KGetsIt

Resources · Getting started

What to include in a small business AI policy (template included)

Updated 2026-08-25

A small business AI policy fits on one or two pages and needs seven things: a short list of approved tools on business accounts, plain rules for what data can never be pasted into an AI tool, a requirement that a person reviews AI output before it reaches a customer, a disclosure rule for when AI interacts with customers directly, one named owner for the policy, a line on who owns AI-assisted work, and a review date so it stays current. Write it in plain English and share it with the team the same week. The point is not legal cover. It is replacing the accidental policy you already have, where whatever each employee pastes into a free chatbot quietly becomes company practice nobody chose.

One page, seven decisions

An AI policy for a small business is not a binder. It is one or two pages that answer seven questions your team is already answering on their own, tool by tool and paste by paste. Here is the list, then the reasoning, then a template you can copy.

  1. Which AI tools are approved, on which accounts
  2. What data never goes into an AI tool
  3. Who reviews AI output before it leaves the building
  4. When and how you tell customers AI is involved
  5. Who owns the policy
  6. Who owns AI-assisted work
  7. When the policy gets reviewed

If you write nothing else, write items one and two. They prevent the two expensive mistakes: company data in tools you never vetted, and AI-written mistakes going out under your name.

1. Approved tools, on business accounts

Name the tools your business actually sanctions, and be specific: the product, the plan, and whose account. A business or team plan matters more than most owners realize, because the paid business tiers of the major AI tools let you keep your conversations out of model training, and the free personal tiers often do not.

Two or three tools is plenty to start. If someone wants a new one, the policy should say who they ask, so the list can grow without growing in the dark. For the broader question of what a general chatbot is and is not good for, we wrote up should you just use ChatGPT.

2. Data that never goes in

This is the section that earns the whole page. Write a short, concrete list of what must never be pasted, uploaded, or dictated into an AI tool, approved or not:

  • Customer names tied to anything sensitive: health details, finances, disputes
  • Payment data, bank details, Social Security numbers
  • Passwords, API keys, and anything from your password manager
  • Employee records, payroll, and anything from a personnel file
  • Contracts or documents covered by an NDA
  • Anything you would not want read back to a competitor

The habit to teach is substitution: describe the situation without the identifying details. “A customer is disputing an invoice, draft a firm but polite reply” works exactly as well as pasting the customer’s name and account history, and it risks nothing. We cover how these tools actually handle your data, and what the paid tiers change, in is your business data safe with ChatGPT. If you are in Massachusetts, the state data security regulation already requires a written information security program for any business holding residents’ personal information, and this section should line up with it; we explain the rule in IT consulting in Salem, MA.

3. A person checks it before it ships

AI output is a draft until a human approves it. Put that sentence in the policy nearly word for word. Chatbots produce confident text that is sometimes wrong, and the mistakes are hardest to spot exactly where you are least expert. So the rule is simple: whoever sends it, owns it. If an AI-drafted quote goes out with the wrong price, that is not the tool’s mistake, it is the sender’s.

For most businesses this costs a minute per item. That minute is the difference between AI as a fast drafting tool and AI as an unsupervised employee nobody hired.

4. Tell customers when it matters

You do not need to disclose that AI helped draft an email a human read and approved. You do need to be straight with people when AI is acting on its own: an automated assistant handling inquiries, a bot doing intake on your website, automated follow-ups running without review. Say what it is, and give people a path to a human.

This is not just good manners. The FTC has said plainly that there is no AI exemption from the laws on the books, and it has already acted against companies for overstating what their AI does. The safe and honest version is short: do not pretend a bot is a person, and do not claim AI abilities you do not have.

5. One named owner

Policies without owners rot. Name a person, in a two-person shop that is you, who approves new tools, answers questions, and updates the page when something changes. The name matters more than the title: when someone wonders whether a new tool is allowed, they should know exactly who to ask, and asking should be easy, because the alternative is that they do not ask.

6. Who owns the work

Add one line making it explicit that work produced with AI assistance on company time is company work, same as anything else. This heads off two headaches: an employee treating an AI-built spreadsheet or client list as personally theirs, and confusion about whether AI-assisted work product can be used commercially. For most day-to-day business use, drafts, summaries, internal tools, treating it as normal work product is the practical answer, and your policy should say so.

7. A review date

AI tools change terms, change models, and appear and disappear faster than any other software category your business touches. Put the next review date on the policy itself and treat the review as a fifteen-minute calendar item: is the tool list current, has any tool changed its data terms, has anything moved from “drafting with review” to “acting on its own.” That last shift is the big one. The moment AI stops drafting and starts doing, you have moved from chatbots to AI agents, and the oversight rules deserve a fresh look.

If you ever want the heavyweight version of this thinking, NIST publishes an AI Risk Management Framework that large companies use. You do not need it. The seven items above are the small-business-sized version of the same idea: know your tools, know your data, keep a human accountable.

The template

Copy this, fill in the blanks, delete what does not apply. It should fit on one page.

[BUSINESS NAME] AI POLICY
Owner: [name]   Last reviewed: [date]   Next review: [date]

1. APPROVED TOOLS
   We use these AI tools, on company accounts only:
   - [Tool 1, plan, account owner]
   - [Tool 2, plan, account owner]
   Want to use something else? Ask [name] first. Personal
   accounts are not approved for company work.

2. WHAT NEVER GOES INTO AN AI TOOL
   - Customer names tied to sensitive details
   - Payment data, bank details, government ID numbers
   - Passwords, keys, anything from the password manager
   - Employee records and payroll
   - Anything under NDA
   When in doubt, describe the situation without the details.

3. REVIEW BEFORE IT SHIPS
   AI output is a draft. A person reads and approves anything
   that goes to a customer, a vendor, or the public.
   Whoever sends it, owns it.

4. TELLING CUSTOMERS
   If AI interacts with customers on its own, we say so, and
   we always offer a path to a human. We do not claim AI
   abilities we do not have.

5. OWNERSHIP
   Work produced with AI assistance on company time is
   company work.

6. QUESTIONS AND CHANGES
   [Name] owns this policy, approves new tools, and updates
   this page. This policy is reviewed every six months or
   when our tools change.

Mistakes that make policies useless

  • Writing it and never mentioning it again. Walk the team through it once, ten minutes, with examples from your actual work.
  • Making it a ban in disguise. If the policy is all “never” and no “here is what to use instead,” people route around it on their phones.
  • Copying a corporate policy. A ten-page document written for a company with a legal department will not be read by anyone at a ten-person company.
  • Forgetting the accounts. The same tool can be fine on a business plan and risky on a free personal one. The account is part of the policy.
  • Treating it as done. The tool list from six months ago is already out of date.

Where this fits

A policy keeps casual AI use from hurting you. It does not answer the bigger question, which is where AI would actually pay off in your business, and that answer is different for a plumber, a property manager, and an accounting firm. That is what the assessment is for: a look at your actual operations, what is worth automating, what is not, and in what order.

Questions people ask

Do I really need an AI policy if only a couple of people here use AI?
You need it precisely because you do not know who uses it. In most small businesses, someone is already pasting customer emails or pricing into a free chatbot, usually with good intentions and a personal account. A one-page policy does not slow that person down much. It just makes sure the tools are ones you chose, on accounts you control, with your customer data kept out.
Should I just ban ChatGPT instead of writing a policy?
Bans mostly push AI use onto personal phones and personal accounts, where you have zero visibility and zero control. A short approved-tools list works better: pick one or two tools, put them on business accounts with training on your data turned off, and name what must never go in. People get the speed, you keep the data where you can see it.
Who should write the policy, and do I need a lawyer?
The owner or the operations lead should write version one, because it is really a set of operating decisions: which tools, what data, who checks the output. Plain English beats legalese for getting people to actually follow it. If you are in a regulated field like healthcare, finance, or law, have counsel read it before it goes out, because your confidentiality obligations do not pause for new software.
How often should the policy be updated?
Put a review date on it, every six months is a sensible default, and also revisit it any time something real changes: a new tool comes in, a tool changes its data terms, or you start letting AI act on its own instead of just drafting. A policy with a stale tool list gets ignored, and an ignored policy is the accidental policy all over again.

Sources

Want this figured out for your business?

The assessment tells you where AI is worth it for you, fixed price, and the fee comes off the build.

Get an assessment

new guides by email

When a new guide is published, you get it.

That is the whole list. We send a confirmation email first, and leaving takes one click.