AI Policy for Small Business: 12 Rules to Set Before Your Team Uses AI
Updated: Aug 25

The first warning that you need an AI policy for small business is rarely dramatic.
A contractor pastes an unpublished proposal into a public chatbot because it saves an hour. An employee includes an AI-generated statistic in a client deck and assumes the confident citation must be real. Someone connects a tool to email using their personal account because the official setup seemed too slow.
Nobody wakes up intending to expose data or mislead a customer. They are trying to get the work done.
That is exactly why an AI policy for small business matters. It is a short operating agreement that makes the safe action obvious before convenience, deadline pressure and unclear ownership make the decision for you.
The direct answer: define approved tools, prohibited data, verification requirements, disclosure rules, human approval points and accountability. Keep the first policy to one or two usable pages. Attach examples from the work your people actually perform.
Once those rules are clear, this 30-day AI training rollout plan shows how to turn them into practical team habits, exercises and approval checks.
This is practical operational guidance, not legal advice. Requirements vary by industry, contract, data type and country. The policy should be reviewed by qualified advisers where the risk requires it.
A policy is useful only when it improves the decision someone makes at 4:45 p.m. under pressure.
The 28-Day AI Mastery course helps owners turn boundaries like these into approved context, review gates and controlled workflows rather than a policy document nobody uses.
In This Article
Why You Need an AI Policy for Small Business Now

Small companies often assume AI governance belongs to enterprises with lawyers and compliance teams. The reality is the opposite: when six people share work informally, one unclear decision can move quickly through the entire business.
The risk is not limited to model training. It includes:
confidential material entering an unapproved account;
inaccurate output reaching a customer;
copyrighted or licensed material being reused incorrectly;
an automation sending, publishing, purchasing or deleting without the right approval;
different contractors using different standards;
and nobody being able to reconstruct how a consequential decision was made.
The NIST Generative AI Profile is a voluntary framework designed to help organizations manage risks across the AI lifecycle. A small business does not need to reproduce every control. It can translate the core logic into four plain-English actions: govern the use, map the situation, measure the risk and manage the response.
Product terms also differ. OpenAI states in its current business-data commitments that business and API data is not used for model training by default. Anthropic’s commercial-product privacy guidance similarly says commercial chats and coding sessions are not used for training unless the customer explicitly opts in or supplies feedback. Those commitments do not mean every consumer account, third-party connector or copied data set is appropriate for every business task.
The practical rule is: verify the exact account, product, connector and data path. “We use ChatGPT” is not a security assessment.
The prompt-injection safety guide explains one product-level risk created by untrusted instructions. This policy turns the broader privacy and safety questions into repeatable behavior.
Verified case: Samsung’s reactive ban
Samsung learned the cost of writing rules after adoption. A Thomson Reuters report records that the company restricted employee use of generative AI after discovering that sensitive code had been uploaded to an external AI service. The lesson is not that every business should ban public tools. It is that “be careful” was not an operating rule. A usable policy would have named the approved account, prohibited source code and confidential material, offered a safe alternative and made the escalation path obvious before someone was working against a deadline.
The Four Decisions Every AI Policy Must Make

Use the Tool–Data–Decision–Owner framework.
Tool: which products and accounts are approved?
List approved services, plan types and login method. A business workspace may have different privacy, retention and administration controls from a personal account.
State whether browser extensions, custom GPTs, plugins, integrations and consumer accounts require separate approval. A tool can be approved for public research but prohibited for client files.
Data: what may enter the system?
Define categories people recognize:
Public: already approved for public use.
Internal: ordinary business material that is not public.
Confidential: proposals, strategy, financials, source code and unpublished work.
Personal or regulated: customer records, health information, identification, payment data and other protected material.
“Do not upload sensitive information” fails because people disagree about sensitive. Name examples from your company.
Decision: what may AI prepare, and what must a human approve?
AI may brainstorm, summarize and prepare reversible drafts. Keep visible approval for actions involving:
publication;
customer communication;
pricing and promises;
hiring and employment;
payments and purchases;
legal, medical or financial advice;
deletion or permission changes;
and decisions materially affecting a person.
Owner: who is accountable?
Every consequential workflow needs a named owner. “The AI did it” is not an incident report. The owner approves the inputs, standard, review and response when something fails.
An AI workflow becomes safer when ownership is designed into the steps rather than added at the end.
The 12 Rules to Put in Your AI Policy

1. Use only approved tools and business accounts
Maintain a short register containing product, account type, approved jobs, data limits, owner and review date. Personal accounts should not become the default route around business controls.
2. Never enter secrets or authentication material
Passwords, private keys, payment-card data, recovery codes and authentication tokens do not belong in a prompt.
3. Limit confidential information
Do not upload confidential customer or company material unless the use is authorized, the service is approved and the minimum necessary data is used.
4. Remove unnecessary personal information
Redact names, email addresses, phone numbers, identifiers and other personal details when the task does not require them.
5. Treat generated output as unverified
AI output begins as a draft. The confidence of the language is not evidence.
6. Verify high-consequence claims against primary sources
Factual, legal, medical, financial, safety and security claims require authoritative confirmation by a qualified person.
7. Never fabricate proof
Do not invent testimonials, citations, research, customer results, case studies, identities or product capabilities.
8. Disclose material AI use when required
Follow contracts, professional rules, platform policies and audience expectations. The policy should identify who decides when disclosure is necessary.
9. Keep human approval over irreversible actions
The system may prepare. A responsible person approves sending, publishing, purchasing, deleting, changing permissions, setting prices and making commitments.
10. Preserve a record for consequential work
Record source material, material instructions, model or product, reviewer, decision and date when the output affects customers, money, rights or reputation.
11. Report incidents quickly and without punishment for honest escalation
People hide mistakes when the culture punishes the messenger. Define whom to contact, what to preserve and which connected actions should be paused.
12. Review the policy quarterly
Tools, terms, laws and business uses change. Review after a material incident, new connector or expansion into higher-risk work.
These rules are a starting structure. The policy becomes useful when every rule includes one “yes” example and one “no” example from your actual work.
Match the Rule to the Risk

Use three levels:
Low risk
Examples:
brainstorming titles from public information;
summarizing a public report;
restructuring your own non-confidential notes;
generating internal meeting questions.
Low-risk work can move quickly with ordinary review.
Medium risk
Examples:
drafting a client proposal from approved information;
analysing anonymized customer feedback;
preparing marketing claims;
producing internal recommendations.
Medium-risk work requires approved inputs, source checking and a named reviewer.
High risk
Examples:
uploading regulated or sensitive personal data;
making financial, legal, employment or health decisions;
automating payments, deletion or customer access;
issuing a public statement during a crisis.
High-risk work may require a specialized service, professional advice, formal testing or a decision not to use generative AI.
Think of the risk levels as keys in a building. A brainstorming assistant may enter the lobby. A system handling customer records does not receive the master key because it was helpful downstairs.
The AI readiness assessment can identify whether inputs, standards and ownership are mature enough for a proposed use. The AI automation guide helps prioritize reversible internal work first.
Apply the Policy to Three Real Business Scenarios

Scenario 1: a contractor drafts a proposal
The contractor wants to upload a customer’s existing proposal and call transcript.
Ask:
Is the account approved for confidential material?
Does the contract allow this use?
Can identifying details be removed?
Which claims require verification?
Who approves the final proposal?
If those answers are missing, the task pauses. The contractor can work from an approved, redacted brief instead.
Scenario 2: marketing generates a statistic
The model says “businesses using AI increase productivity by 40%.”
The policy requires the writer to locate the primary research, verify population and methodology, and decide whether the claim applies. If the source cannot be found, the statistic is removed.
This is not excessive caution. It prevents a fluent sentence from becoming a public liability.
Scenario 3: an agent monitors leads
An automated system reviews new leads and drafts follow-ups.
Allow:
classification against approved criteria;
preparation of an internal summary;
a draft response;
routing to a human owner.
Require approval before:
sending a message;
changing price or terms;
deleting a contact;
altering access;
or making a customer commitment.
A controlled AI brain can supply approved context without turning every connected folder into open territory.
Launch the Policy Without Creating Bureaucracy

Week 1: observe
Ask employees and contractors which tools they use, for what jobs and with what data. Do not begin with punishment; hidden use becomes safer only when it becomes visible.
Week 2: draft one page
Write the approved tools, prohibited data, verification rule, human approval points, incident contact and owner.
Week 3: test three scenarios
Walk through:
a customer spreadsheet;
a confidential proposal;
an AI-generated statistic.
If people give different answers, the policy is not clear enough.
Week 4: install the workflow
Put the policy where work happens. Add it to contractor onboarding, project templates and the approval checklist. Give people a safe alternative when the answer is “do not upload that.”
Track incidents and near misses. The goal is not zero questions. It is faster escalation before a mistake travels.
Governance should reduce hesitation at the moment of use, not create a PDF everyone ignores.
Trust Has to Move at the Speed of the Tools

If you are thinking, This feels like a lot for a small business, consider what the absence of a policy asks your people to do.
It asks a contractor to interpret privacy terms during a deadline. It asks an employee to decide whether a customer list is “sensitive.” It asks you to reconstruct a decision after a confident mistake has already reached the client.
That is not agility. It is outsourced uncertainty.
As AI makes output cheaper, judgment becomes more valuable. Small businesses cannot compete by producing the largest volume of synthetic material. They compete through trust, relevance and the speed with which they can make a sound decision.
The faster your tools can act, the clearer your boundaries must become.
I have spent years examining what happens to entrepreneurs when technology changes faster than their operating habits. The answer is not fear or a ban. It is to build a standard people can use while the pressure is real.
In The Wolf Is at the Door, I explore that wider shift in human responsibility. The 28-Day AI Mastery course helps turn the principle into controlled workflows, approved context and practical review gates.
Start with one page. Make tomorrow’s decision safer than today’s.
Frequently Asked Questions

Does a one-person business need an AI policy?
Yes. It may be a personal checklist rather than an employee document, but it should still define approved tools, data boundaries, verification and irreversible actions.
Is this policy legal advice?
No. It is an operational starting point. Obtain qualified legal, privacy, security or industry advice where your data, contracts and jurisdiction require it.
Can employees use personal ChatGPT or Claude accounts?
Only if your policy explicitly permits the product, account type, data and task. Business and consumer offerings can have different controls and terms.
Should we ban confidential data from all AI tools?
That may be appropriate for some businesses. Others may use approved commercial services under suitable contracts and controls. Apply the minimum necessary data and verify the exact service.
How often should an AI policy be updated?
Review quarterly and after a new tool, connector, high-risk use case, contract requirement or incident.
Who should own the AI policy?
Assign one accountable business owner with access to legal, privacy, security or technical expertise when necessary. Ownership must be clear even in a very small team.
What should happen after an AI incident?
Pause connected actions, preserve relevant records, notify the policy owner, assess affected data and people, follow contractual or legal notification requirements, and repair the control that failed.




Comments