Draft your one-page AI policy in five minutes.
Free, no card. Take the draft to your DPO and your management.
The interview is not live yet — check back shortly.
Why? Shadow AI is not shadow IT: tools rotate every quarter, share nothing with each other, and act on your systems instead of just advising. Under EU law the employer is accountable, unless the policy is written, training is done, and instructions were followed.
Read the full article: Shadow AI is not your employees' fault. You have not written the rules.
What you walk away with.
A one-page AI Acceptable Use Policy (AAUP) for your employees, signed-ready, with the seven clauses your DPO and auditor expect: scope, approved tools by data tier, prohibited uses (EU AI Act Article 5), customer disclosure (Article 50), oversight, training, and review cadence. It is the document you hand to every employee, contractor and intern using AI for work.
The chat fills in the blanks from a short interview. You edit anything inline, then export the PDF.
Frequently asked
Why no account?
No password, no profile, no dashboard. Your draft stays in your browser. We ask for your email once, at the end of the chat, before you edit the draft. On submit we receive your draft alongside your email so we can support you.
Why do you ask for my email?
Two reasons. One: in a future version we will deliver the PDF straight to your inbox, so you do not have to download it yourself. Two: if you tick the separate opt-in box, we will notify you when our next free tool, the operational checklist, ships. The email is stored with Brevo in the EU.
Can I edit my draft later?
Yes, from the same browser. Drafts live in your browser's local storage, up to 10 at a time. Pick Clear my draft on the chat screen to wipe one.
Is this legal advice?
No. It is a starting draft you can take to your DPO, your legal counsel, and your management. The schema is based on Belgian and EU law (GDPR, EU AI Act Articles 4, 5 and 50). It becomes a real policy once your DPO and management sign off.
Which AI model, and where?
Mistral Large, called directly through Mistral's EU API. Your chat goes through an airlock edge worker in the EU that does not log message content unless you submit the final draft. No US hop, no third-party logging.
Does the bot look up my company online?
Once, on the first turn, with the legal name you give. It uses that to pre-fill obvious public defaults like sector, country, and regulated overlay so you spend the chat editing instead of typing. It will not search for individual people, your customer lists, or anything non-public.
What if I hit the 5-per-day limit?
You can come back tomorrow when the window resets. If you want a reminder, leave your email on the limit page. We will also let you know when our next free tool, the operational checklist, ships.
Can I share the chat with someone else?
You can download the PDF and share that. The chat itself stays in your browser and has no share link.
Made by airlock. The cross-vendor governance layer for MCP, Skills and Agents.
EU-hosted on AWS Frankfurt. Backed by Start it @KBC.