AI Governance

What AI Policies Should My Business Have?

⚡ The quick answer

At minimum, every business using AI needs a short AI Use Policy covering: which tools are approved, what data may and may not go into them, when to disclose AI use, who is accountable for checking output, and a plain statement that staff stay responsible for their work. One clear page beats a fifty-page framework nobody reads.

The goal isn't bureaucracy. It's letting your team use AI confidently without anyone guessing at the rules.

The moment your team starts using AI, and they have, whether it is official or not, you need some rules. Not a doorstop of a document, and not a ban that just pushes usage underground. A short, sensible policy that tells people what is allowed, so they can get on and use these tools without inadvertently causing a problem. Here is what it should cover.

The essentials, on one page

What an AI use policy must cover

  • Approved tools - which AI tools are allowed, and which aren't
  • Data rules - what information may go in, and what must never
  • Accountability - staff remain responsible for checking and owning output
  • Disclosure - when to be transparent that AI was used
  • Accuracy - the requirement to verify before relying on anything
  • Who to ask - a named person for questions and grey areas

Get those six right and you have covered the overwhelming majority of real-world risk. Everything else is refinement. The how to write an AI policy guide walks through each in detail, and there is a downloadable template to start from.

Why 'just ban it' backfires

Some businesses, especially cautious ones, reach for an outright ban. It rarely works and often makes things worse. Staff use these tools anyway, on personal accounts, outside your oversight, which is precisely the unsafe scenario a policy should prevent. A ban does not stop AI use. It stops safe AI use. Far better to say "here is how we do this properly" than "do not, or else".

The data rule matters most

If you read only one line of your own policy twice, make it the data one. The most common real incident is not some sophisticated attack, it is a well-meaning employee pasting confidential information into a free tool to save five minutes. Your policy should state clearly what may go in (general, non-sensitive material), what must never (personal data, client-confidential information, credentials), and which approved tools to use. For law firms, accountants and IFAs, this is not optional, it is a regulatory expectation.

Keep it human-readable. A policy your team actually reads and remembers beats a legally exhaustive one they skim once and forget. Plain English, one or two pages, real examples.

Match the policy to your risk

A five-person marketing agency and a fifty-partner law firm do not need the same document. Scale it to your risk. If you handle sensitive client data, regulated advice or health records, you will want a fuller governance approach, covering vetting of tools, records of what is used, and how you would answer a regulator. Our governance framework guide covers that end. For most small businesses, a clear one-pager is genuinely enough to start.

Write your AI policy in one session

Our AI Policy Workshop takes you from a blank page to a clear, practical policy your whole team can follow.

Make it live, not a drawer document

A policy only works if people know it exists. Introduce it properly, ideally alongside a bit of training so people understand the why, not just the what. Review it every few months, because these tools change fast and last year's rules may have gaps. And keep the door open, the named person for questions matters, because the grey areas are where sensible judgement beats rigid rules.

An AI policy is not red tape. It is the thing that lets your team use powerful tools with confidence instead of nervous guesswork, and it is the difference between AI being an asset and AI being an incident waiting to happen. One clear page, done this month, is worth more than a perfect framework you never quite get around to.

Frequently asked questions

Does my small business really need an AI policy?

Yes, if anyone uses AI, which they probably do. Even a single clear page prevents the most common problems, like sensitive data going into the wrong tool. It needn't be long or bureaucratic to be effective.

What should an AI use policy include?

Approved tools, data rules (what may and may not go in), staff accountability for checking output, when to disclose AI use, an accuracy requirement, and a named person for questions. Six points on a page or two cover most needs.

Should I just ban AI to be safe?

Banning usually backfires, since staff use the tools anyway on personal accounts, outside your oversight. A clear policy on how to use AI safely prevents more risk than a ban that simply drives usage underground.

Do regulated businesses need a stronger AI policy?

Yes. Law firms, accountants, IFAs and healthcare providers should document tool vetting, data handling and how they'd answer a regulator. See our governance framework guide.

How do I actually write an AI policy?

Start from a template and tailor it, or do it in a focused session. Our AI Policy Workshop takes you from blank page to finished policy, and the written guide walks through each section.

Book your free 10-minute intro call

No jargon, no hard sell. Just a friendly chat about where AI could actually help your business.

Book A Call