AI POLICY · WORKSHOP

How do I use AI
safely within the
boundaries of
GDPR and AI Act?

Design a workable AI policy for your organisation in one working day.

AI is already being used on your shop floor today. Often without policy, without oversight and without security. In one working day KODIFY designs the foundation together with you: a workable AI policy that facilitates innovation within safe boundaries.

View the 7 pillars
Kodify team in AI policy workshop session
1 Working Day
One intensive session
7 Pillars
Complete policy framework
GDPR & AI Act
Compliant by design
Workable Policy
Ready to implement
THE REALITY

AI & GDPR: Things go wrong quite often.

Copilot, ChatGPT, Claude, Gemini — fantastic innovations, but they hallucinate, aren't always critical and the output is only as good as the prompt or data used. Employee knowledge levels vary, and are on average too low to use these tools wisely. Two real-world examples:

! Data breach · Municipality Den Haag

Personnel file uploaded to ChatGPT

An employee asked ChatGPT for help and uploaded the personnel file containing personal data. This type of data breach almost always occurs because individual employees use AI models on their own initiative without any framework.

Who
Municipality Den Haag
What
Personal data in open AI tool
Cause
No policy, no training
! Trend · Data Protection Authority

Dozens of data breach reports due to incorrect AI use

The privacy watchdog received dozens of reports of data breaches in the workplace through the use of AI chatbots such as ChatGPT, Claude and Gemini over two years. Most cases arise from employee initiatives.

Source
Privacy watchdog (AP)
Period
Past 24 months
Pattern
Shadow AI in the workplace
Conclusion

Employees are insufficiently trained on the safe use of IT applications and AI tools.

CONSEQUENCES

Far-reaching. Including for you as a director.

Uncontrolled AI use leads to serious risks: from board liability and fines under the EU AI Act to reputational damage and exclusion from the chain. Without policy, you lose grip on your business-critical data.

01

Board liability

The EU AI Act obliges organisations to invest in AI literacy. Not facilitating this knowledge is seen as a lack of governance and compliance.

EU AI ActCompliance
02

Reputational damage

Data breaches through AI use are under a magnifying glass from citizens, clients and supervisors. Trust is difficult to restore.

TrustSupervision
03

Legal & financial sanctions

Direct fines from the Data Protection Authority and heavy sanctions under the EU AI Act for irresponsible use of AI models.

GDPR fineAI Act sanction
04

Exclusion from the chain

Organisations that cannot demonstrate their data integrity and AI safety are excluded from modern data networks and ecosystems.

Data integrityEcosystem
05

Loss of control — Shadow AI

Without central policy, employees use unsafe tools on their own initiative, causing business-critical information to end up outside the organisation unmanaged.

Shadow AIBusiness-critical data
DEADLINES · EU AI ACT

The legislative clock is ticking — phased until August 2026.

The AI Act comes into force in phases. AI literacy has been a hard obligation since February 2025. Waiting until 2026 is not an option: supervision and enforcement are already underway. Policy is your proof of preparation.

AUG 2024
AI Act in force

The European AI Regulation has been officially adopted. The legal framework is a fact.

FEB 2025
AI literacy mandatory

Employees working with AI must demonstrably be AI-literate. Prohibited applications take effect.

NOW VALID
AUG 2025
GPAI models

Obligations for providers of general-purpose AI models — transparency, documentation, copyright.

AUG 2026
Full compliance

All provisions — incl. high-risk AI in HR, credit granting and medical context — apply.

THE SOLUTION · STRATEGIC PARTNERSHIP

Start with values. Not with prohibitions.

Good AI policy is not a list of prohibitions. It is a translation of what characterises your organisation — vision, values, customer promise — into concrete frameworks within which people can work freely and responsibly with AI. AI is already being used, today.

KODIFY supports as a strategic partner. Our "Route 1" focuses on fast and responsible organisation: we embrace tools like Microsoft Copilot, but safely. And we don't stop there: we take you on the journey towards AI maturity.

Route 1: A safe and effective rollout of Microsoft Copilot as a first concrete step, embedded in a multi-year path towards data and AI maturity.
"
Data maturity and AI adoption are not resolved in one year.
Dennis Reurings
Dennis Reurings Strategic Partner · KODIFY
7 PILLARS

The AI policy frameworkfor safe and effective AI use

Workshop objective A complete, workable AI policy that helps employees use AI safely and effectively. With clear guidelines for permitted use, risk management and responsibilities. Developed via proven KODIFY templates in one working day.
01 Core principle

Human-centred AI

  • AI supports people, does not replace them
  • Human oversight is mandatory
  • AI gives advice, never makes decisions independently
02 Protection

Safety & privacy

  • Strict access control — users only see permitted data
  • No personal data in open AI tools
  • Privacy, data minimisation and safe processing central
03 Responsibilities

Clear role distribution

  • Clear role distribution per function
  • Policy determines which data and prompts are permitted
04 Training

AI literacy

  • Employees trained & certified before AI use
  • Fixed prompts and example scenarios reduce errors
  • Awareness: generic prompts lead to errors
05 Phased

Phased implementation

  • Small pilots, learn and scale safely
  • Well-configured SharePoint/Teams environment for smooth adoption
06 Governance

Oversight & compliance

  • Logging and audit trail mandatory
  • Escalation procedure for data breaches
  • Regular evaluation of the policy
07 Awareness

Practical rules

  • Concise, daily guidelines for employees
  • Risks named: hallucinations, Shadow AI, agent risks
  • Ownership of output clearly regulated
AI policy workshop
FROM POLICY TO BEHAVIOUR

Workshops & training that directly connect to your context.

An effective AI policy stands or falls with its practical application. Employees not only need to know what is and is not permitted, but also understand how to use AI responsibly, safely and effectively in their daily work.

Our programmes comply with the EU AI Act and strengthen AI literacy at all levels — from operational teams to management and board.

EU AI ACT Complies with literacy requirements Art. 4

AI literacy workshops

INTERACTIVE SESSION · ½ DAY
  • Recognising AI risks and limitations
  • Responsible handling of data and privacy
  • Critically evaluating AI output — human-in-the-loop
  • Working within the AI policy frameworks

In-company training

CUSTOMISED · 1–2 DAYS
  • Effective prompting and output validation
  • Safe working with AI within existing IT structures
  • Applying policy to own use cases
  • Practical theory directly applied to daily processes
COMMON MISTAKES

This is where it usually gets stuck.

Six pitfalls we see time and again and how an experienced partner avoids them before they let policy disappear into a drawer.

01

Starting too strict

A policy that prohibits everything is ignored. Shadow AI grows.

The right approach Start with clear frameworks and room for guided experimentation.
02

Letting only IT handle it

AI policy touches HR, legal, finance and the shop floor. It is not purely a tech issue.

The right approach Form a multidisciplinary team with mandate and final responsibility.
03

Creating it once

Policy from six months ago is outdated. Tools and legislation move faster.

The right approach Plan quarterly evaluations. Policy is a living document, not a PDF in a drawer.
04

No role-specific distinction

A developer needs different AI rights than a receptionist or HR manager.

The right approach Make the policy role-specific with clear permitted and prohibited tools per group.
05

Focusing only on risks

A list of prohibitions without opportunities misses the whole point — and slows productivity gains.

The right approach Emphasise equally where AI does contribute: speed, quality, relief.
06

Starting with rules instead of values

Without vision and values, your policy is an arbitrary collection of do's and don'ts.

The right approach Start with what characterises your organisation. Derive frameworks from there.
ROUTE 1 · TIMELINE

From course to choices in one day.

Via proven KODIFY templates you go through all themes and make sharp choices immediately — IT and Security involved from day one.

1
Preparation · 1 wk
Intake & scope

We scan current AI use, involve IT and Security and align templates to your context.

2
Workshop · 1 day
Policy in 7 pillars

One working day, all themes. We make concrete choices per pillar and record them immediately.

3
Implementation · 2–4 wk
Rollout & training

Policy is translated into communication, technical guardrails and AI literacy sessions.

4
Ongoing
Evaluation & governance

Logging, audit trail and periodic recalibration. Your AI policy keeps moving with law and practice.

FREQUENTLY ASKED QUESTIONS

FAQ — AI Policy workshop

What does the workshop deliver exactly?
A workable AI policy document that can be shared internally that same week, plus an implementation roadmap for the following weeks.
+
Which roles need to attend the workshop?
The person ultimately responsible (CTO/CISO/COO), someone from IT, from Security/Privacy and a business representative. We prefer a mix of decision-makers and doers.
+
Is this policy GDPR and EU AI Act-proof?
The policy framework is built around the literacy requirements of the EU AI Act (Art. 4) and the processing bases of the GDPR. We involve your legal department where necessary.
+
What if we already have an AI policy on paper?
No problem — then this is an audit and upgrade. We test your existing policy against the 7 pillars and focus on the gaps.
+
How do you handle Microsoft Copilot specifically?
Copilot is often the first concrete tool on which policy lands. We set up a secure tenant (data boundaries, retention, logging) before the rollout goes broad.
+
START NOW

Design the foundation of your AI policy.

Sharp choices on all 7 pillars in one working day — delivered as a ready-made policy document with implementation roadmap.

Download the step-by-step plan #LetsGetKodified
DIRECT CONTACT

Prefer to brainstorm with a senior consultant?

30 minutes, no pitch deck — just a whiteboard and your question. We immediately share where most organisations get stuck.

info@kodify.eu →