An AI acceptable-use policy for fashion teams: a checklist
A practical checklist for writing a short, enforceable AI policy covering tools, data, disclosure, review and incidents, mapped to the AI Act and NIST guidance.

KEY TAKEAWAYS Summary by the editors
- An AI acceptable-use policy should say which tools are approved, what data may be entered, when output needs human review, when AI use must be disclosed and who to tell when something goes wrong.
- Article 4 of the EU AI Act asks providers and deployers to take measures to support the AI literacy of staff and others operating AI on their behalf, which a policy and training together can evidence.
- Article 5 of the AI Act prohibits using AI to infer the emotions of people in the workplace, except for medical or safety reasons, so a policy should rule out such tools for staff.
- The NIST AI Risk Management Framework is voluntary and organises AI risk work into Govern, Map, Measure and Manage, which gives a policy a recognised structure.
- A policy that fits on a few pages and is tied to named owners is more likely to be read and followed than a long document that nobody maintains.
An AI acceptable-use policy for a fashion business should answer six questions on a few pages: which tools are approved, what data may go in, what must be checked before output is used, when AI use has to be disclosed, what is off limits, and who to tell when something goes wrong. The checklist below turns those questions into items a team can tick off, with references to the EU AI Act and to the voluntary NIST framework where they help.
Why does a fashion team need an AI acceptable-use policy?
AI tools reach fashion teams from several directions at once: generative tools for copy and imagery, features embedded in PLM, merchandising and e-commerce platforms, and personal accounts that staff open on their own. Without a policy, each team decides separately what to paste into a prompt, which may include unreleased collections, supplier prices, retailer terms or customer data.
There is also a legal reason. Article 4 of the AI Act asks providers and deployers to take measures to support the AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, education, training and context. The article states that it does not require a guaranteed level of literacy for any individual. A written policy, training records and named owners are a reasonable way to show that such measures exist.
What should the policy cover? The checklist
Use the following list as a starting structure. Each item should end up as a sentence or two in the policy, with an owner.
- Purpose and scope: state who is covered (employees, freelancers, agencies) and which tools (generative assistants, embedded features, agents).
- Approved tools list: name the tools allowed for work, the versions or accounts, and who approves additions.
- Personal accounts: state whether work content may be entered into consumer accounts.
- Data classes: define what may never be entered (for example personal data of customers or staff, unreleased designs, contract terms, supplier cost data) and what is permitted.
- Human review: set which outputs need a named person to check them before use, such as product claims, size and fabric information, legal text and customer messages.
- Disclosure: say when AI use must be disclosed to customers, retail partners or colleagues.
- Intellectual property: state rules for generated designs, prompts that reference named designers or brands, and use of third-party images as inputs.
- Prohibited uses: list uses that are off limits.
- Incidents: explain how to report a wrong, harmful or leaked output, and to whom.
- Training: require onboarding and refreshers, with a record.
- Ownership and review: name the policy owner and a review cycle.

Which data should staff never put into an AI tool?
Data rules are the part of a policy that staff most need to be concrete about. A short table helps.
| Data type | Examples in fashion | Suggested rule |
|---|---|---|
| Personal data | Customer names, order histories, staff records | Only in tools approved for personal data, with a data protection check |
| Confidential commercial data | Unreleased collections, supplier prices, retailer terms, order books | Only in approved tools under contract terms that restrict training and retention |
| Third-party material | Photographs, patterns, licensed text | Only where licence terms allow the use |
| Public information | Published product descriptions, press releases | Generally acceptable |
Retailer and supplier contracts may restrict how their data is processed, so the policy should tell staff to check before entering such material. Where personal data is involved, EU data protection law applies alongside the AI Act, which states in Article 2 that it leaves that law untouched.
When must a human check AI output?
Set review rules by consequence, not by tool. Output that is published, sent to a customer or partner, used in a legal or regulatory statement, or used to make decisions about people deserves a named reviewer. Typical items in fashion include sustainability and material claims, size and care information, price or availability statements, and any text presented as coming from the company. Internal drafts and brainstorming can have lighter review. The policy should also say that the person who publishes the output remains accountable for it, a principle that courts and tribunals have applied to chatbot output on company websites.
What should the policy prohibit?
A prohibited list is short but specific. Candidates drawn from the AI Act include using AI to infer the emotions of employees, which Article 5 bans in the workplace and in education except for medical or safety reasons. Beyond the law, many companies add: entering restricted data into unapproved tools, presenting AI output as human-made where disclosure is expected, generating imagery of real people without consent, and using AI to make or support employment decisions without a documented review. Recruitment and worker-management tools are named as high-risk uses in Annex III of the Act, with obligations applying from December 2027 following the digital omnibus.

How should the policy handle disclosure?
Two layers apply. Legally, Article 50 of the AI Act, applicable from 2 August 2026, requires that people are told when they interact with an AI system, that synthetic content is marked by providers, and that deepfakes are disclosed by deployers. Commercially, retail partners may ask suppliers to state how AI is used in product content. The policy should name who decides on disclosure wording for customers and for partners, so that individual teams do not improvise.
The NIST AI Risk Management Framework, released in January 2023, is intended for voluntary use and is built around four functions: Govern, Map, Measure and Manage. NIST also published a generative AI profile in July 2024. A fashion company can borrow the structure without adopting the whole framework. Govern maps to the owner, approvals and training. Map maps to the register of tools and use cases. Measure maps to review sampling and error tracking. Manage maps to incident handling and tool retirement.
Assign one accountable owner, often from legal, IT or a cross-functional AI group, and a representative from design, merchandising, e-commerce, wholesale and HR. Roll out through short sessions that use fashion examples rather than abstract rules, record attendance, and set a date for the first review. Track questions that arrive in the first months, since they show where the policy is unclear.
Frequently asked questions
Does the AI Act require a company to have an AI policy?
Not by that name. Article 4 asks providers and deployers to take measures to support the AI literacy of their staff and others using AI on their behalf, and a policy plus training is a practical way to evidence such measures. Other duties depend on the risk class of the systems used.
What should a fashion AI policy ban?
At a minimum, entering restricted data into unapproved tools and using AI to infer employees' emotions, which Article 5 of the AI Act prohibits in the workplace except for medical or safety reasons. Many firms also restrict generating imagery of real people and unreviewed use of AI in employment decisions.
Is the NIST AI Risk Management Framework mandatory?
No. NIST describes it as intended for voluntary use. It organises AI risk work into Govern, Map, Measure and Manage and can give an internal policy a recognised structure.
How long should an AI acceptable-use policy be?
Short enough to be read, usually a few pages with a one-page quick reference. Length matters less than named owners, concrete data rules and a review date.
One edition every weekday morning. Read in five minutes. Free for industry professionals.
SOURCES
- AI Act Service Desk (artificialintelligenceact.eu): Article 4, AI literacy
- AI Act Service Desk (artificialintelligenceact.eu): Article 5, Prohibited AI practices
- NIST: AI Risk Management Framework
- AI Act Service Desk (artificialintelligenceact.eu): Article 50, Transparency obligations
- AI Act Service Desk (artificialintelligenceact.eu): Article 2, Scope




