Write one or two pages covering six things: which AI tools and accounts are approved, what information must never go in, which work needs a person to check it, when customers are told, who approves new tools, and what to do when something goes wrong. Base it on how your team already uses AI, and review it every six months.
A small-business AI policy should read like instructions, not like a contract. Most templates online are written for large companies and run to ten pages that nobody finishes. Below: how to find out current use, each section with wording you can adapt, a data traffic-light table, a worked example of a first draft that changed after staff read it, and a one-page version to start from. It isn't legal advice: if you handle sensitive data or work in a regulated profession, have an adviser review your final version.
Find out how AI is already used before you write anything
Your team is almost certainly using AI already, some of it on personal accounts. A policy that bans what people rely on every day gets quietly ignored. Spend a week finding out first, with a short anonymous survey:
- Which AI tools have you used for work in the last month?
- Were they on a work account, a personal paid account or a free account?
- What tasks did you use them for?
- What kind of information did you paste in? (Tick any: none, general business information, customer names, customer details, staff details, financial information.)
- What would you like to use AI for but haven't, because you weren't sure it was allowed?
The answers are often more useful than owners expect. A week of replies from an illustrative nine-person garden-design and landscaping firm might tally like this:
| Question | What came back | What it meant for the policy |
|---|---|---|
| Tools used | 7 of 9 had used ChatGPT, 2 had used Gemini on their phones | Approve one assistant on a business plan rather than ban both |
| Account type | 4 on free personal accounts, 3 on the owner's shared login | A shared login means nobody can tell who pasted what: end it |
| Tasks | Planting descriptions, client emails, turning site notes into quotes | All three are fine with the right data rules |
| Information pasted | 3 had pasted client names with home addresses | Addresses become amber: business account only |
| Wished they could | "Cost a planting list from our supplier price sheet" | Supplier prices are internal: allowed in the business account, never in personal ones |
The shared login was the finding the owner hadn't guessed, and it changed the policy's first section more than anything else.
Say clearly that nobody will be in trouble for honest answers. The results tell you which tools to approve, which data rules matter most, and where people need permission rather than restriction. If the answers surprise you, shadow AI in small businesses explains what to do next. And if you're still deciding whether a business your size needs a written policy at all, does a five-person business really need an AI policy? weighs it up.
Budget three to four hours of your own time, spread over two weeks: about an hour to run the survey and read the answers, an hour and a half to draft, half an hour to work through comments, and 20 minutes at a team meeting.
The policy, section by section
Eight short sections cover what a small business needs. The wording below comes from the tutoring agency in the worked example; swap in your own details.
1. Purpose and who it covers
This policy explains how we use AI tools at [business]. It applies to everyone who works with us, including employees, self-employed tutors and anyone else who handles our pupils' or parents' information. AI can save us time; this policy is here so we use it safely and stay responsible for everything we send.
2. Approved tools and accounts
Name the tools. "Approved AI tools" means nothing unless people know which ones they are.
| Tool and plan | Who | Approved for |
|---|---|---|
| ChatGPT Business, on our workspace | All staff and tutors | Drafting, summarising, lesson materials, progress notes (see data rules) |
| Gemini in our Google Workspace | All staff | Email and documents in our work accounts |
| Any free or personal AI account | Nobody, for work involving pupils, parents or staff | General research with no personal or business information only |
That's one of the main reasons to insist on business accounts: the business tiers of the main assistants keep your content out of model training unless you choose otherwise, whereas consumer accounts rely on each person finding the right privacy setting. Confirm the privacy settings on each tool you list.
3. Information that never goes into AI tools
Refer to a traffic-light table (next section) rather than writing paragraphs. People remember three colours; they don't remember clause 3.4(b).
4. Checking AI output
You are responsible for anything you send or publish, whether or not AI helped write it. Before anything goes to a pupil, parent or anyone outside the business, read it in full and check every name, date, time, price and fact. AI tools sometimes invent details that sound right. If you're not sure something is correct, don't send it.
Some work deserves a second pair of eyes as well. Keep the list short and specific, for example:
These need a second person to read them before they go out: anything sent to all parents at once, new text for our website, and anything that mentions fees, refunds or changes to a family's arrangements.
5. Telling people when AI was used
We tell parents that we use AI tools to help draft some messages and materials, and that a person checks everything. Our website explains this. If a parent asks whether AI was used on something, answer honestly.
For the website side of this, see how to write an AI disclosure statement.
6. New tools and features
If you'd like to use an AI tool or feature that isn't listed above, ask [owner] first. Don't sign up for it with a work email or connect it to our accounts until it's approved. We'll usually decide within a week.
A simple request form speeds this up; an AI tool approval process has one you can copy.
Include "connect it to our accounts" deliberately, because that's where the surprises come from. Picture a small interior-design studio where one designer links an AI note-taking app to her work calendar to try it out. By default it joins every video call on the calendar, including a client meeting where the client's builder is also invited, and afterwards emails a full summary to every attendee, budget discussion included. Nobody broke a data rule by pasting anything. The line that would have stopped it is short: "Don't connect any AI tool to your work email, calendar or files without approval."
7. When something goes wrong
If you paste information you shouldn't have, or AI-assisted work containing a mistake reaches a pupil or parent, tell [owner] the same day. Nobody will be disciplined for reporting a mistake promptly. Hiding one is a different matter.
It helps to show people what a good report looks like, so reporting feels routine rather than a confession:
Today about 2.15pm I pasted a parent's email into my personal
ChatGPT by mistake instead of the work one. It had the parent's
full name, mobile number and the child's school. I've deleted
the chat. Nothing was sent to anyone. Let me know if you need
anything else from me.
Four facts (what, when, which tool, what's been done) are all the owner needs to start. Put an example like this in the policy's guidance notes or the team channel, and the first real report is far more likely to arrive the same day.
What happens after the report belongs in a separate, short plan; an AI incident response plan covers the steps.
8. Ownership and review
[Owner] is responsible for this policy. We review it every six months, and sooner if we add a tool, start using AI with a new kind of information, or something goes wrong.
The data section for a tutoring agency: a traffic-light table
Make the examples specific to your business. Generic categories such as "confidential information" leave people guessing.
| Colour | Rule | Examples |
|---|---|---|
| Green | Fine in any approved tool | Course descriptions, general worksheets, marketing copy, lesson topics, anonymised examples |
| Amber | Only in approved business accounts, first names only, nothing else identifying | Session progress notes, timetable emails to families, tutor profiles for matching |
| Red | Never in any AI tool unless the owner has specifically approved a tool for it | Anything about a pupil's health, learning needs, family circumstances or welfare concerns; full names with dates of birth or addresses; payment details; passwords and login details |
Welfare concerns about a child are the clearest red item in a tutoring business. They follow your safeguarding procedure and should never be drafted, summarised or reworded by an AI tool.
Worked example: how a tutoring agency's first draft changed
As an illustration, take a tutoring agency where around fifteen self-employed tutors are supported by the owner and two office staff. The owner's first draft, adapted from a large-company template, ran to five pages and banned all pupil information from AI tools.
She shared it with the team for comments. Seven people replied, and the feedback was consistent: the main use of AI in the agency was drafting progress notes to parents after sessions. Under the draft, that became impossible, so in practice tutors would either stop using the approved tool or keep going on their personal accounts, where the agency had no control at all.
The second draft was two pages long and made three changes:
- A new amber category: progress notes allowed in the agency's ChatGPT Business workspace, first names only, with no information about health, learning needs or family.
- A sector-specific rule the first draft had missed: "We don't use AI to produce work that a pupil will hand in as their own." Tutors can use AI to create practice material and explain topics, but not to write pupils' homework or coursework.
- Named tools instead of "approved AI solutions", and the owner's name instead of "the responsible officer".
From first draft to signed version took two weeks. Because tutors had shaped the rules, the owner found far fewer surname slips in her monthly spot check than she'd expected.
Why first-draft AI policies get ignored
- Too long. Past two pages, people skim. Put detail in linked guidance, not in the policy.
- Bans everything. If the policy makes people's actual work impossible, they'll work around it.
- Copied from a large company. References to a security team, a steering committee or a procurement process that doesn't exist tell staff the policy isn't really meant for them.
- Vague. "Use AI responsibly" gives nobody anything to act on. "Check every date and price before sending" does.
- No tools named. Staff can't follow a rule about "approved tools" if they don't know which tools those are.
- No route to ask. Every policy needs a named person to ask when something isn't covered.
The difference between a copied clause and a usable one is easiest to see side by side. Before, from a large-company template:
"Employees shall ensure that outputs generated by AI systems are subject to appropriate human oversight commensurate with the risk profile of the relevant use case."
After, for a small business:
"Read every AI draft in full before it leaves the business. If it mentions a price, a date or a promise, check it against the price list or the diary. If it goes to all customers at once, ask [name] to read it too."
Both say "check AI output". Only the second tells someone at 5pm on a Friday what to actually do, and who to ask.
A one-page version you can start from
AI USAGE POLICY: [BUSINESS NAME] Version [1.0], [date]
Owner: [name]. Next review: [date + 6 months]
WHO: Everyone who works with us, including contractors.
APPROVED TOOLS
[Tool, plan]: [who], for [tasks]
[Tool, plan]: [who], for [tasks]
Free or personal AI accounts: not for any work involving
customer, staff or business information.
DATA
Green (any approved tool): [examples]
Amber (business accounts only, names removed): [examples]
Red (never): [examples]
CHECKING
You're responsible for what you send, AI or not. Check every
name, date, price and fact before anything leaves the business.
TELLING PEOPLE
Our website explains how we use AI. If asked, answer honestly.
NEW TOOLS
Ask [owner] before using any AI tool or feature not listed here.
MISTAKES
Tell [owner] the same day. Prompt reporting is never punished.
ALSO NEVER
[Sector rule, e.g. "No AI-written work for pupils to submit."]
I have read and will follow this policy.
Name: ____________ Signed: ____________ Date: ________
Getting it signed and keeping it current
Share the draft, give people a week to comment, then take 20 minutes at a team meeting to go through the final version and answer questions. Ask everyone to sign or acknowledge it, add it to new-starter induction, and store the signed copies with other staff records.
A signature shows someone received the policy, not that they can apply it. A month later, test it with three short scenarios at a team meeting and ask people to answer before anyone discusses them. For the tutoring agency they might be:
- A parent emails two paragraphs about their son's recent dyslexia assessment and asks how tutoring will adapt. Can you paste it into ChatGPT to help draft a reply? No. Learning needs are red. Write the reply yourself, or draft a general reply about adapting sessions with no details from the email.
- You want to turn this week's session notes for a 14-year-old pupil into a progress note for his parents. Allowed? Yes, in the agency's ChatGPT Business workspace, using his first name only, and reading the draft before it goes.
- A free AI flashcard app looks perfect for your exam revision sessions and asks you to sign in with Google. What do you do? Ask the owner first, and don't sign in with the work account in the meantime.
If most of the room gets all three right, the policy is working. If one scenario splits the room, that section's wording is unclear, and it's the section to rewrite at the next review, not the people to retrain.
Set the six-month review in the diary now. Review sooner if any of these happen: you approve a new tool, you start using AI with a new kind of information, something goes wrong, or the rules that apply to you change, for instance if you start selling to customers in the EU and the EU AI Act becomes relevant.
A review needn't be a rewrite. The tutoring agency's six-month review took the owner about 40 minutes and produced four changes: Gemini in Workspace had gained features the office staff were using on parent emails, so it moved from "email and documents" to the same amber rule as ChatGPT; two tutors had asked about an AI marking tool, which went through the approval route and was turned down because it kept pupils' work for training; the incident log held two reports, both surnames in progress notes, so the placeholder in the progress-note prompt now reads [FIRST NAME ONLY]; and the version number went to 1.1, with everyone re-acknowledging only the changed lines. Writing the policy is the easier half; rolling out an AI policy so staff actually follow it covers the rest.
Questions about writing the policy
Do I need a lawyer to write an AI usage policy?
Not to write a first version. A short, practical policy based on how your team works is something an owner can draft. Have a solicitor or data-protection adviser review it if you handle sensitive data such as health or children's information, work in a regulated profession, or plan to use the policy in disciplinary matters.
Can I simply ban AI tools at work?
You can, but a ban rarely stops use. It usually moves it to personal free accounts on phones, where you have no control over what data goes in. If you're not ready to approve a tool, a better short-term rule is: no customer, pupil or staff information in any AI tool until we've chosen an approved one.
Does the policy cover AI features inside other software?
It should. Many everyday tools now include AI features, such as writing assistants in email, design and accounting software. Add a line saying that AI features inside other software follow the same data rules, and list any you've specifically approved or switched off.
Does it apply to freelancers and contractors?
It should apply to anyone who handles your customers' information or produces work in your name, including self-employed tutors or freelancers. Put the key rules into their contract or engagement terms, not just a staff handbook, and give them the same approved tools where you can.
Further reads
- AI Acceptable Use Policy for a Small Professional Firm — A version for accountants, solicitors and consultants.
- How to Classify Business Data Before Using AI Tools — Build the traffic-light categories properly.
- How to Set Up Human Review for AI Work Without Slowing Down — Set up the checking rules without slowing work down.
- How to Stop AI Tools Training on Your Business Data — Settings to check for every approved tool.
- How to Write an AI Policy for a Small Charity — How the same policy works for a small charity.
- AI Compliance Checklist for Small Businesses: What Applies to You — Which laws your policy may need to reflect.
- A Simple AI Risk Register for Small Businesses (With Template) — A one-table AI risk register with a scoring scale, a template to copy, twelve filled-in rows from a florist and the triggers for updating it.
- How to Handle Staff Who Over-Rely on AI — Signs of AI over-reliance, a conversation script, a three-rule standard to put in writing, and when a pattern needs a formal process.
- How to Get Started With AI in Your Small Business: First 7 Steps — Seven steps that take about a month, from a five-day time log to a keep-or-drop decision, with a yoga studio's numbers at each stage.
- How to Write a One-Page AI Strategy for Your Business — The seven boxes a one-page AI strategy needs, a filled-in garden centre example, and five tests that show whether your page will guide real decisions.
- Who Should Own AI in a Small Business? Roles and Responsibilities — The four roles AI needs in any small firm, how they're split in a barber shop, an optician and a garden centre, and a responsibilities chart to copy.
- AI Change Management for Small Teams: A Practical Plan — An eight-week plan sized for five to twenty people, with a meeting script, a resistance table and a worked nursery example.
- How to Get Your Staff to Actually Use AI Tools — Diagnose low AI use, fix the six usual blockers, and see how a tutoring agency went from 3 regular users out of 12 seats to 9.
- How to Train Staff to Use AI in a Small Business — A three-layer training plan with learning outcomes, a 75-minute session agenda, a copyable error-spotting exercise and a language-school example.
- How to Survey Your Staff Before an AI Rollout (With Questions) — Fifteen ready-to-use questions, an invitation email and anonymity settings for surveying a small team before you choose any AI tools.
- AI Governance for a Small Business: Who Decides, Approves, Checks — Who says yes to AI in a small firm, and who looks back: a decision-rights table, three approval tiers, a 30-minute monthly check and a one-page register.
- AI Tools and AI Development: The Complete 2026 Guide — the AI hub, including every tutorial in the AI-for-business series.
Sources: vendor plan information for ChatGPT Business and Google Workspace (checked September 2026). Policy wording is illustrative and not legal advice.