No provision of the EU AI Act says "thou shalt have an AI policy". Several of its obligations are, however, close to impossible to demonstrate without one, which amounts to much the same thing when somebody asks you to prove it.
The question worth asking is not whether you need a policy. It is what the policy is for, because most of the ones we read are written to be filed rather than used.
What the law actually requires
AI literacy is a live obligation on providers and deployers alike, regardless of risk tier. You must take measures to ensure your people have sufficient AI understanding for the systems they operate. A policy is the usual evidence that you did.
Human oversight applies to high-risk systems, and requires named people with the authority and competence to intervene. That is an organisational arrangement, not a technical one, and it has to be written somewhere.
Transparency duties require somebody to have decided how disclosure is done, consistently.
Underneath all of it sits GDPR, which has never stopped applying and which is where most Irish AI exposure actually lives.
What belongs in the document
1. Scope, stated honestly. Which systems this covers, including the ones people use without asking. A policy that pretends the free tools are not in use is already fiction.
2. What is permitted, what is conditional, what is forbidden. Three lists. The forbidden list should name the prohibited practices, and also anything forbidden for commercial reasons of your own - client data into public models is the usual one.
3. Named ownership. Who decides whether a new tool may be adopted. Who reviews. Who is told when something goes wrong. A policy without names is a wish.
4. Data rules. What may be put into which systems. This is the clause staff will actually read, so it should be short and unambiguous - a table of data classes against tools beats two pages of prose.
5. Human oversight arrangements. Which decisions must have a person in them, what that person can actually overrule, and how they are trained to spot when the system is wrong rather than merely confident.
6. Disclosure. How you tell customers they are dealing with AI, and how generated content is marked.
7. Incident handling. What counts as an AI incident, who it goes to, how quickly. Most firms discover they need this only after the first one.
8. Review date. An unreviewed policy is evidence of the wrong thing.
What to leave out
Definitions copied from the Regulation. A summary of the legislation. Anything aspirational about being responsible and ethical without a mechanism attached.
The test is simple: could somebody do something differently tomorrow because of this sentence? If not, cut it.
Policy is not the artefact that saves you
We say this to every client and it lands about half the time. The policy is the cheapest part. The thing a regulator, a customer's procurement team or an insurer actually asks for is evidence that it operates - the inventory, the risk assessments, the oversight records, the incident log, the training records.
Everyone agrees on principles. Almost nobody keeps a log. The gap between those two facts is where nearly all of the real risk sits.
The same question in the UK, the United States and Australia
The answer has the same shape in all three. No statute says write a policy. Several regimes require the things a policy is the cheapest way to produce.
United Kingdom. Since 5 February 2026, UK GDPR Articles 22A to 22D require you to know which of your decisions are solely automated and significant, to tell the person, and to give them a route to human intervention and to contest the outcome. You cannot answer any of that without a register of systems and a written rule about when a human decides. The ICO is under a statutory duty, in force since 12 May 2026, to publish a code of practice on AI and automated decision-making, so the expectations will get more specific, not less.
United States. Texas requires government entities to disclose that a person is interacting with AI. Illinois requires notice to employees where AI is used in employment decisions. California requires disclosure at collection and, from 1 January 2027, pre-use notices and opt-outs for automated decision-making technology. New York City requires an annual independent bias audit and 10 business days of notice to candidates. Each of those is a procedure with an owner and a trigger. A policy is simply where you write the procedures down so that the same thing happens when you are not in the room.
Australia. The Commonwealth policy for the responsible use of AI in government, version 2.0, requires an accountable official, a public AI transparency statement, an internal AI use-case register with named owners, and an impact assessment before deployment - and those requirements travel to suppliers through procurement, so private firms selling to government inherit them. From 10 December 2026 the Privacy Act requires the privacy policy itself to describe the kinds of decisions made by a computer program.
The test is the same everywhere. A policy that names an owner, points at a register and states a trigger is an instrument. A policy that states principles and commits to being responsible is decoration, and it will read as decoration to an Irish market surveillance authority, a UK regulator, a state attorney general and an Australian privacy commissioner alike. We draft the instrument version, in Ireland, the United Kingdom, the United States and Australia.
A reasonable order of work
Inventory first - you cannot write a policy for systems you have not listed. Then the three lists. Then ownership and oversight. Then the policy document itself, which by that point almost writes itself, because it is a description of arrangements that already exist rather than a promise about ones that do not.