The short answer: a small business AI use policy should cover which AI tools are approved, what information can never be entered into them, how customer data is handled, when documents may be uploaded, account security requirements, and a rule that a human reviews AI output before it's used externally. You don't need a long legal document — a clear one-page policy that employees will actually read is more useful than a comprehensive one nobody opens.

Why a written policy matters, even for a small team

Most small businesses didn't decide, as a company, to start using AI tools — employees simply started using them because they're useful for drafting emails, summarizing documents, or writing code. That's a normal, organic adoption pattern, and it isn't a mistake. But it does mean that without a written policy, every employee is making their own judgment call about what's safe to type into an AI tool, and those judgment calls will differ from person to person.

A short written policy replaces guesswork with a shared, consistent standard. It doesn't need to slow anyone down — the goal is clarity, not bureaucracy.

What to include

1. Approved AI tools

Name the specific tools employees are approved to use for work, and note whether that's a business/team plan or open to personal accounts (it generally shouldn't be, for reasons covered in the next section).

2. Prohibited information

Be specific: customer and client personal data, confidential business information, employee/HR data, and credentials should never be typed or uploaded into an AI tool. Vague guidance like "use good judgment" isn't guidance — it's an invitation for inconsistent decisions.

3. Customer and client data handling

State plainly how customer information relates to AI tool use, and who to ask when an employee is unsure whether something counts as customer data.

4. Document upload rules

Uploading a full document is often riskier than typing a question, because a document can contain far more sensitive information than the employee realizes at a glance. The policy should say what needs to be checked before a document goes into an AI tool.

5. Account and security requirements

Work AI accounts should use unique passwords and multi-factor authentication where available — the same basic hygiene as any other business account.

6. Human review of AI output

AI-generated content should be treated as a draft. Before it's sent to a customer, published, or used for a business decision, a qualified person should review it. This single rule prevents a large share of avoidable AI-related mistakes.

7. Incident reporting

If sensitive information is entered into an AI tool by mistake, employees need to know who to tell — and that reporting it is the right move, not something to hide.

What this policy is not

A one-page internal policy is a starting point for consistent behavior, not a substitute for legal, compliance, or cybersecurity advice specific to your industry and jurisdiction. Businesses in regulated industries (healthcare, financial services, legal) should have this reviewed by a qualified professional before adopting it formally.

Industry- or jurisdiction-specific regulatory requirements (e.g., HIPAA, GLBA, provincial/state privacy law) are not addressed in the free template and should be verified with a qualified professional for your specific business.

Get the free template

We've put the structure above into a ready-to-adapt, one-page template you can download or print directly.

View the Free AI Use Policy Template

Related: What Is Shadow AI? · Take the free AI Risk Check