Only 14% of Icelandic companies have an AI policy in place (Statistics Iceland 2025). At the same time, 80% of professionals in the Icelandic labour market use AI at work (Viska 2025). That means that in most companies the use has already begun, just without rules, without oversight and without anyone being responsible.
Why a policy, and why now?
An AI policy is not bureaucracy. It is the answer to three questions your staff are already answering for themselves, each in their own corner: Which tools may I use? Which data may I put into them? How do I know whether the result is correct?
When no policy exists, everyone answers as they see fit. The sales rep pastes a customer list into a free chatbot. The specialist trusts a summary nobody read over. Neither is ill-intended, but both are risks that managers are responsible for, whether they know about them or not.
The good news: the first version of a usable policy is not a months-long project. It fits on two to three pages and it needs four core parts.
Part 1: Approved tools
Start with a list. Do not ban everything and do not allow everything; instead, define three categories: approved tools that the company pays for and configures correctly, tools under review that may be tried with non-identifiable data, and prohibited tools.
The key point about approved tools is the type of subscription. Company subscriptions usually offer the option that data is not used to train models and that administrators have an overview of usage. Free versions rarely do. The same tool can therefore be safe under one subscription and prohibited under another, and the policy needs to say so clearly.
Part 2: Data categories
This is the most important part and the one most often missing. Staff need a simple rule they can remember under time pressure. A three-category system is enough for most:
Public data. examples: Website content, published reports, general enquiries · may go into AI tools?: Yes, into all approved tools
Internal data. examples: Working documents, drafts, procedures, meeting notes without personal data · may go into AI tools?: Only into approved tools with a company subscription
Sensitive data. examples: Personal data, national ID numbers, health data, payroll data, customer data, confidential agreements · may go into AI tools?: No, except with specific approval and documented authorisation
Test the rule on real examples from your own operations. If a customer service employee cannot say within five seconds which category an email from a customer falls into, the classification is too complicated.
Part 3: Verification rules
AI without verification is more dangerous than no AI at all. Research shows that untrained use can make experienced people slower and more confident in the wrong answer (Harvard/BCG 2023). The policy therefore needs to say when output can be trusted and when it cannot.
Simple guidelines that work in practice:
- Everything that leaves the company, to customers, the media or public bodies, goes through human review. Always.
- Figures, dates, names, legal provisions and quotations are verified against the primary source before they are used.
- The person who sends the material is responsible for it, not the tool. "The AI said so" is not a valid excuse, and the policy says so in plain words.
- In tasks where an error is costly, contracts, financial statements, hiring decisions, AI is an aid for drafting but never the final decision.
Part 4: Incident response
Something will go wrong. Someone puts sensitive data in the wrong place, or a wrong answer finds its way to a customer. The policy needs to answer: who reports it, to whom, and what happens next.
The most important decision here is the tone. If an employee who makes a mistake can expect a telling-off, they will keep quiet next time, and that is when the incident becomes dangerous. A policy that punishes honesty produces shadow AI. Define a single place to report, promise that the first response is a solution rather than a hunt for a culprit, and document every incident so the policy learns from them.
Then add an owner and a review cadence: one named person responsible, and a review every three months, because the tool landscape changes monthly.
What you can do right now
- Write one page today. Four headings: approved tools, data categories, verification, incidents. An imperfect policy that exists beats a perfect policy that is still on the drawing board.
- Survey actual usage. Send an anonymous three-question survey: which tools do you use, for which tasks, with which data? The answers show where the policy needs to start.
- Choose an owner. One person with the authority to answer questions about usage within a day. A policy without an owner is a document nobody reads.
[ Get in touch ]
Book a free assessment
90 minutes that pay off immediately: we map your AI usage, risks and 3 to 5 automatable workflows, and deliver a report within a week. No commitment.
In the AI Sprint this is the first task: in week 0 we shape an AI policy with your technical and legal people, tailored to your data, systems and risks. You get a finished usage policy in your hands, a job that takes many companies a whole year, before the training itself begins.
Related articles: