Governance · 7 min read

Writing an AI usage policy for an Irish SME: what to include

Published 9 June 2026 · last updated 12 June 2026

A workable AI usage policy for an Irish SME covers four things: which tools staff may use, the rules for using them, who is responsible for what, and how the policy is reviewed. It should fit in three or four pages, plug directly into your EU AI Act obligations — especially the Article 4 literacy duty in force since February 2025 — and be written so a new hire can follow it on day one.

Why a policy, and why now

Staff are already using AI, with or without permission, and an SME without a policy has shadow AI by default: unknown tools, unknown data flows, no training and nothing to show a customer or regulator who asks. A policy is also the natural place to discharge duties the EU AI Act already imposes — the Article 4 literacy duty in force since 2 February 2025, and the housekeeping for the Article 50 disclosure deadlines arriving in 2026.

Section 1: scope and approved tools

Open with what counts as AI for the policy’s purposes — including AI features inside ordinary software, not just chatbots — and keep an approved-tools list: the systems staff may use, for what, with what accounts. The list should mirror your AI register — same systems, same owners — and include a simple request route for new tools. A request route is what keeps shadow AI out: if asking is easy, staff ask.

Section 2: rules of use

  • Data rules: no personal data, customer-confidential or commercially sensitive material in tools not approved for it — the GDPR overlap in plain words.
  • Human review: AI output is a draft; a named person checks anything going to a customer, a candidate or the public.
  • High-stakes uses need approval: anything touching recruitment, worker management, credit or other decisions about people goes through the owner first — that is the high-risk territory of the Act.
  • Disclosure: customer-facing AI is disclosed, and AI-generated content for the public is labelled — aligned to the Article 50 dates of 2 August and 2 December 2026.

Section 3: roles and responsibilities

Name a policy owner with authority to approve tools and handle escalations; a system owner for each entry on the approved list; and the training expectation for staff — what each role completes and how it is recorded, which is your Article 4 evidence. New AI tools should also trigger vendor due diligence before approval, and the policy should say so.

Section 4: incidents and review

Tell staff what to do when something goes wrong — wrong data pasted into a tool, a harmful or badly biased output, a complaint about an AI interaction: report to the policy owner, no blame for honest reports. Then commit to a review cycle: annually at minimum, and on trigger events such as a new high-stakes tool or a change in the law — the Annex III date moving to 2 December 2027 under the Omnibus agreement, subject to formal adoption, being the current case in point.

Common drafting mistakes

  1. Banning everything — staff route around it and you lose visibility.
  2. Writing ten pages of borrowed enterprise language nobody reads; three clear pages outperform it.
  3. No named owner, so the policy has no one to enforce or update it.
  4. No link to the register, leaving the approved list and the inventory to drift apart.
  5. Publishing once and never reviewing.

The policy and the register, together

A policy says what should happen; the register proves what does. AI Register Ireland keeps the approved tools, owners, classifications and training evidence in one place, so the policy has something real behind it. See how it works.

Put your AI register in place

Inventory, classification, obligations and an evidence trail. Join the waitlist for early access.

Join the waitlist