Small Business AI Use Policy: What to Put in It Before Your Team Uses AI at Work
A practical small business AI policy guide with employee rules, risk checks, and a template-ready outline.
Small Business AI Use Policy: What to Put in It Before Your Team Uses AI at Work
Your team is probably already using AI. Someone is asking ChatGPT to rewrite customer emails. Someone is pasting meeting notes into a summarizer. Someone is generating product descriptions, spreadsheet formulas, ad copy, or code snippets. The problem is not that employees are curious. The problem is that most small businesses have no shared rules for what is safe, what needs review, and what should never be pasted into an AI tool.
A small business AI policy does not need to be a 40-page legal document. It needs to answer practical questions employees actually face: Can I put customer names into this tool? Can AI write a quote for a client? Can I use AI images in marketing? Who checks the output before it goes live? What happens if someone accidentally shares confidential information?
This guide gives you a useful starting point. It is an implementation aid, not legal advice. But it can help you turn AI use from a quiet free-for-all into a controlled business process.
Start with the actual jobs AI is doing
Do not begin with a generic statement like "we support responsible innovation." Begin with an inventory.
Make a simple table with five columns:
| AI use | Tool | Data involved | Output destination | Review owner |
|---|---|---|---|---|
| Draft customer support replies | ChatGPT, Gemini, Claude, helpdesk AI | Customer issue, order details | Email/helpdesk | Support lead |
| Product description drafts | ChatGPT or ecommerce platform AI | Public product facts | Storefront | Marketing owner |
| Meeting summaries | Otter, Teams, Zoom, AI note taker | Internal discussion, client details | Internal notes | Meeting host |
| Spreadsheet formulas | ChatGPT or Copilot | Operational data | Internal workbook | Requesting employee |
This one page will show you where your real risk lives. A staff member using AI to brainstorm blog topics is very different from a staff member pasting payroll records, medical details, legal documents, source code, client strategy, or customer complaints into an outside system.
NIST's AI Risk Management Framework describes risk work in terms of govern, map, measure, and manage. For a small business, "map" can mean writing down where AI is used, what data goes in, what output comes out, and who reviews it. NIST also released a Generative AI Profile covering risks specific to generative AI. See: https://www.nist.gov/itl/ai-risk-management-framework and https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-generative-artificial-intelligence
Define data rules employees can remember
Most employee AI use policies fail because the data rules are too vague. "Do not share sensitive information" sounds fine until someone asks whether a customer email is sensitive.
Use three or four simple data categories:
- Public: already public product copy, published FAQs, public website content, generic business descriptions.
- Internal: process notes, internal drafts, non-public pricing plans, vendor notes, operating procedures.
- Confidential: customer records, contracts, financial records, employee information, client strategy, credentials, unreleased product plans.
- Restricted: regulated data, passwords, API keys, payment card data, Social Security numbers, health data, children's data, legal privileged material.
Then turn the categories into rules:
| Data category | AI use rule |
|---|---|
| Public | Allowed in approved tools. |
| Internal | Allowed only if the tool is approved for business use and the output is reviewed. |
| Confidential | Do not enter unless a manager has approved the specific tool and use case. |
| Restricted | Do not enter into public or unapproved AI tools. Use only approved systems with written controls. |
This gives employees a decision path without forcing them to interpret privacy law during a busy workday.
Choose approved tools instead of banning everything
A total AI ban is often unrealistic. A better approach is an approved-tools register. List each tool, who owns it, what it may be used for, what data categories are allowed, whether training-on-your-data is disabled where available, and whether a paid business plan is required.
At minimum, track the tool name, business owner, approved users, approved use cases, allowed data categories, human-review requirements, vendor-terms status, and next review date.
The EU AI Act is not a small-business handbook, and its obligations depend on roles, locations, and risk categories. Still, it signals where AI governance is heading. The European Commission describes the Act as a risk-based framework for developers and deployers. The official Regulation (EU) 2024/1689 text is on EUR-Lex. See: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai and https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng
For a U.S. small business, the practical takeaway is not "you are automatically covered by every AI Act obligation." The practical takeaway is that documented tool ownership, approved use cases, human review, and worker notice are becoming normal expectations.
Write acceptable-use rules in plain English
Your AI acceptable use policy should tell employees what is allowed, what is allowed with approval, and what is prohibited.
Allowed examples:
- Brainstorming outlines, taglines, FAQs, and internal drafts
- Rewriting public-facing copy when a human reviews it
- Summarizing internal notes that do not contain confidential or restricted data
- Creating spreadsheet formulas from non-sensitive examples
- Translating or simplifying approved business content, subject to review
Approval-required examples:
- Using customer, employee, vendor, or client information
- Using AI output in paid ads, legal documents, HR decisions, financial advice, or compliance materials
- Uploading contracts, proposals, datasets, source code, or client deliverables
- Adding a new AI tool to a business workflow
- Using AI-generated images, audio, video, or likenesses in marketing
Prohibited examples:
- Entering passwords, API keys, payment card data, Social Security numbers, or private health data into unapproved tools
- Treating AI output as legal, tax, medical, financial, or HR advice without qualified review
- Publishing AI output that has not been checked for accuracy, ownership, tone, and customer impact
- Using AI to impersonate customers, employees, competitors, or real people
- Hiding AI use from a manager when the policy requires disclosure
Keep these rules visible. Put them in onboarding, the employee handbook, a shared drive, and the tools your team actually uses.
Require human review where mistakes matter
AI output can sound polished and still be wrong. Your policy should say which outputs require review before they are sent, published, or used.
Require review for:
- Customer-facing claims about pricing, refunds, warranties, delivery times, safety, health, finance, or legal rights
- Client deliverables
- Hiring, firing, performance, or disciplinary materials
- Financial projections and tax-related summaries
- Compliance documents and policy language
- Code or automation that touches customer data, payments, or production systems
The reviewer should check facts, tone, confidentiality, source rights, and business judgment.
Add an incident path
Employees need to know what to do when something goes wrong. Include a short incident rule: if you entered confidential or restricted data into an unapproved AI tool, relied on questionable output, generated harmful or biased content, exposed client data, or discovered unauthorized AI use, notify your manager or AI policy owner immediately. Do not delete evidence or continue using the output until it is reviewed.
A written process makes reporting normal.
A basic AI policy outline you can use today
Use this structure for your first draft:
- Purpose: why the policy exists and who it applies to.
- Scope: employees, contractors, departments, tools, and work devices.
- Approved tools: where the approved-tools register lives.
- Data classification: public, internal, confidential, restricted.
- Allowed uses: practical examples by team.
- Approval-required uses: when to ask first.
- Prohibited uses: hard lines.
- Human review: outputs that need review and who approves them.
- Customer/client disclosure: when AI use must be disclosed.
- Vendor review: who can approve new tools.
- Incidents: what to report and to whom.
- Training and acknowledgment: how employees confirm they understand the rules.
- Review cycle: when the policy is updated.
You can build this in a document today. It will be imperfect, but it will be much better than no policy.
Where the getdigi kit fits
The AI Policy + AI Literacy Starter Kit packages this work into ready-to-edit worksheets and templates: an AI acceptable-use policy, approved-tools register, data classification cheat sheet, human-review SOP, vendor checklist, incident log, staff acknowledgment, and a short team training workflow. It is for owners who want to move faster without pretending a template is a lawyer.
Use it as an implementation aid. Customize it for your tools, customers, contracts, industry, and state or country rules. If AI affects employment decisions, regulated services, legal rights, financial advice, health information, children, biometrics, or high-risk customer outcomes, get qualified legal or compliance help before relying on any template.