hostme.ie YOUR IT DEPARTMENT
Home› Blog› Business IT
Business IT

AI Policy for Employees: Practical Steps for Irish SMEs

Practical AI policy for Irish SMEs: what to include, DPIA triggers, human review before decisions, and an 8 point checklist you can adapt without a big IT...

Small business team reviewing AI policy tools

Yes. Every employer should have a written AI policy that defines what staff can and can’t use AI for, sets out when a Data Protection Impact Assessment is required, and insists on human review before any AI output shapes a decision about a person. The policy needs clear scope, defined approval steps and named owners, and this guide walks through each part with a checklist you can adapt.


TL;DR:

  • AI risk depends on the intended use, the data involved and the people affected. Recruitment and employee-monitoring tools need particular scrutiny; using customer data does not by itself establish an AI Act high-risk classification.
  • A GDPR Data Protection Impact Assessment is required before personal-data processing likely to create high risk to people’s rights and freedoms. Assess that threshold separately from the AI Act classification.
  • Human review of AI outputs must precede any decisions impacting staff or customers, and vendors should provide documentation on training and testing of their AI models.
  • A simple AI policy should list all tools in use, specify unacceptable uses, assign ownership, and include DPIA triggers plus oversight procedures. A policy alone does not establish legal compliance.
  • Smaller enterprises benefit from focusing on core controls like human oversight, DPIAs when required, and clear ownership rather than extensive governance frameworks.

Hostme
Put Practical AI Controls in Place
Hostme helps small businesses set up practical AI tools, train staff and create workflows suited to everyday business needs.

Explore AI support

Table of Contents

What an AI policy should cover

A usable AI policy starts with definitions. “AI” should cover generative tools like ChatGPT, Claude and Copilot, plus any plugins, browser extensions or embedded AI features inside your existing software. Without a clear scope, staff will assume a tool doesn’t count just because it wasn’t built specifically as “AI”.

From there, the policy needs to set out what’s allowed, what needs sign-off first, and what’s off-limits entirely. Most small businesses find a simple traffic-light approach works better than a long list of exceptions.

The policy should include:

  • Scope and definitions, naming the tools covered and the tasks they’re approved for.
  • Acceptable and prohibited uses, including any approval workflow for new tools staff want to try.
  • Roles and responsibilities, naming who in HR, IT and management owns each part of the policy.
  • Transparency commitments, explaining how you’ll tell employees and customers when AI is involved in a decision that affects them.
  • Record-keeping requirements, covering what gets logged when AI is used for anything customer-facing or HR-related.

If you don’t have a data protection officer, name whoever handles data protection queries: it might be you, or it might be an external adviser. The point is that someone owns it, and staff know who to ask when a new AI tool turns up. Our guide to GDPR for small Irish businesses introduces the underlying data protection considerations.

GDPR already applies to most AI use involving personal data, and it sets the floor for your policy. A Data Protection Impact Assessment becomes mandatory when processing is likely to create a high risk to people’s rights, which official DPIA guidance says includes systematic monitoring and automated decision-making with legal or significant effects on someone. If you’re using AI to screen CVs, monitor performance or make decisions about pay, promotion or discipline, a DPIA is very likely required before you switch it on.

The EU AI Act adds a second layer. It takes a risk-based approach, meaning your obligations depend on how a system is classified. Employment-related AI, including recruitment tools and systems used to evaluate staff, can fall into the higher-risk categories, which brings documentation, transparency and human oversight requirements with it according to the risk category assigned. Mapping which systems you use, and what they’re classified as, is the first practical step.

Check the European Commission’s current AI Act guidance for classification, applicable obligations and phased dates, and the DPC’s DPIA guidance for the separate GDPR assessment. Do not assume every AI tool has the same requirements.

Enforcement under the AI Act carries penalties scaled to the severity of breaches and organisational size. That’s reason enough to treat mapping and risk classification as a priority rather than something to get to eventually.

Common risk areas and practical controls

Some AI uses carry more risk than others, and it helps to know where to focus.

  • Recruitment and scoring tools can embed bias from historical data, so any automated shortlisting needs human review before a candidate is rejected.
  • Covert monitoring through AI-powered tracking or analytics tends to breach transparency requirements, similar to the concerns raised in DPC guidance on vehicle tracking, which calls for a clear legal basis and proportionate use.
  • Location tracking through AI-enabled apps requires a documented purpose, lawful basis, necessity and proportionality assessment, with clear information for staff. An opt-out alone does not establish lawful monitoring, particularly outside working hours.
  • Hallucinated output from generative tools can look confident and be wrong, which is why AI-generated text or figures should never go straight into a contract, a reference or a customer communication unchecked.

The controls that matter most: human review before any AI output affects a real decision, bias checks on scoring tools, data minimisation so AI systems only see what they need, sensible retention limits, and access controls that stop unapproved staff experimenting with sensitive data in public AI tools.

Before adopting a new AI tool, ask the vendor for documentation on how the system was trained and tested, and evidence they’ve considered their own EU AI Act obligations as a provider. A vendor who can’t answer basic questions about their model is a vendor to be cautious with.

Pro Tip: Treat every AI output the same way you’d treat a first draft from a junior colleague: useful, but not final until someone checks it.

Policy checklist and template elements

Turning the above into a document doesn’t need to be complicated. Work through this order:

  1. List every AI tool in use, including ones staff have adopted informally, before writing a single clause.
  2. Flag which tools touch personal data or decisions about people, since these are your DPIA candidates.
  3. Run DPIAs where triggered, using the DPC’s DPIA guidance as your checklist for what to assess.
  4. Draft the acceptable use clause, stating plainly what’s approved, what needs sign-off and what’s banned.
  5. Draft the human oversight clause, requiring review of AI output before it affects a customer, employee or business decision.
  6. Assign owners, naming who approves new tools and who handles incidents.
  7. Set a training timetable, covering what staff need to know before they’re allowed to use approved tools unsupervised.
  8. Add consequences, describing what happens if the policy is breached, in the same tone as your other conduct policies.

Sample wording you can adapt: for acceptable use, try “Staff may use [tool] for [task] but must not input customer personal data without approval from [role].” For oversight, try “No AI-generated content or decision may be finalised or acted upon without review by a named human decision-maker.”

Assign the tool inventory to whoever manages IT day to day, the DPIA to whoever owns data protection, and training to HR, with a realistic first review date rather than an open-ended promise to “get to it”.

Implementing, monitoring and enforcing the policy

Roll the policy out in phases rather than all at once: inventory the tools in use, assess and DPIA where needed, train staff, set up approval routes, then monitor. Review the policy at least annually, or sooner if a new tool or use case appears.

Phased implementation process for an AI policy

Set a simple review cadence: who checks the tool inventory, how often, and what triggers an update. Any incident, a data leak, a wrongly automated decision, or a tool behaving unexpectedly, should have a clear reporting route and a named person to escalate to.

For small teams, proportionality matters. Spend the most effort on recruitment tools, performance monitoring and anything touching customer data, and keep lighter-touch rules for low-risk uses like drafting internal emails.

How hostme.ie helps small businesses put this into practice

Hostme.ie provides hands-on setup and staff training for ChatGPT, Claude and Microsoft Copilot, tailored to what your business actually needs day to day. We can help map your current AI tools, tighten technical controls inside Microsoft 365, and support AI-linked workflows in Dynamics 365 Sales Hub or Customer Service Hub.

A proportionate view on AI governance for small teams

Small businesses don’t need a fifty-page AI governance framework. They need the two or three controls that catch real risk: human review before an AI output affects someone, a DPIA where the law requires one, and a named person who owns the policy. Keep the documentation proportionate, but assess all applicable obligations with an appropriate adviser. Build the controls around actual tasks and review them as your AI use changes. Hostme can help with the technical tool inventory, setup and staff training. Legal interpretation and approval of a compliant policy should come from a suitably qualified adviser.

— hostme.ie

Get help drafting and running your AI policy

Writing the policy is one thing. Setting up the tools properly, training staff to use them safely and keeping the controls working is another. Hostme.ie offers practical, fee-based support for small businesses: clearly scoped projects and training, with the terms agreed before work starts. Ongoing managed IT support has its own minimums and initial contract term.

Work is billed per project or per month, with scope agreed upfront. Message us on WhatsApp to talk through what your business needs, or see our AI for business page for more detail.

Sources

This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.

FAQ

What should be included in an AI policy?

A workable AI policy defines the tools it covers, states acceptable and prohibited uses, names who approves new tools, and requires human review before AI output affects a real decision. It should also set out DPIA triggers, transparency commitments to staff and customers, and record-keeping expectations.

What is the informal “30% rule” for AI?

An informal percentage rule is not a substitute for assessing the task, data and applicable obligations. Record approved uses and review the relevant official guidance before deploying a tool.

Should employers have an AI policy?

Yes. A written policy sets clear expectations for staff, reduces the chance of a data protection breach, and gives you a documented approach if a regulator or employee ever questions how AI was used. It also helps meet DPIA obligations where AI touches high-risk processing.

Which 3 jobs will survive AI?

No official source names specific job categories as immune to AI, so treat any such claim with caution. What’s clearer is that roles requiring judgement, human oversight and accountability for decisions, the same principle your AI policy should apply, tend to keep a human firmly in the loop regardless of which tools are involved.

HHostme
Discuss AI Setup and Training
Contact Hostme to discuss practical AI tool setup, staff training and workflows for your small business.
Got a question about this?
Message me and I'll talk it through — no charge, no jargon.
Message me