How to Write an AI Policy for Your Small Business
Why every SMB needs an AI use policy in 2026, the 9 sections it must contain, and a copy-paste policy template you can adapt in 30 minutes.
What Actually Goes Wrong Without an AI Policy?
What Are the 9 Sections Every SMB AI Policy Needs?
The Copy-Paste AI Policy Template
How Do You Roll Out an AI Policy Without It Being Ignored?
When Should You Involve a Lawyer?
The Bottom Line
1. Approved Tools and Accounts
2. Prohibited Data
3. Output Review Requirements
4. Client Disclosure
5. Intellectual Property Ownership
6. Security Requirements
7. Compliance Overlays
8. Training and Acknowledgment
9. Enforcement
An AI policy is a short written document — usually one to three pages — that tells employees which AI tools they may use, what data must never go into them, and when AI output requires human review. Thirty minutes spent adapting a template prevents the three incidents I see most at SMBs: confidential data leaked into consumer AI tools, hallucinated AI content reaching clients, and unmanaged "shadow AI" accounts.
Your employees are already using AI at work. Every survey says so, and every audit I run confirms it — including at companies whose owners were sure "we haven't rolled that out yet." The only question is whether they're using it under rules you wrote, or improvising with your client data in a free consumer account. This guide gives you the reasons, the nine required sections, and a complete copy-paste template so you can close that gap this week.
These are composites of real situations from my consulting and security audit work, anonymized but not exaggerated:
None of these people were malicious. They were productive employees filling a vacuum. A policy fills the vacuum first — and if you're still deciding which tools to sanction, our Claude vs. ChatGPT business comparison and 2026 SMB AI stack guide will get you to a shortlist quickly.
I've written and reviewed AI policies for companies from 5 to 200 employees. The ones that work all cover the same nine areas. Keep each to a short paragraph — the template below shows how compact this can be.
Name the specific tools and account tiers employees may use — for example, "Claude Team and ChatGPT Team accounts provisioned by the company." The tier matters as much as the tool: business plans exclude your data from model training by default, while free consumer accounts may not. Include a simple request path for new tools ("ask the owner; answer within a week") so the list can grow without being bypassed.
The most important section. List, concretely, what never goes into an AI tool at any tier: customer personal data, employee HR and payroll records, financial account numbers, credentials and API keys, unreleased financials, and anything under NDA. Concrete beats abstract — "no Social Security numbers, no bank details, no client contract terms" is followed; "no sensitive information" is interpreted.
Define when a human must review AI output before it's used. My default rule for clients: anything leaving the building — client emails, proposals, published content, invoices — and anything involving numbers, legal claims, or compliance statements gets human review, every time. Internal brainstorms and first drafts don't. This single rule would have prevented the $12,000 HIPAA incident above.
Decide, in advance, when you tell clients AI was involved. Check your client contracts first — a growing number of MSAs restrict or require disclosure of AI processing of client data. A defensible default: disclose when AI materially produced a deliverable or processes client data in an ongoing way (like meeting transcription), and name a human accountable for every deliverable regardless.
State that work product created with AI assistance on company time belongs to the company, and require employees to flag AI-generated content in deliverables where originality matters. Also note the flip side: purely AI-generated material may have limited copyright protection, so anything you need to own outright — logos, flagship content, product code — should have meaningful human authorship layered in.
Require company-managed accounts (not personal), multi-factor authentication, and no AI browser extensions or plugins without approval — extensions that can read every page an employee views are a data-exfiltration risk hiding in plain sight. If you automate workflows with AI steps, inherit the controls from our automation security guide: least-privilege API keys, logging, and human approval gates on anything touching money or client communication.
If you're in a regulated space, add the overlay that applies: HIPAA (no PHI in any AI tool without a BAA in place), legal privilege (no privileged material in third-party tools), financial regulations, defense/ITAR, or state privacy laws like the Texas data privacy act if you sell to consumers at scale. This is the section where AI readiness and compliance intersect — and the one most worth an attorney's hour.
A policy nobody has read protects nobody. Require a short onboarding session (30 minutes is enough), an annual refresher, and a signed acknowledgment kept in each personnel file. The signature isn't bureaucracy — if you ever face a client dispute or insurance claim over an AI incident, documented training is the difference between "company negligence" and "individual violation of a communicated policy."
Say what happens when the policy is broken, and mean it. A workable SMB standard: honest mistakes and gray areas get coaching and a policy clarification; knowing violations involving prohibited data follow your existing disciplinary process, same as any confidentiality breach. Name one person (owner, ops lead, or fractional CTO) as the decision-maker for questions, so ambiguity has somewhere to go besides guesswork.
Here's the complete template I hand to clients. Replace the bracketed items, delete what doesn't apply, and you'll have a working policy in about 30 minutes. It's written for a company of 5-50 people using business-tier AI chat tools.
The policy is the artifact; the rollout is what changes behavior. This sequence takes about two weeks:
For most unregulated SMBs, an owner-adapted template plus a one-hour attorney review — typically $300-$600 — is the right level of investment. Move counsel from "nice to have" to "required" if any of these apply:
What I'd caution against is the opposite failure: waiting six months for a perfect legal review while employees improvise daily. Ship the one-page version now, schedule the review, iterate.
An AI policy is the cheapest risk control in your entire technology budget: 30 minutes of adaptation, one 30-minute training, roughly $25-30 per user per month for sanctioned tools — versus data-leakage incidents, client-trust damage, and compliance cleanup jobs that routinely run five figures. Write the nine sections, use the template, provision real accounts, and make compliance the path of least resistance. Then get on with the productive part: actually putting AI to work, starting with the right first workflow.
Want a second set of eyes on your draft — or a compliance-ready rollout for a regulated shop? Book a free call and bring your current policy (or the blank template). We'll pressure-test it against how your team actually works.
- The pasted client list. A sales coordinator at a 20-person distributor pasted the full customer list — names, contacts, pricing terms — into a free AI account to "clean up the formatting." Nothing catastrophic happened, and that's the point: nobody knew it happened for months, no one could say what the consumer tool's data terms allowed, and the company's largest client had an NDA that arguably prohibited exactly this. Discovered during an audit, disclosed awkwardly, relationship survived. Barely.
- The hallucinated compliance answer. An office manager at a healthcare-adjacent firm asked a chatbot whether a specific patient-communication practice was HIPAA-compliant, got a confident and wrong answer, and built a workflow around it. Unwinding it cost roughly $12,000 in consulting and remediation. AI output that sounds authoritative is precisely the output that needs review.
- The shadow AI sprawl. A 35-person professional-services firm asked me to help them "start using AI." Discovery found 11 employees already using 6 different AI tools on personal accounts — including one who had connected an AI notetaker to every client call for four months. No client had been told; several client contracts required disclosure of third-party data processors. The cleanup took longer than the original rollout would have.
- Provision the approved tools first. Buy the business-tier seats before you announce the rules. A policy that says "don't use personal accounts" while providing no alternative is a shadow-AI generator. Budget roughly $25-30/user/month per platform.
- Announce with the why, not just the what. Share one anonymized horror story (borrow mine above). Employees follow rules they understand; they route around rules that look like paranoia.
- Run one 30-minute training. Walk through the prohibited-data list with examples from your actual business: "our customer spreadsheet — no; a blank proposal outline — yes." Collect signed acknowledgments the same day.
- Offer amnesty for existing shadow AI. Give everyone two weeks to declare tools they're already using, no consequences. You'll learn more about real AI usage in your company from this than from any survey — and you'll often discover your best power users and future champions.
- Revisit at 90 days. What tool requests came in? What gray areas surfaced? Update the policy to version 1.1 and re-share. Pair this with the broader readiness work in our 12-point AI readiness checklist if you're also scaling up automation.
- You handle regulated data: health information (HIPAA), consumer financial data, defense-related work (ITAR/CMMC), or you're subject to state privacy statutes.
- Your client contracts contain confidentiality, subcontractor, or data-processing clauses — an AI tool can qualify as a data processor you're obligated to disclose.
- You're in a licensed profession (law, accounting, medicine, engineering) with professional-responsibility rules that touch AI use.
- You plan to train or fine-tune AI on customer data, or ship AI-generated content where copyright ownership is commercially important.
Frequently Asked Questions
Does a small business really need a formal AI policy?
Yes, once even one employee uses AI for work — and surveys consistently show a majority already do, often without telling their boss. A one-page policy takes about 30 minutes to adapt from a template and directly addresses the three most common AI incidents: confidential data pasted into consumer tools, unreviewed AI errors reaching clients, and unsanctioned shadow-AI accounts.
How long should an SMB AI policy be?
One to three pages. A 20-page policy written for a Fortune 500 will not be read, let alone followed, at a 15-person company. Cover approved tools, prohibited data, review requirements, and consequences in plain English. If an employee cannot summarize the rules after one read, the policy is too long.
What data should employees never put into AI tools?
At minimum: customer personal data, employee HR and payroll records, financial account numbers, passwords and API keys, unreleased financials, and anything covered by an NDA or regulation such as HIPAA. On consumer-tier AI accounts, treat every prompt as if it were being sent to an outside vendor — because it is.
Do we have to tell clients we use AI?
It depends on your industry and contracts, which is why disclosure gets its own policy section. Professional-services firms increasingly face client contracts that restrict AI use on their data, and some regulated fields require disclosure. A sensible default: disclose when AI materially produced a deliverable, and always keep a human accountable for the final product.
When should a lawyer review our AI policy?
Bring in counsel if you handle regulated data (HIPAA, financial, defense), your client contracts contain confidentiality or AI clauses, or you operate in a licensed profession. For a typical unregulated SMB, an owner-adapted template is far better than nothing, and a one-hour attorney review — typically $300-$600 — is cheap insurance once the draft exists.
How do we enforce an AI policy without becoming the AI police?
Make compliance easier than violation. Provide paid business-tier accounts for approved tools so nobody needs a personal workaround, run a 30-minute training with real examples, and treat first offenses as coaching moments. Reserve discipline for knowing violations involving prohibited data — the same standard you would apply to any confidentiality breach.