Regulation & Safety

How to Create a Simple AI Policy for a Small Business

Most small teams use AI with no rules until something leaks. Here is a one-page policy template covering data, tools, approval, disclosure, and sensitive information.

· Jul 16, 2026 · updated Jun 16, 2026
How to Create a Simple AI Policy for a Small Business
Table of contents
  1. Why a one-page policy beats no policy
  2. The policy template
  3. Data and sensitive information rules
  4. Disclosure, approval, and review
  5. Bottom line
  6. Sources and further reading

Most small businesses adopt AI the same way they adopted social media: one person tries a tool, it works, and soon the whole team is pasting customer emails, financials, and draft contracts into whatever chatbot is open in a browser tab. That informal phase is fine until something goes wrong — a confidential figure ends up in a public model, a client spots an obvious AI hallucination in a proposal, or a regulator asks how you handle personal data. A short, written AI policy prevents most of those problems without slowing anyone down.

You do not need a legal department or a 40-page document. A useful policy for a team of two to fifty people fits on a single page, answers a handful of predictable questions, and gets reviewed every few months. This guide gives you a template you can copy, fill in, and circulate today.

Why a one-page policy beats no policy

The goal is not to restrict AI — it is to make safe use the default. Frameworks like the voluntary NIST AI Risk Management Framework organize governance around four ideas: govern, map, measure, and manage. Translated for a small business, that means: decide who owns AI decisions, know where AI is being used, watch for problems, and have a plan when they appear.

The biggest risk for a small company is rarely exotic. It is data leakage — staff pasting sensitive information into tools whose terms allow that data to be retained or used for training. The second is unverified output presented to customers as fact. A written policy turns these from accidents waiting to happen into rules everyone has read once.

Keep the tone permissive. A policy that bans AI outright just pushes usage into the shadows, where you have no visibility at all.

The policy template

Copy this table, replace the example entries with your own decisions, and you have a working draft. Each row answers one question your team will actually ask.

Area The question it answers Example policy
Approved tools Which AI tools may we use? Listed business-tier accounts only; no personal free accounts for work data
Data rules What can I put into a tool? No customer PII, financials, passwords, or unpublished IP in any AI tool
Sensitive information What is always off-limits? Health, legal, HR records, and anything under NDA — never entered into AI
Approval Who decides on new tools or uses? Designated AI owner reviews and approves new tools within one week
Disclosure When do we tell people AI was involved? Customer-facing AI chat and AI-written marketing labeled; internal drafts need not be
Verification Who checks AI output? The person publishing it is responsible for accuracy and sources
Account security How do we protect access? Company accounts only, MFA on, no shared logins

Fill in the right column to match your reality. The act of deciding each row is most of the value.

Data and sensitive information rules

This is the section that prevents the worst incidents, so make it concrete. List the categories that must never enter any AI tool: customer personal data, payment details, health and HR records, anything under a non-disclosure agreement, and unpublished plans or source code. Use plain examples your team will recognize — "don't paste the contents of a customer's support ticket," not "avoid processing personal data."

Then state your tool posture. Prefer business or enterprise tiers, where vendors typically commit in writing not to train on your inputs, over free consumer accounts where data handling is looser. Require company-managed accounts so logins can be revoked when someone leaves. Note that you cannot control what a vendor does, only what you send — which is exactly why the input rules matter more than the tool choice.

Disclosure, approval, and review

Disclosure is partly a trust issue and partly a legal one. Consumer-protection regulators have signaled that AI-generated claims and content must not mislead, and several jurisdictions are moving toward labeling rules for synthetic media. A safe default: label customer-facing AI interactions (a support bot should not pretend to be a named human) and AI-generated public content, while leaving internal drafting unlabeled.

Approval needs one named person — the AI owner — who maintains the approved-tools list and signs off on additions. This stops tool sprawl without creating a bottleneck.

Review keeps the policy alive. Put a date on it and revisit quarterly, because tools, terms, and capabilities change fast. A policy nobody has reread in a year is closer to no policy at all.

Bottom line

A small-business AI policy is a one-page agreement, not a compliance project. Decide your approved tools, your hard data limits, who approves new uses, when you disclose AI involvement, and who is accountable for verifying output. Write it in plain language, share it once so everyone has read it, and put a review date at the bottom. That single page captures most of the protection larger governance frameworks aim for — at a cost of an afternoon's work.

Sources and further reading

Sources

  • NIST: AI Risk Management Framework nist.gov