An AI policy is the set of internal rules that determines how, why and under what conditions your organisation may use artificial intelligence. Under the قانون الاتحاد الأوروبي للذكاء الاصطناعي (Regulation (EU) 2024/1689) it is the most practical way to show a supervisory authority that you know which AI systems you run, how they are classified and who is accountable for them. It is not a legally prescribed document, but without one you cannot evidence compliance with the AI Act, the GDPR or Dutch employment law.
Artificial intelligence has moved from the IT department into ordinary business processes. Generative tools draft correspondence, recruitment software ranks candidates, service platforms answer customers and finance systems flag transactions. Much of this happens through features quietly added to software the organisation already licenses, and through public tools that employees start using on their own initiative. This article sets out what a workable AI policy contains, which obligations already apply and which have been postponed, and how to build the policy without turning it into a document nobody reads.
What an AI policy is and why it is necessary
An AI policy translates external legal duties into instructions an employee can follow on a Tuesday morning. It states which systems fall within its scope, what may be entered into them, who decides that a new tool may be bought, when a human must review the outcome, and what happens when something goes wrong. Management uses the same document to keep oversight as the technology changes faster than the procurement cycle.
The risk of leaving this unregulated is concrete rather than theoretical. Employees paste client data or draft contracts into consumer chatbots. A selection tool systematically filters out a group of applicants. A generated text is published as fact and turns out to be wrong. Each of these is a legal problem before it is a technical one, and in each case the organisation that deployed the system carries the responsibility, not the supplier that built it.
The legal framework: EU AI Act, GDPR and Dutch employment law
Three bodies of rules apply at the same time, and an AI policy that addresses only one of them is incomplete. The AI Act regulates the system: how it is built, documented, monitored and explained. The General Data Protection Regulation regulates the data that goes through it. Dutch employment law regulates what you may do to your own staff with it.
The AI Act follows a risk-based approach. A small number of practices are prohibited outright, including social scoring and certain manipulative or exploitative techniques; you can read more in our article on ممارسات الذكاء الاصطناعي المحظورة. A defined group of uses counts as الذكاء الاصطناعي عالي المخاطر, notably recruitment and selection, decisions on promotion and termination, creditworthiness assessment, and access to essential public and private services. For those systems the Act requires a risk management system, data governance, technical documentation, logging, transparency towards the deployer, human oversight and a level of accuracy and robustness appropriate to the purpose. Everything else is subject mainly to transparency duties or to no specific AI Act obligation at all.
The GDPR applies in full wherever personal data is processed. The principles that bite hardest in AI projects are purpose limitation and data minimisation, the requirement of a lawful basis for training as well as for use, and Article 22, which restricts decisions based solely on automated processing that produce legal effects or similarly significantly affect a person. Where a system is likely to result in a high risk to individuals, Article 35 requires a data protection impact assessment before deployment. Our article on using AI in your Dutch business works through those obligations in more detail.
The Dutch layer is the one most often overlooked. Under Article 27 of the Wet op de ondernemingsraden (Works Councils Act) the works council has a right of consent for any arrangement concerning the processing and protection of employees personal data, and for any arrangement on facilities intended or suitable for observing or monitoring the presence, behaviour or performance of staff. An AI policy that governs monitoring, productivity analytics or automated assessment of employees will regularly fall within that provision. A decision taken without the required consent can be invalidated by the works council, which makes the consultation a sequencing question rather than a formality.
Which AI Act deadlines apply now, and which have moved
The AI Act entered into force on 1 August 2024 and applies in stages. The prohibitions on unacceptable-risk practices and the AI literacy duty have applied since 2 February 2025. The obligations for providers of general-purpose AI models, together with the governance and penalty provisions, have applied since 2 August 2025. The general date of application was 2 August 2026, and from that date the transparency duties of Article 50 apply: people must be told when they are interacting with an AI system, and AI-generated or manipulated content must be marked as such.
One block of obligations has been postponed. Regulation (EU) 2026/1744, the AI part of the European Commission digital omnibus, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It moves the application of the high-risk regime for the stand-alone systems listed in Annex III, which include employment, education, credit and essential services, to 2 December 2027. For AI that functions as a safety component in products already regulated under Union harmonisation law, listed in Annex I, the date becomes 2 August 2028. The same regulation softens the AI literacy duty, which now requires providers and deployers to take measures to support a sufficient level of AI literacy rather than to guarantee it.
The practical reading is straightforward: the prohibitions, the general-purpose AI rules and the transparency duties are enforceable today, and the heavy compliance apparatus for high-risk systems arrives at the end of 2027. That is a preparation window, not a reprieve. Organisations that select a recruitment or credit-scoring system now will still be running it in December 2027, and the supplier contract signed today determines whether the documentation, logging and human-oversight features exist by then.
Scope and content: what the policy must cover
Define the scope before writing a single rule, because an AI policy that nobody can apply to their own situation is worse than none. The policy should name the departments it binds, typically HR, marketing, customer service, finance, operations, legal and research and development, and it should name the categories of system: purchased AI software, AI features embedded in existing platforms, models built in house, generative assistants, chatbots, scoring and ranking tools, and recommendation engines.
Two boundary questions deserve an explicit answer. The first is whether employees may use public AI tools on their own account for work, and on what conditions. The second is what happens to AI functionality that appears in software the organisation already uses, without a purchase decision and often without a notification. Both are the routes by which AI enters an organisation unnoticed, and both are governed by the policy or by nothing at all.
Start with definitions that match the broad concept of an AI system in the AI Act but are written in language an employee recognises, supported by examples from their own department. Someone in HR should be able to tell, without asking legal, whether the tool in front of them falls within the policy.
Then divide use into three categories. Prohibited use covers the practices banned by the AI Act and any application the organisation has decided against for its own reasons. Conditional use covers everything permitted subject to safeguards: a documented risk classification, a data protection impact assessment where the GDPR requires one, approval by a named role, and agreed technical and organisational measures. Permitted use covers low-risk applications that need no more than the general rules on confidentiality and verification. The categories only work if the policy also says who moves an application from one category to another, and on what evidence.
Governance is the part that determines whether the rest is real. Allocate final accountability for AI compliance, usually at board level, and name the roles that may select and approve new applications, that maintain the inventory, and that handle incidents. Supplier management belongs here too. Where a system may become high-risk, the contract should oblige the provider to supply technical documentation, instructions for use, logging capability and the information the deployer needs for its own assessment, and should allocate responsibility for changes that alter the intended purpose of the system.
البيانات، والخصوصية، والأمن، والشفافية
Because an AI system is only as lawful as the data it runs on, the policy should state what may and may not be entered into which system. Confidential business information, client files, special categories of personal data and anything covered by professional secrecy generally do not belong in a public tool. Set out where anonymisation or pseudonymisation is required, how long inputs and outputs are retained, and how training data is kept separate from production data. Where personal data is involved, the assessment under the GDPR and the classification under the AI Act are best carried out in a single exercise; they ask different questions about the same system.
Security follows the ordinary rules. Access rights are granted by role, use is logged, and AI incidents are routed into the existing incident and data breach procedure rather than into a separate track that nobody remembers. A personal data breach must be reported to the Autoriteit Persoonsgegevens (Dutch Data Protection Authority) without undue delay and, where feasible, within 72 hours of becoming aware of it.
Transparency is now an operational duty rather than a good intention. Since 2 August 2026, Article 50 of the AI Act requires that individuals are informed when they interact with an AI system unless that is obvious from the circumstances, and that synthetic audio, image, video and text content is marked in a machine-readable way. Emotion recognition and biometric categorisation systems trigger their own notification duty. Translate this into concrete instructions: what the chatbot says in its opening message, how AI-assisted content is labelled, and what candidates are told about the role of AI in a selection procedure.
Human oversight, bias and AI literacy
For any system that affects a person, the policy must say when a human decides and what that person is actually able to do. Meaningful oversight means the reviewer understands the limitations of the system, can interpret its output, and has the authority and the time to disregard it. A sign-off box in a workflow is not oversight. Under Article 22 GDPR, a decision that produces legal effects or similarly significantly affects someone may not be based solely on automated processing except in defined situations, and even then the person retains the right to obtain human intervention, to express their point of view and to contest the decision.
Bias testing belongs in the policy as a recurring obligation with a named owner. Systems used in recruitment, performance assessment, onboarding and credit decisions should be tested periodically for disparate outcomes and error rates across groups, and the results should be recorded. That record matters twice over: it supports the AI Act documentation, and it is the evidence an employer needs if a rejected candidate alleges discrimination under the Algemene wet gelijke behandeling (Equal Treatment Act), where an unexplained disparity can shift the burden of proof to the employer.
The AI Act obliges providers and deployers to take measures to support a sufficient level of AI literacy among the staff who work with these systems, taking account of their technical knowledge, experience and the context of use. The standard is understanding, not expertise. Staff should be able to recognise an AI system, know what it is reliable for, know what it is not reliable for, and know when to escalate.
In practice this means a baseline module for everyone and deeper training for the roles that carry the risk: HR, IT and data teams, procurement, compliance and management. Record who was trained and when. Repeat it when a significant new system is introduced or the legal framework shifts, which in this field is not a rare event.
Who supervises the AI Act in the Netherlands
Supervision is being organised through existing regulators rather than a single new agency. The government published the draft Uitvoeringswet AI-verordening (AI Regulation Implementation Act) for public consultation on 20 April 2026, with the consultation running until 1 June 2026. Under the draft, the Rijksinspectie Digitale Infrastructuur (Netherlands Authority for Digital Infrastructure) takes a coordinating role, the Autoriteit Persoonsgegevens acts as supervisor where no sector regulator is designated, and existing sector supervisors keep their own domains. The bill has not yet been adopted, and its entry into force will be determined by royal decree; until then the allocation of national enforcement powers is not final. The penalty ceilings, however, come from the AI Act itself, with the highest tier of up to seven per cent of total worldwide annual turnover reserved for the prohibited practices.
From first inventory to a working AI policy
A policy that arrives before the inventory tends to prohibit things nobody does and permit things nobody checked. Begin by finding out what is actually in use, including AI features inside existing software and the tools employees adopted themselves. A short, confidential survey usually produces more than a formal request to department heads.
Classify each application next: prohibited, high-risk under Annex III, subject to transparency duties, or low-risk. Then assess the legal and organisational risk of the applications that matter, combining the AI Act classification with the GDPR analysis and, where staff are affected, the employment law and works council questions. Only then draft the policy, and align it with the privacy, information security, procurement and HR frameworks that already exist rather than writing a parallel set of rules.
Implementation is where most policies fail. The rules have to reach the places where decisions are made: procurement templates and supplier contracts, the intake process for new software, the recruitment procedure, the incident procedure and the training calendar. Finally, set a review cycle. Review at least annually, and always when a significant new system is introduced, when the legal framework changes, or after an incident.
Three things are worth doing before the end of this quarter. Check that no application in use falls within the prohibited practices, because those rules have been enforceable since February 2025. Check that your customer-facing and content-producing systems meet the Article 50 transparency duties that took effect on 2 August 2026. And check that any system heading for the Annex III high-risk category is contractually capable of meeting the December 2027 requirements, because renegotiating that in 2027 will be considerably more expensive than agreeing it now.
Law & More advises organisations on the classification of AI systems, on drafting and implementing AI policies, on supplier and licence agreements for AI applications, and on the privacy and employment law questions that come with them. Our محامو تكنولوجيا المعلومات are happy to review your current position and tell you where the gaps are. Please contact us to discuss your situation.
الأسئلة الشائعة
هل تُعدّ سياسة الذكاء الاصطناعي إلزامية بموجب قانون الذكاء الاصطناعي للاتحاد الأوروبي؟
لا يشترط قانون الذكاء الاصطناعي للاتحاد الأوروبي صراحةً على المؤسسات امتلاك وثيقة بعنوان "سياسة الذكاء الاصطناعي". إلا أنه عملياً، تُعدّ سياسة الذكاء الاصطناعي ضرورية لإثبات الامتثال للالتزامات التي يفرضها قانون الذكاء الاصطناعي واللائحة العامة لحماية البيانات، مثل إدارة المخاطر، والإشراف البشري، والشفافية، والتوعية بالذكاء الاصطناعي.
ما هي المنظمات الخاضعة لقانون الذكاء الاصطناعي للاتحاد الأوروبي؟
ينطبق قانون الاتحاد الأوروبي بشأن الذكاء الاصطناعي على جميع المؤسسات تقريبًا التي تُطوّر أو تطرح أو تستخدم أنظمة الذكاء الاصطناعي داخل الاتحاد الأوروبي. ولا يقتصر ذلك على شركات التكنولوجيا فحسب، بل يشمل أيضًا أصحاب العمل ومقدمي الخدمات والمؤسسات التي تستخدم الذكاء الاصطناعي في الموارد البشرية والتسويق والتفاعل مع العملاء والتمويل وعمليات صنع القرار.
هل ينطبق قانون الذكاء الاصطناعي للاتحاد الأوروبي إذا استخدمنا فقط برامج قياسية جاهزة للاستخدام؟
نعم. حتى في حال دمج وظائف الذكاء الاصطناعي في برامج خارجية، تظل المؤسسة المستخدمة للنظام مسؤولة عن استخدامه. ولا يُعفي الاعتماد على مزود الخدمة المستخدم من التزاماته بموجب قانون الاتحاد الأوروبي للذكاء الاصطناعي واللائحة العامة لحماية البيانات.
ما الفرق بين أنظمة الذكاء الاصطناعي منخفضة المخاطر، ومحدودة المخاطر، وعالية المخاطر؟
يصنف قانون الاتحاد الأوروبي بشأن الذكاء الاصطناعي أنظمة الذكاء الاصطناعي بناءً على مستوى المخاطر التي تشكلها على الحقوق والمصالح الأساسية للأفراد. وتشمل أنظمة الذكاء الاصطناعي عالية المخاطر الأنظمة المستخدمة في التوظيف والاختيار، وتقييم الموظفين، وتقييم الجدارة الائتمانية، أو الوصول إلى الخدمات الأساسية. وتخضع هذه الأنظمة لمتطلبات أكثر صرامة.
هل يجب تقييم جميع تطبيقات الذكاء الاصطناعي مسبقاً؟
عملياً، نعم. ينبغي على المؤسسات حصر تطبيقات الذكاء الاصطناعي وتقييمها قبل نشرها وتصنيفها وفقاً لمستوى المخاطر. بالنسبة لتطبيقات الذكاء الاصطناعي عالية المخاطر، يلزم إجراء تقييم شامل، غالباً ما يُدمج مع تقييم أثر حماية البيانات بموجب اللائحة العامة لحماية البيانات (GDPR).
كيف ترتبط سياسة الذكاء الاصطناعي باللائحة العامة لحماية البيانات (GDPR)؟
يكمل قانون الذكاء الاصطناعي للاتحاد الأوروبي واللائحة العامة لحماية البيانات (GDPR) بعضهما بعضًا. فبينما يركز قانون الذكاء الاصطناعي على الحوكمة وإدارة المخاطر وتشغيل أنظمة الذكاء الاصطناعي، تنظم اللائحة العامة لحماية البيانات معالجة البيانات الشخصية. وتضمن سياسة الذكاء الاصطناعي الفعالة دمج كلا الإطارين والامتثال المتسق لهما.
Is a data Protection impact assessment always required when using AI?
ليس دائمًا، ولكن في كثير من الأحيان. إذا كان نظام الذكاء الاصطناعي يعالج بيانات شخصية ومن المحتمل أن يُعرّض الأفراد لمخاطر عالية، فإن إجراء تقييم أثر حماية البيانات (DPIA) إلزامي بموجب اللائحة العامة لحماية البيانات (GDPR). وفي حالة أنظمة الذكاء الاصطناعي عالية المخاطر بموجب قانون الذكاء الاصطناعي للاتحاد الأوروبي، غالبًا ما يكون إجراء تقييم أثر حماية البيانات أمرًا لا مفر منه عمليًا.
هل يمكن لأنظمة الذكاء الاصطناعي اتخاذ قرارات مستقلة بشأن الموظفين أو العملاء؟
يخضع ذلك لشروط صارمة فقط. يقيد النظام الأوروبي العام لحماية البيانات (GDPR) اتخاذ القرارات الآلية بالكامل، ويشترط قانون الذكاء الاصطناعي للاتحاد الأوروبي إشرافًا بشريًا فعالًا على أنظمة الذكاء الاصطناعي عالية المخاطر. في كثير من الحالات، يجب أن يكون بإمكان الإنسان التدخل أو مراجعة أو إلغاء القرارات التي يقودها الذكاء الاصطناعي.
هل يمكن لسياسة الذكاء الاصطناعي أن تقيد استخدام الموظفين لأدوات الذكاء الاصطناعي العامة؟
نعم. من أهم أهداف سياسة الذكاء الاصطناعي تحديد ما إذا كان يُسمح للموظفين باستخدام أدوات الذكاء الاصطناعي العامة، وتحت أي شروط. ويشمل ذلك عادةً قواعد إدخال المعلومات السرية، والبيانات الشخصية، أو معلومات العمل الحساسة.
من المسؤول عن الامتثال لسياسة الذكاء الاصطناعي؟
ينبغي أن تحدد سياسة الذكاء الاصطناعي بوضوح مسؤولية الامتثال لمعاييره. تقع المسؤولية النهائية عادةً على عاتق الإدارة العليا أو مجلس الإدارة، مع أدوار مهمة للشؤون القانونية، والامتثال، وتقنية المعلومات، والموارد البشرية. وبدون حوكمة واضحة، يصبح الإشراف الفعال أمراً غير مرجح.
ما هي المخاطر التي قد تنجم عن عدم وجود سياسة خاصة بالذكاء الاصطناعي في أي مؤسسة؟
يؤدي غياب سياسة للذكاء الاصطناعي إلى زيادة مخاطر عدم الامتثال لقانون الاتحاد الأوروبي بشأن الذكاء الاصطناعي ولائحة حماية البيانات العامة (GDPR). وقد ينتج عن ذلك غرامات باهظة، وإجراءات إنفاذ، وتشويه للسمعة، ومسؤولية مدنية محتملة. كما أنه يزيد من صعوبة إثبات حوكمة مسؤولة للذكاء الاصطناعي أمام الجهات التنظيمية.
كم مرة ينبغي مراجعة سياسة الذكاء الاصطناعي؟
لا ينبغي التعامل مع سياسة الذكاء الاصطناعي كوثيقة ثابتة. فالمراجعات الدورية ضرورية، لا سيما عند إدخال أنظمة ذكاء اصطناعي جديدة، أو تغيير التشريعات أو التوجيهات التنظيمية، أو وقوع حوادث. وغالبًا ما تُعتبر المراجعة السنوية الحد الأدنى.
هل يُشترط إلمام جميع الموظفين بالذكاء الاصطناعي؟
ينص قانون الذكاء الاصطناعي للاتحاد الأوروبي على إلزام المؤسسات باتخاذ تدابير لتعزيز الوعي بالذكاء الاصطناعي. لا يعني هذا أن يصبح كل موظف خبيرًا تقنيًا، ولكن ينبغي أن يفهم ماهية الذكاء الاصطناعي، وكيفية استخدامه داخل المؤسسة، والمخاطر التي ينطوي عليها.
متى يُنصح بطلب المشورة القانونية؟
يُنصح بشدة باستشارة محامٍ عند استخدام أنظمة الذكاء الاصطناعي عالية المخاطر، أو عند وجود شكوك حول مشروعية تطبيقات معينة، أو عند ظهور تساؤلات تتعلق بالإنفاذ أو التدقيق أو المسؤولية. فالمراجعة القانونية المبكرة تُجنّب اتخاذ إجراءات تصحيحية مكلفة لاحقاً.


