A small team needs one page, not a policy document. The four things that actually matter are: what you may put into AI tools, what must be checked before it leaves the business, what must be disclosed, and who to ask. Everything beyond that is decoration for a five-person company.
The template below is written to be copied, edited in ten minutes and pinned somewhere people will see it. It is not legal advice, and it deliberately avoids the enterprise framing that makes most AI policies unread.
Key takeaways
- One page, four rules. Longer policies get skimmed and ignored.
- Lead with what’s allowed, not what’s banned — a ban-list policy pushes AI use underground.
- The data rule is the important one: name what must never be pasted in.
- Disclosure obligations are now legal, not just ethical, if you serve EU customers.
- Name a person to ask. Policies without an owner produce guesswork.
Why Do You Need a Policy at All?
Because your team is already using AI, with or without one. The realistic question is not whether AI enters your business but whether anyone has said what may be pasted into it.
Three risks make this worth ten minutes. Client data being pasted into a consumer tool with unclear training terms. Unchecked output reaching a customer with a wrong figure in it. And, since 2 August 2026, disclosure obligations for businesses serving EU customers — covered in the AI transparency rules.
A policy also protects the people doing the work. Without one, someone using AI sensibly still worries they’re breaking an unwritten rule, and someone using it carelessly has no way of knowing.
What Should the Policy Cover?
| Section | Answers | Length |
|---|---|---|
| 1. What you can use it for | Which tasks are encouraged | 4–6 bullets |
| 2. What must never go in | Data that can’t be pasted | 4–6 bullets |
| 3. What must be checked | Output needing review before it leaves | 3–4 bullets |
| 4. What must be disclosed | Where you tell customers | 2–3 bullets |
| 5. Who to ask | A name | One line |
Order matters. Starting with permissions rather than prohibitions signals that AI use is expected, which is what stops people hiding it.
The Template
Copy this, change the bracketed parts, delete anything irrelevant to you.
AI Use Policy — [Business name], [date]
1. Using AI here is encouraged. Use it to draft and edit text, summarise long documents, brainstorm, research, write and check formulas, and turn rough notes into something readable. If it saves you time and the four rules below are met, go ahead.
2. Never put these into an AI tool: customer or client personal data (names with contact details, addresses, financial details); anything covered by an NDA; login credentials or API keys; employee records or anything HR-related; health, financial or children’s data; unreleased commercial information such as pricing under negotiation. If unsure, remove the identifying details first or ask.
3. Check before it leaves the business. Every figure, date, name and price in AI-assisted output must be verified against the source. Anything going to a customer, a regulator or the public is read in full by a person first. You remain responsible for what you send, exactly as if you had typed it yourself.
4. Disclose where required. Any chatbot or automated responder on our channels identifies itself as AI. Synthetic images, video or voice in marketing are labelled. AI-generated content published to inform the public is reviewed and attributed to a named person.
5. Approved tools: [list them]. Anything else gets checked with [name] first, because tools differ on whether your data trains their models.
6. Ask [name] if you’re not sure. Asking is always the right call and there is no penalty for it.
How Do You Decide the Data Rule?
Work from what would embarrass you if it appeared in someone else’s output. That’s a more useful test than a category list, because it catches the specifics of your business.
| Data | Rule | Why |
|---|---|---|
| Customer names with contact details | Never | Personal data, and you don’t control retention |
| NDA-covered material | Never | You’ve contractually promised not to |
| Credentials and keys | Never | No legitimate reason exists |
| Anonymised customer scenarios | Fine | Strip identifiers and it’s just a description |
| Your own drafts and notes | Fine | This is the main use case |
| Published material | Fine | It’s already public |
Check your tool tier too. Business and team plans commonly exclude your inputs from model training while consumer tiers sometimes do not, and that single setting changes what’s reasonable to allow.
What About Disclosure Specifically?
Three places matter for a small business, and only one is likely to catch you out.
Chatbots must identify themselves as AI — usually the vendor builds this in, so your job is confirming it’s switched on. Synthetic media in advertising needs labelling: a generated spokesperson or cloned voice requires disclosure regardless of subject. And AI-generated text published to inform the public on matters of public interest needs handling carefully, though ordinary marketing content sits outside that category.
What you do not need is a disclaimer on every AI-assisted email. Drafting with AI and editing properly is normal work, and over-disclosing dilutes the disclosures that matter.
How Do You Make It Stick?
| Action | Why it works |
|---|---|
| Keep it to one page | Longer means unread |
| Include it in onboarding | Day one, alongside everything else |
| Name a person, not a department | “Ask the team” means ask nobody |
| Review every six months | Tools and rules both move |
| Say what’s allowed first | Prohibition-led policies drive AI use underground |
| Don’t punish honest questions | One telling-off ends all future questions |
What Should the Checking Rule Look Like?
Specific enough to act on. “Review AI output carefully” is not a rule — it’s a hope. The version that changes behaviour names what gets checked and against what.
| Output contains | Check it against | Who |
|---|---|---|
| A price or figure | The source system, not memory | Whoever sends it |
| A date or deadline | The contract or calendar | Whoever sends it |
| A named person or company | The CRM record | Whoever sends it |
| A factual claim about your service | What you actually offer | Whoever sends it |
| Anything going public | Full read, plus a second reader | Named owner |
Print it, or pin it next to the policy itself. A checking rule that lives in a document nobody opens is the same as no rule at all. Note who holds responsibility in every row: the person sending it. That framing matters more than the checklist, because it removes the idea that the tool shares the blame. If your name is on the email, the content is yours.
What If You’re a Sole Trader?
Write it anyway, and make it four lines. The value isn’t governance — it’s having decided in advance what you’ll paste in, so you’re not making that judgement while rushing a proposal at 11pm.
It’s also increasingly a commercial asset. Larger clients and public-sector buyers now ask about AI use in procurement, and “yes, here’s our one-page policy” is a materially better answer than an improvised one. That’s the same reason the disclosure rules are worth understanding rather than ignoring.
Frequently Asked Questions
What should a small business AI policy include?
Five short sections: what AI may be used for, what data must never be entered, what output must be checked before leaving the business, what must be disclosed to customers, and who to ask when unsure. One page total.
Do small businesses need an AI use policy?
If anyone on the team uses AI, yes — and they almost certainly do. The policy exists mainly to state what data can be pasted in, which is the risk most likely to cause real harm, and to protect staff using AI sensibly.
What data should never be put into AI tools?
Customer personal data, anything under NDA, credentials and API keys, employee and HR records, health or financial data, and unreleased commercial information such as pricing under negotiation. Anonymised scenarios with identifiers removed are generally fine.
Do I have to tell customers I use AI?
For chatbots and synthetic media in marketing, yes if you serve EU customers — those obligations applied from 2 August 2026. You do not need a disclaimer on every AI-assisted email; over-disclosing dilutes the disclosures that matter.
How long should an AI policy be?
One page. Longer documents get skimmed and then ignored, which leaves you with the appearance of a policy rather than one. If it doesn’t fit on a page, the extra content is probably not changing anyone’s behaviour.
Who should own the AI policy in a small team?
A named individual, not a department or “the team”. People need someone specific to ask, and a policy with no owner produces guesswork. In most small businesses this is the owner or whoever handles operations.
The Bottom Line
Copy the template, spend ten minutes on section two, and put a name at the bottom. That’s the whole exercise, and it puts you ahead of most businesses your size.
Lead with permission. A policy that opens by listing what’s forbidden teaches people to use AI quietly and not mention it, which is precisely the outcome that creates risk. Encouraging use within clear limits is both safer and more useful.
Then diarise a six-month review, because both the tools and the rules are moving. Next: what the AI disclosure rules require, how to contain an AI agent, or the case studies and ROI hub.
Want one practical automation you can set up in 15 minutes, twice a month? Join the free newsletter.
Sources
- EUR-Lex — Regulation (EU) 2026/1744 (Digital Omnibus on AI)
- EU Artificial Intelligence Act — Implementation timeline
- NIST — AI Risk Management Framework
- NCSC — Guidelines for secure AI system development
- OWASP — Top 10 for Large Language Model Applications
All sources retrieved 11 August 2026. This template is a practical starting point for a small team, not legal advice, and it does not cover sector-specific obligations. If you handle health, financial or children’s data, operate in a regulated industry, or build and sell AI systems, take qualified advice on your position.



