AI Usage Policy for Small Business: The Template to Steal Today
Here's a sentence I can say with more authority than most consultants: your employees are using AI right now. Not maliciously - helpfully. The meeting notes they summarized, the customer email they reworded, the contract clause they asked about. The question was never "should we use AI." It's whether you get ahead of it before a confidential paste becomes a client phone call.
Why does a 10-person company need an AI policy?
Because "we're too small for policies" is how small companies end up in big-company trouble. One employee pasting a customer's financials into a free-tier chatbot is a data incident whether you have 10 people or 10,000. Regulators, clients, and cyber insurers have all started asking the same question: do you have a written AI usage policy? "No" is becoming an expensive answer.
What does a good AI usage policy actually cover?
Four things. Anything more is a novel; anything less is a wish.
- Approved tools. A named list - the paid, business-tier accounts with data-retention terms you've read. Everything not on the list is unapproved.
- The never-paste list. Client PII, financials, credentials, health data, unpublished contracts, anything under NDA. Written in plain language with examples, because "confidential information" means nothing at 4:45 PM on a Friday.
- The review rule. AI drafts, humans decide. Anything that goes to a customer, a court, or a regulator gets read by a person who owns the outcome.
- The ask-first path. One named person who answers "can I use it for this?" in under a day. If asking is slow, people stop asking.
Can I see the skeleton?
Sure. This is the spine of the two-pager:
1. Purpose. We use AI tools to work faster. We never trade client trust for speed.
2. Approved tools. [List your paid, vetted accounts here.] Personal accounts are not approved for company work.
3. Never input. Client names with identifying details, financial data, passwords, health information, anything covered by an NDA, anything you wouldn't email to a stranger.
4. Human review. AI output is a draft. A named human reviews and approves everything client-facing, legal, financial, or public.
5. New tools. Want a new tool? Ask [name]. Answer within one business day.
6. Mistakes. Pasted something you shouldn't have? Tell [name] immediately. Reporting fast is never punished.
That last clause matters more than it looks. Policies that punish honest mistakes get silence, not compliance.
What are the dealbreakers when evaluating AI tools?
When you vet the tools for your approved list, three answers end the conversation: the vendor trains on your data with no opt-out, the vendor can't say where your data is stored, or the vendor has no way to delete your data. Everything else is negotiable. Those three aren't.
How do I roll it out without eye-rolls?
Fifteen minutes in a team meeting. Show two real examples of good use, one example of a paste that would have been a problem, and hand out a one-page do/don't sheet. Then the manager FAQ handles the next month of edge cases. Total cost: one afternoon. Total avoided cost: the phone call.
FAQ
What should an AI usage policy include?
What should employees never paste into ChatGPT or other AI tools?
Can I just ban AI tools at my company instead?
Do I need a lawyer to write an AI usage policy?
Be done by lunch.
The AI Usage + Guardrails Kit is the whole afternoon in one download: the two-page policy, the employee one-pager, the manager FAQ, and the 30-question vendor questionnaire with dealbreaker flags. $49, editable, yours forever.
Let's Go - $49