An AI policy template for small business should give employees clear answers to five questions: which AI tools they may use, what information they may give those tools, which uses need human review, what is prohibited, and what to do when an AI-related mistake occurs.
For most small businesses, the policy does not need to regulate every prompt. It needs to control the situations where AI can expose confidential information, produce unreliable work, make an inappropriate decision, or take an action that is difficult to reverse.
The following framework can be adopted as a starting policy without filling a page with blank fields. A business can then adjust individual rules to match its software, data, contracts, industry requirements, and actual level of risk.
A Practical AI Policy for a Small Business
Purpose
The business permits the use of approved artificial intelligence tools when they help employees work more efficiently without compromising confidential information, security, accuracy, customer trust, or professional judgment.
AI is an assistance tool rather than an independent authority. The person using AI remains responsible for the final work and for following the same business standards that would apply if AI had not been used.
Who the Policy Covers
The policy should apply to employees, contractors, temporary workers, consultants, and anyone else using AI while performing work for the business.
It should cover more than standalone chatbots. AI features can also appear inside:
- email and office software;
- meeting and transcription tools;
- design applications;
- customer relationship management systems;
- accounting and analytics software;
- coding environments;
- browsers and search tools;
- customer-service platforms;
- workflow automation systems.
An AI feature built into software the company already uses should not automatically be considered approved. Its access to business information and the way it handles that information still matter.
Use Only Approved AI Tools
Employees should use AI services that the business has reviewed and approved for the type of work being performed.
Approval should consider the specific service and account configuration, not merely the product name. A business account with administrative controls may have different settings and data-handling arrangements from a personal or free account for the same product.
Employees should obtain approval before introducing an AI tool that will:
- receive non-public business information;
- connect to company email or cloud storage;
- access customer or employee records;
- connect to a CRM or financial system;
- interact directly with customers;
- execute code or modify business systems;
- take actions without individual approval.
Personal AI accounts should not be used as a workaround when a business tool has not been approved.
A small business does not need a complicated software register. A maintained list of approved tools, permitted uses, allowed data categories, required account types, and responsible owners is usually enough to make the rule practical.
Decide What Information AI May Receive
One of the most important parts of an AI policy is defining information boundaries before an employee uploads a file, pastes text into a prompt, records a meeting, or connects an AI service to another system.
A simple three-level classification works well for many small teams.
Public Information
Information already intended for public distribution generally presents the lowest confidentiality risk.
Examples include:
- published website content;
- public product information;
- public reports;
- press releases;
- published FAQs;
- publicly available research.
Public information can usually be used with approved AI tools, provided the proposed activity itself is permitted.
Internal Information
Internal information is not necessarily highly sensitive, but it was not created for unrestricted public distribution.
Examples may include internal procedures, routine meeting notes, draft documents, non-sensitive planning material, and ordinary internal communications.
Employees should use internal information only with AI services approved to process it.
Restricted Information
Restricted information requires the strongest controls.
Depending on the business, this can include:
- passwords and authentication codes;
- API keys and security credentials;
- payment card or banking information;
- customer personal information;
- employee records;
- payroll information;
- confidential contracts;
- information covered by a nondisclosure agreement;
- trade secrets;
- proprietary source code;
- confidential financial information;
- unpublished strategic plans;
- legally privileged material;
- sensitive health information;
- identity documents.
Restricted information should not be entered into an AI system unless the business has specifically determined that the tool, account, configuration, purpose, and handling process are appropriate for that information.
Employees should not assume that removing a person's name makes a record anonymous. A combination of dates, account details, locations, transaction information, job titles, or other facts can still identify an individual or reveal confidential information.
Allowed AI Uses
Approved AI tools can support ordinary low-risk work where a person remains in control of the result.
Typical uses can include:
- brainstorming ideas;
- developing outlines;
- improving grammar and clarity;
- creating first drafts;
- organizing non-sensitive information;
- summarizing material the tool is permitted to process;
- generating alternative wording;
- assisting with routine analysis;
- supporting coding under appropriate review;
- identifying questions that deserve further investigation.
An allowed activity can become restricted when sensitive information is introduced.
For example, drafting a generic customer-service response may be low risk. Uploading a real customer's confidential case history to generate that response is a different activity and should be evaluated separately.
Uses That Require Additional Approval
Some AI activities create substantially more risk than ordinary drafting or brainstorming and should not begin merely because the underlying AI product is approved.
Additional approval is appropriate before AI is used to:
- process sensitive customer or employee information;
- provide individualized legal, medical, financial, or similarly high-stakes guidance;
- screen or rank job applicants;
- evaluate employees;
- determine a person's eligibility for a significant service or benefit;
- communicate autonomously with customers;
- publish material without human approval;
- connect to sensitive business databases;
- change production systems;
- make or approve payments;
- execute consequential automated actions.
The important distinction is between approving an AI tool and approving an AI use. A service that is acceptable for drafting marketing ideas is not automatically acceptable for evaluating job candidates or handling confidential customer records.
Prohibited AI Uses
Employees should not use AI to:
- disclose information they are required to protect;
- expose passwords, credentials, or security secrets;
- fabricate business records or evidence;
- create intentionally deceptive customer communications;
- impersonate another person deceptively;
- bypass access controls or security procedures;
- conceal an error or unauthorized activity;
- make prohibited discriminatory decisions;
- create unlawful, fraudulent, or harassing material;
- make unauthorized commitments on behalf of the business;
- circumvent established approval requirements.
Employees also should not attempt to defeat safeguards simply because an AI service refuses to perform an activity.
Treat AI Output as Unverified
Fluent writing is not proof of accuracy.
AI systems can produce incorrect facts, nonexistent references, faulty calculations, outdated information, insecure code, inappropriate assumptions, or answers that omit important context.
The employee using the output remains responsible for checking it before the business relies on it.
Verification should match the consequences of being wrong.
A list of brainstorming ideas may require only a quick review. A customer quotation, financial calculation, contract provision, public factual claim, production code change, or important business recommendation deserves much closer checking.
Depending on the work, review may involve:
- confirming names, dates, and figures;
- recalculating numerical results;
- checking claims against reliable source material;
- confirming that cited documents actually exist;
- testing code;
- checking whether important context is missing;
- reviewing confidentiality and privacy concerns;
- checking contractual requirements;
- obtaining specialist review.
Human review should be meaningful rather than ceremonial. Reading an AI answer once and approving it because it sounds convincing is not adequate verification for high-impact work.
Keep Humans Responsible for Important Decisions
AI can organize information and assist analysis, but consequential decisions should not be delegated to an AI system without appropriate human oversight.
Extra care is necessary when a decision can materially affect someone's:
- employment;
- finances;
- access to services;
- contractual rights;
- safety;
- legal position;
- insurance;
- healthcare;
- other significant interests.
A qualified person should understand the basis of the decision, review the relevant evidence, consider information the AI may have missed, and retain authority to reject the AI-assisted recommendation.
The greater the possible harm from an incorrect decision, the stronger the human control should be.
Set Rules for Customer-Facing AI
A customer-facing AI system creates different risks from an employee using AI privately to draft an internal note.
Before an AI chatbot, voice system, assistant, or automated agent communicates directly with customers, the business should determine:
- which subjects it may handle;
- which information it may access;
- which actions it may perform;
- when a person must take over;
- how incorrect responses will be corrected;
- how conversations are recorded and retained;
- how personal information is protected;
- whether disclosure of AI interaction is appropriate or required.
There should always be a workable escalation path for situations the system is not qualified or authorized to resolve.
A customer should not be trapped in automation when the issue requires human judgment.
Control AI Agents and Automated Actions
AI becomes more consequential when it can act instead of merely generating a response for someone to review.
An AI agent may be able to send emails, modify records, execute code, interact with applications, publish material, make purchases, or trigger additional workflows.
Those capabilities require explicit boundaries.
A useful rule is to consider both impact and reversibility.
Drafting an email that an employee must approve is relatively easy to control. Automatically sending thousands of messages, deleting records, changing permissions, transferring money, or modifying production systems can create consequences before anyone has a chance to intervene.
High-impact or difficult-to-reverse actions should require human authorization at the appropriate stage.
Protect Intellectual Property and Confidential Material
AI does not remove existing confidentiality or intellectual property responsibilities.
Employees should continue to follow contractual restrictions, confidentiality agreements, licensing requirements, and company rules when providing material to AI or using AI-assisted output.
AI-generated material should not automatically be assumed to be unique, accurate, owned by the business, or free of third-party rights.
Where intellectual property is commercially important, the business should determine whether additional review is necessary before publishing, licensing, selling, or incorporating AI-generated material into a product.
Apply Additional Controls to AI-Generated Code
AI-assisted programming can accelerate development, but generated code should be treated as code requiring normal technical review.
Before AI-generated code reaches production, appropriate checks may include:
- functionality testing;
- security review;
- dependency inspection;
- license review;
- validation of data access;
- testing error handling;
- checking for exposed secrets;
- maintainability review;
- peer review.
Passwords, production credentials, private keys, confidential source code, customer records, or other restricted information should not be submitted to coding assistants unless that use has been specifically approved.
AI-generated code that appears to work can still contain security weaknesses or subtle logic errors.
Decide When AI Use Should Be Disclosed
Not every minor use of AI requires a disclosure.
Using an approved tool to improve the grammar of an internal note is different from allowing an AI system to interact directly with a customer or substantially generate professional work presented as independently prepared.
Disclosure may be appropriate when:
- a customer is directly interacting with AI;
- AI involvement is material to the service;
- a contract requires disclosure;
- applicable rules require it;
- failing to disclose AI involvement could reasonably mislead the recipient.
A business should establish consistent disclosure rules for recurring situations rather than leaving every employee to make the decision independently.
Create a Clear AI Incident Process
Employees need to know what to do when AI use goes wrong.
An AI-related incident can include:
- confidential information entered into an unauthorized service;
- credentials accidentally exposed;
- inaccurate information sent to customers;
- an unapproved AI integration connected to business systems;
- inappropriate automated decisions;
- unexpected actions by an AI agent;
- potentially infringing material used commercially;
- harmful output incorporated into business work.
Employees should report suspected incidents promptly rather than attempting to hide or quietly correct them.
The response should focus first on limiting further harm. Depending on the incident, that can mean revoking credentials, disabling an integration, stopping an automated workflow, correcting customer information, preserving relevant records, or involving the person responsible for security, privacy, legal, HR, or operational matters.
After the immediate problem is controlled, the business should determine why the existing safeguards failed and whether its policy, configuration, training, or approval process needs to change.
Assign Responsibility for AI Use
A policy without ownership can quickly become outdated.
At least one person or role should be responsible for:
- maintaining the approved-tool list;
- reviewing proposed AI uses;
- coordinating exceptions;
- receiving incident reports;
- arranging appropriate training;
- reviewing significant changes to AI services;
- updating the policy.
This does not mean one person must be an expert in every risk.
Higher-risk situations may require input from appropriate legal, cybersecurity, privacy, HR, financial, technical, or industry specialists.
Individual employees remain responsible for complying with the policy and reviewing the work they produce with AI.
Use a Simple Risk Test Before AI
Employees should be able to recognize higher-risk situations without performing a formal assessment before every prompt.
Four questions provide a practical first check.
What information will AI receive?
Public website text presents a different risk from customer records, credentials, contracts, payroll files, or confidential plans.
What will happen to the output?
Private brainstorming is different from public content, customer advice, production code, an employment decision, or an automated transaction.
What happens if the output is wrong?
The greater the possible financial, legal, security, privacy, safety, or reputational harm, the stronger the review should be.
Can the action be reversed?
Generating a draft for review is easily reversible. Sending a payment, deleting records, changing permissions, publishing material, or automatically contacting customers may not be.
If any answer indicates significant consequences, employees should obtain the level of approval appropriate to that activity before proceeding.
Keep an Approved AI Tool Register
The main policy should contain stable rules. Information that changes frequently is easier to maintain separately.
An approved-tool register can record:
|
Record |
What It Should Identify |
|
AI service |
Exact service being approved |
|
Account type |
Business, enterprise, or other authorized account |
|
Permitted use |
Tasks employees may perform |
|
Permitted information |
Data classifications the service may receive |
|
Restrictions |
Activities requiring additional approval |
|
Integrations |
Business systems the service may access |
|
Owner |
Person responsible for the service |
|
Review status |
Whether approval remains current |
This avoids rewriting the entire policy whenever the business adopts or removes a tool.
It also prevents a common misunderstanding: approval of one AI service does not mean employees may use every feature, integration, model, plugin, or account configuration associated with it.
Review AI Tools After They Change
Approval should not be permanent by default.
AI services can add new capabilities, integrations, memory features, agents, data controls, or automated actions. Business use can also evolve.
A tool initially approved for drafting public marketing copy may later be connected to customer records or given permission to send messages automatically. The product name has not changed, but the risk has.
Review is appropriate when there is a material change in:
- the AI service;
- its business use;
- the information it can access;
- its integrations;
- its ability to take actions;
- contractual requirements;
- applicable obligations;
- security controls.
The policy itself should also be reviewed periodically and after significant AI-related incidents.
Train Employees With Real Examples
Employees are more likely to follow a rule when they can recognize how it applies to their work.
Training should show realistic examples of:
- information that can safely be used;
- information that should not be submitted;
- approved and unapproved tools;
- outputs requiring verification;
- activities requiring additional approval;
- customer-facing AI;
- incident reporting.
For example, telling employees not to share "sensitive information" leaves room for interpretation. Showing that customer exports, payroll records, passwords, confidential contracts, and authentication keys are restricted creates a much clearer boundary.
Training does not need to be lengthy. It needs to make the decisions employees face during ordinary work unambiguous.
Common AI Policy Mistakes
Writing a Blanket Ban
A blanket ban may fail to address AI features already built into ordinary workplace software and can encourage unapproved use outside company-controlled accounts.
A stronger policy distinguishes permitted low-risk activity from restricted and prohibited activity.
Approving Products Instead of Uses
The same AI system can support both low-risk and high-risk work.
Approval for brainstorming should not automatically authorize access to customer databases, employment decisions, or autonomous transactions.
Protecting Only Obviously Sensitive Data
Names are not the only information capable of identifying a person or exposing confidential business activity.
Context can make otherwise ordinary information sensitive.
Treating Every AI Output the Same
A spelling suggestion and a financial recommendation do not need identical controls.
Review should increase with potential impact.
Forgetting Embedded AI
Employees may use AI through office software, meeting applications, design platforms, browsers, CRM systems, or development tools without opening a dedicated chatbot.
The policy should therefore govern AI functionality rather than a handful of familiar product names.
Assuming Human Review Solves Everything
A person cannot meaningfully verify work without appropriate information, knowledge, and authority.
High-risk work may need testing, source verification, comparison with original records, or specialist review.
Publishing the Policy and Forgetting It
AI capabilities and business processes change too quickly for an indefinitely static policy.
The approved tools, permitted uses, incidents, and material changes should feed back into policy maintenance.
A Short Version Employees Can Remember
A detailed policy needs a simple operating rule behind it:
Use approved AI. Protect restricted information. Verify important output. Get approval before high-risk or autonomous use. Report mistakes quickly.
Those five principles cover most everyday decisions without forcing employees to interpret a lengthy governance document each time they use an AI feature.
The detailed sections exist to explain where those boundaries sit.
FAQ
What should an AI policy for a small business include?
It should cover approved AI tools and accounts, information handling, permitted and prohibited uses, human review, higher-risk activities, customer-facing AI, automated actions, incident reporting, responsibilities, exceptions, training, and periodic review.
Does every small business need the same AI policy?
No. A small company using AI only for public marketing drafts has different risks from a business processing customer records, developing software, handling regulated information, or automating consequential decisions.
The policy should reflect actual use and potential harm.
Can employees enter customer information into AI?
Not automatically. Customer information should be used only when the specific AI service, account, purpose, configuration, and business process have been approved for that information and relevant privacy, contractual, and other obligations have been addressed.
Can employees use personal AI accounts for work?
A business should establish an explicit rule. Where company information or customer information is involved, approved business-controlled accounts provide clearer administrative and information-handling boundaries than employees independently choosing personal services.
Does AI-generated content need human review?
AI-assisted business work should receive review proportionate to its consequences. Routine internal brainstorming may require little checking, while public claims, customer communications, financial work, code, contracts, or consequential decisions require substantially stronger verification.
Should AI be allowed to make decisions automatically?
Low-impact automation can sometimes be appropriate, but consequential decisions and difficult-to-reverse actions need stronger controls. Decisions materially affecting individuals, money, access, security, or important business systems should retain appropriate human oversight.
How often should a small business review its AI policy?
A scheduled review should occur at least periodically, with additional review when tools, integrations, business processes, contractual requirements, relevant obligations, or risk levels materially change. Significant incidents should also trigger reconsideration of the affected controls.
Is an AI policy the same as an AI tool list?
No. The policy establishes the rules that remain relatively stable. The approved-tool list records which specific services, accounts, uses, data categories, and integrations are currently authorized.
Keeping them separate makes both easier to maintain.
Final Thoughts
A useful AI policy for a small business is not measured by how many restrictions it contains. Its value comes from whether employees can make the correct decision before information is exposed, unreliable output is used, or an AI system is given more authority than the task requires.
The strongest structure separates ordinary low-risk assistance from sensitive data use, consequential decisions, customer-facing systems, and autonomous actions. It keeps people accountable for important work while allowing appropriate AI use to continue.
Most importantly, the policy should govern what the business is actually doing. Approved tools, information boundaries, human review, escalation, incident handling, and periodic reassessment turn a written policy into an operational control rather than a document that is filed away and forgotten.


