Skip to main content

How to Write an AI Policy for Your Small Business (Without a Lawyer)

How to Write an AI Policy for Your Small Business (Without a Lawyer)

If you’re waiting until you have time to commission a proper AI policy from a lawyer, you’ll be waiting a long time. And in the meantime, your team is making decisions about AI on their own — without any guidance from you.

The good news: a small business AI policy doesn’t need to be long, complex, or expensive. One page is enough. Clear enough that your team actually reads it. Specific enough that it covers the risks that matter. And flexible enough that it doesn’t become outdated the moment a new tool launches.

This post walks you through exactly what to include — and gives you a fill-in-the-blanks template you can adapt and send to your team today.

Why Every Small Business Needs an AI Policy Right Now

More than 58% of small businesses are already using AI in some form, according to the U.S. Chamber of Commerce — and that number is rising fast. But most of them have no policy in place to govern how it’s used.

Without a policy, you’re exposed to:

  • Client data being entered into third-party AI tools without consent
  • AI-generated content going out under your name without human review
  • Employees making consequential decisions based on AI outputs they haven’t verified
  • Legal liability — “the AI did it” is not a defence in court, with regulators, or with your clients
  • Reputational damage when something goes wrong publicly
The Air Canada lesson In 2024, Air Canada’s chatbot told a grieving passenger he could apply for a bereavement discount after his flight — a discount that didn’t exist. The court ruled Air Canada was responsible for its AI’s output. The business, not the AI, was held accountable. Your AI policy needs to make clear that the same principle applies to your team.

The FTC made this explicit in March 2026: AI-generated content used to mislead consumers is actionable under existing consumer protection law. A clear internal policy is your first line of defence.

What a Good Small Business AI Policy Actually Covers

You don’t need a 20-page document with legal definitions and committee sign-offs. You need something your team will actually read, remember, and follow. Here’s what to include:

1. Purpose — why the policy exists

One or two sentences. The goal is to frame AI as something your business welcomes — within sensible limits. Avoid starting with a list of prohibitions. Start with intent.

Example: “We want our team to use AI to work smarter and faster — and we want to make sure we’re doing it in a way that protects our clients, our data, and our reputation.”

2. Who it applies to

Everyone — employees, contractors, freelancers, anyone working on your behalf. Make this explicit. It’s a common gap.

3. Approved tools

List the specific tools your team is allowed to use for work. Be concrete: not “AI writing tools” but “ChatGPT Team account (accessed through [URL]) and Grammarly Business.” Anything not on the list requires approval before use.

This is also where you address the shadow AI risk we covered in our last post. Most employees using unapproved tools aren’t being reckless — they just haven’t been told what’s allowed. A clear approved list fixes that.

4. What must never go into AI tools

This is the most important section for risk management. Be specific about what categories of information are off limits:

  • Client personal data (names, addresses, financial details, health information)
  • Contracts, pricing, and commercially sensitive information
  • Login credentials or security information
  • Anything covered by a non-disclosure agreement
  • Employee personal information

The reason to be specific rather than vague (“don’t share sensitive information”) is that employees genuinely don’t always know what counts as sensitive. Give them a checklist they can refer to.

5. Human review is always required

AI tools hallucinate — they produce confident, plausible-sounding wrong answers. Your policy needs to be explicit: no AI-generated output gets used, published, sent, or acted upon without a human checking it first.

This applies to written content, data analysis, summaries, recommendations — everything. The human who reviews it is also the human who is responsible for it.

6. How to request a new tool

AI tools launch constantly. Your team will find new ones they want to use. Give them a clear, low-friction process for requesting approval — otherwise they’ll just use the tool without asking.

A simple email to a named person, with a two or three working day turnaround, is enough. The point is that someone with context reviews it before it enters your workflows.

7. Accountability

Make it explicit: the person who uses an AI tool is responsible for its output. Not the tool, not the vendor, not the company that built the model. This matters legally and operationally.

8. Review date

AI is moving fast. A policy you write today may need updating in six months. Set a review date and keep it. Twice a year is a sensible cadence for most small businesses.

The One-Page Template — Fill In and Use Today

Here’s a template you can adapt for your business. Replace the bracketed sections with your specifics, then share it with your team — ideally with a brief note from you explaining the intent behind it.

AI ACCEPTABLE USE POLICY — ONE-PAGE TEMPLATE
Purpose This policy sets out how [Business Name] uses artificial intelligence tools — and how we expect every team member to use them responsibly.
Who it covers All employees, contractors, freelancers, and anyone else working on behalf of [Business Name].
Approved tools The following AI tools are approved for work use: [list tools]. Any tool not on this list requires written approval from [Name/Role] before use.
What must never go into AI tools Client personal data · Financial records · Contracts and pricing · Login credentials · Any information covered by NDA or confidentiality agreement
Human review required All AI-generated content — written, analytical, or otherwise — must be reviewed and verified by a human before it is used, shared, or acted upon.
How to request a new tool Submit a request to [Name/Role] with: tool name, intended use, data it will access. Approval within [X] working days.
Compliance Use of AI tools must comply with GDPR, any applicable industry regulations, and our existing data protection policy. When in doubt, ask before using.
Accountability “The AI did it” is not an acceptable explanation. Every AI-assisted decision or output remains the responsibility of the team member who used it.
Review date This policy will be reviewed every 6 months or when significant new AI tools or regulations emerge. Next review: [Date].

You can also download our full AI Governance Toolkit — which includes this template alongside a risk assessment form, a model card template, and a tool tracking dashboard. All free.

Three Mistakes to Avoid

1. Making it too restrictive

A policy that effectively bans AI use will be ignored — or worse, it will drive your team toward shadow AI use rather than away from it. The goal is responsible adoption, not prohibition. Lead with what’s allowed.

2. Making it too vague

“Use AI responsibly” is not a policy. “Do not enter client data into any AI tool not on the approved list” is a policy. The more specific you are, the more useful it is — and the more protection it gives you if something goes wrong.

3. Writing it and forgetting it

AI tools, regulations, and your own workflows will change. A policy that was accurate when you wrote it may be dangerously out of date a year later. Build the review date into your calendar now, not as an afterthought.

What to Do After You’ve Written It

Writing the policy is step one. Here’s what comes next:

  • Send it to your team with a covering note that explains the intent — not just the rules
  • Ask each team member to confirm they’ve read it (a simple email reply is fine)
  • Add it to your onboarding process for new hires and contractors
  • Set a calendar reminder for your first review date
  • Consider a free AI Readiness Assessment to identify any gaps the policy alone won’t fix
The Blue Narwhal take “A short, well-understood policy is more effective than a long, ignored one.” Your AI policy doesn’t need to be a legal masterpiece. It needs to be clear enough that your team knows what to do — and what not to do — without having to ask.

Before you roll out this policy, get clear on where you stand. Take the 3‑minute AI Assessment — you’ll get instant results and a full report delivered straight to your inbox.

If you’d like a second pair of eyes on your policy before you share it, or you want to go deeper on your AI governance overall, book a free 30-minute call. We do this regularly with clients and it usually surfaces two or three things worth fixing that aren’t obvious from the inside.

Related Reading

Your Employees Are Already Using AI — Here’s How to Get Ahead of It — the shadow AI problem your policy is designed to solve

JM Wofford

About JM Wofford

Founder of The Blue Narwhal, AI governance advisor, researcher, author, and graduate computer science instructor. The work connects technical capability to institutional accountability and real organizational decisions. Full profile →