Skip to content

Your team is probably already using AI tools. The question is not whether, but whether anyone has told them what is safe to paste in.

A written policy answers that, and it protects you in three ways:

  • Confidential information stays in. Customer details, financial figures and passwords should not end up in a tool you have not vetted.
  • Mistakes get caught. AI is fluent and sometimes wrong. Someone has to be responsible for checking it before it reaches a customer.
  • People stop guessing. Most staff want to do the right thing. They need to know what it is.

What a good policy covers

It fits on one page and answers six questions:

  1. Which AI tools may we use for work?
  2. What may we put into them?
  3. What may we never put into them?
  4. Who checks the output, and before what?
  5. When do we tell customers that AI was involved?
  6. Who do we ask, and who do we tell if something goes wrong?

The template

Copy this into a document, replace everything in [brackets] and delete what does not apply. Keep it short enough that people will actually read it.

[Company name] AI-use policy
Effective [date]. Owner: [name].

1. Purpose. This policy explains how [Company name] uses AI tools safely and what is expected of everyone who works here.

2. Approved tools. You may use only these AI tools for work: [list the tools and the plan, such as the team workspace the company pays for]. Do not use personal accounts or other tools for work.

3. What you may enter. [Examples: public information, your own draft text, general questions, examples with the names and details removed.]

4. What you may never enter. Customer names and contact details, financial account numbers, passwords or access keys, health information, employee records, contracts and anything marked confidential, unless [name] has approved the tool for that kind of information in writing.

5. Check the output. AI makes mistakes. A person is responsible for everything sent to a customer or used in a decision. Check facts, figures and quotes before you use them.

6. Tell people when it matters. [State when AI-generated content must be disclosed to customers, or in contracts.]

7. Ask first. If you are not sure whether something is allowed, ask [name] before you use the tool.

8. Reporting. If you enter something you should not have, tell [name] right away. Honest reporting will not be punished.

9. Review. [Name] reviews this policy every six months, and whenever we add a tool.

I have read and understand this policy. Name: ______ Date: ______

What is fine and what is not: examples your team will recognize

A policy lands better with examples from your own business. Here are the kinds worth including:

Usually fine, in an approved tool:

  • Asking for a first draft of a general blog post, or for ways to reword a paragraph you wrote.
  • Summarizing a public article, or explaining a concept you are new to.
  • Brainstorming names, subject lines or agenda items that contain nothing about a specific customer.

Not allowed unless the tool is approved for it in writing:

  • Pasting a customer’s email thread, contract or invoice to get a summary.
  • Uploading a spreadsheet of customer names, phone numbers or account details.
  • Entering anything about an employee’s pay, performance or health.

When two cases look alike, say which side of the line they fall on. Staff follow examples faster than rules.

Five common mistakes in AI policies

  1. Banning AI outright. People will use it anyway, on personal accounts, where you cannot see or protect anything.
  2. Naming no approved tool. A policy with no safe option leaves the unsafe ones as the only ones.
  3. No owner. Somebody has to answer questions and keep the document current.
  4. Writing it once and never reviewing it. The tools change every few months, and so should the list.
  5. Copying a large company’s policy. A twelve-page policy written for a bank will be ignored in a twelve-person shop. Short and specific wins.

Questions owners ask

Do we have to tell customers when we use AI? There is no single rule for every business. Some contracts and some industries require it, and many customers simply appreciate being told. Decide your approach, write it into the policy and be consistent.

Can we use the free version of a tool? Free consumer versions often have different data terms from business plans. Check the terms for any tool you approve, and prefer a business plan for anything beyond casual use.

What if someone makes a mistake? Make it easy to report. People who fear punishment hide mistakes, and a hidden mistake is the expensive kind.

How to roll it out

  1. Choose the approved tools first. A policy that bans everything gets ignored. Give people one workspace that is allowed, so the easy path is the safe one.
  2. Have the owner sign it. It carries weight when it comes from the top.
  3. Ask everyone to read it and sign. Keep the signed copies with your other HR records.
  4. Run a 30-minute session. Walk through two or three real examples from your own business: what is fine, what is not. Record it for new hires.
  5. Set a review date. Tools change quickly. Put the next review on the calendar before you finish.

What a policy does not do

A template is a starting point, not legal advice. If you handle health information, financial records or other regulated data, you need more than one page, including signed agreements with the tool vendors. Have your attorney review the policy before you adopt it.

A policy is the start, not the finish

The policy tells people what not to do. The bigger win is giving them something good to do instead: an approved AI workspace, and an assistant that answers questions from your own procedures and price lists, so nobody has to paste anything sensitive into a public tool. That is what our AI consulting for small businesses sets up. If you want a second pair of eyes on your policy, book a free Tech Bottleneck Call.