Yes. If anyone in your business uses ChatGPT, Copilot, Gemini or any other AI tool, and they almost certainly do, you need a short AI usage policy. It does not need to be long or written by a lawyer to be useful. It needs to tell people which tools they can use, what information must never go into them, and that a person is responsible for anything AI helps produce.

Download our free AI usage policy template and adapt it in an afternoon.

Why a small business needs one

Your staff are already using AI. Free AI tools are a browser tab away. People use them to draft emails, summarize documents and analyze spreadsheets, usually with good intentions and no guidance.

The main risk is data leaving your control. When someone pastes a client list, a contract or financial figures into a consumer AI tool, that information may be stored by the provider and, depending on the service and its settings, used to improve their models. Business versions of these tools usually offer stronger protections, but only if people use them.

AI makes confident mistakes. AI tools can produce answers that sound right but are wrong: invented figures, incorrect legal or tax statements, or references that do not exist. Without a rule that a person checks the output, those mistakes reach customers.

Clients and partners are starting to ask. Larger customers, insurers and regulators increasingly ask how suppliers use AI with their data. A written policy is an easy, credible answer.

A policy makes AI easier to use, not harder. Clear rules give people permission to use AI confidently for the things that are fine, instead of guessing or avoiding it altogether.

What a good AI usage policy covers

Keep it to one or two pages. Cover these points in plain language:

  1. Purpose and scope. Who the policy applies to (employees, contractors) and which tools it covers.
  2. Approved tools. A short list of AI tools people may use for work, ideally business accounts managed by the company. Everything else needs approval.
  3. Data that must never go into AI tools. For example customer personal information, financial account details, passwords, health information, confidential contracts and anything covered by an NDA.
  4. Acceptable uses. Examples of what is fine, such as drafting, summarizing public information, brainstorming and reformatting.
  5. Human review. A person is responsible for checking anything AI helps produce before it is sent, published or relied on.
  6. Transparency. When to tell customers or colleagues that AI was used, for example in customer-facing content or decisions about people.
  7. Accounts and access. Use company accounts, not personal ones, so access can be removed when someone leaves.
  8. Getting help and reporting problems. Who to ask, and what to do if sensitive data was shared by mistake.
  9. Review date. AI tools change fast. Review the policy at least every six months.

Make it stick

A policy only works if people know about it and find it easy to follow:

  • Walk the team through it in a short session with real examples from your business.
  • Provide approved tools. If the business-grade tool is easier to reach than the free one, people will use it.
  • Name an owner. One person who keeps the approved tool list current and answers questions.
  • Revisit it when you adopt new tools or AI features appear in software you already use.

Get the template

Our AI usage policy template covers all of the points above in plain English, with [bracketed] fields to fill in. It is free to download as a Word document.

The template is a starting point, not legal advice. If you work in a regulated industry, such as healthcare, finance or legal, have it reviewed by your advisor.

If you would like help tailoring the policy, choosing approved tools and training your team, see our adoption and enablement service, or start with an AI readiness assessment, which includes a recommended policy.