Your company already has an AI charter. It’s not written down and can be summed up in one line: anything goes as long as no one is watching.
If you manage an SME, an IT department, or a team, this rule applies whenever an employee pastes a client email into a free account to save twenty minutes. What you lose by letting it slide: personal data sent to a provider without a contract, a fabricated figure sent to a client, an AI Act audit with nothing to show.
This article replaces it with a page: seven rules written in the first person, ready to copy, each linked to what it proves under the European regulation as of September 17, 2026, followed by the three mistakes that render a charter ineffective and the signature plan within a week.
In brief
- Copy the seven blockquote formulations: they form the charter, just replace the list of tools with yours.
- Limit the list of approved tools to three or five: professional offer, data processing agreement, non-training commitment, adjustable retention by an administrator.
- Separate mandatory from recommended: articles 4 and 50 are mandatory, the charter and the register are the pieces that prove it.
- Appoint an AI contact and a non-punitive reporting channel: an incident reported the same day can be managed, a hidden incident is discovered during an audit.
- Go through the works council under article L.2312-8: the internal regulations only change if the charter provides for sanctions beyond 50 employees.
- Keep a five-column register and review it every six months: tool, usage, contact, risk level, validation date.
Your employees already have an AI charter, but it’s not yours
What shadow AI circulates daily beyond your radar
Shadow AI refers to the use of generative AI tools by employees without employer approval, and Senate information report no. 572 (2025-2026) dedicates an entire chapter to it.
According to the IFOP barometer for Talan 2025 cited in this report, 43% of employees use generative AI at work. A study from September 2025 mentioned by the senators adds that 75% of them use tools neither provided nor approved by the company, and 44% train themselves.
On the employer side, 9% of employees have access to an internally provided tool, and nearly half of the companies have no intention of providing one, according to the INRIA report of 2025.
The classic case remains Samsung in 2023: engineers pasted internal source code into ChatGPT for debugging, and the company banned the tool immediately after. The Senate draws the opposite lesson: a framework that guides usage towards approved tools, such as an AI usage charter, reduces shadow AI.
What the AI Act requires of you by September 17, 2026
The European regulation never mentions the word “charter.” It imposes obligations on deployers (the company using an AI tool provided by a third party, in other words, you), and the AI charter is the support for this.
Three dates matter. Article 4 on AI mastery by staff has been in effect since February 2, 2025; the Digital Omnibus (EU regulation 2026/1744, effective since July 27, 2026) redefined it as an obligation of means, as explained in the seven changes of the Digital Omnibus. Article 50 on transparency has applied to deployers since August 2, 2026, without delay, and national authorities have been conducting audits since that date.
Only the automatic marking of content by providers of systems already on the market is pending until December 2, 2026. High-risk uses from annex III (recruitment, credit, education) are postponed to December 2, 2027 and fall under a separate framework, described in our guide on AI Act obligations for French companies.
A point that marketing content leaves unclear: the AI Act imposes no register on an SME using low or minimal risk systems. The charter and register are evidence to produce in case of an audit, not obligations.
The four everyday rules every employee should know by heart
Think of the highway code displayed on one page: seven signs everyone recognizes, not the entire code.
A short list of tools, and a professional account for each
I only use tools from the official list with my professional account. Never a personal account or a free version for work documents.
The list consists of three to five tools, similar to the list of approved suppliers in purchasing: you don’t order a computer from just anyone. Five criteria qualify a tool, not its brand.
- A professional or enterprise offer, never the consumer version.
- A signed DPA (data processing agreement, required by GDPR as soon as a provider handles personal data).
- A written commitment of non-training on your exchanges.
- Adjustable retention by the administrator, up to ZDR (Zero Data Retention: the provider does not keep your exchanges), extended by OpenAI to Business and Enterprise offers in August 2026.
- Hosting in the EU or equivalent contractual clauses.
A brand changes its offer in six months; the criteria remain.
What never goes into a prompt, even on an approved tool
I do not enter any personally identifiable data, non-anonymized client data, contracts, non-public prices, source code, or strategic documents into an AI tool. If in doubt, I ask first.
A generative AI tool is like a friendly stranger on the train: it means no harm, but you don’t know who it might repeat to. The rule applies even on an approved tool for the most sensitive secrets, because a contract limits risk without eliminating it.
Sensitive data as defined by GDPR (health, opinions, origin) are the last to be shared, and each prohibition comes with an alternative: anonymizing a client email takes two minutes.
Why nothing goes out without human review
I review and verify all AI-generated content before sharing it externally, and I remain responsible for what I send. No decision affecting a person is based on AI output without human validation.
Reviewing a generated text is like reviewing the work of a brilliant intern who has never set foot in the company: quick, knowledgeable, confident, capable of inventing a figure with the same assurance as a real one. Sources are required for any numerical or legal content.
Responsibility remains with the person who disseminates, and this review also protects your rights over the content (rule 5).
Reporting an error costs nothing, hiding it costs a lot
If I think I’ve entered prohibited data into an AI tool, I notify the AI contact the same day. Reporting is never punished, hiding is.
The AI contact can be the DPO, the IT department, or a business manager; what matters is that they are appointed. An incident covers prohibited data entry, AI output shared without review, or an unapproved tool.
The deadline is the same day: requesting conversation deletion within the hour is better than discovery during an audit. The absence of punishment for reporting makes the other six rules credible.
The three rules management must decide before signing
The first four rules can be read in five minutes during a team meeting; the next three require a management decision.
Who owns what AI produces?
What I produce with AI in the course of my work belongs to the company, and I always add my own contribution: selection, rewriting, verification, formatting.
The European Parliament study of 2025 on generative AI and copyright is clear: content produced 100% by AI, without human creative input, falls into the public domain. AI-assisted content with human creative control remains protectable.
Hence two decisions: require human input on all deliverables and clarify in writing the assignment to the employer. A brochure generated from a single prompt can be reused by a competitor.
Saying when it’s AI speaking
When AI speaks to a client on our behalf, or when generated content could be mistaken for authentic, I clearly indicate it. Internally, I mention “produced with AI assistance” on relevant documents.
The first sentence is mandatory under article 50 since August 2, 2026: a client chatbot introduces itself as AI, a deepfake is marked, AI-generated public interest text indicates it. The second is a best practice: an internal report doesn’t circulate without knowing it wasn’t reviewed.
The distinction protects the charter: when everything becomes mandatory, nothing is.
Training in 45 minutes and keeping the register up to date
I attend the company’s AI training session before using a tool from the list, and any new tool is entered in the register before its first use.
Article 4 requires measures to promote AI mastery by staff, according to the Digital Omnibus wording. A 45-minute session on the charter, with an anonymization exercise, addresses this better than a 20-hour MOOC that no one completes.
The AI systems register is like a fire extinguisher inventory: no one thinks about it until the day of the audit when it’s the first thing you’re asked for. Five columns suffice (tool, usage, contact, risk level, validation date), three lines cover an SME of 30 people, and a review every six months keeps it alive.
The three mistakes that render an AI charter ineffective
The first mistake is the 12-page charter that no one reads. The JPI model in nine articles and the government charter are excellent sources and poor documents to distribute: an employee doesn’t memorize nine articles.
The sign fits on one page, pinned in the messaging system: an AI charter that can be recited is a charter that is applied.
The second mistake is the total ban, like Samsung in 2023. It creates shadow AI instead of reducing it, because the tools are already in place: Gemini in Google Workspace, Copilot in Microsoft 365, an AI function in the CRM.
Banning ChatGPT is like closing the front door while leaving the windows open. A useful charter authorizes before it prohibits: every “no” comes with the approved tool that says “yes.”
The third mistake is the charter without training. A signed document that no one has explained proves nothing under article 4, which requires measures, and leaves the 44% of employees who train themselves where they were.
Regarding sanctions, the field is emerging: no landmark labor court decision on generative AI is identified as of September 17, 2026. The jurisprudence on internet and email use at work serves as a reference for proportionality, hence an AI charter that informs and trains before sanctioning.
Signing the AI charter this week
Day 1 is for adapting the framework: copy the seven formulations, replace the list of tools with yours, appoint the AI contact. Day 2 goes before the DPO, IT department, or your IT provider to check contracts and sign any missing DPAs.
Day 3 is institutional: the works council is consulted under article L.2312-8 of the Labor Code (introduction of new technologies); beyond 50 employees and if the charter provides for sanctions, it joins the internal regulations (articles L.1321-1 and following).
Below this threshold, or without planned sanctions, a service note signed by management suffices. Days 4 and 5 cover the 45-minute session, signing, email distribution, and tool registration, with a six-month review scheduled in the calendar.
Your company’s AI charter already exists, written or not. The one your employees silently follow says anything goes as long as no one is watching; the one on this page says what is allowed, with which tools, and who to talk to when something goes wrong.
The seven formulations cover articles 4 and 50 as of September 17, 2026, and leave high risk to its December 2027 schedule. For the personal data aspect, our analysis of OpenAI’s Privacy Filter addresses anonymization before sending.
One thing to do this week: copy the seven blockquotes, replace the list of tools with yours, and place the page on the management’s desk by Friday.
FAQ: ten questions about the company AI charter
Is an AI charter mandatory with the AI Act?
No, the regulation never mentions this document. It requires AI mastery by staff (article 4) and transparency (article 50), and the charter is the simplest way to prove these obligations are addressed.
What should an AI charter contain to fit on one page?
Seven rules: approved tools, prohibited data, human review, reporting, ownership of productions, transparency, training, and register. Each fits in one or two first-person sentences.
What data should my employees never enter into an AI tool?
Personally identifiable data, sensitive data as defined by GDPR, non-anonymized client data, contracts, non-public prices, source code, and strategic documents. The rule applies even on an approved tool for the most sensitive secrets.
How do I know if an AI tool is approved?
It meets five criteria: professional offer, signed DPA, written non-training commitment, adjustable retention by the administrator, EU hosting or equivalent clauses. A free version or personal account meets none of the five.
Should the works council be consulted to adopt an AI charter?
Yes, under article L.2312-8 of the Labor Code on the introduction of new technologies. The internal regulations only change if the charter provides for sanctions and the company exceeds 50 employees.
Can an employee be sanctioned for using an unauthorized AI?
Yes, provided the rule was communicated, the sanction is provided in an enforceable document, and it remains proportionate. No landmark labor court decision exists yet on generative AI, and the jurisprudence on internet use at work serves as a reference.
Who owns the texts and images generated by AI at work?
Content produced 100% by AI without human creative input falls into the public domain, according to the European Parliament study of 2025. AI-assisted content with human control remains protectable, hence the requirement for human input in the charter and the assignment clause to the employer.
What is the AI systems register, and should a 20-person SME keep one?
An internal table with five columns (tool, usage, contact, risk level, validation date) listing what the company uses. SMEs using low-risk systems are not required to keep one; it remains the simplest evidence to produce in case of an audit.
What does article 50 change for an SME since August 2, 2026?
A chatbot addressing clients must present itself as AI, a deepfake must be marked, AI-generated public interest text must indicate it. The internal mention “produced with AI assistance” remains a best practice, not an obligation.
Is a one-page charter sufficient for recruitment or scoring use?
No, these uses fall under annex III of the regulation and separate obligations, applicable from December 2, 2027. The one-page charter covers common uses of generative AI, not high-risk systems.
Related Articles
The real risks of AI for your business, beyond science fiction
Les vrais risques de l’IA pour votre activité, au-delà de la science-fiction : fuites de données, erreurs non vérifiées, dépendance fournisseur, responsabilité.
Claude Opus 5: what Anthropic’s new model means for your business
Anthropic released Claude Opus 5 on July 24, 2026. The announcement is simple: the model approaches the intelligence of Claude Fable 5 at half the price. Put this way, the…