An AI usage policy is a short document that tells your team which AI tools they can use at work, what information they can put into them, and who is responsible for checking what comes out. Most businesses need one sooner than they think, because staff started using chat assistants long before anyone wrote a rule about it.
This guide walks through what to decide before you write, a simple outline you can adapt, the data rules that matter most, and how to roll the policy out so people actually follow it. It is practical guidance, not legal advice; if you work in a regulated sector, have your adviser review the final version.
Why you need an AI usage policy now
Banning AI rarely works. People find it useful for drafting emails, summarising long documents and tidying spreadsheets, so they keep using it on personal accounts where you have no visibility at all. That is the worst outcome: the risk is still there, but nobody is managing it.
A policy turns quiet, inconsistent use into something you can see and improve. It gives careful staff the confidence to use AI properly, and it gives managers a clear standard to point to when something goes wrong.
The main risks a policy addresses are fairly predictable:
- Data leaving the business. Client details, contracts or staff records pasted into a free tool whose terms allow it to keep or learn from that data.
- Wrong answers sent as fact. AI tools can produce confident, plausible text that is simply incorrect.
- Unclear ownership. Nobody knows who approved a piece of AI-assisted work, or who should have checked it.
- Inconsistent quality. Customers get very different answers depending on which staff member, and which tool, handled the request.
Before you write anything
Spend an hour finding out what is already happening. A policy written in a vacuum tends to ban things people rely on, which guarantees it gets ignored.
- Ask staff which AI tools they use and for what. Make it clear this is a fact-finding exercise, not a disciplinary one, or you will get polite silence.
- List the tools you already pay for. Many office suites, CRMs and help desk platforms now include AI features that may already be switched on.
- Map your sensitive data. Note where client data, financial records, health information, staff files and commercially sensitive material live.
- Check any obligations you already have. Client contracts, insurance terms and data protection duties may already restrict where data can be processed.
- Pick an owner. One named person keeps the policy current, answers questions and approves new tools.
If you want a wider view of where AI could help before setting rules, our guide to practical AI use cases for small businesses is a useful starting point.
A simple AI usage policy outline
Keep it short. Two to four pages is plenty for most growing businesses. You can adapt the headings below.
1. Purpose and scope
One paragraph explaining why the policy exists and who it covers. Include employees, contractors and anyone else working with your data or on your behalf.
2. Approved tools
Name the tools staff may use, and which account type. "The company workspace version of a chat assistant" is very different from "any free AI website". Say how someone requests a new tool and who approves it.
3. Data rules
The most important section. Spell out what can and cannot go into an AI tool. We cover this in detail below.
4. Acceptable and unacceptable uses
Give real examples from your business rather than abstract principles. For instance:
- Acceptable: drafting a first version of a proposal, summarising internal meeting notes, rewording a help article, generating ideas for a campaign.
- Needs approval: anything customer-facing that will be sent without edits, AI features that act on systems automatically, new integrations.
- Not allowed: making hiring, credit or disciplinary decisions with AI alone, uploading client files to unapproved tools, presenting AI output as checked work when it has not been checked.
5. Human review
Who checks AI output before it is used, and how carefully, depending on the risk.
6. Transparency
When you tell customers or colleagues that AI was involved. Some businesses disclose any AI-written customer communication; others only disclose automated chat. Decide, and write it down.
7. Incidents and questions
What to do if someone pastes the wrong data into a tool or spots harmful output. Make reporting easy and blame-free, so mistakes surface quickly.
8. Review date
AI tools change quickly. Put a date on the policy and revisit it at least twice a year.
The data rules that matter most
If staff remember only one part of the policy, it should be this. A simple traffic light system works well because people can apply it in seconds.
- Green, fine in any approved tool: public information, your own marketing copy, general questions, anonymised examples.
- Amber, approved business tools only: internal documents, non-sensitive project notes, draft proposals without client identifiers.
- Red, never in a general AI tool: personal data about clients or staff, passwords and access keys, financial account details, health information, confidential client material, anything covered by a non-disclosure agreement.
Red data can still be processed by AI in some cases, but only through a system built for it, with proper agreements, access controls and logging. That is a design decision for the business, not something an individual should improvise. Our article on cloud security basics for small businesses covers the wider controls that sit around this, such as access reviews and offboarding.
When you assess a tool, ask the supplier plainly: is our data used to train models, how long is it kept, where is it stored, can we delete it, and can we manage user accounts centrally? If the answers are vague, treat the tool as amber at best.
Human review and accountability
The simplest rule is also the most useful: the person who uses the output owns it. If you send an AI-drafted email, it is your email. If you publish an AI-summarised report, you are responsible for its accuracy.
Match the level of review to the risk:
- Low risk, such as internal notes or brainstorming: a quick read is enough.
- Medium risk, such as customer emails or marketing copy: check facts, names, figures and tone before sending.
- High risk, such as contracts, financial figures, advice to clients or anything about a person: a qualified person reviews it in full, and AI should only assist, never decide.
Where AI is built into a workflow, for example drafting replies or extracting data from documents, design the review step into the system rather than relying on memory. Exceptions go to a person; approvals are recorded. This is the approach we take when we build AI automation for business processes, and it is what makes an automated workflow safe to depend on.
Rolling the policy out to staff
A policy that sits in a shared drive changes nothing. Rollout matters as much as wording.
- Explain the why in a short team session. Show a real example of a risky prompt and a safe alternative. Concrete beats abstract every time.
- Give people the approved tools first. If you restrict free tools without offering a business version, staff will route around the rules.
- Publish a one-page summary. The traffic light data rules, the approved tool list and who to ask. Pin it where people work.
- Ask for acknowledgement. A simple sign-off makes the expectation clear and gives you a record.
- Add it to onboarding and offboarding. New starters learn the rules on day one. Leavers have their AI tool accounts removed with everything else.
- Collect feedback after a month. Find out which rules are unclear or blocking useful work, then adjust.
Consider naming a few enthusiastic staff as informal AI champions. They share good prompts, flag problems early and make the policy feel like support rather than restriction.
Common mistakes to avoid
- Copying a large company template. A policy written for thousands of staff will be too long and too abstract for a team of forty.
- Banning everything. It pushes use underground and wastes the genuine time savings.
- Vague data rules. "Do not share sensitive information" means different things to different people. Name the categories.
- Forgetting built-in AI features. AI assistants inside your existing software count too, and they may have access to far more data than a chat window.
- No owner and no review date. The policy goes stale within months and people stop trusting it.
- Ignoring AI that acts, not just writes. Tools that can send emails, update records or make bookings need tighter rules. Our explainer on AI agents for business owners covers why.
Frequently asked questions
How long should an AI usage policy be?
For most businesses with 10 to 200 staff, two to four pages plus a one-page summary is enough. If it is longer, people will not read it, and the important rules get lost.
Do we need an AI usage policy if we do not officially use AI?
Usually yes. Staff often use free AI tools on their own, and many business applications now include AI features. A short policy clarifies what is acceptable before a problem forces the question.
Should the AI usage policy be separate from our IT or data protection policy?
It can be a section of an existing policy, but a separate short document is easier to update and easier for staff to find. Make sure it refers to your existing data and security rules rather than contradicting them.
Can staff use free AI tools for work?
That is your decision. Many businesses allow free tools only for green data, such as public information and general questions, and require approved business accounts for anything internal.
Who should own the AI usage policy?
Someone senior enough to make decisions and close enough to daily work to understand it, often an operations lead or the person responsible for IT. They approve new tools and run the regular review.
Your first step this week
Start with the short staff survey and the traffic light data rules. Those two things alone remove most of the risk, and they give you the information to write the rest of the policy properly.
If you are also deciding which AI tools and workflows to adopt, our AI strategy and consulting work covers both questions together, so the rules and the tools fit each other.