Most AI acceptable use policies still look like basic HR housekeeping: a short list of approved tools, a caution about confidential data, and a signature line.

What they rarely address is the legal distinction that now carries practical weight in the EU — the difference between employees simply using AI tools and AI systems being used to make decisions about employees.

One sits under the Article 4 literacy duty (already enforceable). The other falls into Annex III high-risk territory (deferred until December 2027).

A practical template and supporting briefing have been published that treat this boundary properly:

The template covers tiered tool approval, data classification rules tied to GDPR triggers, human-review requirements linked to legal effect, and a structure designed to serve as Article 4 evidence rather than a static onboarding PDF.

For teams responsible for AI governance, HR policy, or compliance in organisations operating in the EU, the materials are available for immediate use.