How to Write an AI Policy for Your Small Business

Why every SMB needs an AI use policy in 2026, the 9 sections it must contain, and a copy-paste policy template you can adapt in 30 minutes.

What Actually Goes Wrong Without an AI Policy?

What Are the 9 Sections Every SMB AI Policy Needs?

The Copy-Paste AI Policy Template

How Do You Roll Out an AI Policy Without It Being Ignored?

When Should You Involve a Lawyer?

The Bottom Line

1. Approved Tools and Accounts

2. Prohibited Data

3. Output Review Requirements

4. Client Disclosure

5. Intellectual Property Ownership

6. Security Requirements

7. Compliance Overlays

8. Training and Acknowledgment

9. Enforcement

An AI policy is a short written document — usually one to three pages — that tells employees which AI tools they may use, what data must never go into them, and when AI output requires human review. Thirty minutes spent adapting a template prevents the three incidents I see most at SMBs: confidential data leaked into consumer AI tools, hallucinated AI content reaching clients, and unmanaged "shadow AI" accounts.

Your employees are already using AI at work. Every survey says so, and every audit I run confirms it — including at companies whose owners were sure "we haven't rolled that out yet." The only question is whether they're using it under rules you wrote, or improvising with your client data in a free consumer account. This guide gives you the reasons, the nine required sections, and a complete copy-paste template so you can close that gap this week.

These are composites of real situations from my consulting and security audit work, anonymized but not exaggerated:

None of these people were malicious. They were productive employees filling a vacuum. A policy fills the vacuum first — and if you're still deciding which tools to sanction, our Claude vs. ChatGPT business comparison and 2026 SMB AI stack guide will get you to a shortlist quickly.

I've written and reviewed AI policies for companies from 5 to 200 employees. The ones that work all cover the same nine areas. Keep each to a short paragraph — the template below shows how compact this can be.

Name the specific tools and account tiers employees may use — for example, "Claude Team and ChatGPT Team accounts provisioned by the company." The tier matters as much as the tool: business plans exclude your data from model training by default, while free consumer accounts may not. Include a simple request path for new tools ("ask the owner; answer within a week") so the list can grow without being bypassed.

The most important section. List, concretely, what never goes into an AI tool at any tier: customer personal data, employee HR and payroll records, financial account numbers, credentials and API keys, unreleased financials, and anything under NDA. Concrete beats abstract — "no Social Security numbers, no bank details, no client contract terms" is followed; "no sensitive information" is interpreted.

Define when a human must review AI output before it's used. My default rule for clients: anything leaving the building — client emails, proposals, published content, invoices — and anything involving numbers, legal claims, or compliance statements gets human review, every time. Internal brainstorms and first drafts don't. This single rule would have prevented the $12,000 HIPAA incident above.

Decide, in advance, when you tell clients AI was involved. Check your client contracts first — a growing number of MSAs restrict or require disclosure of AI processing of client data. A defensible default: disclose when AI materially produced a deliverable or processes client data in an ongoing way (like meeting transcription), and name a human accountable for every deliverable regardless.

State that work product created with AI assistance on company time belongs to the company, and require employees to flag AI-generated content in deliverables where originality matters. Also note the flip side: purely AI-generated material may have limited copyright protection, so anything you need to own outright — logos, flagship content, product code — should have meaningful human authorship layered in.

Require company-managed accounts (not personal), multi-factor authentication, and no AI browser extensions or plugins without approval — extensions that can read every page an employee views are a data-exfiltration risk hiding in plain sight. If you automate workflows with AI steps, inherit the controls from our automation security guide: least-privilege API keys, logging, and human approval gates on anything touching money or client communication.

If you're in a regulated space, add the overlay that applies: HIPAA (no PHI in any AI tool without a BAA in place), legal privilege (no privileged material in third-party tools), financial regulations, defense/ITAR, or state privacy laws like the Texas data privacy act if you sell to consumers at scale. This is the section where AI readiness and compliance intersect — and the one most worth an attorney's hour.

A policy nobody has read protects nobody. Require a short onboarding session (30 minutes is enough), an annual refresher, and a signed acknowledgment kept in each personnel file. The signature isn't bureaucracy — if you ever face a client dispute or insurance claim over an AI incident, documented training is the difference between "company negligence" and "individual violation of a communicated policy."

Say what happens when the policy is broken, and mean it. A workable SMB standard: honest mistakes and gray areas get coaching and a policy clarification; knowing violations involving prohibited data follow your existing disciplinary process, same as any confidentiality breach. Name one person (owner, ops lead, or fractional CTO) as the decision-maker for questions, so ambiguity has somewhere to go besides guesswork.

Here's the complete template I hand to clients. Replace the bracketed items, delete what doesn't apply, and you'll have a working policy in about 30 minutes. It's written for a company of 5-50 people using business-tier AI chat tools.

The policy is the artifact; the rollout is what changes behavior. This sequence takes about two weeks:

For most unregulated SMBs, an owner-adapted template plus a one-hour attorney review — typically $300-$600 — is the right level of investment. Move counsel from "nice to have" to "required" if any of these apply:

What I'd caution against is the opposite failure: waiting six months for a perfect legal review while employees improvise daily. Ship the one-page version now, schedule the review, iterate.

An AI policy is the cheapest risk control in your entire technology budget: 30 minutes of adaptation, one 30-minute training, roughly $25-30 per user per month for sanctioned tools — versus data-leakage incidents, client-trust damage, and compliance cleanup jobs that routinely run five figures. Write the nine sections, use the template, provision real accounts, and make compliance the path of least resistance. Then get on with the productive part: actually putting AI to work, starting with the right first workflow.

Want a second set of eyes on your draft — or a compliance-ready rollout for a regulated shop? Book a free call and bring your current policy (or the blank template). We'll pressure-test it against how your team actually works.

Frequently Asked Questions

Does a small business really need a formal AI policy?

Yes, once even one employee uses AI for work — and surveys consistently show a majority already do, often without telling their boss. A one-page policy takes about 30 minutes to adapt from a template and directly addresses the three most common AI incidents: confidential data pasted into consumer tools, unreviewed AI errors reaching clients, and unsanctioned shadow-AI accounts.

How long should an SMB AI policy be?

One to three pages. A 20-page policy written for a Fortune 500 will not be read, let alone followed, at a 15-person company. Cover approved tools, prohibited data, review requirements, and consequences in plain English. If an employee cannot summarize the rules after one read, the policy is too long.

What data should employees never put into AI tools?

At minimum: customer personal data, employee HR and payroll records, financial account numbers, passwords and API keys, unreleased financials, and anything covered by an NDA or regulation such as HIPAA. On consumer-tier AI accounts, treat every prompt as if it were being sent to an outside vendor — because it is.

Do we have to tell clients we use AI?

It depends on your industry and contracts, which is why disclosure gets its own policy section. Professional-services firms increasingly face client contracts that restrict AI use on their data, and some regulated fields require disclosure. A sensible default: disclose when AI materially produced a deliverable, and always keep a human accountable for the final product.

When should a lawyer review our AI policy?

Bring in counsel if you handle regulated data (HIPAA, financial, defense), your client contracts contain confidentiality or AI clauses, or you operate in a licensed profession. For a typical unregulated SMB, an owner-adapted template is far better than nothing, and a one-hour attorney review — typically $300-$600 — is cheap insurance once the draft exists.

How do we enforce an AI policy without becoming the AI police?

Make compliance easier than violation. Provide paid business-tier accounts for approved tools so nobody needs a personal workaround, run a 30-minute training with real examples, and treat first offenses as coaching moments. Reserve discipline for knowing violations involving prohibited data — the same standard you would apply to any confidentiality breach.