Back to the kit

Evidence Kit · Samples

Full samples, nothing held back

These are complete documents, generated for a fictional company — Northwind Talent, a recruiter whose CV-ranking tool lands in Annex III point 4. Nothing is truncated and nothing is watermarked. If they are not worth paying for, you will know before you pay.

Placeholders marked [to be completed] are deliberate: they are the points where only you can supply the fact, and a blank invites the conversation that a confident guess would skip.

Sample. Fictional organisation and system. Do not use this as your own record — the reasoning in it belongs to a company that does not exist.

AI usage policy

Northwind Talent GmbH, HRB 998877, Berlin

For all staff, contractors and anyone acting on behalf of the organisation.

1. Purpose and scope

This policy governs how everyone working for Northwind Talent may use artificial intelligence tools, whether those tools are provided by the organisation or found by staff themselves. It exists to keep our use of AI lawful under Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744 (the "Digital Omnibus on AI"), in force 27 July 2026 and the GDPR, to protect confidential and personal information, and to make sure decisions that affect people remain ours.

It applies to employees, contractors, temporary staff and anyone else acting on behalf of Northwind Talent, in every department, including use on personal devices for work purposes.

Organisation
Northwind Talent GmbH, HRB 998877, Berlin
Policy owner
Jana Novak — Head of People Operations, acting AI compliance owner
Effective from
2026-09-11
Approximate population in scope
51-250 people using AI tools at work
Next review
[to be completed]

2. Why this matters legally

Art. 3(4); Art. 25; Art. 26; Art. 99

When we use an AI system under our own authority we are a deployer under Article 3(4), and deployers have their own obligations — they are not simply the customer of a compliant vendor. Two specific traps matter for an organisation of our size:

  1. Becoming a provider by accident. Under Article 25, putting our name or trademark on a high-risk AI system, making a substantial modification to one, or changing the intended purpose of a system so that it becomes high-risk makes us the provider, with the full Chapter III obligations. Fine-tuning a model and shipping it as our own feature crosses that line.
  2. Drifting into a high-risk use case. A general tool used for a specific purpose can land in Annex III. One recruiter using a chatbot to screen CVs can put the organisation inside Annex III point 4, whatever the tool was bought for.

3. What is never allowed

Art. 5

The following are prohibited outright, by law and by this policy. There is no approval route and no business case that makes them acceptable.

  • Using AI to score people on social behaviour or personal characteristics in a way that leads to detrimental treatment (Article 5(1)(c)).
  • Inferring the emotions of colleagues or candidates in the workplace, or of students in education, other than for genuine medical or safety reasons (Article 5(1)(f)).
  • Using biometric data to deduce race, political opinions, trade-union membership, religious or philosophical beliefs, sex life or sexual orientation (Article 5(1)(g)).
  • Predicting whether an individual will commit a criminal offence based solely on profiling or personality traits (Article 5(1)(d)).
  • Scraping facial images in an untargeted way from the internet or CCTV to build or expand a face-recognition database (Article 5(1)(e)).
  • Exploiting someone's age, disability, or social or economic situation, or using subliminal or manipulative techniques, to distort their behaviour to their significant detriment (Article 5(1)(a) and (b)).
  • Generating intimate imagery of an identifiable person without their consent, or any child sexual abuse material. These two become prohibitions on 2 December 2026 under Article 5(1)(ba) and (bb), and they are already a dismissal matter here.

4. Confidentiality and personal data

GDPR Arts. 5, 6, 9, 28, 32, 44–49

Do not enter any of the following into an AI tool that has not been approved for that class of data:

  • Personal data of clients, candidates, patients, pupils or employees — including CVs, contact details and anything that identifies a person indirectly.
  • Special categories of personal data: health, biometric data used to identify someone, racial or ethnic origin, political opinions, religious beliefs, trade-union membership, sex life or sexual orientation.
  • Client confidential material: contracts, commercial terms, unpublished financials, drafts covered by an NDA.
  • Our own trade secrets, unreleased product plans, security details or credentials of any kind.
  • Anything a client has told us in confidence, whether or not it is personal data.

Before a tool is approved for personal data, the policy owner must confirm: a lawful basis exists; a data processing agreement under GDPR Article 28 is in place; the transfer position outside the EEA is covered; the retention and training-use settings are configured so our inputs are not used to train the vendor's models unless we have decided otherwise in writing; and, where required, a data protection impact assessment has been done.

5. Approved tools, and how to get one approved

ToolApproved forPersonal data allowed?OwnerReviewed
ChatGPT[to be completed][to be completed]Jana Novak[to be completed]
Microsoft Copilot[to be completed][to be completed]Jana Novak[to be completed]
DeepL[to be completed][to be completed]Jana Novak[to be completed]
Pre-filled from the tools you told us are in use. Complete the remaining columns; an entry you cannot complete is an entry you should not be using yet.

To add a tool, send the policy owner: what it is for, what data it will see, who the vendor is, and whether its output will influence a decision about a person. The owner records the answer in the register above and in the AI system inventory. Using an unapproved tool for client or personal data is a disciplinary matter.

6. Human responsibility for output

Art. 14; Art. 26(2); Art. 26(4)

  • You remain responsible for anything you send, publish or decide with AI assistance. "The tool produced it" is not an explanation.
  • Check facts, figures, names, citations and quotations before they leave the organisation. These tools produce fluent text that is sometimes wrong, and the fluency is the risk.
  • Never let an AI system take a final decision about a person — hiring, promotion, dismissal, credit, pricing, access to a service, discipline, or anything with a comparable effect. AI may inform such a decision; a named person takes it and can explain it.
  • Where a system is high-risk, oversight must be assigned to people with the necessary competence, training and authority, and with the support to override or stop the system (Article 26(2)). Where we control the input data, it must be relevant and sufficiently representative of the intended purpose (Article 26(4)).

7. Telling people when they are dealing with AI

Art. 50

Where we deploy AI that people interact with or that produces content they see, disclosure duties under Article 50 apply, and they apply now. Nobody outside the organisation should be left believing they are dealing with a person when they are not, or that generated content is genuine.

  • Customer-facing chat, voice or automated correspondence must say it is AI at or before the first interaction (Article 50(1)).
  • Deep fakes and other generated or manipulated image, audio or video must be disclosed as artificially generated (Article 50(4)).
  • Emotion recognition or biometric categorisation requires a notice to the people exposed to it (Article 50(3)) — and check Article 5 first, because several such uses are prohibited.
  • Do not claim that a human reviewed something unless a named human actually did.

8. High-risk systems

Art. 26; Art. 27; Art. 49

If a system we deploy is high-risk — most commonly in recruitment, worker management, education, creditworthiness, insurance pricing or access to essential services — the following apply in addition to everything above, from 2 December 2027 for Annex III systems:

  • Use it in accordance with the provider's instructions for use, and obtain those instructions before deployment.
  • Assign human oversight to named, competent people with authority to intervene (Article 26(2)).
  • Keep the automatically generated logs we control for at least six months (Article 26(6)).
  • Inform workers' representatives and affected workers before putting it into use in the workplace (Article 26(7)).
  • Inform people that they are subject to the system where it is used to make or assist decisions about them (Article 26(11)).
  • Carry out a fundamental rights impact assessment before first use if we are a public-law body or a private entity providing public services, or if the system is an Annex III point 5(b) creditworthiness or 5(c) life and health insurance system (Article 27). It may be done together with a GDPR DPIA (Article 27(4)).
  • Confirm the system is registered in the EU database (Article 49) — a duty that is not deferred.

9. When something goes wrong

Art. 73; GDPR Art. 33

Report immediately to Jana Novak if: confidential or personal data was entered into an unapproved tool; an AI output caused or nearly caused harm to a person; a decision about a person turned out to rest on an AI error; or you suspect a tool is doing something in the prohibited list.

Reporting promptly is always the right call and will not itself be treated as misconduct. Concealing it will. Where personal data is involved the GDPR 72-hour breach clock may be running, and for high-risk systems the provider has serious-incident reporting duties under Article 73 that depend on us telling them.

10. Training and acknowledgement

Art. 4

Article 4, as rewritten by Regulation (EU) 2026/1744, expects providers and deployers to ensure a sufficient level of AI literacy among staff dealing with AI systems, proportionate to the context and the risk. Our approach is set out in the AI literacy plan. Everyone in scope completes the induction module before using AI tools for work, and a refresh annually.

Policy owner

Approved by

Date

Staff acknowledgement

I have read the Northwind Talent AI usage policy dated 2026-09-11. I understand what I must not put into an AI tool, that I remain responsible for output I use, and that I must report incidents to the policy owner without delay.

Name: ______________________  Signature: ______________________  Date: ____________

What a lawyer should check

Hand this list to counsel with the document. It is short on purpose — these are the points where a generated record most often diverges from the facts of a real organisation.

  1. Whether the policy is consistent with your employment contracts, works council agreements and disciplinary procedure — in several Member States a policy of this kind requires consultation before it can be enforced.
  2. Whether the confidentiality rules match your client contracts and professional obligations, which may be stricter than the law.
  3. Whether the approved-tools register reflects a lawful basis and an Article 28 GDPR processor agreement for each tool handling personal data.
  4. Whether any current use has already drifted into Annex III or engaged Article 25, which would change the obligations before 2027.
  5. Whether the incident-reporting route aligns with your existing GDPR breach procedure and reporting lines.
  6. This document is a structured record of an assessment you made, drafted for your review. It is not legal advice and it does not bind any authority.
  7. It reflects Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744 (the "Digital Omnibus on AI"), in force 27 July 2026. The Commission's guidelines on high-risk classification under Article 6(5) were due on 2 February 2026 and remain in draft (version of 19 May 2026), so classification positions that depend on them may change.
  8. No harmonised standard has yet been cited in the Official Journal, so the presumption of conformity in Article 40 is not available to anyone.
Generated by euai-act.com — a documented self-assessment, not legal advice.

Generate these for your own system

Run the free Navigator to classify your system, then the kit fills these documents in from your answers.