Many small firms postpone an AI policy because the word policy sounds like a large-company activity. By the time the subject reaches the agenda, staff have often been using public tools for months. The business has a policy already. It is just an unwritten collection of individual decisions, made when people are busy.
The first policy does not need a legal department, a committee or fifty pages of definitions. It needs to establish a few decisions that staff should not have to improvise.
Here is a useful test: could a new employee understand what they may use AI for, what they must never enter, how they should check output, and who to ask when the answer is unclear? If not, the business has not yet given people a workable rule.
Begin with purpose, not fear
The opening line should make clear that the firm is not banning experimentation. It is defining responsible use. For example:
We use approved AI tools to support useful work, improve service and reduce avoidable administrative effort. Staff remain responsible for the accuracy, confidentiality and appropriateness of work produced with AI assistance.
That line does two jobs. It acknowledges that the tools can be useful, and it prevents responsibility being passed to the tool when something goes wrong.
Name permitted uses
List examples that fit the business. Typical permitted uses might include drafting a first outline from non-confidential information, summarising internal notes, improving the clarity of a routine message, translating public material, or generating options for a workshop.
Examples matter because “use responsibly” means different things to different people. A staff member preparing public marketing copy is working in a different context from someone handling payroll, health information or a client dispute. The policy should help them see the difference.
Name information that stays out
This is usually the most valuable part of the first policy. State plainly that staff may not paste confidential client information, personal data, bank details, passwords, contracts, employee records, unpublished financial information or commercially sensitive material into public AI services unless a specific approved arrangement is in place.
The list should reflect the firm’s actual work. A recruitment business has different concerns from an engineering practice. A financial adviser should name client financial information directly. Generic policy language is less useful than a short list people recognise from their own desk.
Require human review
The policy should say that AI output is a draft, recommendation or starting point. It is not a source of truth. The person using it remains responsible for checking facts, calculations, citations, tone, omissions and suitability for the audience.
This is especially important for content that may affect a client, employee or member of the public. In higher-consequence situations, review cannot be symbolic. A real reviewer needs enough knowledge and enough authority to reject the result.
Assign one owner
Someone should maintain the approved-tool list, collect questions and decide when a new use case needs a closer look. In a small business, this may be an owner, operations lead or technology lead. It does not need to become a new department.
The owner’s role is not to approve every prompt. It is to make sure there is a place for uncertainty to go. Without that, staff either avoid useful tools altogether or use them quietly.
Add one escalation rule
Finish with a clear instruction: stop and ask before using AI with sensitive information, before relying on it for a decision about a person, or when the output is difficult to verify. This rule is more useful than a long list of edge cases because it catches the moments where ordinary judgement should pause.
Keep it alive
Review the policy after a few months of actual use. Ask staff where it is unclear, which tools have appeared and whether a useful workflow has been blocked unnecessarily. The goal is not a perfect document. It is a shared working boundary that gets better as the business learns.
Standards such as NIST’s AI Risk Management Framework can help organisations design a fuller governance approach. A small firm does not need to reproduce them to make its first sensible move. It needs a one-page policy that changes what people do today.