The short answer
A good AI usage policy for a small business fits on one page. It names the tools staff can use, lists what must never be pasted in, such as client data or anything confidential, requires a human to check AI output before it goes out, and says who to ask when unsure. You can copy the template below and adapt it in an afternoon.
Most AI policy templates you find online are written for large enterprises, run to twenty pages, and quietly terrify a five-person business. You do not need that. You need something short enough that everyone reads it and clear enough that everyone follows it.
Only 31 percent of UK employers have a formal AI policy, according to the CIPD, while staff use the tools daily. If you get a simple one in place, you are already ahead of two thirds of the market. Here is a template built for a small UK business. Copy it, change the bits in brackets, and you are most of the way there.
The one-page AI usage policy template
1. Purpose
[Company name] encourages the responsible use of AI tools to do better work, faster. This policy sets out how we use them safely. It applies to everyone, including contractors.
2. Approved tools
You may use [e.g. ChatGPT Team, Microsoft Copilot, Claude] for work, on your [company] account only. Do not use personal free accounts for company work, and check with [name] before using any tool not on this list.
3. What you must never put into an AI tool
Never paste in client or customer personal data, anything under a confidentiality agreement, login details or passwords, financial account details, or anything commercially sensitive that we would not want a competitor to read. If in doubt, leave it out.
4. Always check the output
AI can be confidently wrong. You are responsible for anything you produce with its help. Check facts, figures, names and quotes before anything goes to a client or the public.
5. Be transparent
Use judgement about telling clients when AI has played a meaningful part in work we deliver. Never present AI-generated material as something it is not.
6. Data and clients
Only use approved, paid business tools for anything involving client information, and only where the tool does not train on our data. When unsure whether a tool is safe for client work, ask [name] first.
7. Who to ask
[Name, role] owns this policy. Bring them any question you are not sure about. Asking is always the right call. We review this policy every [quarter].
What to change for your business
The brackets are the work. Name your real approved tools and the accounts they run on. If you handle health, legal or financial data, tighten section 3 and take advice on your sector rules. If you are a regulated firm, add a line pointing to the specific regulator guidance that applies to you.
How to roll it out so it sticks
A policy nobody reads changes nothing. Share it in a short team session rather than a silent email. Walk through section 3 with a couple of real examples from your own work. Put it somewhere people can find it in five seconds. Then, once it is agreed, pair it with a bit of hands-on training so people know not just what they cannot do, but what they very much can.
AI Usage Policy for Small Businesses – frequently asked questions
What should be in an AI usage policy?
Purpose, approved tools, what must never be entered, a requirement to check output, rules on transparency, data and client handling, and one named owner with a review date. The template above covers all of these on a single page.
Is there a free AI policy template?
Yes. The seven-section template on this page is free to copy and adapt. Fill in the bracketed details with your real tools, contacts and sector rules, and you have a working policy.
What should employees never put into AI tools?
Client or customer personal data, anything confidential or under NDA, passwords and login details, financial account numbers, and anything commercially sensitive. The rule of thumb: if you would not email it to a stranger, do not paste it into a tool.
How do we get staff to follow the AI policy?
Involve a couple of them in writing it, launch it in a short session rather than a silent email, use real examples, and pair it with hands-on training so people know what they are allowed to do, not only what they are not.
How often should we update our AI policy?
Review it every quarter. AI tools change quickly, and a policy that named last year's tools loses authority fast. A short quarterly check keeps it credible.
Which Oxford AI School training fits this need?
Get the template turned into your policy, agreed with your team and paired with practical training. In person or live online.
Want this done for your business, properly?
Our AI Policy Workshop turns this template into your policy, agreed with your team and paired with the practical habits that make it work. Half a day, jargon free.
Book the AI Policy Workshop Do you need a policy?