Why one page beats a policy binder

Most AI policies fail for one reason: nobody reads them. Your team needs three things they can remember on a Tuesday afternoon: which tool to use, what must never be pasted in, and when a person has to check the output. Everything else belongs in training, not in the document.

This template is written for owner-led businesses with no compliance department. If you have regulatory or contractual obligations, treat it as a draft for your attorney to review.

What to include

  1. Purpose. One sentence on why the policy exists.
  2. Approved tools. The specific tools and accounts staff may use for work.
  3. Prohibited data. The categories that never go into any AI tool, approved or not.
  4. Human review. When output must be checked by a person before it is used.
  5. Transparency. When customers and colleagues must be told AI was involved.
  6. Accounts and access. No personal accounts for work data; least access by default.
  7. Questions and exceptions. Who decides, and how fast.
  8. Review date. When the policy gets updated next.

The template

Copy everything below the line into a document, replace the bracketed text, and date it.


[Company name] AI Acceptable Use Policy

Effective [date]. Owner: [name, role]. Next review: [date].

1. Purpose

We use AI tools to do better work faster. This policy exists so we can do that without exposing client information, our own data, or our reputation.

2. Approved tools

You may use the following tools for work, on the company account only: [tool 1, business tier], [tool 2], [tool 3]. Any other AI tool, extension, plugin, or meeting note-taker needs approval from [name] before use.

3. What never goes into an AI tool

Do not enter the following into any AI tool, approved or not, unless [name] has confirmed in writing that the specific tool is cleared for it:

  • Client or customer personal information (names with contact details, IDs, account numbers)
  • Financial records, bank exports, payroll, and tax documents
  • Health, HR, or legal matters about any individual
  • Anything covered by an NDA or client confidentiality agreement
  • Passwords, keys, and login details of any kind
  • [Industry-specific items, for example patient records, case files, tenant applications]

4. Human review

AI output is a draft. A person must review before it is used for: anything sent to a customer or client, prices and quotes, contracts and legal language, financial figures, and anything published under our name. Check facts, numbers, and names against the source.

5. Transparency

Be honest when asked whether AI was used. Do not present AI-generated work as a personal opinion or expert judgment when it is not. AI assistants that interact with customers must identify themselves as AI.

6. Accounts and access

Use company accounts for work. Personal AI accounts may not be used with work data. Do not connect AI tools to company files, email, or systems without approval. Access to documents follows the principle of least access: people and tools see only what they need.

7. Questions and exceptions

If you are unsure, ask [name] before you paste. Exceptions are granted in writing and recorded in [location]. We would rather answer ten questions than clean up one incident.

8. Review

This policy is reviewed every [three] months and whenever a new tool is approved. The current version is always at [location].


Rolling it out

  • Give people the approved tool first. A policy that only takes things away gets ignored. Seats on a business tier make the rule free to follow.
  • Walk through it in 20 minutes. Read it together, show the three examples of prohibited data most relevant to your business, and answer questions.
  • Fix the permissions that matter. Payroll, legal, HR, and client files. The policy assumes least access; make it true.
  • Train on real work. The fastest way to end shadow AI is to make the approved tool obviously better on the team's actual tasks.

If you want the inventory, the permissions model, and the policy done for you, that is exactly what the AI audit delivers in two weeks. For the training half, see AI for your whole team.

FAQ

Policy questions, answered

Do small businesses really need an AI usage policy?

If anyone on your team can reach a chatbot, yes. The policy is one page and it does two jobs: it tells people which tool to use and what must never be pasted into it. Without it, staff make those calls alone.

How long should an AI acceptable use policy be?

One page. Longer policies do not get read. Cover approved tools, prohibited data, review rules, transparency, and who to ask. Put the details in training, not the document.

Should we ban personal AI accounts?

For work data, yes. Give everyone a seat on an approved business tier instead, so the ban costs them nothing.

How often should we update it?

Review it quarterly and whenever you approve a new tool. Date the document so everyone knows which version is current.

Is this legal advice?

No. This template is a practical starting point written by an AI consultancy, not a law firm. If you have regulatory or contractual obligations, have your attorney review the final policy.

Done for you

Want the policy, the permissions, and the training handled?

A fixed-fee AI audit inventories what is in use, fixes who can see what, and writes the policy with you. Scoped in a 30-minute call.