Creating an AI Policy: Template & Approval Process
Last updated on August 10, 2026 at 08:06 AM.An AI policy is an internal rulebook that defines which AI tools employees may use, what data may be entered into those tools, who reviews the outputs, and how AI-generated content is documented. From 2 August 2026, the EU AI Act's transparency obligations take effect—companies without a documented AI usage policy risk uncontrolled shadow AI and measurable compliance violations. This article provides the complete structure of an AI policy in six building blocks, the five-stage approval process for AI-generated content, and the framework of a downloadable template that works as a lead magnet.

Why marketing teams need an AI usage policy
79% of companies use AI in at least one business function, and marketing departments are among the most intensive adopters. In Germany, 88% of AI-using companies deploy the technology in customer-facing operations—precisely where brand messaging, customer data, and tone of voice converge. Leaving this usage unregulated means delegating compliance to chance.
Shadow AI is not a fringe issue—it is a real risk: employees enter sensitive data into unapproved tools, and nobody documents what leaves the organisation. Companies that want to place their AI usage on a GDPR-compliant foundation instead will find Crispy Content®'s approach of audits, policies, and secure integrations for robust AI governance and compliance a structured path forward.
Budget owners need planning certainty: a documented AI policy makes costs, risks, and responsibilities transparent. It prevents three departments from licensing the same tool through different accounts, and it gives the legal team a document to reference rather than reassessing every individual question from scratch.
| Criterion | With AI policy | Without AI policy |
|---|---|---|
| Data protection compliance | Systematically secured through defined data classes | Dependent on individual employee decisions |
| Shadow AI risk | Minimised through whitelist and corporate accounts | Uncontrolled, no visibility into tools in use |
| Approval time for new tools | Defined process (avg. 5–10 working days) | Ad hoc, delayed, or not regulated at all |
What an AI policy governs—core concepts and definitions
An AI policy—also referred to as AI guidelines or AI directive—defines the binding framework for the use of generative and analytical AI systems within an organisation. The terms are used interchangeably but differ in their level of obligation: a policy is typically binding, a guideline advisory. An AI policy is distinct from a works council agreement, which requires co-determination, and from a data protection concept, which exclusively addresses personal data.
Approved tools and the whitelist principle
The whitelist approach is the backbone of any AI policy: Only vetted and explicitly approved AI tools may be used. Everything else is blocked until it has passed the approval process. The whitelist categorises tools by purpose—content creation, translation, data analysis, image generation—and documents the approved version, provider, and permissible use cases for each tool. A tool approved for text drafting may not automatically be used for customer data analysis.
Data classification and input rules
Data classification operates on three tiers: non-critical, internal, and restricted. Non-critical covers general text drafts without company reference—for example, a generic social media post about an industry trend. Internal means: usable only via the corporate account with training-data opt-out enabled, such as internal strategy papers or competitive analyses. Restricted covers customer data, trade secrets, contract contents, and personal data—this information must under no circumstances be entered into an AI system.
Responsibilities and roles
Three roles carry the AI policy operationally: The AI Officer acts as governance owner and decides on whitelist additions and policy updates. The department head approves AI-generated content in day-to-day operations. The Data Protection Officer reviews new tools for GDPR compliance before they are added to the whitelist. Without this role clarity, any policy remains a paper tiger.
The five-stage AI approval process—from creation to documentation
The approval process ensures that no AI-generated content leaves the organisation without being reviewed, assessed, and documented. The five stages—creation, human review, transparency check, approval, documentation—run sequentially and produce a complete audit trail. Each stage has a responsible role, a defined timeframe, and a measurable output.
Stages 1–2: Creation and human quality review
In stage 1, the content owner creates the raw draft using an approved AI tool. In stage 2, a subject-matter expert reviews the draft for factual accuracy, brand voice, and correctness. For external content—blog articles, press releases, customer communications—the four-eyes principle applies: a second person reviews before the draft advances to stage 3. The human review is not a formality. It is the point at which hallucinations, tonal errors, and factual inaccuracies are caught—or missed.
Stages 3–4: Transparency check and approval
The transparency check answers a single question: Does this content need to be labelled as AI-generated? From August 2026, Article 50 of the EU AI Act requires the labelling of synthetic content intended for the public. The AI Officer makes this determination using a checklist. The designated approver—Head of Marketing, team lead, or department head—then issues the formal approval sign-off.
Stage 5: Documentation and audit trail
The following are documented: tool used including version, a summary of the prompt, name of the reviewer, approval date, and the labelling decision. The retention period aligns with GDPR deletion requirements and internal compliance standards—in practice, this means 12 to 36 months. The audit trail is not bureaucracy for its own sake. It is the evidence if a supervisory authority asks how a specific piece of content was produced.
| Stage | Responsible | Timeframe | Output |
|---|---|---|---|
| 1. Creation | Content creator + AI tool | 1–2 hours | Raw draft |
| 2. Human review | Editorial / team lead | 1–4 hours | Reviewed draft |
| 3. Transparency check | AI Officer | 30 minutes | Labelling decision |
| 4. Approval | Head of Marketing | 1 hour | Approval sign-off |
| 5. Documentation | Content creator | 15 minutes | Audit entry |
Worked example—time savings through a standardised AI approval process
Without a defined process, coordinating an AI-generated blog article takes 3 to 5 working days: email back-and-forth, unclear responsibilities, duplicate reviews by people who haven't aligned. With a standardised process, turnaround drops below 8 hours—because every role knows what it reviews, and nobody waits for a decision that isn't theirs to make.
A marketing team produces 12 AI-assisted content pieces per month. Without a process, each piece ties up an average of 4 person-days in coordination: 12 × 4 = 48 person-days. With the five-stage process, effort drops to 0.8 person-days per piece: 12 × 0.8 = 9.6 person-days. The difference is 38.4 person-days per month. At an internal day rate of €500, that yields monthly savings of €19,200—or €230,400 per year. The figure is conservative because it does not factor in opportunity costs from delayed publications.
| Metric | Without process | With process |
|---|---|---|
| Turnaround per content piece | 3–5 working days | < 8 hours |
| Person-days/month (at 12 pieces) | 48 | 9.6 |
| Monthly cost (at €500/day) | €24,000 | €4,800 |
EU AI Act and GDPR—the regulatory framework for AI communication policies
Two regulatory frameworks interlock and form the legal foundation of any AI policy: The EU AI Act governs transparency and risk classification of AI systems; the GDPR protects personal data. For marketing teams, both apply simultaneously—the transparency obligations from August 2026 cover chatbots, synthetic content, and deepfakes, while the GDPR prohibits entering customer data into AI prompts without a legal basis.
Shadow AI is not a fringe issue—it is a real risk: employees enter sensitive data into unapproved tools, and nobody documents what leaves the organisation. Companies that want to place their AI usage on a GDPR-compliant foundation instead will find Crispy Content®'s approach of audits, policies, and secure integrations for robust AI governance and compliance a structured path forward.
The sanction frameworks of both regulations are substantial: The EU AI Act provides for fines of up to €35 million or 7% of global annual turnover; the GDPR up to €20 million or 4% of annual turnover. For a mid-sized company with €50 million in revenue, this means a theoretical maximum exposure of €3.5 million from the AI Act alone. The AI policy is the document that, in an emergency, proves the company took its duty of care seriously.
| Aspect | EU AI Act | GDPR |
|---|---|---|
| Scope | AI systems by risk class | Personal data |
| Obligation from | Transparency: 02.08.2026 | Already in force |
| Marketing relevance | Labelling of AI-generated content | No customer data in AI prompts without legal basis |
| Sanctions | Up to €35m or 7% annual turnover | Up to €20m or 4% annual turnover |
Creating an AI policy—structure in six building blocks
An effective AI policy comprises six building blocks that fit on 2 to 4 pages. What matters is not length but specificity: each building block contains practical examples rather than abstract language. A policy that demands "responsible use of AI" without defining what that means in daily work will be ignored—rightly so.
Building blocks 1–3: Scope, whitelist, data rules
The scope defines who is bound by the policy: all employees, freelancers, agencies, and external service providers using AI tools on behalf of the company. The whitelist lists approved tools with version number, provider, and permissible use case—not as a static list but as a living document with a defined onboarding process. The data rules operationalise the three-tier classification with two concrete examples per tier, so employees can look up rather than interpret.
Building blocks 4–6: Approval process, labelling, training and review cycle
Building block 4 references the five-stage approval process and defines which content types must pass which stages—an internal draft does not require a transparency check; a customer magazine article does. The labelling rules specify: externally published AI-generated content will always be labelled from August 2026; internal content as needed. Building block 6 governs training—an onboarding module for new employees plus a biannual update—and the review cycle: the policy is reviewed every 6 months and updated immediately upon regulatory changes.
Shadow AI is not a fringe issue—it is a real risk: employees enter sensitive data into unapproved tools, and nobody documents what leaves the organisation. Companies that want to place their AI usage on a GDPR-compliant foundation instead will find Crispy Content®'s approach of audits, policies, and secure integrations for robust AI governance and compliance a structured path forward.
Download template as lead magnet—structure and application
An AI policy template as a downloadable PDF works as a lead magnet for marketing decision-makers with concrete implementation intent—people who are no longer researching whether they need a policy, but how to build one. The template is editable and contains placeholders for company name, tool list, data classification, and approval roles. It does not replace legal counsel, but it provides a structure that prevents essential building blocks from being overlooked.
- Cover page with versioning: Document name, version number, effective date, responsible person—so every employee can immediately verify whether they have the current version.
- Whitelist table: Columns for tool name, provider, use case, approval date, and reviewing person—the operational core of the policy.
- Data classification matrix: Three tiers with two practical examples each, enabling employees to look up rather than interpret.
- Approval process flowchart: Visual representation of the five stages with responsibilities and timeframes.
- Documentation template: Fields for tool, prompt summary, reviewer, date, and labelling decision—the audit trail in table form.
A documented AI policy makes responsibilities and budgets plannable. Companies that prefer not to build it internally can develop it with a specialised communications agency like Crispy Content®—as one option alongside internal resources or legal counsel.
Trends 2026/2027—how AI policies will evolve
AI policies are not static documents. Three developments are fundamentally changing requirements over the next 12 to 18 months—and anyone writing their policy today should factor them in now rather than starting from scratch in six months.
- Agentic AI and autonomous workflows: AI agents act independently—they research, decide, and publish without human intervention. Policies must define escalation thresholds for autonomous decisions: at what risk level must a human intervene?
- Tightened transparency obligations: From December 2026, systems introduced before August 2026 must also label synthetic content in machine-readable form. The transition period ends, and legacy systems lose their protection.
- AI governance as competitive advantage: Companies with responsible AI programmes report 60% higher ROI—governance is shifting from a compliance obligation to a differentiator that attracts customers and talent.
- Integration into existing management systems: AI policies are merging with ISO 27001 processes and existing compliance frameworks rather than existing as an isolated document alongside the information security policy.
The AI policy as the foundation for the AI communications setup
The AI policy is the first operational step toward a complete AI communications setup: it defines the rules of engagement before tools are configured, prompts standardised, and workflows automated. Without this foundation, every AI investment in marketing remains an unmanaged risk—like a toolbox without an inventory list, where nobody knows what's inside or who is authorised to use it. The logical next step after the policy is the technical setup: tool selection based on the whitelist, building a prompt library for recurring use cases, and a reporting structure that makes the ROI of AI usage measurable. Methods deliver guarantees—here, too.
Sources
Bitkom e.V. (2025): Generative KI im Unternehmen – Leitfaden 2025. URL: https://www.bitkom.org/Bitkom/Publikationen/Generative-KI-im-Unternehmen (accessed 20.07.2026).
Bitkom Research (2025): Künstliche Intelligenz in Deutschland – Studie 2025. URL: https://www.bitkom.org/sites/main/files/2026-02/bitkom-studienbericht-ki.pdf (accessed 20.07.2026).
McKinsey & Company (2025): The State of AI: Global Survey 2025. URL: https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai (accessed 20.07.2026).
Mittelstand-Digital Zentrum Berlin (2026): KI-Richtlinie für Unternehmen in 7 Schritten: Mit kostenfreien Vorlagen und Praxistipps. URL: https://digitalzentrum-berlin.de/ki-richtlinie-fuer-unternehmen-in-7-schritten-mit-kostenfreien-vorlagen-und-praxistipps (accessed 20.07.2026).
Bitkom e.V. (2024): Umsetzungsleitfaden zur KI-Verordnung. URL: https://www.bitkom.org/sites/main/files/2024-10/241028-bitkom-umsetzungsleitfaden-ki.pdf (accessed 20.07.2026).
Bitkom e.V. (2025): Künstliche Intelligenz und Datenschutz – Leitfaden, Auflage 2. URL: https://www.bitkom.org/sites/main/files/2025-08/bitkom-leitfaden-kuenstliche-intelligenz-und-datenschutz-auflage-2.pdf (accessed 20.07.2026).
Europäische Kommission (2024): KI-Gesetz – Gestaltung der digitalen Zukunft Europas. URL: https://digital-strategy.ec.europa.eu/de/policies/regulatory-framework-ai (accessed 20.07.2026).
PwC (2025): 2026 AI Business Predictions. URL: https://www.pwc.com/us/en/tech-effect/ai-analytics/ai-predictions.html (accessed 20.07.2026).
Gerrit Grunert
Gerrit Grunert is the founder and CEO of Crispy Content®. In 2019, he published his book "Methodical Content Marketing" published by Springer Gabler, as well as the series of online courses "Making Content." In his free time, Gerrit is a passionate guitar collector, likes reading books by Stefan Zweig, and listening to music from the day before yesterday.