AI Policy at Your Company and ISO/IEC 42001 — Governance That Doesn't Kill Innovation
RETURN_TO_BLOG
AI & Security 14 min

AI Policy at Your Company and ISO/IEC 42001 — Governance That Doesn't Kill Innovation

Paweł Wiszniewski
Paweł Wiszniewski
SEO & GEO Specialist · AI Engineer

August 6, 2026 marked six months since the Article 4 "AI literacy" obligation took effect, and on August 2, 2026 specifically, national market surveillance authorities across the EU got formal powers to check compliance with it. The Digital Omnibus package, politically agreed on May 7, 2026 and in force since July 27, 2026, softened the wording — from a "duty to ensure" AI literacy to a "duty to support its development" — but didn't remove it. In practice this means one thing: a company must demonstrate real, documented effort, not just good intentions. And that document — a written AI policy — is exactly what the vast majority of SMEs already using AI day-to-day don't have.

Six weeks ago, national market surveillance authorities across the EU got formal powers to check whether companies actually meet the Article 4 AI literacy obligation — and whether they have documents to prove it, not just good intentions. Most SMEs that have deployed AI are missing one thing: a written AI policy. Here's what such a policy must contain, how to build an AI systems register, when to reach for ISO/IEC 42001 instead of an internal document, and who at a small company should be the “AI owner” without a Chief AI Officer title.

This closes the third piece of a puzzle I've been building across earlier posts: Shadow AI diagnoses the problem — employees using AI without the company's knowledge. The AI Act and GDPR and AI describe the legal obligations you can't avoid. This post is the systemic fix: how to build a voluntary AI management system that organizes those obligations once, instead of putting out fires with every new tool.

Why "no policy" is the default state at most companies

/// AI GOVERNANCE 2026 — KEY DATES AND NUMBERS

08/02/2026
national market surveillance authorities across the EU gain formal powers to check the AI literacy obligation
AI Act, Art. 4
05/07/2026
political agreement on the Digital Omnibus package, in force since 07/27/2026
Consilium
~70%
of the documentation required for high-risk AI Act systems is covered by implementing ISO/IEC 42001
ISO/IEC 42001
39 controls
across 9 categories — the scope of ISO/IEC 42001 Annex A for an AI management system
ISO/IEC 42001

I talk to dozens of companies deploying AI, and the pattern is identical: someone on the team starts using ChatGPT or Claude, it works well, so the tool "spreads on its own." A few months later the company has five different AI assistants deployed by five different people, zero shared data classification, and zero answer to "who's responsible if something goes wrong." This isn't a hypothetical risk — it's the default state described in Shadow AI for a company with no policy. The difference between a company with an AI policy and one without doesn't show up on a calm day — it shows up on the day of an incident, an inspection, or an enterprise client's audit asking about your AI management system.

What an AI policy must contain — six elements, not a hundred pages

An AI policy that actually works fits on 2-4 pages and answers six specific questions. Nobody reads a longer document — and an unenforced policy is worse than none, because it creates a false sense of security.

/// AI POLICY — SIX ELEMENTS, NOT A HUNDRED PAGES

Nobody reads a longer document

01
APPROVED TOOLS
Specific names — what's allowed, what not to paste in, for which tasks
02
DATA CLASSIFICATION
Public / internal / specially protected — and which AI environment is allowed for each
03
HUMAN-OVERSIGHT THRESHOLD
Which decisions AI makes on its own, and which need approval before deployment
04
INCIDENT PROCEDURE
Who to report an incorrect, biased, or data-exposing AI response to, and how fast
05
ROLES AND RESPONSIBILITY
Who is the "AI owner," who approves tools, who updates the register
06
TRAINING AND REVIEW
Onboarding for new hires plus an annual, documented policy review
  1. 1.An approved-tools list. Specific names: "ChatGPT Enterprise — yes, for general tasks and documents without PII" / "free ChatGPT in a browser — no, for anything work-related." Without this list, every employee decides for themselves what's safe — and usually lacks the expertise to do so.
  2. 2.Data classification. Three simple categories: public data (no restrictions), internal data (tools with a DPA only), specially protected data — customer PII, financial data, trade secrets (Zero Data Retention or self-hosted environments only). I break down the full classification methodology and DPA requirements in GDPR and AI and AI data security.
  3. 3.A human-in-the-loop threshold. A clear rule: which decisions AI can make on its own, and which require human approval before deployment — especially important for systems touching customers or employees (GDPR Article 22).
  4. 4.An incident reporting procedure. One sentence: "if AI generated an incorrect, biased, or data-exposing response — report it to [whom] within [how many] hours." Without this path, incidents disappear silently until they blow up publicly.
  5. 5.Roles and responsibility. Who is the "AI owner," who approves new tools, who updates the systems register — I expand on this in the AI owner section below.
  6. 6.Training and review. A short onboarding for new employees plus an annual policy review. This is exactly the "documented effort" under AI Act Article 4 that inspectors are now looking for — I break down the AI Act obligations in detail here.

An AI systems register — a spreadsheet is enough to start

An AI systems register doesn't need to be GRC software costing tens of thousands a year. For a company under 100 people, one spreadsheet with six columns is enough:

ColumnWhat to enterExample
System / toolName and vendorChatGPT Enterprise (OpenAI)
PurposeWhat it's used for at the companyDrafting email replies, summarizing documents
Risk level (AI Act)Minimal / limited / highLimited — no automated decisions
Personal data?Yes/No + whether a DPIA was doneYes — DPIA completed 03/2026
OwnerWho's accountable for this deploymentCustomer service team lead
StatusActive / under review / retiredActive since 01/2026

This same spreadsheet is your starting point for the risk classification from the AI Act guide and for assessing whether a given deployment needs the DPIA described in GDPR and AI. Updating the register with every new tool — not once a year — is the only way to keep it in touch with reality.

ISO/IEC 42001, the EU AI Act, and NIST AI RMF — when to use which

This question comes up in almost every consultation: "I've got the AI Act covered, isn't that enough?" Not quite — these are three different layers that complement, not replace, each other:

StandardWhat it isWhen to reach for itCost and effort
EU AI ActMandatory EU regulation, risk tiers, fines up to €35MAlways, if you operate in the EU market — there's no opting outDepends on risk; usually low for SMEs
ISO/IEC 42001Certifiable, voluntary AI management system (39 controls across 9 categories), valid 3 yearsWhen selling to enterprises or a regulated sector that require proof of governance$20,000-$60,000, 4-9 months to certify
NIST AI RMFFree, non-certifiable framework (Govern/Map/Measure/Manage functions) with a GenAI profile (NIST AI 600-1)When serving US clients or federal contracts referencing the RMFNo license cost — just implementation time

Implementing ISO/IEC 42001 covers roughly 70% of the documentation required for high-risk AI Act systems in practice — if you have to document it anyway, certification is often cheaper than it looks once you factor in avoided legal work. For a typical SME not selling to large enterprises, the best starting point is an internal policy loosely modeled on the NIST AI RMF functions — no certification, no cost, full flexibility. ISO 42001 gets added only once a client or the market actually demands it.

The AI owner at an SME — who does this without a Chief AI Officer title

The biggest myth blocking AI policy adoption at small companies: that it needs a dedicated role. It doesn't. It needs one person with clearly assigned responsibility — usually 10-20% of their time, not a full position.

/// AI OWNER — 10-20% OF THEIR TIME, NOT A NEW HEADCOUNT

What matters is clarity: one named person, not "the team"

01
APPROVES NEW TOOLS
Checks them against the approved-tools list and data classification before deployment
02
MAINTAINS THE AI REGISTER
Updates it with every new deployment, not once a year
03
FIRST POINT OF CONTACT
Gathers facts on an incident, escalates to the DPO or legal counsel if personal data is involved
04
RUNS THE ANNUAL REVIEW
And documents it — the evidence of "supporting AI literacy" that inspectors look for
  • Approves new tools before deployment — checking them against the approved-tools list and data classification.
  • Maintains the AI systems register — updating it with every new deployment, not once a year.
  • Is the first point of contact for an incident — gathering facts, escalating to the DPO or legal counsel if personal data is involved.
  • Runs the annual policy review — and documents that review, because that's exactly the evidence of "supporting AI literacy development" that inspectors are looking for.

At companies under 20 people, this role is usually taken on by the owner, the COO, or the IT lead. What matters isn't the title — it's clarity: one named person, not a "team" or "everyone."

The most common mistakes when building an AI policy

/// THE MOST COMMON MISTAKES BUILDING AN AI POLICY

A good policy scales deployments safely — it doesn't slow them down

A POLICY THAT WORKS
  • 2-4 pages, six concrete rules
  • A register updated with every new tool
  • One named person as AI owner
  • An annual review documented in writing
A DEAD DOCUMENT OR A ROADBLOCK
  • A dozens-of-pages PDF nobody has read
  • A register updated once a year "just in case"
  • Responsibility diffused across "the whole team"
  • The policy blocks every initiative instead of organizing it

A good AI policy doesn't slow deployments down — it lets you scale them safely and actually measure their return, instead of guessing the way you would in an AI automation ROI calculation. A bad one does the opposite: either it blocks every initiative with bureaucracy, or it exists only as a PDF nobody has read.

An AI policy template — how to start this week

You don't need to write a policy from scratch. The six-element structure above fits into a simple template: one page of rules, one systems-register tab, one incident procedure. I build these templates — tailored to a specific industry and company size — as the first step of every AI governance audit I run as part of AI consulting and AI training for teams. Reach out — I'll prepare a policy draft tailored to your company and help you implement it without hiring anyone new.

---

I run AI governance audits for SMEs — from zero to a finished policy, a systems register, and a clearly assigned AI owner role, without hiring anyone new. I do this as part of AI consulting and team training. Reach out — I'll start by reviewing what AI systems are already running at your company and what's actually missing from your documentation.

Worth reading next:

/// RELATED_RECORDS

AI & Security

GDPR and AI — Personal Data in Prompts, DPIA and LLM Vendor Agreements (Practically)

Pasted a customer's email into ChatGPT to speed up your reply? That's already personal data processing under GDPR — with the full weight of obligations most teams have never heard of. Six weeks ago Poland's data protection authority (UODO) published the first official self-assessment checklists for AI/GDPR compliance — proof the regulator is already watching, not just theorizing. When does a prompt trigger a DPIA, how does the “meaningful human involvement” test from Article 22 hold up against a lead-scoring chatbot, and how do OpenAI's, Anthropic's and Google Cloud's DPA agreements actually differ — a practical guide without the legal jargon.

15 min
AI & Security

Shadow AI — Your Employees Are Using AI Without Your Knowledge and That's Your Problem

68% of employees use unsanctioned AI tools without IT's knowledge. They paste contracts, customer data, source code, and strategies into public chatbots — and the company has no idea. Shadow AI isn't a technology problem, it's a governance problem. I explain how to detect what your team is actually using, how to write an AI policy that actually works, and why an outright ban is the worst possible solution.

16 min
AI & Security

The EU AI Act in Practice — What Your Company Must Do in 2026 (No Panic, No Legalese)

The AI Act sounds scary, but 90% of SMB automation is "minimal risk" with no extra obligations. I explain the four risk tiers, the provider vs deployer distinction, what applies right now (AI literacy, chatbot transparency), when you fall into "high risk", and what a realistic compliance checklist looks like. With an up-to-date timeline after the May 2026 Digital Omnibus package.

13 min
/// AUTHOR
Paweł Wiszniewski – AI & Web Engineer

Paweł Wiszniewski

SEO & GEO Specialist & AI Engineer

SEO/GEO specialist (10 years) and AI engineer (3 years). I build search visibility, AI systems and automations that reduce costs and improve operational efficiency.

Signal received?

Terminate
Silence

Initiate protocol. Establish connection. Let's build something loud.

> WAITING_FOR_INPUT...