Govern how your staff use artificial intelligence across your authority or public body, without slowing them down. Download our free AI policy template (Word and PDF, ready to adapt) and discover, point by point, what a public-sector AI policy should contain.
An AI policy for the public sector is an internal document that sets the rules for how staff and elected representatives use artificial intelligence: permitted uses, data protection (GDPR), transparency towards citizens and systematic human validation. It is not mandatory, but it is strongly recommended to deploy AI responsibly and to reassure both staff and citizens. You can start from our free template to download and adapt it to your organisation.
An AI policy is an internal frame of reference. It answers a simple question more and more public-sector staff are asking: “Am I allowed to use ChatGPT or another AI tool for this case, and how?”. Rather than letting everyone improvise — or avoid AI out of caution — the policy sets clear, shared and owned rules.
For a public sector organisation, the stakes are specific: you handle citizens' data, you are subject to the GDPR and to the duty of transparency of public action, and you must guarantee equal treatment of citizens. An AI policy lets you capture the time savings of AI (drafting letters, minutes, replies to citizens) while securing these requirements.
No, no law currently requires a specific AI policy. However, several existing obligations make it strongly advisable: the GDPR (protection of personal data), the duty of transparency of algorithmic processing, and the general responsibility of public officials. The policy is the simplest way to turn these principles into concrete rules for your teams.
A policy is not a brake on innovation: it is what lets your staff use AI without fear, because the frame is clear.
Your staff know what is permitted, restricted or prohibited. No more AI on the sly or self-censorship out of caution.
The policy forbids entering citizens' data into unmanaged tools and mandates EU-hosted tools.
You inform citizens when a service relies on automated processing, as public action requires.
AI prepares and suggests, the officer validates and decides. No administrative decision is left to AI alone.
The policy comes with awareness: good practice, data vigilance, detection of errors and bias.
Towards elected officials, staff and citizens: showing a managed use of AI enhances the organisation's image.
Here are the nine sections we built into the downloadable template. You can reuse them as-is and adapt them to your organisation.
Who is covered (staff, elected representatives, interns, contractors) and which tools are in scope — from consumer assistants to AI built into your business software.
The non-negotiable values: human responsibility, transparency, data protection, equal treatment, proportionality and restraint.
The most concrete part: what staff may do (draft a letter, summarise a document), what needs extra caution, and what is strictly prohibited (entering personal data into an unmanaged tool).
Data minimisation, defined purpose, EU hosting, the role of the DPO. Citizens' data is never used to train public models.
The information owed to citizens when a decision is based on algorithmic processing.
Any output intended for external use (letter, act, reply to a citizen) is reviewed and validated by a competent officer before release.
The commitment to raise awareness and train staff in the responsible use of AI, and to support them with every new tool.
Appointing an AI lead (or committee) who oversees the policy, centralises questions and validates new tools with the DPO.
An annual review clause, plus every significant regulatory or technological change, to keep the policy alive and up to date.
A ready-to-use template, structured in 9 articles, with fields to fill in ([Organisation name], AI lead, date). Available in Word (editable) and PDF. Adapt it freely to your authority or public body. Free, no sign-up.
This template is a sample document provided for information. It does not constitute legal advice: have it validated internally (DPO, legal) before adoption.
A policy sets the rules, but it doesn't save time on its own. The real lever is to deploy AI agents tailored to the public sector: drafting letters and resolutions, first-line replies to citizens, document summaries. All on a sovereign France / EU infrastructure, GDPR-compliant by default.
Not sure where to start? We offer a free 15-minute AI training and audit: together we identify your organisation's automatable tasks, with no jargon and no commitment.
We help you move from the frame to action: AI agents for your letters, resolutions and citizens, on sovereign infrastructure. First call free, remote.
Book a first call →