Your employees are already using AI. Not because they are reckless or going rogue. Because they are trying to get their work done faster. Someone on your team has pasted a client email into ChatGPT to draft a reply. Someone else has used an AI tool to summarize meeting notes, clean up a spreadsheet, or write a first draft of a proposal.
Most of the time, nobody asked permission. Nobody checked whether it was okay. And nobody told them what not to share. That is the gap a policy is designed to close.
Those numbers are for organizations of all sizes. Among small and mid-sized businesses, the figures are significantly worse. If you do not have a written AI policy today, you are in the majority. But that majority is carrying a growing liability.
Why "no policy" is now a real risk
A year ago, you could argue that AI was still experimental and a formal policy was premature. That argument does not hold anymore. Your team is using these tools whether you have given them guidance or not.
The risk is not that someone is doing something malicious. It is that well-meaning employees are using AI tools you have never vetted, feeding them data you have never approved for sharing, and making decisions based on outputs nobody is checking. Research shows that roughly 34.8% of employee inputs to AI tools contain sensitive data (Concentric / Metomic, 2025). That is one in three prompts including information your business would not want shared publicly.
Without a policy, you have no way to draw a clear line between acceptable and unacceptable use. And if something goes wrong, you have no documentation showing that your business took reasonable steps to prevent it. That matters for regulatory exposure, client trust, and basic operational risk.
If your business is still getting oriented on AI, a policy might feel premature. It is not. Even a simple one-page document puts you ahead of most businesses your size.
What a good AI policy actually covers
You do not need a 30-page legal document. A useful AI policy for a small business covers six things:
- Which AI tools are approved for work use. A short list of tools the business has vetted and considers acceptable.
- What data can and cannot go into those tools. Clear categories, not vague principles. For specifics on data risks, see our guide on what not to paste into AI tools at work.
- How to request a new tool. A simple process for employees who want to use something not on the approved list.
- Who owns the output. Clarity on whether AI-generated content belongs to the business, the employee, or the client.
- Who is accountable. A named person or role responsible for reviewing and updating the policy.
- What happens if someone violates the policy. Not to be punitive, but so everyone understands the stakes.
That is it. Six sections, each a few paragraphs long. The rest of this article walks through each one with sample language you can adapt.
If you want the template as a ready-to-fill document, download the free AI Use Policy Template (PDF).
Section-by-section walkthrough
Below is sample language for each section. It is written to be plain and direct. Adjust the specifics (tool names, data categories, contact names) to fit your business.
Section 1: Approved tools
This section names the AI tools your team is allowed to use for work purposes. If a tool is not on this list, it is not approved.
Sample language: "The following AI tools are approved for business use: [Tool A, Tool B, Tool C]. These tools have been reviewed for data privacy and security and are approved for use with the data categories described in Section 2. Using AI tools not on this list for work purposes is not permitted without prior approval (see Section 3)."
A few notes on this section. Be specific. "AI tools" is vague. Name the actual products. If your team uses ChatGPT Team, say so. If you use Microsoft Copilot through your existing Microsoft 365 subscription, say so. And specify the tier. A free ChatGPT account and a ChatGPT Team account have very different data handling policies.
Keep this list short. Three to five tools is plenty for most small businesses. The goal is not to list every AI product that exists. It is to give your team a clear, short list they can actually remember.
Section 2: Data boundaries
This is the most important section. It defines what types of information your team can and cannot share with AI tools.
Sample language:
Permitted: "You may use approved AI tools with general business content that does not contain client-identifiable information, financial data, credentials, or legally protected material. Examples: drafting marketing copy, summarizing publicly available research, brainstorming ideas, improving the clarity of your own writing."
Prohibited: "Do not enter the following into any AI tool, including approved ones: client names paired with financial or personal data, Social Security numbers or government IDs, passwords or access credentials, proprietary source code, health or medical records, contract terms or legal documents, employee performance data or compensation details."
The key is to be concrete. "Sensitive data" means different things to different people. Listing specific categories removes the guesswork. If you want a deeper look at what is and is not safe to share, our guide to what not to paste into ChatGPT at work covers this in detail.
Section 3: Approval process for new tools
Your team will discover new AI tools. That is a good thing. You do not want to shut that down. You just want a lightweight process so someone reviews the tool before it becomes part of your workflow.
Sample language: "If you would like to use an AI tool that is not on the approved list, submit a request to [name/role]. Include the tool name, what you want to use it for, and what data it would need access to. We will review it within [X business days] and update the approved list if it passes our review."
Keep this process fast. If it takes three weeks to get a new tool approved, people will skip the process and use it anyway. A 48-hour turnaround is realistic for most small businesses. The review does not need to be exhaustive. It just needs to answer three questions: Does the tool have a business-grade data policy? What data will flow through it? Is there a paid tier that provides better privacy protections?
Section 4: Ownership of AI-generated work
This section clarifies who owns the content AI helps create. For most small businesses, the answer is simple: the business owns it, just like any other work product.
Sample language: "Content created with the assistance of AI tools during the course of business operations is the property of [company name], subject to the same intellectual property policies that apply to all work product. Employees should not represent AI-generated content as entirely their own original work when accuracy of authorship matters (for example, in expert testimony, credentialed professional opinions, or signed attestations)."
The second sentence matters more than it seems. There are situations where passing off AI-generated content as fully human-authored creates legal or professional risk. A CPA firm using AI to draft an audit opinion, for instance, still needs a qualified human to review and stand behind it.
Section 5: Accountability
Someone needs to own this policy. Not in a bureaucratic sense, but practically. Someone who answers questions, reviews tool requests, and keeps the policy current.
Sample language: "Questions about this policy should be directed to [name/role]. This person is responsible for reviewing the approved tools list quarterly, updating data boundaries as new regulations or business requirements emerge, and addressing any reported concerns about AI use within the company."
In a small business, this is usually the owner, the operations lead, or whoever handles IT decisions. It does not need to be a dedicated role. It just needs to be a named person.
Section 6: Consequences of violations
Nobody likes this section, but it serves a purpose. It signals that the policy is real, not decorative.
Sample language: "Violations of this policy will be addressed on a case-by-case basis. Unintentional misuse will be treated as a learning opportunity with additional training provided. Repeated or deliberate violations, especially those involving client data or credentials, may result in disciplinary action up to and including termination. The goal of this policy is to help you use AI safely, not to catch you doing something wrong."
The last sentence is important. If your policy reads like a list of threats, people will hide their AI usage instead of asking questions about it. That is the opposite of what you want.
Rolling it out so people actually follow it
Writing the policy is the easy part. Getting your team to read it and follow it is what matters.
The biggest mistake: Sending a PDF and asking everyone to "review and acknowledge." Nobody reads those. Instead, walk through it in person or on a video call. Fifteen minutes is enough. Explain the why, not just the what.
Here is a practical rollout plan:
Week 1: Announce and explain. Share the policy and hold a brief team meeting. Focus on three things: here is what you can use, here is what not to share, and here is who to ask if you are unsure. That is the entire message.
Week 2: Answer questions. After people have had a few days to actually use AI with the new guidelines in mind, collect questions. What felt unclear? What situations came up that the policy did not address? Use these to refine the document.
Ongoing: Make it easy to find. Pin the policy in your team's primary communication channel. Add a link to your employee handbook or onboarding checklist. If someone has to search for it, they will not look.
One more thing. Frame the policy as an enabler, not a restriction. The message to your team is not "stop using AI." The message is: "We want you to use AI. Here is how to do it safely so we can all move faster without worrying about risk."
If you have not yet assessed whether your business is ready to formalize AI adoption, our readiness self-assessment can help you identify gaps before writing your own policy.
Keeping it current
AI tools change fast. Your policy needs to keep up. A document written in January can be outdated by March if a major new tool launches or your team's usage patterns shift.
Build in a review schedule. Quarterly is the right cadence for most small businesses. Once every three months, the accountable person (named in Section 5) should review three things:
- The approved tools list. Are there new tools the team is asking about? Has a tool on the list changed its data policies? Did a free tool you were using move to a paid model with different terms?
- The data boundaries. Has the business taken on new clients with stricter data requirements? Are there new regulations in your industry? Has anything happened (internally or in the news) that suggests a category should be added to the "never share" list?
- How the policy is actually being used. Is the team following it? Are people asking questions, or are they quietly ignoring it? If nobody has mentioned the policy in three months, that is a signal. Either it is working perfectly, or nobody remembers it exists.
Update the document, notify the team of changes, and move on. This should take an hour, not a week.
A policy that gets reviewed every quarter and stays at two pages will protect your business better than a 20-page document that sits in a drawer.
Frequently asked questions
What should a small business AI use policy include?
A practical AI policy covers which tools are approved, what data can and cannot go into them, how to request new tools, who owns AI-generated work, and who is accountable. Being specific, with named tools and clear data categories, matters more than length.
Why does a small business need an AI policy?
Employees are already using AI to get work done, often without guidance on what is safe to share. A policy closes that gap by telling people how to use AI safely, which lowers the risk of leaking sensitive or client data.
Should an AI policy restrict employees from using AI?
No. The most effective policies frame AI as encouraged, with clear guardrails, rather than banned. The goal is to help your team move faster with AI while keeping sensitive data protected.
Getting started today
Download the free AI Use Policy Template (PDF) and customize it for your business.
You do not need a legal team to write an AI use policy. You need to answer six straightforward questions (the six sections above), write them down in plain language, and share them with your team. A useful policy can be a single page. The value is not in the length. It is in the clarity.
If you would like help tailoring a policy to your specific business, or if you want to pair it with a broader plan for adopting AI safely, we work with small businesses on exactly this. Let us know where you are and we will go from there.