How to Write an AI Usage Policy for Your Small Business

Coding Liquids tutorial cover featuring Sagnik Bhattacharya for How to Write an AI Usage Policy for Your Small Business.
Coding Liquids tutorial cover featuring Sagnik Bhattacharya for How to Write an AI Usage Policy for Your Small Business.

Write one or two pages covering six things: which AI tools and accounts are approved, what information must never go in, which work needs a person to check it, when customers are told, who approves new tools, and what to do when something goes wrong. Base it on how your team already uses AI, and review it every six months.

A small-business AI policy should read like instructions, not like a contract. Most templates online are written for large companies and run to ten pages that nobody finishes. Below: how to find out current use, each section with wording you can adapt, a data traffic-light table, a worked example of a first draft that changed after staff read it, and a one-page version to start from. It isn't legal advice: if you handle sensitive data or work in a regulated profession, have an adviser review your final version.

Follow me on Instagram@sagnikteaches

Find out how AI is already used before you write anything

Your team is almost certainly using AI already, some of it on personal accounts. A policy that bans what people rely on every day gets quietly ignored. Spend a week finding out first, with a short anonymous survey:

Connect on LinkedInSagnik Bhattacharya
  1. Which AI tools have you used for work in the last month?
  2. Were they on a work account, a personal paid account or a free account?
  3. What tasks did you use them for?
  4. What kind of information did you paste in? (Tick any: none, general business information, customer names, customer details, staff details, financial information.)
  5. What would you like to use AI for but haven't, because you weren't sure it was allowed?

The answers are often more useful than owners expect. A week of replies from an illustrative nine-person garden-design and landscaping firm might tally like this:

Subscribe on YouTube@codingliquids
QuestionWhat came backWhat it meant for the policy
Tools used7 of 9 had used ChatGPT, 2 had used Gemini on their phonesApprove one assistant on a business plan rather than ban both
Account type4 on free personal accounts, 3 on the owner's shared loginA shared login means nobody can tell who pasted what: end it
TasksPlanting descriptions, client emails, turning site notes into quotesAll three are fine with the right data rules
Information pasted3 had pasted client names with home addressesAddresses become amber: business account only
Wished they could"Cost a planting list from our supplier price sheet"Supplier prices are internal: allowed in the business account, never in personal ones

The shared login was the finding the owner hadn't guessed, and it changed the policy's first section more than anything else.

Say clearly that nobody will be in trouble for honest answers. The results tell you which tools to approve, which data rules matter most, and where people need permission rather than restriction. If the answers surprise you, shadow AI in small businesses explains what to do next. And if you're still deciding whether a business your size needs a written policy at all, does a five-person business really need an AI policy? weighs it up.

Budget three to four hours of your own time, spread over two weeks: about an hour to run the survey and read the answers, an hour and a half to draft, half an hour to work through comments, and 20 minutes at a team meeting.

The policy, section by section

Eight short sections cover what a small business needs. The wording below comes from the tutoring agency in the worked example; swap in your own details.

1. Purpose and who it covers

This policy explains how we use AI tools at [business]. It applies to everyone who works with us, including employees, self-employed tutors and anyone else who handles our pupils' or parents' information. AI can save us time; this policy is here so we use it safely and stay responsible for everything we send.

2. Approved tools and accounts

Name the tools. "Approved AI tools" means nothing unless people know which ones they are.

Tool and planWhoApproved for
ChatGPT Business, on our workspaceAll staff and tutorsDrafting, summarising, lesson materials, progress notes (see data rules)
Gemini in our Google WorkspaceAll staffEmail and documents in our work accounts
Any free or personal AI accountNobody, for work involving pupils, parents or staffGeneral research with no personal or business information only

That's one of the main reasons to insist on business accounts: the business tiers of the main assistants keep your content out of model training unless you choose otherwise, whereas consumer accounts rely on each person finding the right privacy setting. Confirm the privacy settings on each tool you list.

3. Information that never goes into AI tools

Refer to a traffic-light table (next section) rather than writing paragraphs. People remember three colours; they don't remember clause 3.4(b).

4. Checking AI output

You are responsible for anything you send or publish, whether or not AI helped write it. Before anything goes to a pupil, parent or anyone outside the business, read it in full and check every name, date, time, price and fact. AI tools sometimes invent details that sound right. If you're not sure something is correct, don't send it.

Some work deserves a second pair of eyes as well. Keep the list short and specific, for example:

These need a second person to read them before they go out: anything sent to all parents at once, new text for our website, and anything that mentions fees, refunds or changes to a family's arrangements.

5. Telling people when AI was used

We tell parents that we use AI tools to help draft some messages and materials, and that a person checks everything. Our website explains this. If a parent asks whether AI was used on something, answer honestly.

For the website side of this, see how to write an AI disclosure statement.

6. New tools and features

If you'd like to use an AI tool or feature that isn't listed above, ask [owner] first. Don't sign up for it with a work email or connect it to our accounts until it's approved. We'll usually decide within a week.

A simple request form speeds this up; an AI tool approval process has one you can copy.

Include "connect it to our accounts" deliberately, because that's where the surprises come from. Picture a small interior-design studio where one designer links an AI note-taking app to her work calendar to try it out. By default it joins every video call on the calendar, including a client meeting where the client's builder is also invited, and afterwards emails a full summary to every attendee, budget discussion included. Nobody broke a data rule by pasting anything. The line that would have stopped it is short: "Don't connect any AI tool to your work email, calendar or files without approval."

7. When something goes wrong

If you paste information you shouldn't have, or AI-assisted work containing a mistake reaches a pupil or parent, tell [owner] the same day. Nobody will be disciplined for reporting a mistake promptly. Hiding one is a different matter.

It helps to show people what a good report looks like, so reporting feels routine rather than a confession:

Today about 2.15pm I pasted a parent's email into my personal
ChatGPT by mistake instead of the work one. It had the parent's
full name, mobile number and the child's school. I've deleted
the chat. Nothing was sent to anyone. Let me know if you need
anything else from me.

Four facts (what, when, which tool, what's been done) are all the owner needs to start. Put an example like this in the policy's guidance notes or the team channel, and the first real report is far more likely to arrive the same day.

What happens after the report belongs in a separate, short plan; an AI incident response plan covers the steps.

8. Ownership and review

[Owner] is responsible for this policy. We review it every six months, and sooner if we add a tool, start using AI with a new kind of information, or something goes wrong.

The data section for a tutoring agency: a traffic-light table

Make the examples specific to your business. Generic categories such as "confidential information" leave people guessing.

ColourRuleExamples
GreenFine in any approved toolCourse descriptions, general worksheets, marketing copy, lesson topics, anonymised examples
AmberOnly in approved business accounts, first names only, nothing else identifyingSession progress notes, timetable emails to families, tutor profiles for matching
RedNever in any AI tool unless the owner has specifically approved a tool for itAnything about a pupil's health, learning needs, family circumstances or welfare concerns; full names with dates of birth or addresses; payment details; passwords and login details

Welfare concerns about a child are the clearest red item in a tutoring business. They follow your safeguarding procedure and should never be drafted, summarised or reworded by an AI tool.

Worked example: how a tutoring agency's first draft changed

As an illustration, take a tutoring agency where around fifteen self-employed tutors are supported by the owner and two office staff. The owner's first draft, adapted from a large-company template, ran to five pages and banned all pupil information from AI tools.

She shared it with the team for comments. Seven people replied, and the feedback was consistent: the main use of AI in the agency was drafting progress notes to parents after sessions. Under the draft, that became impossible, so in practice tutors would either stop using the approved tool or keep going on their personal accounts, where the agency had no control at all.

The second draft was two pages long and made three changes:

  • A new amber category: progress notes allowed in the agency's ChatGPT Business workspace, first names only, with no information about health, learning needs or family.
  • A sector-specific rule the first draft had missed: "We don't use AI to produce work that a pupil will hand in as their own." Tutors can use AI to create practice material and explain topics, but not to write pupils' homework or coursework.
  • Named tools instead of "approved AI solutions", and the owner's name instead of "the responsible officer".

From first draft to signed version took two weeks. Because tutors had shaped the rules, the owner found far fewer surname slips in her monthly spot check than she'd expected.

Why first-draft AI policies get ignored

  • Too long. Past two pages, people skim. Put detail in linked guidance, not in the policy.
  • Bans everything. If the policy makes people's actual work impossible, they'll work around it.
  • Copied from a large company. References to a security team, a steering committee or a procurement process that doesn't exist tell staff the policy isn't really meant for them.
  • Vague. "Use AI responsibly" gives nobody anything to act on. "Check every date and price before sending" does.
  • No tools named. Staff can't follow a rule about "approved tools" if they don't know which tools those are.
  • No route to ask. Every policy needs a named person to ask when something isn't covered.

The difference between a copied clause and a usable one is easiest to see side by side. Before, from a large-company template:

"Employees shall ensure that outputs generated by AI systems are subject to appropriate human oversight commensurate with the risk profile of the relevant use case."

After, for a small business:

"Read every AI draft in full before it leaves the business. If it mentions a price, a date or a promise, check it against the price list or the diary. If it goes to all customers at once, ask [name] to read it too."

Both say "check AI output". Only the second tells someone at 5pm on a Friday what to actually do, and who to ask.

A one-page version you can start from

AI USAGE POLICY: [BUSINESS NAME]        Version [1.0], [date]
Owner: [name]. Next review: [date + 6 months]

WHO: Everyone who works with us, including contractors.

APPROVED TOOLS
[Tool, plan]: [who], for [tasks]
[Tool, plan]: [who], for [tasks]
Free or personal AI accounts: not for any work involving
customer, staff or business information.

DATA
Green  (any approved tool): [examples]
Amber  (business accounts only, names removed): [examples]
Red    (never): [examples]

CHECKING
You're responsible for what you send, AI or not. Check every
name, date, price and fact before anything leaves the business.

TELLING PEOPLE
Our website explains how we use AI. If asked, answer honestly.

NEW TOOLS
Ask [owner] before using any AI tool or feature not listed here.

MISTAKES
Tell [owner] the same day. Prompt reporting is never punished.

ALSO NEVER
[Sector rule, e.g. "No AI-written work for pupils to submit."]

I have read and will follow this policy.
Name: ____________  Signed: ____________  Date: ________

Getting it signed and keeping it current

Share the draft, give people a week to comment, then take 20 minutes at a team meeting to go through the final version and answer questions. Ask everyone to sign or acknowledge it, add it to new-starter induction, and store the signed copies with other staff records.

A signature shows someone received the policy, not that they can apply it. A month later, test it with three short scenarios at a team meeting and ask people to answer before anyone discusses them. For the tutoring agency they might be:

  1. A parent emails two paragraphs about their son's recent dyslexia assessment and asks how tutoring will adapt. Can you paste it into ChatGPT to help draft a reply? No. Learning needs are red. Write the reply yourself, or draft a general reply about adapting sessions with no details from the email.
  2. You want to turn this week's session notes for a 14-year-old pupil into a progress note for his parents. Allowed? Yes, in the agency's ChatGPT Business workspace, using his first name only, and reading the draft before it goes.
  3. A free AI flashcard app looks perfect for your exam revision sessions and asks you to sign in with Google. What do you do? Ask the owner first, and don't sign in with the work account in the meantime.

If most of the room gets all three right, the policy is working. If one scenario splits the room, that section's wording is unclear, and it's the section to rewrite at the next review, not the people to retrain.

Set the six-month review in the diary now. Review sooner if any of these happen: you approve a new tool, you start using AI with a new kind of information, something goes wrong, or the rules that apply to you change, for instance if you start selling to customers in the EU and the EU AI Act becomes relevant.

A review needn't be a rewrite. The tutoring agency's six-month review took the owner about 40 minutes and produced four changes: Gemini in Workspace had gained features the office staff were using on parent emails, so it moved from "email and documents" to the same amber rule as ChatGPT; two tutors had asked about an AI marking tool, which went through the approval route and was turned down because it kept pupils' work for training; the incident log held two reports, both surnames in progress notes, so the placeholder in the progress-note prompt now reads [FIRST NAME ONLY]; and the version number went to 1.1, with everyone re-acknowledging only the changed lines. Writing the policy is the easier half; rolling out an AI policy so staff actually follow it covers the rest.

Questions about writing the policy

Do I need a lawyer to write an AI usage policy?

Not to write a first version. A short, practical policy based on how your team works is something an owner can draft. Have a solicitor or data-protection adviser review it if you handle sensitive data such as health or children's information, work in a regulated profession, or plan to use the policy in disciplinary matters.

Can I simply ban AI tools at work?

You can, but a ban rarely stops use. It usually moves it to personal free accounts on phones, where you have no control over what data goes in. If you're not ready to approve a tool, a better short-term rule is: no customer, pupil or staff information in any AI tool until we've chosen an approved one.

Does the policy cover AI features inside other software?

It should. Many everyday tools now include AI features, such as writing assistants in email, design and accounting software. Add a line saying that AI features inside other software follow the same data rules, and list any you've specifically approved or switched off.

Does it apply to freelancers and contractors?

It should apply to anyone who handles your customers' information or produces work in your name, including self-employed tutors or freelancers. Put the key rules into their contract or engagement terms, not just a staff handbook, and give them the same approved tools where you can.

Further reads

Sources: vendor plan information for ChatGPT Business and Google Workspace (checked September 2026). Policy wording is illustrative and not legal advice.

Want an AI policy that fits how your team works?

On a 1:1 call we'll go through how your team uses AI now, agree the tools and data rules, and turn them into a two-page policy people will actually read.

Book a 1:1 call with me