Why you should write an AI usage policy in your EU trade association and how you start today
Article 50 applies from 2 August 2026, 99% of the Brussels professionals we surveyed already use AI, and only a minority work somewhere with written rules. Here is how to close that gap in about an hour.
Sebastián Rodríguez Pérez is a European campaign strategist with direct experience running and advising campaigns for some of Europe's largest pro-European organisations. He founded the European Campaign Playbook to codify practitioner knowledge across the EU's 27 political environments and make it accessible to campaign professionals, advocacy teams, and civic organisations working at the European level. His work spans electoral strategy, EU public affairs, digital campaigning, and the integration of AI tools into political communication workflows.
Disclosure
Sebastián Rodríguez Pérez is the founder of the European Campaign Playbook and Campaign Intelligence Library. He has worked with pro-European organisations across multiple EU member states. He maintains editorial non-partisanship in all published content; where articles relate to campaigns or organisations he has directly worked with, this is disclosed within the article. He holds no current positions in active electoral campaigns.
What it covers
Why an internal AI usage policy is now a compliance and credibility necessity for EU trade associations and NGOs, and a step by step method to draft the first version with your own team.
Who it is for
Secretaries general, policy directors, communications leads and operations managers in trade associations, NGOs, consultancies and political parties in the EU affairs space, whose staff already use AI without written guidance.
When to use it
When your team already uses AI tools and nothing is written down, before an incident forces the conversation, or when a member, board or auditor asks what your AI rules are.
Key takeaway
Governance starts with principles. Staff guidance starts with decisions. Give people five rules they can remember, classify your information before your tools, and treat AI as something that finds claims rather than something that proves them.
In brief
- Article 50 transparency obligations apply from 2 August 2026, with Annex III high-risk rules from 2 December 2027 and Annex I from 2 August 2028.
- The obligations split by role: providers handle machine-readable marking, deployers handle disclosure of deepfakes and certain public-interest text.
- 99% of the Brussels professionals we surveyed already use AI tools. Only a minority work somewhere with a written AI policy.
- Classify information as Public, Internal, Confidential or Restricted, then tag personal data separately. Treating personal data as a class is what makes most first drafts contradict themselves.
- Public affairs needs two rules a general policy misses: stakeholder intelligence, and what an AI agent may do out in the world on its own.
- You can draft the foundations in 45 to 60 minutes with the people who actually do the work.
Everyone is using it. Almost nobody has written the rules.
At european campaign playbook we run hands on workshops that turn practitioners into the AI lead inside their own organisation. Level 1 covers the fundamentals and your first AI agents, level 2 goes deep into agents and automation, and level 3 is a working session on the policy this article describes. Dates are on our workshops page.
The obligations are already live
Article 50 transparency obligations apply from 2 August 2026. Providers of generative AI systems have obligations concerning machine-readable marking of AI-generated or manipulated outputs. Organisations deploying AI systems have separate obligations, including disclosure of deepfakes and certain AI-generated or manipulated text published to inform the public on matters of public interest. The precise obligation depends on the organisation’s role and the use case. The Commission has set this out in its guidelines on transparency obligations.
Read that twice, because the distinction does real work. If your association uses somebody else’s model, you are a deployer. The marking obligation sits with your vendor. The disclosure obligation sits with you, in the specific situations the Act names.
Everyone uses it. Almost nobody has written the rules.
In our own surveys of communications, policy and public affairs professionals in Brussels, 99% already use AI tools. Chatbots are simply part of the working day now. Only a small minority of those people work somewhere with a written AI policy. That gap, between universal use and near absent rules, is where the trouble sits.
And it smells like trouble because it is. Here is an ordinary Tuesday in an association with nothing written down:
- Someone pastes a member position paper, still under embargo, into a free consumer chatbot to get a summary before a meeting.
- A policy briefing goes out with three invented citations, because nobody checked what the model produced.
- A CV shortlist gets ranked by a chatbot, which is an AI decision about individuals, with legal exposure attached.
- A staff member uploads a spreadsheet of member contacts to a tool that trains on user input, and your members’ personal data leaves your control permanently.
- A photoreal image of a named commissioner at an event that never happened goes out unlabelled, which is squarely the deepfake case the Act has in mind.
- A translated press release goes out in a language nobody on the team reads, with an error that changes the political meaning.
None of these need bad intent. They need a helpful person, a deadline, and no written rule telling them where the line sits. A policy moves that decision from the individual under pressure to the organisation in advance.
What the law actually asks of you
You do not need to become an AI lawyer. You do need to know which duties already bite, and which ones are aimed at somebody else.
The AI Act, and who it is talking to
Article 50 splits its obligations by role. Providers of generative systems handle machine-readable marking of outputs. Deployers handle disclosure, and only in the situations the Act names: deepfakes, and certain AI-generated or manipulated text published to inform the public on matters of public interest.
One clarification saves a lot of pointless argument internally. Every AI-generated image is not a deepfake. The Commission frames that category around content resembling existing people, objects, places, entities or events that falsely appears authentic. An abstract illustration heading a blog post sits a long way outside it. A photoreal image of a named official at a meeting that never happened sits right inside it.
Three dates worth writing on the wall
- 2 August 2026: general application, including the Article 50 transparency obligations.
- 2 December 2027: the Annex III high-risk rules for standalone systems, which is where recruitment tools live.
- 2 August 2028: the Annex I rules for high-risk AI embedded in regulated products.
The Digital Omnibus moved several of these, so anything written before mid-2026 is likely to quote the old dates. The Commission maintains the current implementation timeline.
The GDPR did not go anywhere
Nothing about AI suspends data protection law. It also does not say that AI plus personal data equals prohibited. The processing needs its own lawful basis, necessity, safeguards and a governance assessment, which is the ground the EDPB covers in Opinion 28/2024 on AI models and personal data. Consumer tier chatbots rarely give you any of that, which is a procurement problem rather than a legal impossibility.
AI literacy is already an obligation
Article 4 requires providers and deployers to take measures supporting AI literacy among the staff operating AI systems on their behalf. There is no mandated individual proficiency level, and internal records of training or guidance can be sufficient evidence of the measures you took. So write the sentence into your policy and then actually keep the record:
Staff authorised to use AI for organisational work receive role-appropriate guidance covering permitted tools, data rules, verification, transparency and escalation. The organisation maintains a record of these measures.
Your own credibility
The rules that hurt you first are the ones with no fine attached. An invented statistic in a position paper damages the thing an association actually sells, which is being a trustworthy source. That bill arrives long before a regulator does.
Governance starts with principles. Staff guidance starts with decisions.
Principles are for the board. Decisions are for the person with a deadline at six o’clock who is looking at a chatbot and wondering whether to paste the document in.
Both matter, and they are different documents doing different jobs. Nobody has ever recalled eight principles under time pressure. Give staff five rules instead, short enough to hold in your head while the kettle boils.
- AI is not a source. Material claims get verified against the actual source before use.
- A named human reviews and owns anything that leaves the building.
- What you put in is decided by the information class, before you think about the tool.
- Only approved tools, and only up to the class each tool is approved for.
- Disclose when the law, a contract, or your own policy says to.
Everything below is detail hanging off those five. If your staff remember nothing else, the policy is still doing most of its work.
The eight principles underneath
The principles are the governance layer. They are what you point at when a new tool appears and somebody asks whether it fits. Agree them once and most novel questions answer themselves.
| Category | Principle | What it means in practice |
|---|---|---|
| Accountability | Human primacy | AI assists human judgement, it does not replace it. Every output used in our work must be owned by a named person who is accountable for its accuracy, tone and appropriateness. |
| Values | Mission alignment | AI use must be consistent with the organisation’s values on transparency and accountability. Tools, providers or practices that contradict these values should not be adopted. |
| Quality | Accuracy and integrity | AI-generated content must be verified before use. Credibility rests on the rigour of the work. A policy that treats AI output as reliable by default is incompatible with that standard. |
| Privacy | Data minimisation and confidentiality | Only the minimum data necessary for any task should be used. Sensitive, personal and confidential information must never enter AI systems that do not meet data protection requirements. |
| Openness | Transparency | Be honest about how AI is used, with staff, with members and with the public. Where AI has contributed substantively to an output, this will be disclosed where appropriate and required by law. |
| Sustainability | Environmental responsibility | AI use should be proportionate to the task. The environmental cost of AI infrastructure is real and should be factored into decisions about which tools to adopt and how intensively to use them. |
| Justice | Equity and non-discrimination | AI tools must not be used in ways that reproduce or amplify bias, particularly in relation to the Global South, women and racialised minorities. Outputs must be critically reviewed for bias before use. |
| Adaptability | Continuous learning | The AI landscape is changing rapidly. The policy must be a living document, reviewed regularly, updated in response to new developments, and shaped by staff experience and feedback. |
AI assists human judgement, it does not replace it. Every output used in our work is owned by a named person who is accountable for its accuracy, tone and appropriateness.
If you adopt one line from the whole framework, adopt that one. Almost every incident in the list at the top of this article is a failure of named human ownership.
Classify the use: acceptable, restricted, prohibited
Staff should be able to look at a task and know within a couple of seconds which bucket it falls into. Where it is genuinely ambiguous, the more restrictive category applies and they ask first.
Acceptable uses
No special authorisation needed, provided the information class allows it and the output gets reviewed before use.
| Use | What it covers |
|---|---|
| Drafting and editing publicly available content | Reports, briefings, social media, website copy |
| Summarising public documents | Reports, policy texts, public briefings |
| Supporting research | Literature reviews, identifying sources, comparing arguments |
| Summarising publicly stated positions | What policymakers and stakeholders have actually said on the record |
| Translation assistance | Public or internal texts, with competent review before anything goes out |
| Meeting preparation | Questions, talking points, background briefings from public sources |
| Internal administrative tasks | Scheduling support, meeting summaries, document formatting |
| Illustrative and conceptual imagery | Non-deceptive artwork that does not depict real people, places or events |
| Learning and skill development | Exploring how tools work, testing prompts, building capacity |
Restricted uses
These need explicit approval, an appropriate enterprise environment, a confirmed data protection position, and enhanced human review.
| Use | What it covers |
|---|---|
| Processing documents containing personal data | Lawful basis, necessity and safeguards confirmed before you start |
| Drafting formal external policy positions | Anything presented externally as the organisation’s position |
| Recruitment, shortlisting or candidate assessment | Any AI involvement in hiring, with legal and ethical limits |
| Confidential material of any kind | Unpublished strategy, member positions, commercial intelligence |
| Internal financial, HR or funder-related documents | Including grant reports and funder communications |
| Stakeholder prioritisation, scoring or relationship mapping | Anything that ranks or predicts people rather than summarising what they said |
| Realistic synthetic imagery | Photoreal people, events or locations, even where no real individual is depicted |
| AI systems taking actions in live systems | Writing to a CRM, sending mail, publishing, anything beyond drafting |
Prohibited uses
Hard stops. Keep this list short enough that everyone remembers it.
| Use | Why it is prohibited |
|---|---|
| Restricted-class information in any AI tool | Credentials, special-category data, leaked, embargoed or privileged material |
| Personal data in consumer-tier tools | No lawful basis, no processing agreement, no control over retention or training |
| AI making or substantially determining decisions about individuals | Hiring, performance, access to resources: a human decides |
| Publishing AI-assisted content without substantive human review and sign-off | Unreviewed output may never appear externally under the organisation’s name |
| Deceptive synthetic representations of real people or events | Politicians, officials, stakeholders or real events, absent authorisation and disclosure |
| Deceptive personas used to engage policymakers | Straightforwardly incompatible with legitimate advocacy |
| Inferring political opinions or other sensitive characteristics | Special-category data under the GDPR, and usually simply invented |
| Unassessed tools above the Public class | Any tool not assessed against data protection requirements |
Classify the information, then tag personal data separately
The most common flaw in a first draft policy is a data rule that argues with itself. One paragraph permits personal data with approval and an enterprise tool. Two paragraphs later, personal data is banned outright. Staff notice, and then they stop trusting the document.
The fix is to stop treating personal data as a classification. Sensitivity is the classification. Personal data is a property that sits on top of it.
| Classification | Examples | Typical AI rule |
|---|---|---|
| Public | Published legislation, websites, public speeches | Approved AI permitted |
| Internal | Internal drafts, templates, routine working notes | Approved organisational AI |
| Confidential | Unpublished client strategy, member positions, commercial intelligence | Specifically approved enterprise environment |
| Restricted | Credentials, highly sensitive HR information, special-category data, leaked or privileged material | Normally prohibited, exceptional approval only |
Then tag two things separately on top of the class:
- Personal data: yes or no.
- Special-category or highly sensitive personal data: yes or no.
This matters because personal data covers an enormous range. A policymaker’s published name and job title is personal data. So is an inferred political opinion, a health detail, or a private mobile number. Treating those two as the same category gives you a rule that is simultaneously too strict to follow and too blunt to protect anybody.
Stakeholder intelligence, the blind spot in most policies
This is the section that turns a general association policy into a public affairs policy. Stakeholder work is where AI is most tempting and least well governed, because summarising a committee’s position and predicting how a named official will vote feel like the same activity when you are typing the prompt.
They are separated by a bright line. One describes what somebody said. The other invents a claim about a person.
| Activity | Treatment |
|---|---|
| Summarising publicly stated positions of policymakers | Acceptable |
| Identifying relevant committees, ministries, regulators or associations | Acceptable |
| Comparing stakeholders’ documented public positions | Acceptable |
| AI-generated stakeholder prioritisation | Restricted |
| Predicting someone’s likely policy position | Restricted |
| Scoring stakeholder receptiveness | Restricted |
| Relationship mapping | Restricted |
| Analysing large stakeholder databases | Restricted |
| Inferring political opinions or other sensitive characteristics that are not known | Prohibited, or specialist review |
| Political persuasion based on sensitive personal characteristics | Prohibited, or specialist review |
| Creating deceptive personas to engage policymakers | Prohibited |
Two legal anchors make this concrete. Political opinions are special-category personal data under the GDPR. And Regulation (EU) 2024/900 on political advertising imposes specific constraints on personal-data-based targeting and prohibits profiling using special-category personal data for that purpose. Your association may never buy a political ad in its life. The conceptual boundary is still the right one to borrow.
Synthetic media, without the blanket ban
Plenty of draft policies ban AI-generated images outright. For some organisations that is a perfectly legitimate values decision, and if your members would be uncomfortable, own it and write it down.
As a default framework it will not survive contact with the next two years. The blanket ban has to justify why Canva generative fill is prohibited while a stock photograph of models pretending to be farmers is fine. The honest answer is that the risk lives in whether the image deceives anyone, and that varies enormously.
| Imagery | Treatment |
|---|---|
| Illustration, conceptual imagery, non-deceptive campaign artwork | Permitted with review |
| Realistic synthetic people, events or locations | Restricted |
| Deceptive synthetic representations of politicians, officials, stakeholders or real events | Prohibited without appropriate authorisation and disclosure |
| Content meeting the statutory deepfake definition | Article 50 disclosure applies |
That scales. A ban does not.
When AI stops advising and starts acting
Most AI policies quietly assume one shape: input goes in, content comes out, a human reviews the content. That assumption is ageing fast.
Agents run a different shape. Input goes in, the system reasons, it reaches into your systems, and then it does something. Review after the fact is no longer a control, because the thing already happened.
| AI behaviour | Rule |
|---|---|
| Search or read internal information | Depends on data permissions |
| Draft correspondence | Usually permitted |
| Prepare CRM updates for approval | Usually permitted |
| Write directly to the CRM | Restricted |
| Send email externally | Restricted, human approval |
| Publish content | Restricted, human approval |
| Contact policymakers automatically | Normally prohibited |
| Commit expenditure | Prohibited without explicit delegated authority |
| Make decisions about individuals | Prohibited or restricted according to context |
The more authority an AI system has to take actions outside the AI environment, the greater the required approval and monitoring.
Human primacy already points this way. Agents make it worth saying out loud, in a table, before somebody connects a chatbot to the mailbox.
Human review, and the rule that AI is not a source
Review is the control, and editing is not
Picture an AI draft of a two-sentence summary that happens to be completely correct. A senior analyst checks every statement, verifies the primary source, weighs the political nuance, approves it, and changes not a single word.
Now picture someone making three cosmetic edits without checking anything. The first is far safer, and a policy written around editing rewards the second. The Commission’s own Article 50 guidance talks in terms of human review and editorial control, and expects deliberate examination of substance by someone with relevant knowledge and professional judgement. Superficial grammatical checking does not qualify.
Externally distributed AI-assisted content must undergo substantive human review or editorial control by a person with appropriate subject-matter competence. Review must address factual accuracy, sources, context, confidentiality and appropriateness.
AI is not a source
This one deserves to be a standalone operational rule rather than an implication buried in a principle about quality.
AI systems are not authoritative sources. Material factual claims, statistics, quotations, legal references, stakeholder positions and citations produced or identified by AI must be verified against the underlying source before use.
Three lines make it stick, and they fit on a sticky note:
- AI finds it.
- The primary source proves it.
- A human takes responsibility for it.
Language competence, not language
One thing to avoid while you are here. Treating everything that is not in English as restricted is an odd rule for a European organisation with French, Spanish and German native speakers on staff. The real risk is simpler: nobody competent in that language read it before it went out.
Externally published translated or multilingual content must be reviewed by a person with sufficient proficiency in the target language and, where political or technical nuance is material, appropriate subject-matter knowledge.
Three reasons to disclose, and they are worth separating
A single rule saying "disclose where AI contributed substantively" is a defensible ethical standard. It also quietly merges three different things, and staff end up unable to tell you which one they are complying with.
| Type | When it applies |
|---|---|
| Legal | Required under Article 50 or other applicable legislation |
| Contractual | Required by a client, grant agreement, procurement rule, partner or publication |
| Organisational transparency | You judge AI involvement material enough that saying so supports your credibility |
Separating them matters practically. Under Article 50, AI-generated public-interest text that has been through qualifying human review or editorial control, with editorial responsibility attached, does not require the Article 50 label on that basis. So "we disclose because our policy chooses to" and "EU law requires this disclosure" are genuinely different statements, and conflating them means you cannot explain either one to a member who asks.
Agree one reusable sentence for the voluntary case, and agree what needs no disclosure at all, typically internal drafting help and formatting. A disclosure rule that fires on everything becomes noise within a month.
Turn the tool list into a register
An approved tools list is good. A register is what stops someone reading a vendor privacy policy at ten at night and making a judgement call on your behalf.
| Field | Example |
|---|---|
| Tool | Microsoft Copilot |
| Status | Approved |
| Permitted uses | Drafting, summarisation |
| Maximum data class | Confidential |
| Personal data | Restricted |
| Input used for training | No, by contractual setting |
| Retention | X days |
| Connectors | SharePoint only |
| Owner | IT or AI lead |
| Security and DPO review | Date |
| Next review | Date |
Two columns do the heavy lifting: maximum data class, and whether input is used for training. Fill those in for every tool and most day to day questions stop reaching you at all.
Escalation, incidents and literacy
Give staff one unambiguous rule for the moment they are unsure. Ours is deliberately blunt:
If you are unsure whether AI can be used for a task, do not use it. Ask first.
Then name four people: who answers that question, who reviews high risk cases, who maintains the register, and who updates the policy. If those four names are missing, you have a document rather than a policy.
Add a route for mistakes, and make it obviously safe to use. Someone who pasted the wrong document into the wrong tool needs to tell you within the hour, and they will only do that if the policy reads like a process rather than a trap.
Then keep the training record. It is your evidence of the AI literacy measures the Act asks for, and it costs nothing if you write down what you already do.
Run the 60 minute drafting session
You do not need a consultant for the first draft. You need the people who actually do the work, for about an hour. What comes out is a structured draft rather than an approved policy, and that distinction is worth repeating out loud in the room.
Split by function
Break into groups along the lines of the work, because the risks differ sharply between them.
| Group | Focus area |
|---|---|
| Policy | Research, literature reviews, report analysis, policy briefings |
| Advocacy | Talking points, advocacy notes, meeting preparation, stakeholder work |
| Communications | Social media, website copy, campaign content, imagery, media monitoring |
| Operations | Administration, meeting summaries, internal knowledge management |
| Finance and projects | Funder reporting, project summaries, budgeting support |
| HR | Recruitment, staff guidance, internal policies |
Answer the questions for your own area
Short, practical answers beat elegant ones. Nobody is drafting legislation here.
- Purpose and scope: what could AI usefully support, what stays clearly human led, who does this apply to, which tools will realistically get used?
- Principles: pick your top five of the eight and say why they matter here.
- Acceptable uses: write three for your area.
- Restricted uses: write three, and name the safeguard each one needs.
- Prohibited uses: write three.
- Information classes: give examples of Public, Internal, Confidential and Restricted in your area, and note where personal data shows up.
- Human review: who reviews, what must be verified, which bias risks apply, when does senior or legal review kick in?
- Disclosure: what is legally required, what is contractually required, what you choose to disclose. Draft one sentence.
- Tool approval: choose the five criteria that matter most for your area.
- Actions and agents: what may an AI do on its own, what needs approval first, what is off limits entirely?
- Stakeholder intelligence: what is fine, what needs approval, what will you never do?
- Escalation and incidents: who do staff ask, who reviews, how does someone report a mistake?
- Member facing: what member information never goes into a tool, do you tell members how you use AI, do you publish a public statement?
Finish the sentence
Every group completes this line, and it becomes the accountability clause of your policy:
AI may assist with this work, but a named member of staff must remain responsible for...
Let AI draft it, then attack it
A chatbot is genuinely good at turning messy group answers into a structured draft. It has no view on your risk tolerance. Use it for structure, then go after the result with the critique prompt in the pack below.
The critique step is the one everyone skips, and it is the one that pays. Asking the model to find rules that are too strict, too vague, or open to misreading surfaces the problems that would otherwise arrive six months later as a staff complaint.
Label whatever comes out a discussion draft, and route it through the governance process your association actually uses: the management team, the board, or a policy forum with members.
The one page to put next to the monitor
The checklist at the end of this article helps you build a policy. This one is different: it is what staff need on a Tuesday, and it is the single highest-return page in the whole package.
| Step | Question |
|---|---|
| 1. Task | Is this use acceptable, restricted or prohibited? |
| 2. Tool | Is this tool approved for this use? |
| 3. Data | What information class am I putting into it? |
| 4. Source | Have material claims been verified against the actual source? |
| 5. Human | Who owns and approves this output? |
| 6. Disclose | Is disclosure legally, contractually or organisationally required? |
| 7. Action | Is the AI advising me, or is it taking an action out in the world? |
Three questions before you start, three about the output, one about what the machine is allowed to do on its own. Print it. Stick it up. It will prevent more incidents than the policy document ever will.
What only you can decide
A chatbot can suggest wording, organise your thinking and show you the gaps. It has nothing to say about your values, your risk tolerance, your legal responsibilities or who carries the can when something goes wrong. Those are governance choices and they belong to your leadership and your members.
Associations sit somewhere particular here, because you hold information that belongs to other organisations. Your members will reasonably want to know how their material is handled, and a short public statement on responsible AI use is usually the cheapest trust win available. For a lot of networks the policy itself becomes a resource members ask to reuse, which is a pleasant problem to have.
If you would rather not start from a blank page, that is exactly what our level 3 workshop is for: a working session where your team leaves with a first draft of its own. Dates are on the workshops page.
AI workflow suggestions
- 1.Collect your team’s answers to the thirteen policy questions before you open a chatbot.
- 2.Use the drafting prompt to turn those answers into a structured draft, with no invented rules.
- 3.Run the critique prompt and fix what it finds before anyone else reads the draft.
- 4.Label the result a discussion draft and route it through your normal governance process.
Prompt pack
1. Draft the policy foundations
You are helping a European trade association draft the foundations of an internal AI policy. Use only the answers below. Do not invent rules that are not supported by our answers. This is our focus area: [INSERT AREA] These are our answers: [PASTE GROUP ANSWERS] Please draft an AI Policy Starter Pack for this area with the following sections: 1. Purpose 2. Scope 3. Key principles 4. The five rules staff must remember 5. Acceptable uses 6. Restricted uses 7. Prohibited uses 8. Information classification (Public / Internal / Confidential / Restricted) and personal data tagging 9. Stakeholder intelligence rules 10. Synthetic media rules 11. Rules for AI systems taking actions in live systems 12. Human review and accountability 13. Disclosure (legal, contractual, organisational) 14. Approved AI register criteria 15. Escalation, incident reporting and AI literacy 16. Member-facing considerations 17. Open questions for us to decide Requirements: - Write in plain English - Use practical staff guidance, not legalistic language - Be cautious where risks are high - Do not treat "personal data" as an information class; treat it as a property tagged on top of the class - Clearly flag assumptions - Do not present this as an approved policy - Keep the draft under 1,200 words
2. Challenge the draft
Review your draft critically. Please identify: 1. Any rule that is too strict 2. Any rule that is too vague 3. Any rule that could be misunderstood by staff 4. Any two rules that contradict each other, especially on data 5. Any missing risk 6. Any area requiring legal, data protection or management input 7. Any point that should be discussed with our members 8. Any assumption you made that we would need to confirm
3. Revise it
Revise the draft based on your critique. Make it clearer, shorter and more practical. Keep the structure, but make the guidance easier for staff to follow. Label the document clearly as: Discussion draft, not approved policy.
4. The staff one-pager
From the revised draft, produce a single-page staff guide. It must fit on one side of A4 and be readable in under two minutes. Include: - The five rules staff must remember - The seven questions to ask before using AI and before using the output - The information classes with one example each - Who to ask when unsure, and how to report a mistake Use plain language and short lines. No legal citations.
Checklist
- Agree the principles at governance level, then write five rules staff can actually remember.
- Write three acceptable, three restricted and three prohibited uses for every team.
- Classify information as Public, Internal, Confidential or Restricted, and tag personal data separately.
- Check your data rules do not contradict each other before anyone else reads the draft.
- Write stakeholder intelligence rules, including what you will never infer about a person.
- Set rules for synthetic imagery by whether it deceives, and not by whether AI made it.
- Decide what an AI agent may do in live systems without a human approving first.
- Require substantive human review or editorial control, and say that AI is not a source.
- Separate legal, contractual and organisational disclosure, and agree one reusable sentence.
- Build the approved AI register, with maximum data class and training-on-input for every tool.
- Name who to ask, who reviews, who maintains the register, and who updates the policy.
- Keep a record of AI guidance and training as evidence of your Article 4 literacy measures.
- Label the first version a discussion draft and set a review date.
Sources
- 1.European Commission, Guidelines on transparency obligations for providers and deployers of certain AI systems
- 2.European Commission, AI Act implementation timeline (as amended by the Digital Omnibus, in force 27 July 2026)
- 3.EDPB, Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models
- 4.Regulation (EU) 2024/900 on the transparency and targeting of political advertising
- 5.european campaign playbook participant surveys, Brussels, 2026