AI Policy Template for Small Business: Set Rules Without Slowing the Team
An AI policy template gives a small business clear rules for approved tools, sensitive data, human review, customer disclosure, ownership and incident reporting. Keep the first version short, tie every restriction to a safe alternative, and review it quarterly so employees can use AI productively without inventing the rules themselves.
Updated August 22, 2026
TL;DR: Your team is probably using AI already. A practical policy should say which tools are approved, what information must stay out, which outputs require human review, when AI use must be disclosed, who approves new uses and what happens when something goes wrong. Copy the template below, replace the brackets, test it against real work and have qualified counsel review obligations specific to your industry and location. The policy is an operating guide, not legal advice or a substitute for sensible workflow design.
Why does a small business need an AI policy now?
An AI policy is a short operating agreement for how people may use AI at work. It does not need to predict every tool or write a legal rule for every prompt. It needs to make common decisions clear before an employee is staring at a blank chatbot window with a customer file open beside it.
Workplace adoption has moved faster than many management teams. Microsoft and LinkedIn’s 2024 Work Trend Index surveyed 31,000 people across 31 countries and found that 75% of knowledge workers used AI at work. Among those users, 78% brought their own AI tools to work. Source: Microsoft and LinkedIn, 2024 Work Trend Index, published May 8, 2024 and accessed August 22, 2026.
That second number is the management problem. People do not wait for a formal software rollout when a free tool can draft a proposal, summarize notes or rewrite an email in seconds. Without a policy, each employee decides which tool is safe, which information can be pasted into it and how much checking is enough. Your real policy becomes a collection of private habits.
Adoption continues to broaden. McKinsey’s global State of AI survey, published November 5, 2025, reported that 88% of respondents said their organizations regularly used AI in at least one business function, up from 78% a year earlier. Yet nearly two-thirds said their organizations had not begun scaling AI across the enterprise. Source: McKinsey, The State of AI: Global Survey 2025, published November 5, 2025 and accessed August 22, 2026.
In plain English: use is widespread, but disciplined operating practices lag. A small business does not need an enterprise governance department. It does need a named owner, a short approved-tool list, firm data boundaries and a review process for risky use cases.
The risk is not theoretical. IBM’s 2025 Cost of a Data Breach report studied 600 organizations that experienced breaches between March 2024 and February 2025. Among those breached organizations, 63% either lacked an AI governance policy or were still developing one. Of the organizations reporting an AI-related security incident, 97% lacked proper AI access controls. Source: IBM, Cost of a Data Breach Report 2025, released July 30, 2025 and accessed August 22, 2026.
Those figures describe breached organizations, not every business, so do not treat them as a universal incident rate. They do show the cost of allowing AI use to grow without clear control over tools, information and access.
A useful policy should protect the business without blocking sensible work. If it says only “do not use AI,” employees will ignore it or hide their usage. If it says “use good judgment,” it has made no decision at all. The right middle ground is specific enough to guide ordinary work and short enough to remember.
What should an AI policy cover?
Your first policy should answer eight questions. If an employee can answer these without asking a manager, the policy is doing its job.
- Scope: Who and what does the policy cover?
- Approved tools: Which AI products and company accounts may be used?
- Allowed work: Which low-risk tasks are acceptable?
- Restricted information: What must never be entered into an unapproved tool?
- Human review: Which outputs must a person check before use?
- Disclosure: When should customers, partners or managers be told that AI was used?
- Ownership: Who approves tools, exceptions and connected workflows?
- Incidents and updates: How are mistakes reported, contained and used to improve the policy?
Use this table to set rules by risk instead of writing one blanket instruction for every task.
| Work category | Typical examples | Default rule | Required check |
|---|---|---|---|
| Low-risk drafting | Brainstorming, outlines, rewrites using public or non-sensitive information | Allowed in approved tools | Employee checks facts, tone and relevance |
| Internal operating work | Meeting summaries, process drafts, task suggestions, internal analysis | Allowed only with information permitted for that tool | Named owner checks accuracy before the output becomes a record or action |
| Customer-facing work | Emails, proposals, marketing claims, support responses | Draft assistance allowed; unsupervised sending prohibited unless separately approved | Responsible employee reviews the final message and customer context |
| Sensitive decisions | Hiring, credit, pricing exceptions, legal, medical, safety or disciplinary decisions | AI may support research only when approved; it may not make the final decision | Qualified human reviews inputs, reasoning, obligations and outcome |
| Connected automation | AI that reads company systems, changes records or sends messages automatically | Approval required before launch | Owner tests access, failure handling, limits, monitoring and a shutoff path |
Do not copy this table blindly. A dental practice, law firm and online retailer handle different information and obligations. Adapt the categories to the work your team actually performs.
NIST’s Generative AI Profile, published July 26, 2024 and updated April 8, 2026, organizes AI risk work around four plain ideas: govern, map, measure and manage. For a small business, that means set responsibility, understand the specific use, check how it performs and control what happens over time. Source: NIST, Artificial Intelligence Risk Management Framework: Generative AI Profile, accessed August 22, 2026.
You do not need to reproduce the full NIST framework in a two-page staff policy. Its structure is useful because it prevents a common mistake: writing rules once and assuming the work is finished. AI use changes as tools gain new features, employees connect more information and workflows move from drafting to automatic action.
What AI policy template can you copy and edit?
Use the following as a starting document. Replace every bracketed field. Remove sections that do not match your work. Add specific examples your team will recognize.
AI USE POLICY
Company: [Company name]
Owner: [Name or role]
Effective date: [Date]
Next review date: [Date, normally within three months]
Purpose
We use approved AI tools to improve the speed and quality of our work while protecting customers, employees, company information and business decisions. AI assists our people. A named person remains responsible for every work product, message and decision.
Who this policy covers
This policy applies to employees, contractors and other people using AI for [Company name]. It covers standalone AI tools, AI features inside existing software and automated workflows that generate, summarize, classify, recommend or act.
Approved tools and accounts
Use only these tools for company work: [List approved tools and permitted account types].
Use company-managed accounts where provided. Do not connect a new AI tool to company email, files, customer records, financial systems or other business software without approval from [owner].
Allowed uses
AI may help with [approved examples such as brainstorming, summarizing public material, drafting non-sensitive internal documents, rewriting text and organizing meeting notes]. Employees must use only information allowed for the approved tool and must review the result before using it.
Information that must stay out
Do not enter passwords, access keys, payment details, private customer or employee information, health information, confidential contracts, unpublished financial information, legal advice, trade secrets or other restricted information into an AI tool unless [owner] has approved that exact tool and use.
Our information labels are:
- Public: Approved for public release.
- Internal: For company use and allowed only in tools approved for internal information.
- Restricted: Customer, employee, financial, legal, security or confidential information. Do not use it with AI unless the exact workflow has written approval.
When unsure, stop and ask [owner or channel]. Do not remove names from a document and assume the remaining details are safe. Context can still identify a person or reveal confidential business information.
Human review
A person must review AI-assisted work before it is sent to a customer, published, used as an official record or used to make a decision affecting a person, price, payment, contract, safety matter or legal obligation.
The reviewer must check facts, names, dates, numbers, sources, tone, missing context and whether the output follows this policy. Fluency is not proof of accuracy.
Customer communication and disclosure
AI may assist with customer communication, but the responsible employee owns the final message. AI must not send external messages automatically unless that workflow has written approval, defined limits, monitoring and an escalation route.
Disclose AI use when required by law, contract, customer instruction or professional rule, and when hiding material AI involvement could mislead the recipient. Ask [owner] when the correct approach is unclear.
Decisions that require extra approval
Do not let AI make final decisions about hiring, dismissal, pay, credit, insurance, medical care, legal rights, safety, disciplinary action or other high-impact matters. Any approved use in these areas requires a qualified person to review the information, method and outcome.
Accuracy, intellectual property and source checking
Employees are responsible for checking AI output. Do not present invented facts, quotations, sources or credentials as real. Do not ask a tool to copy protected material or imitate a living creator’s work for publication. Confirm that the business has the right to use important text, images, data and other material.
New tools and connected workflows
Before approving a new tool or workflow, [owner] will record:
- The business problem and expected result.
- The people and information involved.
- The systems the tool can read or change.
- The vendor’s information handling and account controls.
- The human review step.
- What can go wrong and who receives an alert.
- How the workflow can be paused or reversed.
- The measure and review date.
Incident reporting
Immediately report accidental sharing, wrong external messages, harmful output, unexpected system changes or suspected unauthorized AI use to [person or channel]. Do not hide the mistake or continue the workflow. The owner will contain the issue, preserve relevant records, notify appropriate people and update the process or policy.
Training and acknowledgment
Everyone covered by this policy will receive practical examples of allowed and prohibited use. Employees confirm that they have read the policy and know where to ask questions. Managers will discuss real cases rather than relying only on a policy link.
Review cycle
[Owner] reviews this policy every [three months] and after any serious incident, major tool change or new connected workflow. The approved-tool list may be updated more often.
Approval
Approved by: [Name and role]
Date: [Date]
Acknowledged by: [Employee or contractor]
Date: [Date]
This template is educational and operational guidance, not legal advice. Ask qualified counsel to review requirements for your location, contracts and industry before adoption.
How do you adapt the template to your actual business?
A generic template becomes useful only after it meets real work. Start with an inventory, not a committee.
Ask every team member which AI tools they used in the last 30 days, what task each tool helped with, which account they used and what information they entered. Make the exercise non-punitive. If people expect punishment, they will give you a clean list instead of an accurate one.
For each use, record five facts:
- Job: What result was the person trying to produce?
- Information: What did the tool receive?
- Output: What did it create or recommend?
- Consequence: Who could be affected if the output was wrong or exposed?
- Control: Who checks it before it matters?
Then sort the uses into four decisions: allowed, allowed with safeguards, approval required or prohibited. Those four labels are easier to apply than a long risk vocabulary.
Write examples in the language of your business. “Do not enter sensitive information” is easy to agree with and hard to use. “Do not paste a customer export, signed contract, patient note, payroll file, unpublished price list or password into a public AI account” creates a real boundary.
Pair restrictions with an approved route. If staff may not use a public chatbot with customer records, say which approved account or manual process they should use instead. A restriction without an alternative pushes useful work underground.
Name roles, not vague groups. “Management approval required” creates delay. “The operations lead approves connected tools; the account owner reviews customer messages; the finance lead reviews payment-related analysis” tells people where decisions go.
Finally, test the draft against ten common situations. Can an employee tell what to do when summarizing a public article, rewriting a customer email, analyzing a spreadsheet, transcribing a sales call, drafting a proposal, reviewing job applications, connecting an assistant to email, generating an image, handling a customer complaint or choosing a new tool? Every unclear answer reveals a policy gap.
How should you roll out the policy without creating bureaucracy?
Do not launch the policy as an attachment and declare victory. Run a 30-minute working session with real examples.
First, explain the purpose: faster, safer work with clear boundaries. If people hear only security warnings, they will assume the policy exists to stop AI use.
Second, show the approved-tool list and sign-in rule. Demonstrate the difference between a company-managed account and a personal free account. Explain what information each may handle.
Third, walk through three ordinary examples and one difficult edge case. Ask employees to classify each as allowed, allowed with safeguards, approval required or prohibited. Discussion builds better judgment than a quiz about policy wording.
Fourth, make questions easy. Create one channel or named contact for tool requests and uncertain cases. Record the answer so the next person does not ask again.
Fifth, keep the approval process proportionate. A rewrite using public material should not require a review board. A tool that can read every customer record and send messages should require a documented test, limited access, monitoring and a shutoff path.
Sixth, measure whether the policy works. Track:
- Share of active AI tools on the approved list.
- Share of team members who completed the practical session.
- Number and type of exception requests.
- Incidents, near misses and repeated questions.
- Time from a new-tool request to a clear decision.
- Business workflows reviewed, approved, paused or retired.
Do not reward a low incident count without context. Zero reports can mean perfect behavior or fear of reporting. A healthy first quarter may include several near misses because people now know what to surface.
What does a practical AI policy look like in action?
Consider a 20-person professional-services firm. Employees already use AI for meeting notes, proposal drafts, research summaries and customer emails. The founder wants the productivity benefit but does not know which accounts hold client information.
The firm runs a 30-day inventory and finds seven tools. Four were opened on personal accounts. One note-taking tool joins customer calls automatically. Two employees paste sections of contracts into a public assistant to simplify the language. A salesperson uses an AI email feature that can send follow-ups without a final review.
The policy turns this messy picture into decisions:
- One company-managed writing assistant is approved for public and internal information.
- Contract text is classified as restricted and stays out unless the firm approves a suitable account and workflow.
- Call recording requires a clear consent process and an approved retention rule.
- Customer emails may be drafted by AI but require the account owner’s review.
- Automatic external sending remains off until the firm tests a bounded workflow with clear exclusions and alerts.
- The operations lead owns the approved-tool register and reviews it monthly for the first quarter.
The firm has not banned AI. It has replaced seven private rulebooks with one operating standard. Employees know which tool to use, managers know what requires approval and the founder can improve productive uses without guessing where the information goes.
This is also where policy and automation design meet. A policy can say that a person must review customer messages, but the operating workflow must route the draft to the right person, show the supporting customer context and prevent sending until approval is recorded. A sentence in a document does not create that control by itself.
If your policy review reveals scattered tools, unclear ownership or risky connected workflows, book a free growth consultation with Wavicle. We help non-technical leaders inventory the current work, simplify the rules and build dependable AI-assisted workflows with clear human ownership and measurable business outcomes.
How does Wavicle help turn policy into an operating system?
Wavicle treats the policy as a decision layer, not the final deliverable. The useful work begins where the document meets everyday operations.
We can help you:
- Map where AI is already used across sales, marketing, operations and customer service.
- Identify which tools, accounts and information create avoidable exposure.
- Separate low-risk productivity uses from workflows needing tighter approval.
- Define owners, review steps, exceptions, alerts and shutoff paths.
- Connect approved tools to the systems your team already uses.
- Pilot one workflow with a clear baseline, business measure and review date.
- Create simple reporting so leaders can see usage, outcomes and incidents.
The goal is not more policy. It is faster work without invisible risk. A good engagement should leave your team with fewer tools, clearer ownership and one proven workflow rather than a thick document nobody uses.
Start with the AI readiness assessment if you still need to decide where AI fits. Use the AI use case template if you have too many ideas and need to choose one pilot. When you want help turning the chosen use into a controlled operating workflow, book a free consultation.
What are the frequently asked questions about AI policies?
Is an AI policy legally required?
That depends on your location, industry, contracts and how you use AI. A general template cannot answer the legal question for every business. Treat this document as an operational starting point and ask qualified counsel to review applicable employment, privacy, consumer, intellectual-property and sector-specific obligations.
How long should an AI policy be?
For a small team, the core staff policy can often fit in two to four pages, supported by a separate approved-tool list and practical examples. Clarity matters more than length. If employees cannot find the rule during real work, the policy is too complicated.
Should we ban employees from using free AI tools?
Do not begin with a brand-based ban. Decide what information and tasks are permitted in each account type. A free personal account may be acceptable for brainstorming with public information and completely unsuitable for customer records, confidential documents or connected workflows.
Can employees put customer data into an AI tool?
Only when the business has approved the exact tool, account, data type and purpose after reviewing its obligations and controls. “The vendor is well known” is not approval. When in doubt, keep customer information out and ask the policy owner.
Who should own the AI policy?
Give one senior operator clear responsibility for the policy and approved-tool register, with input from people responsible for security, privacy, legal obligations and the affected business process. In a very small company, that may be the founder or operations lead. One owner prevents the policy from becoming everyone’s concern and nobody’s job.
How often should the policy be reviewed?
Quarterly is a sensible default for a first-year policy. Review sooner after an incident, a major vendor change, a new law or contract requirement, or the launch of a connected workflow that can access records, make changes or contact customers.
Does a policy make AI use safe?
No. A policy creates consistent decisions and accountability. Safety still depends on tool selection, information handling, access limits, human review, training, monitoring and workflow design. The document tells people what should happen; the operating system must make the right action easy.
What is the first step if the team already uses many AI tools?
Run a non-punitive 30-day inventory. Ask which tools are used, for what jobs, with which accounts and information, and who checks the output. Freeze new connections while you review the list, but do not force useful work into hiding. Then approve, restrict, replace or retire each use based on evidence.
Ready to turn scattered AI use into clear, productive workflows? Book a free growth consultation with Wavicle.