Reshaping the game - 2026 report
AI governance: from policy to practice
Without one clear, risk-based AI-use policy, companies drift into "shadow AI" - with it, every employee knows which tool, which rules, which review step.
Section 9 in two theses
- The worst-case scenario is "shadow AI", a sprawling portfolio of approved and unapproved tools, with leadership blind to the risks being taken.
- One comprehensive AI Use Policy with risk-based rules per use case turns the legal analysis of Sections 3 to 8 into daily practice, including the documentation that now decides ownership disputes.
The preceding chapters have highlighted the significant opportunities and the complex legal risks associated with generative and agentic AI. Navigating this landscape successfully requires more than a one-time discussion with legal counsel. The insights gained inter alia from analysing copyright law, the AI Act and data protection must be translated into concrete, actionable guidelines for all employees who interact with AI systems. Without a structured approach, companies risk creating a chaotic and dangerous environment.
Since the Omnibus, the AI Act itself frames this task, in softened form. Article 4 AI Act, as amended, now requires providers and deployers to "take measures to support the development of AI literacy" among staff and others operating AI systems on their behalf. The provision no longer requires organisations to ensure a particular level of AI literacy, nor does it guarantee the competence of any individual. It does create an ongoing compliance obligation that has applied, in its original form, since 2 February 2025.
The most practical way to demonstrate compliance will be through a role-specific AI Use Policy supported by targeted training. The Commission is expected to publish practical examples of compliance through its single information platform (Article 4 AI Act as amended).
The worst-case scenario is a company with a sprawling portfolio of both approved and unapproved AI tools, the latter often referred to as "Shadow AI", where leadership has no overview of the risks being taken. In this scenario, it is impossible to ensure that employees are adhering to legal requirements, protecting company IP and safeguarding sensitive data. The most effective countermeasure is a consistent and well-communicated AI Governance framework. The foundational first step is a comprehensive AI Use Policy. This policy should not be a one-size-fits-all document but a practical guide that provides clear rules and risk-based guidance for different employees and specific use cases.
For example:
For AI-assisted coding
The policy should define which co-pilot and agentic coding tools are approved for use, establish procedures for handling code suggestions that may be subject to open-source licensing obligations, and outline security measures to prevent the exposure of proprietary code to the AI model.
For AI-powered asset generation
The policy should mandate the use of legally vetted tools, from providers offering appropriate contractual indemnification (Section 6.2). It should also formalise the screening process (Section 3.3), requiring human review of generated assets to reduce the risk of infringing recognisable third-party IP. Where the studio uses a tiered IP framework (Section 3.6), each output should be mapped to the relevant asset tier, so that the matching review and documentation duties apply automatically.
For marketing and player communication
The policy should provide clear guidelines on the use of AI in personalised advertising to avoid manipulative practices prohibited by the AI Act (Section 4.3) and to ensure compliance with data-protection principles when processing player data (Section 7).
Comprehensive documentation has evolved from good practice into indispensable defence for both IP ownership and multi-layered regulatory compliance. Beyond capturing prompt logs and human version histories to satisfy strict copyright standards, such as the Frankfurt burden shift (LG Frankfurt a.M., 17 Dec 2025, 2-06 O 401/25), robust workflow logging is now essential for evidencing compliance across the AI Act, Digital Services Act, youth protection frameworks, and data protection principles like GDPR data privacy by design.
As this dual-purpose audit trail can never be reliably reconstructed retroactively, it must be built directly into daily operations.
A well-implemented AI governance framework is not about restricting innovation. It is about enabling it responsibly. By providing clear guardrails, companies can empower their teams to leverage the power of AI safely, turning legal compliance into a sustainable competitive advantage.
Contacts

© 2026 Bird & Bird


