Skip to main content
Back to Blog
AI Policy
AI Governance
Small Business
Security
AI Education

How to Write an AI Use Policy for Your Small Business

Jason Oglesby

By Jason Oglesby · May 28, 2026

Your team is already using AI. Somebody on your payroll pasted a customer email into a chatbot this week, whether you gave permission or not.

That's not a scandal. That's an employee trying to work faster with the tools everyone has in their pocket. But it means the question isn't "should we allow AI?" That ship sailed. The question is whether your people are using it inside guardrails you wrote, or guessing in the dark.

An AI use policy exists to fix the guessing. And the biggest mistake I see is treating the policy like a legal shield: ten pages of thou-shalt-nots, drafted to protect the company from its own employees, read by exactly no one.

A policy nobody reads protects nobody.

The job of your policy is different: make the safe path the easy path. If following the rules is easier than working around them, people follow the rules. If the policy is a wall, they climb it, and you're back to shadow AI with extra resentment.

Ban the Ban Reflex

Some owners respond to AI risk by banning the tools outright. I get the instinct. It doesn't work.

Bans don't stop usage. They just push it onto personal phones and personal accounts, where you have zero visibility, zero controls, and zero chance of catching a mistake before it ships. You trade a manageable risk for an invisible one.

The businesses that get this right do the opposite. They name approved tools, draw bright lines around data, and make it dead simple to ask when something's unclear. Simple and secure isn't a slogan here. It's the design requirement. If the policy is complicated, it's wrong.

The Five Sections Every Policy Needs

Here's the whole skeleton. You can draft this in an afternoon.

Name the approved tools. Not "company-sanctioned AI solutions." Names. "We use ChatGPT Team and Copilot, on company accounts, logged in with your work email." Naming tools kills ambiguity, and company accounts matter because they come with the data controls the free consumer versions don't. If a tool isn't on the list, the answer isn't no forever. It's "ask first."

Draw the data line: what never goes in a prompt. This is the section that earns its keep. Customer PII: names tied to accounts, addresses, payment details, health information. Credentials: passwords, API keys, anything that unlocks anything. And anything under NDA or that you'd fight to keep out of a competitor's hands. Give one plain test your team can run in two seconds: if you wouldn't email it to a stranger, don't paste it into a prompt.

A human owns anything that ships. AI drafts, people decide. Any output that reaches a customer, a vendor, a contract, or your books gets reviewed by a named human, and that human owns it like they wrote it themselves. "The AI got it wrong" is not a sentence that exists in your company. Someone approved it. That's the standard.

Set disclosure rules. Decide where you'll tell people AI was involved, and write it down. Internal drafts? Nobody cares. Client deliverables, published content, anything with legal weight? Decide now, in the calm, not later, in the awkward conversation after a client asks. Whatever you choose, consistency is the policy.

Name who to ask when it's unclear. Every policy has gaps, and the failure mode is an employee guessing silently because asking feels like admitting something. Put one name or one channel in the document and set the tone: asking is free, guessing is expensive. Make the question easier than the mistake.

One Page. This Week.

Notice what that adds up to: five short sections. One page.

That's deliberate. A one-page policy gets read, remembered, and actually used. A ten-page policy gets skimmed once at onboarding and never opened again. Length isn't rigor. Length is where policies go to die.

The other trap is perfectionism. Owners tell me they're waiting until they understand AI better, or until the legal landscape settles, or until next quarter's planning cycle. Meanwhile the pasting continues, ungoverned, every single day.

A one-page policy this week beats a perfect policy this quarter. Ship the page, date it, and revisit it in 90 days. It's a living document, not a monument.

If you want a working draft in hand instead of a to-do list item, this is one of the things we build with teams in our AI education workshops: you leave with your policy written, not just discussed.

Your team started using AI without you. Catch up this week, on one page.