Does a Five-Person Business Really Need an AI Policy?

Coding Liquids tutorial cover featuring Sagnik Bhattacharya for Does a Five-Person Business Really Need an AI Policy?
Coding Liquids tutorial cover featuring Sagnik Bhattacharya for Does a Five-Person Business Really Need an AI Policy?

Yes, but a one-page policy, not a handbook. Once any of your five people uses AI with customer details, client files or anything published under your name, write down which tools are allowed, what data never goes in, and who checks the output. It takes about an hour to write and ten minutes to explain at a team meeting.

The exception is a business where nobody uses AI for work and nobody plans to, which is rarer than most owners think. Most five-person firms hit at least one of the six triggers below, and the policy that answers them fits on a page, as the print shop template further down shows. The harder skill is knowing what a team this size can leave out.

Follow me on Instagram@sagnikteaches

Six signs your five-person business already needs one

Go through these honestly. Each is a situation where the lack of a written rule has a real cost.

Connect on LinkedInSagnik Bhattacharya
  1. Someone uses a personal or free AI account for work. If you don't know, assume yes, and see how to find out whether your team uses AI without telling you. Personal accounts belong to the person, not the business, and they leave when the person does.
  2. Customer or client data could end up in an AI tool. Staff need to know which plan can take which data. Without a rule, each person draws the line in a different place.
  3. AI-drafted work goes out under your name. Quotes, emails, social posts and proofs all carry your reputation. Someone has to be responsible for checking them.
  4. A client, tender or insurer asks about AI. Some supplier questionnaires now include a question on AI use. "We have a written policy, here it is" is a much stronger answer than "we're careful".
  5. You sell to customers in the EU. Article 4 of the EU AI Act has applied since 2 February 2025. Since the Digital Omnibus changes took effect on 27 July 2026, providers and deployers must take measures to support their staff's AI literacy, without having to guarantee a particular level. A short policy plus a briefing is the simplest evidence that you've done so.
  6. You've already had a near miss. A wrong price in an AI-drafted quote, a client file pasted into a free tool, an AI image a customer mistook for a proof. One near miss is usually the first of several.

Trigger 4 is where a written page pays for itself fastest. Here's an illustrative answer a small bookkeeping firm could give to a client questionnaire asking "Describe your use of AI tools and the controls in place":

Subscribe on YouTube@codingliquids

"We use ChatGPT Business, in a company workspace that doesn't train on our data by default, to draft emails and summaries. Client figures always come from our accounts software, and every client-facing document is checked in full by the bookkeeper who sends it. No bank details, passwords or identity documents go into any AI tool. Our written AI rules are reviewed every six months; the current version is attached."

Four sentences, all of them true only because the policy exists. Without it, the honest answer is "we're careful", which doesn't survive a follow-up question.

A rule of thumb: two or more of these, write the policy this week. One, write it this month. None, put a reminder in the diary for six months' time and ask the question again.

What a five-person policy can leave out

Most AI policy templates online are written for companies with a legal team and an IT department. Copying one into a five-person business produces a document nobody reads. You can safely skip:

  • An AI committee or steering group. In a business this size, the owner is the committee. Name them.
  • Risk-tiering matrices that sort every AI use into four levels with separate approval routes. A simple list of "never put this in" does the same job for you.
  • A model inventory. You'll have two or three tools. List them by name.
  • Long values statements about responsible AI. One sentence on honesty with customers covers it.
  • Department-by-department procedures. You don't have departments. You have people who all do a bit of everything.

What you can't skip is shorter than you'd expect: the approved tools, the data that never goes in, how output is checked, honesty with customers, what to do when something goes wrong, and who owns the rules.

A one-page AI policy for a five-person print shop

Here's a complete example for an illustrative print shop with five staff. It handles customer artwork, prints business stationery and signage, and uses AI mainly for quote emails, product descriptions and design ideas. Copy it and change the specifics.

[BUSINESS NAME] AI RULES - version 1, [date]
These rules are owned by [owner's name]. Questions go to them.

1. APPROVED TOOLS
   - ChatGPT Business, in the company workspace: drafting emails,
     product descriptions, summaries and ideas.
   - The built-in AI features of our design software: early design
     concepts only.
   Nothing else is used for work without asking [owner] first.
   Personal AI accounts are not used for work.

2. NEVER PUT INTO ANY AI TOOL
   - Card numbers, bank details or passwords.
   - Customer artwork or files marked confidential, or anything
     covered by an NDA.
   - Customers' home addresses or phone numbers, unless the task
     needs them and the tool is on the approved list.
   - Anything about a colleague's health, pay or discipline.

3. CHECKING
   - Every price, quantity, size and date that AI has touched is
     checked against the job sheet before it's sent.
   - Anything going to a customer is read in full by the person
     who sends it. That person is responsible for it.
   - AI-generated images are never sent as proofs of a finished
     print. Proofs come from the actual artwork file.

4. HONESTY WITH CUSTOMERS
   - If a customer asks whether we use AI, we say yes and explain how.
   - Any chat on our website that isn't a person says so.

5. WHEN SOMETHING GOES WRONG
   - Tell [owner] the same day. Nobody is blamed for reporting.
   - Delete the chat, write down what was shared, and we decide
     the next steps together.

6. REVIEW
   - We review these rules every six months and whenever we add
     or drop a tool.

Read and understood: ______________   Date: __________

Notice what's specific to printing: the proof rule in section 3 and the artwork rule in section 2. Your version should have one or two rules like that, drawn from the mistakes most likely in your trade. Those are the lines people remember.

Here's what those trade-specific lines might look like elsewhere, as illustrations:

BusinessThe likely mistakeThe rule that goes in section 2 or 3
Four-person physiotherapy clinicTidying treatment notes with an AI summary button"Nothing about a patient's condition or treatment goes into any AI tool, including AI features inside the booking software, which stay switched off."
Three-person bookkeeping firmAn AI-typed figure in a client letter"Every figure in a client letter is copied from the accounts software, never typed or calculated by AI."
Wedding photographer with two assistantsUploading a couple's photos to an editing tool that trains on uploads"Client photos only go into the approved editing software. Removing or changing a person in an image needs the couple's written OK."
Five-person lettings agencyAI listing copy describing features a property doesn't have"Every feature in a listing is checked against the inventory and photos before it's published."

One gap the template leaves open is people who work for you but aren't staff. The print shop sends overflow design work to a freelance designer, who uses their own AI tools on their own computer. Section 1 can't bind someone the shop doesn't employ, yet the artwork rule matters just as much once files leave the shop. The fix is one line in the job brief or the freelancer's agreement: "Customer artwork we send you doesn't go into any AI tool that trains on uploads, and nothing marked confidential goes into AI at all." Ask them to confirm by reply, and keep the email with the job.

Four everyday questions the one-pager settles in advance

The real test of a short policy is whether it answers the questions staff actually ask on a busy Tuesday. Here's how the print shop's version handles four of them.

"Can I run a customer's blurry logo through a free AI upscaler?" Section 1 says nothing outside the approved list without asking, and section 2 covers customer artwork. So the answer is: ask the owner first. The owner may well say yes for a logo that's already public on the customer's shopfront, and no for artwork sent under a confidentiality agreement. Either way, the decision is made once and then applies to everyone.

"A customer wants to know if we wrote their brochure copy with AI." Section 4 answers it: yes, we used AI to draft it, a person edited and checked it, and here's how we use it. Nobody has to decide on the spot whether to be evasive.

"I pasted last month's order spreadsheet into my own ChatGPT to find our best sellers." Section 5 applies. Tell the owner the same day, delete the chat, and note which columns were in the file. If it held only product codes and totals, that's the end of it. If it held customer names and addresses, the owner decides whether anything more is needed.

"The AI mock-up looks better than the real print will. Can I send it anyway?" Section 3 says no: proofs come from the actual artwork file. That one line prevents the most common complaint a print shop using AI images is likely to get.

If your draft can't answer questions like these, it's too vague. If it needs three pages to answer them, it's too detailed for five people.

Writing yours in an hour

Do it in this order, because each step feeds the next:

  1. List the tools actually in use (10 minutes). Ask the team, don't guess. Decide which to approve, and whether any need moving to a business account. For the print shop, the ten-minute list read: ChatGPT Plus on the owner's personal card (move to Business); a free image generator one designer uses for mood boards (approve, text prompts only); the design software's built-in AI (approve for concepts); a free AI upscaler found last month (ask first, case by case).
  2. Set the data rules (15 minutes). Sort your data into what can go anywhere, what can go only into a business plan, and what never goes in. Whether it's safe to put customer data into ChatGPT gives a three-band version you can borrow.
  3. Write the checking rules (15 minutes). List the three or four things that leave the building with AI's help (for the print shop: quotes, emails, product descriptions, design concepts) and write one checking rule for each.
  4. Add honesty and incidents (10 minutes). Two short sections, as in the template.
  5. Read it aloud with the team (10 minutes). Ask one question: "Is there anything here you'd find hard to follow?" Change whatever they say.

That last step catches the gaps you can't see from the owner's desk. When the print shop reads its draft aloud, the person on the counter points out that phone quotes don't have a job sheet yet, so "checked against the job sheet" can't be followed for about a third of quotes. The line becomes "checked against the job sheet, or the current price list for phone quotes". A second person asks whether "customer artwork" includes logos already on public websites. The owner decides that logos already public can go into approved tools and privately sent artwork can't, and adds one line to section 2. Two changes, five minutes, and a rule that now matches how the shop actually works.

How one page protects a business this small

A policy doesn't make you compliant with anything on its own, and it won't stop every mistake. It does four practical things.

It turns a vague worry into a shared rule, so the newest member of staff makes the same call as the owner. It gives you something to show a client or insurer who asks. It gives you a clear starting point when something goes wrong: you can say what the rule was, whether it was followed and what you're changing. And it makes onboarding quick, because a new starter can read one page on day one. How to onboard new hires onto your AI tools and rules builds that page into a first-week routine.

That starting point is easier to see with a real slip in front of you. Say a quote email for 500 business cards goes out at $45 when the current price list says $65, because the AI drafted it from an old quote someone pasted into the chat. The customer accepts. With the policy in place, the owner's note takes two minutes: the rule existed (section 3, prices checked against the job sheet or, for phone quotes, the price list) and was skipped on a busy afternoon; the shop honours the $45 and absorbs the $20; from now on, quote drafts start from the current price list pasted into the chat, never from an old quote. Without a written rule, the same conversation turns into who should have known what, and nobody is sure what to change.

If you sell into the EU, it also forms part of your answer on AI literacy. Pair it with a short conversation about what AI gets wrong, and keep a note of who attended. What your staff need to know about AI covers what that briefing should include.

When one page stops being enough

The one-pager has limits. Move to a fuller policy when any of these become true:

  • You grow past about 10 to 15 people, or you have separate teams working in different ways.
  • You do regulated work (health, legal, financial advice) where professional rules on confidentiality apply.
  • You put AI in front of customers, such as a chatbot or an automated phone line.
  • AI helps make decisions about people: who to hire, who gets credit, which customers get which price.
  • You build automations that move personal data between systems without a person in the middle.
  • A major client asks for formal controls, perhaps referring to a management-system standard such as ISO/IEC 42001.

At that point, how to write an AI usage policy takes you through a fuller version, section by section. Until then, one page that everyone has read beats ten that nobody has.

Getting five people to follow it

In a team this small, the policy works if the owner follows it visibly. Use the approved tool yourself. Check your own AI-drafted quotes against the job sheet in front of the team. When someone reports a slip, thank them.

Then give it a date. Put the six-monthly review in the diary now, and at that meeting ask two questions: what have we started using that isn't on the list, and which rule has nobody followed? The answers tell you what to change, and the changes are usually small. An illustrative record of the print shop's first review:

  • Section 1: the AI upscaler moves from "ask first" to approved, for logos already public on a customer's website or shopfront.
  • Section 2: new line, "No photos of real people go into image tools without the customer's written OK", after a designer asked about retouching a staff photo for a customer's leaflet.
  • Section 3: quote drafts start from the current price list, never from an old quote, following the $45 business-card slip.
  • Header: version 2 and the new date, with the three changes read out at the next team meeting and everyone signing the new page.

Four lines of change after six months is a sign the page fits the business. If a review rewrites half of it, the first version was copied from somewhere else. For a small team that's most of what rolling out an AI policy so staff follow it involves.

Questions about AI policies for very small teams

Do I need a solicitor to write a one-page AI policy?

Not for an internal rulebook like this. Legal advice becomes worthwhile if the policy will form part of employment contracts, if you work in a regulated profession, or if you're making written promises to clients about how you use AI. Asking an adviser to read it once is inexpensive and catches anything that conflicts with your existing contracts.

Should the AI policy go into staff contracts?

For a five-person team, a standalone page that your staff handbook refers to is usually enough, and it's easy to update. Writing the rules into employment contracts makes every change harder, because contract changes need agreement. If you want the policy to be enforceable in a disciplinary situation, ask an employment adviser how best to reference it.

How often should a small business update its AI policy?

Review it every six months, and straight away when you add or drop a tool, after any incident, or when a client or insurer asks a question your policy doesn't answer. Most reviews take ten minutes. Change the version number and date each time, and tell the team what changed.

Further reads

Sources: EU AI Act Article 4 on AI literacy and the Digital Omnibus on AI amendments; ChatGPT Business plan terms (checked September 2026).

Want a one-page AI policy that fits how you work?

On a 1:1 call we'll look at which tools your team uses, what data they handle and what leaves the building, then shape the rules into a page your staff will actually follow.

Book a 1:1 call with me