AI governance for businesses: a tool inventory, usage policy and human review

Set rules for business AI with a tool inventory, adaptable usage policy and named reviewers. Understand which AI Act transparency duties apply to which uses.

Consider a team preparing a customer proposal. Sales translates the specification, finance checks a spreadsheet and marketing generates a product image. Each person may have used a different AI account. Before the proposal goes out, the business needs to know what information was sent and who checked the work.

AI governance for a small business starts with making those decisions explicit. A tool inventory, a short usage policy and a review before delivery provide a practical starting point. The AI Act adds duties that depend on what the system does and the role your business takes.

Five governance gaps to look for

Check whether every AI use has an owner, permitted data and a review point. Approval needs another look when a tool moves into a different task or starts handling different information.

Cohere’s analysis of AI governance challenges describes five operating problems. Turn them into questions your team can answer:

GapQuestion to ask
Approval treated as permanentWhat has changed since we approved this tool?
Unclear ownershipWho makes decisions and handles incidents?
Controls poorly matched to riskWhat would an error mean for this task?
Unrecorded employee useWhich AI accounts and features do people actually use?
Sensitive data without suitable controlsWhat information enters the tool, and who can access it?

Include AI features added to existing email, meeting and business software. A procurement review completed before a feature existed will not have assessed that feature’s use of your information.

What the AI Act requires in everyday business use

Article 50 transparency obligations have applied since 2 August 2026, with different duties for providers and businesses using their systems. AI literacy provisions began applying on 2 February 2025, well before that August deadline.

Under the AI Act, a business using a system under its authority for work is a deployer. A company that develops a system, or has one developed, and puts it into service under its own name can be a provider. Headcount does not determine the role.

Regulation (EU) 2026/1744, which entered into force on 27 July 2026, changed Article 4. Providers and deployers must take measures to support AI literacy among staff and other people operating systems on their behalf, reflecting their experience and the context. They do not have to guarantee a particular literacy level for each individual. Give people guidance on permitted data, common errors and checking results; retain the materials and a record of participation.

Transparency duties depend on the role and the use

Article 50 separates the following duties. These are the main situations an office team is likely to encounter; specialist uses need their own assessment.

SituationDuty and responsible partyPractical check
Someone interacts directly with AIThe provider must design the system to inform the person, unless the AI interaction is obvious in contextTest that customers see the notice when a conversation starts
A system generates synthetic contentThe provider must add detectable, machine-readable marks, with exceptions including certain ordinary editing functionsCheck the marking documentation and preserve the file’s marks
A business distributes image, audio or video content constituting a deepfake, generated or manipulated by an AI system used under its authorityThe deployer must disclose that it was artificially generated or manipulatedCheck whether it resembles real people, objects or events and could appear authentic
A business publishes text generated or manipulated by an AI system used under its authority to inform the public on matters of public interestThe deployer must disclose the artificial origin, except when both conditions apply: human review or editorial control; and a person or entity holding editorial responsibilityRecord who reviewed the text and who is responsible for publishing it

A deepfake can falsely present an existing person, object, place or event as authentic. The deployer duty covering deepfakes does not impose a visible label on every generated illustration. Clearly artistic or fictional works have a tailored disclosure rule. A business can set a broader internal rule where synthetic material could confuse its audience.

For providers of generative systems placed on the market before 2 August 2026, the amendment gives until 2 December 2026 to comply with Article 50(2) technical marking. That transition does not postpone every transparency duty.

Two official guides provide further detail: the European Commission’s transparency guidelines and CNIL’s guidance on using generative AI. CNIL covers personal data under the GDPR, contractual arrangements and international transfers. The contract needed depends on each party’s role in the processing; buying a paid account does not complete that assessment.

Build an inventory that answers where the information goes

Use one row for each relevant combination of tool, account and business use. The inventory should show what is approved and which unanswered questions prevent approval.

Start with a shared spreadsheet and ask the team to include tools they have tried independently. An initial meeting can identify uses and gaps. Verifying provider terms is follow-up work, not something to declare complete because the meeting ended.

FieldWhat to record
Service and accountProvider, product, plan and whether the account is personal or company-managed
Owner and usersThe decision-maker and teams with access
TaskThe approved work and uses outside that approval
Permitted informationData categories and relevant restrictions
DestinationsProcessing and storage locations; access by providers and subcontractors
Retention and reuseRetention periods, deletion and terms for using inputs or files in training
Output reviewWho checks the work and before which delivery
Status and next reviewApproved, restricted or pending; evidence examined and internal review date

Distinguish storage, processing and support access when the provider documents them separately. European storage alone does not answer all three questions. Our guide to sovereign AI for businesses explains those distinctions.

An illustrative approved use might read: “Translate public product specifications for sales; published technical details only; exclude negotiated prices and customer names; sales manager checks dimensions and terms.” That authorises a defined task. It does not approve every possible use of the service.

When an important condition is unknown, leave that use pending or limit it to information you have already assessed. Avoid inferring a provider’s training policy from the words “free” or “business” in the plan name.

An AI usage policy template for one page

The policy should tell people which tools they may use, which information they may enter and who checks the results. This template also covers training, disclosure and incidents so staff know what to do when a task falls outside the agreed process.

Adapt it to the inventory and fill in real names before approval. These restrictions are proposed company rules; they are not all universal AI Act requirements.

Download the one-page policy template (DOCX).

Internal AI usage policy

An operating template to adapt and approve before use.

Company: [Company] · Owner and contact: [Name and channel] Effective date: [Date] · Next review: [Date] Approved inventory: [Link] · Approved by: [Name and role]

  1. Tools and tasks

We use the tools and accounts in the inventory only for approved tasks. We request a review before adding a tool, enabling a new feature or changing the data or audience. We do not use personal accounts for internal or customer information.

  1. Information we may enter

We provide only the information needed and authorised for the task. We do not enter passwords, access keys or other authentication secrets. Personal or confidential data requires specific assessment and approval of the use, account and provider terms. Public availability does not remove restrictions on information.

  1. Human review

Before work leaves the company or supports a consequential decision, the designated reviewer checks facts, sources, calculations, confidentiality and commitments. If an important point cannot be verified, the reviewer holds the work and consults the owner. Decisions affecting employment, credit, health or rights require specialist assessment before use.

  1. Disclosure

As an internal rule, we tell customers when they interact directly with AI and disclose synthetic content that could be mistaken for a real person, product or event. We preserve provider markings. The person approving publication also checks which disclosures the law requires for that use.

  1. Training

We take part in guidance relevant to our tasks: permitted data, common errors, checking outputs and raising concerns. The owner keeps the materials and a participation record, and updates the guidance when the use changes.

  1. Incidents and changes

If information is sent without authorisation or an error could have consequences, we pause the affected use or distribution and immediately report it through the named channel. We record what happened and the necessary references without repeating confidential information. The owner coordinates the response and reviews this policy after incidents or material changes.

This template organises work; it does not establish legal compliance or approve any provider.

Test the policy against three familiar tasks: a customer email, an internal data file and a marketing publication. If a colleague cannot identify the right account or person to consult, make that instruction more specific before distributing the policy.

Review the work and decide on disclosure before delivery

The reviewer needs access to the source material and authority to hold the work. A grammar check alone leaves figures, commercial terms and claims about customers unexamined.

For a proposal or report, check:

  • Facts and sources: open the links, check their dates and confirm that they support the claim. A plausible citation can still be wrong.
  • Calculations: reconcile amounts, units, taxes and totals against the original material. Keep any sample limitations visible in the result.
  • Commitments and information: check deadlines, warranties, confidentiality and recipients before sending.
  • Disclosure: choose the notice appropriate to the content and use. Keep the publication approval with the final version.

For a product image, also check that the materials, accessories and dimensions shown match what you sell. An AI label cannot correct a misleading product representation.

The template’s internal rule could use wording such as “Illustrative image generated with AI” or “You are speaking with an AI assistant”. Put the notice where the audience will encounter it when viewing the content or starting the conversation. Technical file markings and a notice people can read serve different purposes.

Where a shared workspace helps

A team can agree on one service and common review criteria so that people follow the same working instructions. The business still needs an inventory and someone to approve tools, data and publication.

Ilisai combines research with sources and downloadable document creation with access to the models available in its catalogue. Each person uses an individual account with its own credit balance; see the plans and usage terms. Assess its EU-first approach alongside the actual processing locations and conditions of your chosen model and provider. Before approving confidential information, check that the specific use fits your company policy. Start with a document containing no sensitive data and apply the review process you have defined.

Start using AI today

Create your free account and access multiple AI models from a single interface.

Create free account

In the enterprise: assign owners and match controls to consequences

Give each use a business owner responsible for its operation and a clear decision-maker for material changes. Security, privacy and sector specialists should participate when the information or decisions require their expertise.

Three internal review levels can make the process easier to run. They are an operating proposal, not the AI Act’s legal risk classification:

UseReview before approval
Drafts using public informationUsage instructions and checking by the person preparing the work
Confidential information or external deliverablesProvider and data assessment, limited access and a named reviewer
Decisions affecting employment, credit, health or rightsSpecialist assessment of the use and its possible legal classification before deployment

The department lead approves the purpose and resources. The process owner maintains the inventory and reviews; IT and security assess access and technical conditions; the privacy lead or DPO, where applicable, contributes to personal-data decisions. Everyone should know who can suspend a use while an incident is investigated.

The 2026 amendment sets application of Chapter III, Sections 1–3, except Article 6(5), at 2 December 2027 for Annex III high-risk systems and 2 August 2028 for those under Article 6(1) and Annex I. These dates do not defer data, contractual or transparency duties that already apply.

Review access when people change roles or leave. Set a recurring inventory review, and bring it forward when the provider, feature, information or audience changes. The five phases of AI maturity offer a way to organise the wider adoption programme.

Frequently asked questions

These answers concern ordinary assistant use and the organisation of business work.

Must we tell a customer that AI helped write an email?

Article 50 does not establish a blanket notice for every AI-assisted email or quotation. Consider the actual situation, including direct interaction with a system, deepfakes or public-interest publication. Contract terms, professional rules or other disclosure duties may also apply; a human signature does not remove them.

Does signing an AI policy establish compliance?

No. The template records internal decisions; it does not establish that each use meets its applicable obligations. Explain the rules, provide guidance relevant to people’s tasks and check that they can follow the process with the tools available.

Does a personal AI account always use inputs for training?

That depends on the service, plan, settings and terms. The operating problem is using an account the business has not assessed. Record the use and examine its terms before approving business information.

This article provides operational guidance, not legal advice. Uses affecting people or subject to sector-specific regulation need a separate assessment.

Vicente Pomares
Founder
Focused on making generative AI accessible to everyone.

We use necessary cookies to make Ilisai work. With your permission, we also use analytics cookies to understand how Ilisai is used and improve it.

AI governance for businesses: a tool inventory, usage policy and human review | Ilisai