How to write an AI use policy your small team will actually follow.
The biggest AI risk to a small firm is not a hacker. It is a helpful employee, on a deadline, pasting a client contract into a free chatbot because no one told them not to. A short, clear policy closes that gap. This is how to write one your team will read and follow.
Why a one-page policy beats a perfect one
The failure that catches small teams is almost never dramatic. Someone reasonable, trying to move fast, drops a client's details into a free AI tool to "just summarize this." Nobody told them where the line was, so they did the sensible-looking thing and created a leak. The tool did exactly what it promised. The gap was the missing rule.
A policy only fixes that if people read it. A twenty-page document written to satisfy a lawyer sits unread in a shared drive while the same mistake keeps happening. One page everyone has read beats a thorough one nobody opens. Aim for something a new hire can absorb in five minutes and still remember on a busy Tuesday.
Approved tools, and why the plan matters more than the tool
Your policy should name the specific tools and the specific plans your team may use for work. "Use ChatGPT" is not a policy. "Use the company account, signed in with your work email" is. The account and plan are what carry the data protections, not the brand on the box.
This is the part most people get backwards. The free tier and the business tier of the same product can look identical on screen and behave very differently underneath. On many consumer and free plans, what you type may be retained and used to train future models. Business, team, and enterprise plans typically let you turn training off, limit how long data is kept, and sign a data processing agreement. Choose the plan for its data terms, not just its features.
- The exact tool and plan, for example a business or enterprise tier rather than a personal free account.
- The account to sign in with, so work runs through a company login you can govern.
- What the tool is cleared for, and what still needs a person.
The never-enter list
The heart of the policy is a short, specific list of data categories that must never go into any AI tool, on any plan, without explicit approval. Vague guidance like "be careful with sensitive data" fails because everyone draws that line in a different place. Name the categories so nobody has to guess.
- Client personal information: names tied to details, contact records, anything that identifies a person.
- Financial records: bank details, card numbers, tax information, payroll.
- Credentials and keys: passwords, API keys, access tokens, recovery codes.
- Anything under a non-disclosure agreement or a confidentiality clause.
- Health, legal, or immigration details, which carry extra sensitivity and often extra rules.
A human reviews anything client-facing or regulated
AI is a fast first drafter and a poor final authority. Your policy should say plainly that a person reviews and owns anything that reaches a client, a regulator, or the public. The model can remove the blank page. It cannot be accountable for what ships.
This matters most where a wrong answer is expensive: contracts, tax, compliance filings, anything that becomes a decision about a real person. AI states mistakes as fluently as it states facts, so an unchecked answer in these areas is a liability, not advice. The same person signs off every time. Our companion guide, Using AI in your business without leaking client data, walks through how a single pasted document becomes a leak, and the never-enter list is what stops it.
Name one person to ask when the rule runs out
Every policy eventually meets a situation it did not predict. The difference between a safe team and a leaky one is what happens next. If the honest response to uncertainty is a quick question, you are fine. If it is a quiet guess, you have a problem.
So name one person, give them an easy channel, and make it clear that asking is always the right call and never a bother. A policy that ends with "when in doubt, ask this person" turns every edge case into a short conversation instead of a silent risk.
Label AI-assisted work where it counts
Some work should carry a note that AI helped produce it. Where you are required to disclose it, or where a reader would reasonably expect to know, say so. This is partly honesty and partly self-protection: a labeled draft sets the right expectation about how much it has been checked.
The requirements here depend on your field, your clients, and where you operate, and they are still changing. Rather than guess at specific rules, set a simple internal default: disclose AI assistance where a client or regulator would expect it, and confirm the details for regulated work with a qualified professional. When in doubt, label it.
A one-page policy you can adapt
Here is a compact outline you can lift and fill in. It gathers the parts above into a single page. Keep each line short enough to read aloud.
- Purpose: one sentence on why this exists, to use AI without exposing client data.
- Approved tools and plans: the exact tools, tiers, and accounts cleared for work.
- Never enter: the data categories that must never go into any AI tool.
- Human review: a person reviews and owns anything client-facing or regulated.
- Disclosure: when and how to label AI-assisted work.
- When unsure, ask: the one named person and how to reach them.
- Review: the date this page gets checked again, and who owns it.
Roll it out so the team follows it
A policy is only real once the team has read it and knows where it lives. Keep it to one page. Use concrete examples instead of abstractions: show the kind of document that must not be pasted, the kind of task that is fine, and the person to ask. People follow rules they can picture.
- Walk through it once, live, so questions surface in the room.
- Store it where work happens, not buried in a drive nobody opens.
- Fold it into onboarding so every new hire gets the same five minutes.
Keep it alive as the tools change
AI tools change their plans, their data terms, and their features often, and a policy written against last year's terms can quietly become wrong. The account that used to train on your inputs may stop, and the one that did not may start. Neither change announces itself on the screen you use every day.
So put a recurring reminder to review the page, and update it whenever you add a tool or a vendor changes what it does with your data. Give the page a named owner and a review date. A short policy is quick to revise, which is one more reason to keep it short.
What Alpha Momin does here
Setting up AI so it saves time without opening a gap is part of our IT and admin support. We help you pick the right AI plan for your privacy needs, write the one-page policy your team will read, and configure your Microsoft 365 so sensitive data stays inside systems you control. We will not pretend a page of rules replaces judgment. It just makes the safe choice the easy one, and gives your team a line they can see.
This post is general information, not legal advice. Disclosure and compliance requirements vary by field and location and are still changing; confirm the specifics for regulated work with a qualified professional.
Frequently asked
Does a small business really need a written AI policy?
Yes, even a one-page one. It prevents the most common problem: a well-meaning employee pasting client data into a free tool because no one set a rule. Writing it down turns a vague sense of caution into a bright line everyone shares, and it gives new hires the same guidance on day one. The goal is not bureaucracy. It is one clear page people will remember and use on a busy day.
Should the policy name specific AI tools or stay general?
Name specific tools and plans. General guidance like "use AI responsibly" leaves everyone guessing, and people fill the gap with whatever free account is handy. Listing the exact tools, tiers, and accounts you have cleared removes the guesswork and keeps work on plans whose data terms you have checked. Update the list whenever you add or drop a tool, since a stale list quietly sends people back to guessing.
Why does the plan matter more than which AI tool we pick?
Because the data protections live in the plan, not the interface. The free and business tiers of the same product can look identical while treating your inputs very differently: free tiers may retain and train on what you type, while business tiers usually let you turn that off and sign a data agreement. If you handle anything private, the paid tier is often what makes the tool usable at all. Choose the plan for its terms first, then the tool.
How often should we update our AI policy?
Review it on a regular schedule, and any time you add a tool or a vendor changes its data terms. AI products change their plans and privacy settings often, so a policy written a year ago can quietly go out of date. A short, one-page policy is fast to revise, which is one more reason to keep it short. Put a named owner and a review date on the page so it does not drift and so someone is clearly responsible for the next check.
Want a policy your team will actually follow?
Tell us what your team wants AI to do. We will pick the right plans and write the one-page policy so it saves time without leaking a thing.
Set it up safely