Home  ›  Resources  ›  AI policy for the public sector
🏛️
Public sector · Free template

AI policy for the public sector

Govern how your staff use artificial intelligence across your authority or public body, without slowing them down. Download our free AI policy template (Word and PDF, ready to adapt) and discover, point by point, what a public-sector AI policy should contain.

In short

An AI policy for the public sector is an internal document that sets the rules for how staff and elected representatives use artificial intelligence: permitted uses, data protection (GDPR), transparency towards citizens and systematic human validation. It is not mandatory, but it is strongly recommended to deploy AI responsibly and to reassure both staff and citizens. You can start from our free template to download and adapt it to your organisation.

What is an AI policy?

An AI policy is an internal frame of reference. It answers a simple question more and more public-sector staff are asking: “Am I allowed to use ChatGPT or another AI tool for this case, and how?”. Rather than letting everyone improvise — or avoid AI out of caution — the policy sets clear, shared and owned rules.

For a public sector organisation, the stakes are specific: you handle citizens' data, you are subject to the GDPR and to the duty of transparency of public action, and you must guarantee equal treatment of citizens. An AI policy lets you capture the time savings of AI (drafting letters, minutes, replies to citizens) while securing these requirements.

Is an AI policy mandatory for a public body?

No, no law currently requires a specific AI policy. However, several existing obligations make it strongly advisable: the GDPR (protection of personal data), the duty of transparency of algorithmic processing, and the general responsibility of public officials. The policy is the simplest way to turn these principles into concrete rules for your teams.

Why adopt one

Six good reasons to adopt an AI policy

A policy is not a brake on innovation: it is what lets your staff use AI without fear, because the frame is clear.

Frame the uses

Your staff know what is permitted, restricted or prohibited. No more AI on the sly or self-censorship out of caution.

Protect data (GDPR)

The policy forbids entering citizens' data into unmanaged tools and mandates EU-hosted tools.

Transparency towards citizens

You inform citizens when a service relies on automated processing, as public action requires.

Human responsibility

AI prepares and suggests, the officer validates and decides. No administrative decision is left to AI alone.

Train and reassure staff

The policy comes with awareness: good practice, data vigilance, detection of errors and bias.

Build trust

Towards elected officials, staff and citizens: showing a managed use of AI enhances the organisation's image.

What it should contain

What an AI policy should contain

Here are the nine sections we built into the downloadable template. You can reuse them as-is and adapt them to your organisation.

1. Purpose and scope

Who is covered (staff, elected representatives, interns, contractors) and which tools are in scope — from consumer assistants to AI built into your business software.

2. Guiding principles

The non-negotiable values: human responsibility, transparency, data protection, equal treatment, proportionality and restraint.

3. Permitted, restricted and prohibited uses

The most concrete part: what staff may do (draft a letter, summarise a document), what needs extra caution, and what is strictly prohibited (entering personal data into an unmanaged tool).

4. Data protection and GDPR compliance

Data minimisation, defined purpose, EU hosting, the role of the DPO. Citizens' data is never used to train public models.

5. Transparency towards citizens

The information owed to citizens when a decision is based on algorithmic processing.

6. Human oversight and validation

Any output intended for external use (letter, act, reply to a citizen) is reviewed and validated by a competent officer before release.

7. Training and support for staff

The commitment to raise awareness and train staff in the responsible use of AI, and to support them with every new tool.

8. Governance and AI lead

Appointing an AI lead (or committee) who oversees the policy, centralises questions and validates new tools with the DPO.

9. Review and revision

An annual review clause, plus every significant regulatory or technological change, to keep the policy alive and up to date.

Free template · editable Word

Download your AI policy template

A ready-to-use template, structured in 9 articles, with fields to fill in ([Organisation name], AI lead, date). Available in Word (editable) and PDF. Adapt it freely to your authority or public body. Free, no sign-up.

This template is a sample document provided for information. It does not constitute legal advice: have it validated internally (DPO, legal) before adoption.

The policy is the frame. What next?

A policy sets the rules, but it doesn't save time on its own. The real lever is to deploy AI agents tailored to the public sector: drafting letters and resolutions, first-line replies to citizens, document summaries. All on a sovereign France / EU infrastructure, GDPR-compliant by default.

Not sure where to start? We offer a free 15-minute AI training and audit: together we identify your organisation's automatable tasks, with no jargon and no commitment.

Frequently asked questions

Your questions about AI policies

What is an AI policy for the public sector?
It is an internal document that sets the rules for how staff and elected representatives use artificial intelligence: permitted, restricted and prohibited uses, data protection (GDPR), transparency towards citizens and systematic human validation of AI outputs.
Is an AI policy mandatory?
No, no law requires a specific AI policy. But it turns existing obligations into concrete rules: the GDPR, the transparency of algorithmic processing, and the responsibility of public officials. It is therefore strongly recommended.
What should an AI policy contain?
At minimum: purpose and scope, guiding principles, the list of permitted, restricted and prohibited uses, GDPR rules, transparency towards citizens, human validation, staff training, governance (AI lead) and a review clause. Our free template covers these 9 sections.
Who writes the AI policy in a public body?
It is led by senior management with the support of the Data Protection Officer (DPO) and, ideally, an AI lead. Starting from an existing template speeds up the work: you adapt rather than start from a blank page.
Is the template really free?
Yes, fully and with no sign-up. It is an editable Word document you download and adapt freely to your organisation. It is provided for information and does not replace internal legal validation.
Is the template available in Word and PDF?
Yes, both. Download the Word version if you want to adapt the policy to your organisation, or the PDF if you just want to read, print or circulate it as-is. Both formats are free and need no sign-up.
Is an AI policy enough to be GDPR-compliant?
No. The policy sets usage rules, but GDPR compliance also relies on technical measures (EU hosting, pseudonymisation, strict scope of use) and organisational ones. The policy and a secure architecture are complementary.
Can AI be used safely in a public body?
Yes, provided its use is framed: managed, EU-hosted tools, no personal data in consumer tools, and human validation of every output. That is the role of the policy, complemented by AI agents designed for the public sector.

Need to go beyond the policy?

We help you move from the frame to action: AI agents for your letters, resolutions and citizens, on sovereign infrastructure. First call free, remote.

Book a first call →