Organisations adopting AI without a formal policy are taking on risk they have not measured. A written AI policy defines how AI systems are used and governed within your business - covering risk classification, accountability structures, acceptable use rules, and a review cadence. This guide is built around the two frameworks that every credible AI policy now references: the NIST AI Risk Management Framework (NIST AI RMF, 2023) and the EU AI Act (2024).
What does an organisational AI policy need to cover?
An AI policy must define how AI systems are adopted, used, and governed across your organisation. At minimum it covers risk classification, accountability structures, acceptable use boundaries, and a review cadence. The two anchoring frameworks are the NIST AI Risk Management Framework (2023) and the EU AI Act (2024).
The NIST AI RMF Govern function (2023) establishes the organisational policies and processes that underpin all AI risk management activity.
The EU AI Act (2024) classifies AI systems into four risk tiers - unacceptable, high, limited, and minimal - with conformity assessments required for high-risk applications by August 2026. Full text at artificialintelligenceact.eu.
The OECD AI Principles (2019, updated 2024) establish five due-diligence obligations - inclusive growth, human-centred values, transparency, robustness, and accountability - that complement legally binding frameworks.
ISO 42001 (2023), the first international AI management system standard, provides a certification pathway for organisations seeking to demonstrate governance maturity to customers and regulators.
Framework | Primary Risk Focus | Geographic Applicability | Key Organisational Obligation |
|---|---|---|---|
NIST AI RMF (2023) | Trustworthiness across the AI lifecycle | Global (voluntary) | Implement GOVERN, MAP, MEASURE, and MANAGE functions across AI deployments |
EU AI Act (2024) | Prohibited and high-risk AI applications | EU-wide; extraterritorial scope | Risk classification and conformity assessment for high-risk AI systems by August 2026 |
OECD AI Principles (2019, rev. 2024) | Human-centred values and due diligence | OECD member states (voluntary) | Due diligence on responsible AI business conduct across the full value chain |
ISO 42001 (2023) | AI management system certification | Global (voluntary) | Documented AI management system with independent certification pathway |
How do you categorise AI risk in your organisation?
Risk categorisation is the foundation of any AI policy. The EU AI Act (2024) provides the clearest legislative model: AI applications are classified into four tiers based on the severity of potential harm to health, safety, or fundamental rights – unacceptable risk (prohibited), high risk (requires conformity assessment), limited risk (transparency obligations only), and minimal risk (no regulatory requirement). Organisations should apply this tier structure to every AI system in their current and planned technology stack.
The NIST AI RMF MAP function complements this by providing a structured method for identifying, categorising, and contextualising risks that may not fall neatly into legislative classifications – including reputational, operational, and third-party supply chain risks that the EU AI Act does not address directly. Used together, the two frameworks give a complete picture: legislative exposure on one side, operational risk profile on the other.
In practice, risk categorisation requires:
An inventory of all AI tools in use across the organisation, including third-party and embedded AI in software-as-a-service platforms
A classification decision for each tool against the EU AI Act risk tiers and NIST AI RMF risk categories
Documentation of the rationale for each classification, reviewed and signed off by the designated AI risk owner
A process for reviewing classifications when a tool’s use case changes – for example, when a productivity tool is extended to automate a decision that affects individual employees
For most mid-market organisations, the majority of AI use – productivity tools, content generation, customer-facing chatbots – falls into the limited or minimal risk tiers. The high-risk tier under EU AI Act Annex III applies to AI used in hiring decisions (including CV screening and candidate ranking), credit scoring, biometric identification, or any decision that materially affects individuals’ access to services. If you operate in the EU or serve EU customers, knowing which tier each tool sits in is not optional – it determines your compliance obligations and timeline.
How does the NIST AI RMF Govern function apply to internal AI policy?
The NIST AI RMF Govern function establishes the organisational context in which all other AI risk management activity takes place. It defines the policies, processes, roles, and accountability structures that an organisation puts in place before deploying AI – not after an incident has occurred. For policy writers, the Govern function translates directly into the foundational section of any AI policy document: the organisation’s values and risk tolerances, who is accountable, and what decisions require oversight.
The NIST AI RMF (published January 2023) organises the Govern function around six subcategories: organisational policies, roles and responsibilities, risk tolerance, legal and regulatory alignment, workforce training, and third-party risk management. Each maps to a specific policy provision. An AI policy that addresses all six subcategories is, by definition, NIST AI RMF-aligned – which is increasingly specified as a requirement in public sector contracts and enterprise procurement processes.
Key policy provisions that the Govern function requires:
A formal statement of AI risk tolerance, approved at board or executive level and reviewed annually
Named roles: typically an AI Risk Owner with decision authority, an AI Ethics Lead, and Data Protection Officer involvement where personal data is processed
A vendor assessment process for third-party AI tools, covering data handling, model transparency, and incident disclosure obligations
Workforce awareness requirements specifying which roles need AI literacy training and at what level – from basic awareness for all staff to deeper governance knowledge for decision-makers
The NIST AI RMF is voluntary for most organisations, but its structure is the de facto reference model for AI governance. The NIST AI RMF core functions – GOVERN, MAP, MEASURE, MANAGE – provide a lifecycle model that works regardless of industry sector or organisation size, and they sit alongside the legislative obligations of the EU AI Act rather than replacing them.
What does EU AI Act compliance require from your organisation?
The EU AI Act, which entered into force in August 2024, applies to any organisation that places AI systems on the EU market or whose AI outputs affect EU residents – including UK-based businesses that trade with EU customers or process data relating to EU individuals. Compliance obligations are phased: prohibited practices were banned from February 2025; General Purpose AI (GPAI) model obligations applied from August 2025; and high-risk AI system requirements take full effect in August 2026. The full legislative text is at artificialintelligenceact.eu.
For most organisations, the immediate compliance question is classification: which of your AI systems are high-risk under Annex III of the Act? High-risk categories include AI used in employment decisions (recruitment, performance management, work allocation), access to essential services (credit scoring, insurance underwriting, education admissions), law enforcement, and biometric identification. If any AI system in your stack falls into these categories, you are required to conduct a conformity assessment, maintain technical documentation, implement human oversight measures, and register the system in the EU AI Act database before deployment.
Organisations outside high-risk categories still face transparency obligations. AI systems that interact with users – including customer service chatbots and AI-generated email responses – must disclose that the user is interacting with an AI. Content generated by AI must be machine-readable as AI-generated where it could plausibly be mistaken for human-created material.
The practical first step for any organisation is a gap analysis:
Map your current AI inventory against the Act’s risk classification categories
Identify which applications trigger conformity assessment requirements under Annex III
Document the gap between your current technical documentation standards and what the Act requires
Assign responsibility for closing each gap with a deadline that meets the August 2026 high-risk compliance date
How do you assign governance roles and accountability for AI?
Governance roles define who is responsible for AI risk decisions within the organisation. Without named accountability, AI policies remain aspirational documents rather than operational controls. The NIST AI RMF Govern function specifies that accountability must be assigned at three levels: strategic (board or executive sponsor), operational (an AI Risk Owner with decision authority over deployment and incident response), and functional (team leads or data stewards responsible for day-to-day policy compliance).
In practice, this typically translates to the following named roles:
AI Risk Owner: accountable for the AI risk register, classification decisions, and policy compliance – typically a Chief Risk Officer, General Counsel, or Head of Technology
AI Ethics Lead: responsible for reviewing use cases against acceptable use criteria and flagging potential harms before deployment – often a senior product, legal, or people leader
Data Protection Officer (DPO): where AI systems process personal data, the DPO must be involved in Data Protection Impact Assessments and any EU AI Act conformity assessment
Operational reviewers: team or department leads responsible for ensuring staff in their area understand and apply acceptable use rules in day-to-day work
The OECD Due Diligence Guidance for Responsible AI (2024) reinforces that accountability must extend to the full AI value chain, including third-party AI providers and API integrations. Governance roles must therefore be documented with sufficient clarity that accountability can be demonstrated to an external party – a regulator, a customer, or a court – not merely asserted internally. An AI policy that names roles without defining what those roles are accountable for does not meet this standard.
What should an AI acceptable use policy cover?
An acceptable use policy (AUP) for AI defines the boundaries of how staff may and may not use AI tools in their work. It is the operational layer of an AI governance framework – where the strategic risk tolerance set at board level translates into practical rules that any employee can apply without needing to understand the full regulatory landscape.
A complete acceptable use policy covers:
Permitted tools: the specific AI tools approved for use, and any approval process for using tools not on the approved list – including personal accounts on third-party platforms
Data classification rules: which categories of data may be inputted into AI tools. At minimum: no personal data, confidential commercial information, or client data in unapproved tools without a separate data processing agreement in place
Output review requirements: which AI outputs require human review before use, and at what standard – for example, factual claims in external-facing content must be independently verified
Prohibited uses: applications explicitly banned, such as using AI to generate content that could deceive customers, using AI to make or significantly influence hiring decisions without human oversight, or using AI to process special category data without a lawful basis
Disclosure requirements: when staff must disclose that AI was used in producing work product, both internally and externally
The EU AI Act’s transparency provisions (Article 52) set a baseline for customer-facing disclosure requirements. The NIST AI RMF MAP function recommends that organisations also document the specific contexts in which AI is and is not appropriate for a given task – which is a more operationally useful framing than a blanket list of prohibited tools, because it scales as new AI capabilities emerge.
How do you build an incident response process for AI?
An AI incident response process defines what happens when an AI system causes harm, produces an unacceptable output, or behaves in a way that was not anticipated at the point of deployment. It sits within the MANAGE function of the NIST AI RMF, which covers the ongoing monitoring, adjustment, and incident handling required to maintain acceptable AI performance throughout a system’s operational life.
A functional AI incident response plan includes:
A clear definition of what constitutes a reportable AI incident – covering harmful outputs, data leakage from AI tools, discriminatory or biased decisions, and regulatory non-compliance events
A named incident response lead and escalation path, with explicit triggers for when to involve the DPO, legal counsel, or regulators
Notification obligations: the EU AI Act requires providers of high-risk AI systems to notify relevant national supervisory authorities of serious incidents and malfunctions within 15 working days of becoming aware of them
A root-cause analysis process that documents the incident, the AI system involved, the output that caused harm, and the corrective action taken
A post-incident review mechanism that feeds back into the risk register and, where necessary, triggers a policy update
The OECD AI Principles (2024) specify that organisations must be able to explain the basis of AI-influenced decisions that affect individuals – which means incident documentation must be sufficient to support that explanation if challenged by a regulator or in litigation. An incident log that records only that an incident occurred, without the system context and decision audit trail, will not meet this standard.
How often should an AI policy be reviewed and updated?
An AI policy should be reviewed at minimum annually, but the review cadence must also be triggered by events rather than calendar dates alone. The NIST AI RMF MANAGE function specifies continuous monitoring as a requirement for high-risk AI deployments – meaning the policy framework that governs those deployments needs to be responsive to changes in the technology, the regulatory environment, and the organisation’s own risk profile.
Mandatory review triggers include:
Introduction of a new AI tool or AI-enabled feature in an existing system
A regulatory update – the EU AI Act’s phased implementation schedule creates specific review obligations at each compliance milestone
An AI incident or near-miss that reveals a gap in the current policy
A material change to the organisation’s AI use – for example, moving from internal productivity tools to customer-facing AI applications that alter the applicable risk tier
A significant change to a third-party AI vendor’s terms, data handling practices, or underlying model
ISO 42001 (2023) recommends that the AI management system undergo a formal management review at planned intervals, with documented outputs covering policy changes, resource requirements, and lessons from incidents. For organisations operating in regulated industries or under EU AI Act high-risk obligations, a quarterly operational review supplemented by an annual strategic review is a reasonable baseline cadence.
FAQs: developing an AI policy
What is an AI policy and why does your organisation need one?
An AI policy is a formal document that defines how your organisation adopts, uses, and manages AI systems responsibly. It sets risk boundaries, assigns accountability, and gives staff clear guidance on permitted and prohibited uses. Without one, AI adoption is effectively ungoverned – meaning growing exposure to regulatory, reputational, and operational risks as AI use scales across the business.
What does the NIST AI Risk Management Framework require from organisations?
The NIST AI RMF (January 2023) is voluntary but widely referenced in procurement and regulatory guidance. Its GOVERN function – the most policy-relevant for most organisations – requires documented policies, named roles, a stated risk tolerance, and a process for managing third-party AI risk. Organisations that align to the GOVERN function have the foundation for any subsequent MAP, MEASURE, or MANAGE activity.
Which organisations must comply with the EU AI Act?
The EU AI Act applies to any organisation that develops, deploys, or imports AI systems in the EU, and to organisations whose AI outputs affect EU residents – including UK-based businesses trading with EU customers. Prohibited practices have been banned since February 2025. High-risk AI system obligations take full effect in August 2026. Some reduced obligations apply to small and micro enterprises for specific AI categories.
What is the difference between an AI policy and an AI governance framework?
An AI policy is the specific document setting the rules and boundaries for AI use. An AI governance framework is the broader operational structure – roles, processes, risk registers, audit trails, and review mechanisms – within which the policy sits. The policy is what staff read; the framework is how the organisation implements and enforces it over time.
How do you classify AI systems by risk level?
The EU AI Act provides the primary classification model: unacceptable risk (prohibited), high risk (conformity assessment required), limited risk (transparency obligations), and minimal risk (no regulatory requirement). Apply this to your AI inventory by assessing each system against Annex III of the Act – focusing on whether the system influences decisions that materially affect individuals’ rights, safety, or access to services.
What happens if an organisation fails to comply with the EU AI Act?
Non-compliance carries tiered fines: up to 35 million euros or 7% of global annual turnover for prohibited practice violations, up to 15 million euros or 3% of turnover for other infringements, and up to 7.5 million euros or 1.5% of turnover for providing incorrect information to regulators. High-risk AI systems that are not compliant by August 2026 must be withdrawn from the market or suspended.
Need help writing your AI policy?
Developing an AI policy that meets regulatory requirements and works in practice takes more than a template. Translating NIST AI RMF controls and EU AI Act obligations into internal policy language that legal, HR, and operational teams can implement is a distinct skill – one that requires understanding both the frameworks and the organisation.
ivee’s AI Governance and Policy Writing service works with organisations to produce AI policies, acceptable use frameworks, and governance documentation built around your specific AI use cases. The service covers risk classification, acceptable use policy drafting, governance role design, and incident response frameworks – not a generic checklist applied across industries. If your organisation is deploying AI and does not yet have documented governance, the time to address that is before a compliance deadline or an incident, not after.
Book onto one of our AI programmes at ivee and start learning today.





