An AI usage policy is a short document that tells your team which AI tools they may use, what data they may put into them, and when a human has to review the results. For a small business, it should be one or two pages in plain language, short enough that people actually read it. This guide walks through what to include and gives you a starter template you can adapt today.
Why Your Small Business Needs One
Here is the uncomfortable reality: your employees are almost certainly already using AI. The 2026 U.S. Chamber of Commerce Small Business Survey found 89% of small businesses using AI in some form. Most of that is employee-led and ungoverned: people pasting customer emails, contracts, and spreadsheets into personal ChatGPT accounts because it makes their job easier.
Without a policy, you have all of the risk and none of the control. A policy does not slow your team down; it gives them permission to use AI confidently, within lines that protect your business. It is also the foundation regulators, insurers, and enterprise clients increasingly expect to see.
The Six Things Every AI Policy Should Cover
1. Approved tools. List the AI tools employees may use for work, and note that anything not on the list needs approval. This alone eliminates most shadow-AI risk.
2. Data rules. State clearly what may and may not be entered into AI tools. This is the heart of the policy. (For the reasoning behind these rules, see is ChatGPT safe for business data.)
3. Human review. Define when AI output must be checked by a person before it goes out: client-facing writing, anything with numbers, legal or medical content.
4. Disclosure. Say when AI use must be disclosed, both internally and to clients. Some industries and contracts require it.
5. Accountability. Make clear that the employee, not the tool, is responsible for the work product. AI assists; it does not sign off.
6. Who to ask. Name a person or channel for questions. Most policy violations are honest confusion, not defiance.
A Plain-Language Starter Template
Adapt the following to your business. Keep the tone practical.
[Company] AI Usage Policy
Purpose. AI tools can make our work faster and better when used carefully. This policy explains how to use them safely.
Approved tools. You may use the following AI tools for work: [list, e.g., ChatGPT Team, our transcription tool]. To use any other AI tool for work, ask [name] first.
What you may enter. General questions, public information, drafts of internal documents, and anonymized examples.
What you must never enter. Customer names or personal details, health or financial records, passwords or credentials, contract terms under NDA, or anything you would not post publicly. When in doubt, leave it out and ask [name].
Human review. Anything a client will see, anything with numbers or legal/medical content, must be reviewed by a person before it goes out. You are responsible for the final work, not the AI.
Disclosure. Tell [name] if AI produced a substantial part of a client deliverable. Disclose AI use to clients when a contract or regulation requires it.
Questions. Not sure? Ask [name] before you act. You will never be in trouble for asking.
Common Mistakes to Avoid
- Making it too long. A 20-page policy is a policy nobody reads. One page beats twenty.
- Writing it once and forgetting it. AI tools change monthly. Review the policy at least twice a year.
- Skipping training. A policy in a shared drive changes nothing. A 30-minute walkthrough turns it into behavior. Our guide on training employees on AI covers how.
- Banning everything. A policy that says "no AI" just pushes usage underground. Enable safe use instead.
The Bottom Line
An AI usage policy is the cheapest, fastest risk-reduction step a small business can take. It takes an afternoon, fits on a page, and turns unmanaged AI use into something deliberate and safe. Start with the template above, tailor it to your tools, and pair it with a short training session.
If you would rather have it done for you, a starter AI usage policy is one of the five deliverables of the SafeStart AI Audit, written for your specific tools and team, with training included. Book a free discovery call to learn more.
Frequently Asked Questions
Does a small business really need an AI usage policy?
Yes. If your employees use ChatGPT or similar tools, and surveys show most do, you already have AI in your business, just without any rules. A one-page policy protects your customer data, sets clear expectations, and takes an afternoon to draft. It is the single cheapest risk-reduction step most small businesses can take.
What should an AI usage policy include?
At a minimum: which AI tools are approved, what data may and may not be entered, when AI output must be reviewed by a human, when AI use must be disclosed to clients, and who to ask when unsure. Keep it to one or two pages in plain language.
How long should an AI usage policy be?
One to two pages. A policy people can read in five minutes gets followed. A 20-page legal document gets ignored. Start short and add detail only where a real situation requires it.
How often should we update our AI policy?
Review it at least twice a year, and any time you adopt a major new tool or a new regulation affects your industry. AI tools change monthly, so a policy written once and forgotten quickly goes stale.
One email a week on AI for business: which tools are worth paying for, what to keep out of chatbots, and what's changing for small businesses, in plain language.
Subscribe to the NewsletterMore from SafeLab
Public bids live on dozens of disconnected agency portals. Here is how we built FindBids to read every solicitation with AI and match small contractors to the handful of bids they can actually win.
A staffing agency had AI licenses and almost no adoption. Here is how role-specific training on their own live workflows turned unused seats into daily use, with PII rules agreed on up front.
AEO is how you get named and recommended inside AI answers from ChatGPT, Perplexity, and Google AI Overviews. Here is what it is, how it differs from SEO, and how to do it.