How to Write an AI Policy for a Small Business (Before You Need One)
Most small businesses are already using AI tools — ChatGPT, Copilot, Gemini — without any rules around them. An AI policy does not need to be long or legal. It needs to answer three questions: what tools are allowed, what data can go into them, and who decides when something goes wrong.
Most small businesses have an AI policy problem before they have an AI policy. Someone on your team is pasting customer emails into ChatGPT. Someone else is using Copilot to draft proposals. No one has agreed on what is and is not acceptable. A short, written AI policy fixes that — and it does not need a lawyer to write it.
Why a small business needs an AI policy
Your team will use AI whether or not rules exist. The question is whether they use it in ways that expose the business to risk.
A few real patterns I have seen. A sales manager copies a CRM export — client names, emails, deal values — into a public AI chatbot to generate a summary report. A finance assistant uses an AI writing tool to draft a debt collection letter, and the tool produces a wrong figure. An operations coordinator builds a workflow using a free AI tool that stores all inputs on a third-party server in an unspecified jurisdiction.
None of these people acted maliciously. Each one was solving a genuine problem with the tools available. But the results were a data privacy exposure, a factual error sent to a client, and a potential breach of data residency obligations.
An AI policy is how you get ahead of those scenarios before they happen.
What an AI policy for a small business actually needs to cover
For most SMEs, a workable policy covers four things.
Approved tools. List the tools the business has evaluated and signed off on — for example, ChatGPT Team (which does not train on your inputs), Microsoft Copilot via your existing Microsoft 365 licence, or a specific automation platform. Anything not on the list requires approval before use. This is not about being restrictive. It is about knowing what is running in your business.
Data classification. Not all data carries the same risk. A simple approach: public data can go anywhere, internal data should stay within approved tools, and sensitive data — client PII, financial records, passwords — does not go into any AI tool without explicit sign-off. That last rule, clearly stated, prevents most of the serious incidents.
Output verification. AI tools produce plausible-sounding errors. Your policy should be explicit that AI-generated content — anything quoting numbers, regulations, contract terms, or client-specific information — must be checked by a human before it is sent or acted on. This is obvious in principle and inconsistently practised in reality.
Ownership and escalation. Who can approve a new tool? Who do people ask when they are unsure? For a small business, this is usually the founder or a senior manager. The point is that someone is named, so the answer is not a guess.
How long should it be
One to two pages is enough for most businesses under 50 people. The goal is something your team will actually read. A short, plain-English document that answers three questions — what tools, what data, who decides — is more useful than a comprehensive policy that sits untouched in a shared drive.
If your business operates in a regulated sector — financial services, healthcare, legal — you will need to go further and it is worth getting specific advice. For most growing SMEs in Australia or the UK, a short internal document is a meaningful step up from nothing.
When to write it
Now, even if AI use in your business is still limited. The policy is straightforward to write when stakes are low. It becomes harder once something has gone wrong, or once you have ten tools running across different teams with no common thread.
A useful trigger: the moment you hire someone new and realise you have no way of telling them how AI should and should not be used in your business. That gap is the policy.
How an AI policy connects to your broader AI strategy
An AI policy is the governance layer that sits underneath an AI strategy. Without it, a strategy is just a list of tools and intentions. With it, you have a foundation for making decisions as new tools emerge.
If you are building automations, connecting data pipelines, or using AI to produce board reporting or cash flow forecasts, the policy is what makes that safe to do. It is the reason you can give a team member access to an AI-assisted workflow without worrying about what data they might inadvertently expose. The AI Build & Implementation work GME does always starts with questions about data flows and access — the policy is a natural companion to that.
If you are thinking about AI more strategically across the business — a roadmap rather than a single tool — that is where a Fractional Chief AI Officer engagement can help. Part of that work is making sure governance keeps pace with capability.
A practical starting point
To draft something this week, answer three questions honestly:
- What AI tools are people in your business currently using, officially or otherwise?
- What is the most sensitive data in your business, and could it plausibly end up in one of those tools?
- If an AI tool produced something wrong and it reached a client, who would be accountable?
Answering those three questions in plain language gets you most of the way to a first draft.
Frequently asked questions
Does a small business legally need an AI policy? In most jurisdictions there is no specific legal requirement yet, though that is changing. What you do have clear obligations around is data privacy — GDPR in the UK, the Privacy Act in Australia — and an AI policy is one of the clearest ways to show that personal data is handled responsibly. Think of it as basic operational hygiene rather than a legal checkbox.
Can I just use a template from the internet? A template is a reasonable starting point. The risk is that a generic document does not reflect your specific tools, your data, or how your team actually works. A policy that sits untouched in a shared drive is not a policy. The value comes from customising it to your situation and then making sure people know it exists.
What if my team pushes back on restrictions? The most common pushback is that rules will slow people down. The response is to be specific about what is restricted and why, rather than issuing a blanket ban on AI tools. Most people are reasonable once they understand that the rule about not pasting client data into a public chatbot exists because of privacy obligations, not distrust. Framing it as protection for the business — and for them — usually lands better than framing it as a restriction.
How often should we update it? At minimum, once a year, or whenever the business adopts a significant new AI tool or changes how it handles data. A short annual review is enough for most SMEs.
General information, written to be useful — not financial, tax, investment or legal advice. For decisions specific to your business, take advice from a suitably qualified professional.
Think this might be a fit?
Tell us what you're trying to improve. We'll come back on whether it's a fit and a sensible next step — usually a short call and a free AI & Automation Health Check.