TL;DR: An AI policy is a short written document. It says what AI your product uses. What data feeds it. What users are told. And who owns it. Three groups will ask you for it: big buyers, auditors, and — from August 2, 2026 — EU watchdogs. Lovable, Bolt, and Cursor wrote your code. None of them wrote this. Here are the seven sections it needs, and a plan to ship it this week.

QuestionAnswer
What is an AI policy?
A written record of how your product uses AI: models, data, what users are told, and who owns it.
Who asks for it?
Big buyers, SOC 2 auditors, and EU watchdogs after August 2, 2026.
Which law applies?
EU AI Act Article 50 (tell and label) and Article 4 (AI skills).
What is the fine tier?
Up to €15M or 3% of turnover for transparency breaches — not the €35M headline.
How long should it be?
Two to four pages at seed stage. Seven sections, listed below.

What an AI policy is — and what it is not

An AI policy is one document. It explains your AI features to people outside your team. It is not your privacy policy. It is not the disclosure banner in your chat window. It is not a rule sheet for staff who use ChatGPT. It is the written record that ties all three together.

Think of it as a map. It lists each AI feature. It shows what data flows into each model. It states what users are told, and where. It names the person who owns it. That is the whole job.

Founders mix this up with the wording users see. The two are linked but not the same. The banner in your product is the output. The policy is the record behind it. Need the banner wording itself? We published ready-to-use Article 50 wording you can paste in. This guide covers the document behind the banner.

Three groups will ask for this document

Big buyers. Security forms now carry an AI section. "Does your product use AI? Which models? What customer data reaches them?" A blank answer stalls the deal. One page pulled from your AI policy closes the question in minutes.

Auditors. SOC 2 treats your model vendors like any other vendor. Your auditor will ask how you vetted them. And who reviews that choice. A written AI policy is the proof they want to see. We cover the wider audit path in our SOC 2 guide for AI-built startups. Honest note: we prep you for SOC 2. We do not certify it. The same logic applies to ISO 27001.

EU watchdogs. From August 2, 2026, Article 50 of the EU AI Act sets two duties. Tell users they are talking to AI. Label AI-made content. Article 4 adds a third: your team needs basic AI skills. No duty names one single document. But when a watchdog asks how you meet them, the answer is a written record. The fine tier for these breaches runs up to €15M or 3% of global turnover. The €35M / 7% ceiling applies only to banned practices. Our fines guide maps the full tier system.

The seven sections your AI policy needs

1. AI feature inventory. List every place your product uses AI. The chat helper. The summary writer. The scoring logic. For each one, name the model or API behind it. If you cannot list your own AI features, no one else can check them.

2. Data flows. For each feature, write down what user data reaches the model. Prompts? Uploaded files? Account fields? This section does double duty. It is also the core of your GDPR records. Our data mapping guide for AI apps shows the method.

3. User disclosure. State where and how users learn they are talking to AI. Quote the exact copy. Name the screens it appears on. This is the section that maps to Article 50(1).

4. Content labeling. Does your product make text, images, or reports that users export or share? State how that output is marked as AI-made. This maps to Article 50(4).

5. Human oversight. Say what happens when the AI gets it wrong. Who reviews flagged outputs? Can a user reach a human? One short passage is enough — but it must be true.

6. Retention and deletion. Chat logs and AI outputs need a delete schedule. "We keep prompt logs for 90 days, then delete them" is a policy. Silence is not.

7. A named owner. One person owns this document. That person reviews it each time you ship a new AI feature. At seed stage this is usually the founder. Write the name down anyway.

Selling into the EU? Two free tools help. Our Annex IV generator drafts the deeper technical file for you. The Article 4 team training covers the AI-skills duty.

Your builder wrote the code, not the paperwork

Vibe-coding tools are good at shipping features. They do not write policy papers. And they do not tell you one is missing. The gap stays hidden until someone asks.

Here is the awkward part. It is easy to tell, from the outside, which AI tool built your product. Our scanner fingerprints the platform behind a URL using DNS patterns (platformFingerprintScanner.js:22) and script paths (platformFingerprintScanner.js:289) — no code access needed. A buyer's security team can do the same. If they can see your app was AI-built, and you have no AI policy to show, the security form gets longer, not shorter.

The scan data backs this up. Across 100 AI-built apps we audited, the average Launch Readiness Score was 42/100. The builds that miss security headers and rate limits also skip the AI banner and the paperwork behind it. It is one pattern, not two.

The deadline math: 25 days

August 2, 2026 is 25 days away. The Article 50 duties apply from that date. They follow your users, not your office. A US company with EU users is in scope. There is no small-team carve-out.

The good news: an AI policy is the cheapest compliance win you will ever ship. No code changes. No vendor contracts. A founder who knows the product can draft it in one afternoon with the seven sections above. The banner and labels it describes are small copy changes. Compare that with the cost of facing a watchdog — or losing a big deal — without one.

How to ship your AI policy this week

Day 1: Draft the seven sections. Bullet points are fine. True beats polished.

Day 2: Check the product against the draft. Does the AI banner really appear where the policy says it does? Fix the gaps you find. Our vibe coding compliance checklist walks the wider sweep.

Day 3: Publish a short public version on your site. Keep the full version for buyers and auditors. Link it from your privacy policy.

Day 4: Test your own product like an outsider. Run the free scan for the security side. Want the compliance side measured properly? The Compliance Score runs 60 automated checks — GDPR, EU AI Act, SOC 2 and ISO 27001 foundations — including an AI policy gap analysis. It is $799 one-time. The fee is credited toward DFY Compliance Setup if you want the fixes done for you.

Day 5: Put a review date in the calendar. The policy is alive. New AI feature, new section.

Earlier in the journey? Start broad with the EU AI Act compliance guide and the pre-launch checklist.

FAQ

Do SaaS startups really need an AI policy?

Yes, once your product has any AI feature and real users. Big buyers ask for it in security reviews. Auditors ask for it in SOC 2 prep. And from August 2, 2026, EU watchdogs can ask how you meet the AI Act's duties. One short document answers all three.

Is an AI policy the same as a privacy policy?

No. A privacy policy covers all personal data. An AI policy covers your AI features. Which models you use. What data feeds them. How users are told. And who owns it. The two documents link to each other. Neither replaces the other.

What should an AI policy include?

Seven sections. A list of AI features. The data that flows to each model. What users are told. Content labels. Human review. Delete rules. And a named owner. Two to four pages is normal for a seed-stage SaaS.

Does the EU AI Act require a written AI policy?

The Act does not name one document. But from August 2, 2026, Article 50 says users must be told, and AI content must be labeled. Article 4 requires AI skills in your team. The only way to prove those duties are met is a written record. That record is your AI policy.

What fine applies if my AI transparency duties are not met?

The disclosure tier runs up to 15 million euros or 3% of global turnover. The larger 35 million euro / 7% ceiling applies only to banned AI practices, such as social scoring. A normal SaaS with a chatbot sits in the 15 million euro tier.

How do I find my AI compliance gaps before writing the policy?

Run a check against your live product. Launch Ready Code's Compliance Score runs 60 automated checks across GDPR, the EU AI Act, SOC 2, and ISO 27001 foundations. It also checks your AI policy and shows each gap it finds. The $799 fee is credited toward DFY Compliance Setup if you want the fixes done for you.

The document is small. The doors it opens are not. Write the seven sections. Wire the banner. Let the paperwork match the product. Then check the rest of the build the same way a buyer would.

Run the free scan — $0, about 30 seconds