adapting the directive to new technologies and legislation

The AI landscape is constantly changing. New legislation and technologies mean that your policy needs to be adapted. It is important for your organisation to remain flexible and keep its policies up to date.

Various factors should be taken into account when making adjustments. These include new legislation, advances in AI technology and changes in business requirements.

By continuously monitoring and adapting your AI governance, you can reap the benefits of AI technology. At the same time, you prioritise compliance and risk management.

Specific requirements for different sectors

AI guidelines must be tailored to the needs of each sector. Different sectors face different challenges when it comes to AI systems. This depends on the rules and specific conditions.

Financial sector and insurance

Strict rules are important in the financial sector and in the insurance industry. The Compliance with the EU AI Act helps to make AI systems fair and transparent.

Strict security measures for financial data

Regular compliance audits

Transparency in AI decision-making

Healthcare and Pharmaceuticals

In the healthcare and pharmaceutical sectors, patient data protection is important. A GDPR-compliant AI protects health data.

Requirement

Description

Data Protection

Protection of patient data

Validation

Accuracy tests for AI systems

Transparency

Clear documentation of AI decisions

Production and Logistics

In production and logistics, AI systems improve processes. A good Staff training on AI is important for success.

Training in the use of AI systems

AI for process optimisation

Adapting AI systems to changes in production

Services and Trade

In the service sector and retail, AI systems are used to manage customer interactions. It is important that AI ethical standards is consistent and transparent.

eu ai act compliance

Every sector has specific requirements when it comes to AI guidelines. By taking these requirements into account, AI systems can be efficient, compliant and ethical.

Conclusion: Your AI policy as a strategic competitive advantage

Your AI policy is more than just a necessity. It is a real competitive advantage. It helps to minimise risks and boost your company’s efficiency.

A good AI governance system, as required by the EU AI Act, opens up new opportunities. It enables you to make full use of the benefits of AI technologies such as open-source LLMs. This improves your business processes and boosts staff satisfaction.

We can help you develop an AI policy that suits your business. Our experts will support you in analysing and implementing the necessary measures. Book a free consultation to take your AI strategy forward.

FAQ

What is an AI policy and why is it important?

An AI policy is a set of rules governing the use of artificial intelligence (AI) within organisations. It makes the use of AI safer, thereby reducing risks to data protection and compliance.

How can I ensure that my AI applications comply with the GDPR?

Develop a data protection strategy for your AI systems. It should comply with the requirements of the GDPR. Implement data protection measures and ensure transparency.

What are the advantages of local AI models compared with cloud-based solutions?

On-premises AI models are more privacy-friendly. They do not transfer data to the cloud. This is particularly useful for organisations with strict data protection requirements.

How can I train my staff on the new AI policy?

Develop training programmes for different groups of staff. Make use of workshops, online courses or information materials. This will ensure that all staff understand the policy.

What is an AI governance committee, and why is it important?

An AI governance committee monitors and oversees the use of AI within organisations. It plays a key role in implementing the AI policy and ensuring its ongoing review.

How can I adapt my AI policy to new technologies and legislation?

Carry out regular audits and compliance checks. Amend the policy accordingly. Monitor changes in legislation and analyse new technologies.

What are open-source LLMs and how can they be used in a way that respects data privacy?

Open-source LLMs are language models that are publicly available. They can be used in a privacy-friendly way by running them locally. This means data does not have to be sent to the cloud.

How can I assess the risks associated with my AI applications?

Carry out a risk analysis. Identify potential risks and assess their impact. This will enable you to take steps to minimise risks.

What are the benefits of a structured approach to AI?

A structured approach to AI use brings benefits such as greater efficiency and improved compliance. It ensures that AI is used securely and in accordance with the law within organisations.

Portrait von Muhamed Alahmed, Gründer von bettersorted
About the author

Muhamed Alahmed

With over 10 years’ experience in IT, I develop solutions that not only work from a technical perspective, but also create real added value and open up new possibilities.

More about bettersorted →
Newsletter

Stay up to date on AI topics

Short updates on AI automation, funding programs and new posts — no spam, unsubscribe anytime.

We use Brevo as our marketing platform. By submitting, you agree that your data will be transferred according to Brevo's privacy policy .

CallEmailContact form