How to Write a Simple AI Policy for Your Team (Before Someone Makes a Mess)

A one-page document on a clean desk representing a simple AI policy for a small business team

How to Write a Simple AI Policy for Your Team (Before Someone Makes a Mess)

At some point in the last year or two, your employees started using AI tools. Maybe you encouraged it. Maybe you just looked the other way. Either way, it's happening — and odds are nobody has written down any rules about it.

That's usually fine, right up until it isn't.

Someone pastes a client contract into ChatGPT to summarize it. Someone else publishes a blog post that's 90% AI-generated without mentioning it to anyone. A third person confidently presents research that the AI hallucinated. None of these people did anything malicious. They were just trying to get their work done faster, with no guidance on where the lines are.

That's what an AI policy is for. Not to slow people down or signal corporate seriousness — just to answer three questions before they come up the hard way: What tools can we use? What are we not allowed to do with them? And who's responsible when something goes wrong?

Here's how to write one that fits on a single page.


Why "Just Use ChatGPT" Isn't a Policy

A lot of small businesses are operating on informal permission right now: leadership knows AI is happening, nobody's said stop, so everyone's winging it individually.

The problem isn't the tools — it's the inconsistency. Without shared rules:

  • Your exposure varies by employee. One person is meticulous about reviewing AI output; another treats it as gospel. The difference shows up in your deliverables, your client relationships, or worse, a compliance problem.
  • You have no liability anchor. If a client asks "did a human write this?" or "was our information shared with a third-party AI?" you want a documented answer, not a shrug.
  • Mistakes are harder to prevent. People can't follow rules that don't exist. When something goes sideways, you're managing a crisis instead of citing a policy.

None of this requires a 40-page legal document. A one-pager that your team can actually read and remember will do more good than a dense handbook nobody opens.


The Five Things Your Policy Needs to Cover

1. Approved Tools

Pick a short list. Not every AI product is created equal in terms of privacy, cost, or reliability — and you don't want employees signing up for random tools on their personal emails and running company work through them.

Your list might look like: ChatGPT (business account), Microsoft Copilot (via our M365 subscription), Grammarly. Full stop.

If a tool isn't on the list, employees should ask before using it for work. That's not bureaucracy — it's just the same standard you'd apply to any other software purchase.

A simple table comparing approved and unapproved AI tools for a business policy

2. What Data Is Off-Limits

This is the most important section, and it can be written in two sentences.

Do not paste the following into any AI tool: client names or personal information, financial records, legal documents, passwords or credentials, anything marked confidential.

That's it. The reason is straightforward: most consumer AI tools — and some business ones — send your input to third-party servers where you have limited control over how it's stored or used. Even if the risk is low, there's no reason to take it with information that isn't yours to share.

You don't need to explain the technical details to your team. Just give them a clear list of what doesn't go in.

3. Who Reviews AI Output — and How Carefully

AI tools make things up. Not maliciously, not rarely — just confidently and sometimes wrongly. Specific facts, statistics, citations, legal details, and numerical calculations are all areas where AI output needs a human check before it goes anywhere.

Your policy should say, plainly: AI-generated content must be reviewed and verified by the person submitting it. You own the output. If it's wrong, that's on you.

This matters because it closes the "I thought the AI checked it" escape hatch. It also clarifies that using AI doesn't reduce accountability — it just changes the tool.

For higher-stakes work (client-facing documents, anything with legal or financial implications), you might add a second-reviewer requirement. That's a judgment call based on your business.

4. Disclosure — When to Say You Used AI

This one's worth thinking through, because the right answer varies by context — and in a growing number of situations, disclosure is becoming a legal expectation, not just a courtesy.

Internal drafts? Probably no disclosure needed. A marketing email to customers? Depends on your brand and audience. Work you're billing a client for? That's a conversation worth having with each client relationship in mind.

The goal isn't to require disclosures everywhere — it's to make sure your team isn't making that call alone or inconsistently. Write down when disclosure is expected, and you can have a real conversation if a gray area comes up.

A reasonable default for most SMBs: Disclose AI use when a client, customer, or partner would reasonably expect to know about it, or when asked.

5. Who Owns the Policy and What Happens When Rules Are Broken

A policy with no owner is just a piece of paper. Name someone — probably you, or a senior manager — who is responsible for updating the tool list as things change and handling questions about edge cases.

For violations: don't over-engineer this. You don't need a formal disciplinary matrix. You just need to signal that the policy is real. Something like: Violations will be addressed through our standard performance process is enough. The goal is accountability, not fear.


Starter Template: Copy, Edit, Ship

Here's a version you can adapt. Change the bracketed sections to fit your business, and you're done.


[Your Company Name] — AI Use Policy
Effective date: [Date] | Owner: [Name/Role]

Purpose
We use AI tools to work more efficiently. This policy sets out how to use them responsibly, consistently, and in line with our obligations to clients and each other.

Approved Tools
The following AI tools are approved for work use: [List tools]. Using other AI tools for work tasks requires prior approval from [Owner].

Data You Must Not Enter Into AI Tools
Do not enter any of the following into any AI tool: client personal information, financial records, legal or contractual documents, passwords or credentials, or any information marked confidential. When in doubt, don't paste it in.

Reviewing AI Output
AI tools can and do produce incorrect information. You are responsible for reviewing, verifying, and standing behind anything you submit or publish that was generated or assisted by AI. If AI was used to produce something, the human who submitted it owns the result.

Disclosure
Disclose AI use when a client, customer, or partner would reasonably expect to know, or when directly asked. If you're unsure whether to disclose, ask [Owner] before submitting the work.

Questions and Updates
Questions about this policy go to [Owner]. This policy will be reviewed [annually / as needed] as tools and practices evolve.


One page. You can add a signature line if you want it acknowledged formally. You can strip it down further if that feels right for your team. The point is to have something written down.


A Few Things This Policy Won't Do

To be honest: a one-page policy won't fully protect you from every AI-related risk. It won't make ChatGPT more accurate. It won't automatically keep your client data safe if someone ignores the rules. It won't substitute for actual vendor due diligence if you're thinking about building AI into your core operations.

What it does is give your team a shared frame, give you a documented baseline, and reduce the number of preventable mistakes that happen because nobody knew what the rules were. That's worth an hour of your time.

If you're at the stage where you're thinking about using AI more systematically — building it into specific workflows, evaluating tools, figuring out where the actual ROI is — that's a different conversation than a usage policy. It's the kind of thing we work through with clients during an AI strategy engagement: what's worth doing, what's worth protecting, and how to build on a foundation that doesn't create problems later.


If you'd like a second set of eyes on where AI fits in your business — and what guardrails make sense for your specific situation — let's talk. No pitch, just a practical conversation.