Trust & Safety

AI Policy for Small Business: What Goes on the One Page Your Team Will Read

Updated on September 29, 2026
8 min read

An AI policy for small business is one page that tells your team which AI tools they can use, what information never goes into them, and who checks the output before a client sees it. If your people already use ChatGPT, Claude, or Gemini for work, you can write that page in an afternoon.

The reason to do it now is simple: the tools are already in your business. A 2026 Founder Reports survey of more than 2,000 U.S. workers found that 44% say their employer has no clear AI policy or they are unsure one exists, and the share rises to 59% at businesses with fewer than 10 employees.[^1] Your staff are making these calls alone, one paste at a time.

TL;DR: A workable AI policy for small business has five parts: an approved tools list, a short list of data that never goes into AI, a rule that a person reads every AI output before it leaves the building, a name to ask when someone is unsure, and a signature. Keep it to one page. Write it in plain words, share it in one short meeting, and review it twice a year. DocsAura, an AI document design tool, can turn your finished policy into a clean one-page document your team will open, which matters because a policy nobody reads protects nothing.

What an AI Policy for Small Business Needs to Say

Every template we read agrees on the core. A good AI policy for small business answers three questions and adds two housekeeping lines.

1. Which tools may we use for work? Name them. "ChatGPT on the company account, Claude, and the AI features inside the tools we already pay for" is a complete answer. Name the account type too. Free consumer accounts and paid business accounts treat your data differently, and that difference is the thing your policy exists to manage. If you want the plain-language version of that difference, is it safe to upload business documents to AI covers it.

2. What never goes in? This is the heart of the page. Most owners land on the same list: customer names paired with financial, health, or legal details; employee records and pay; passwords and access keys; anything covered by an NDA; unreleased financials; and any document a client marked confidential. What to redact before uploading a document to AI gives you a checklist you can paste straight into the policy.

3. Who checks the output? AI drafts read confidently and sometimes contain a wrong number or an invented detail. The rule is one sentence: a person on your team reads every AI-produced document, quote, or message before it goes to a client.

4. Who do we ask? One named person. In a ten-person company, that is usually you. Employees who know exactly whom to ask are far less likely to guess.

5. Did everyone see it? A signature line at the bottom, dated. It proves the page was shared and gives you a natural date for the next review.

Why a Ban Fails and an Approved List Works

Some owners respond to AI risk by banning it. The numbers say that plan leaks. In a BlackFog survey, 49% of workers reported using AI tools their employer had not sanctioned, and 63% said using them is acceptable when no approved option is provided.[^2] People want the speed. When the only official answer is "no," they use AI quietly on a personal account, which is the outcome with the least oversight.

An approved list turns the same energy into something you can see. Choose two or three tools, say what each one is for, and tell people what to do when they find a new one worth trying. If tool sprawl worries you, how many AI tools does a small business actually need gives a sensible ceiling.

The Verizon 2026 Data Breach Investigations Report, as summarized by security firm defend-id, ranks shadow AI (AI used without formal approval) as the third most common non-malicious insider action found inside breached organizations.[^3] The everyday version looks ordinary: an office manager pastes a list of new hires with Social Security numbers into a free chatbot to draft offer letters faster. Nobody meant harm, and the data still left the building.

What We Found When We Read Ten Small Business AI Policy Templates

We reviewed ten publicly available AI acceptable-use templates written for small businesses and small teams, from law firms, managed IT providers, and security vendors, and tallied which components each one includes.

Component Templates including it
List of data that must never be entered 10 of 10
Approved tools list 7 of 10
Human review of AI output before use 6 of 10
Employee acknowledgment or signature 4 of 10
Incident reporting (what to do after a mistake) 4 of 10

Every template drew the line on data. Fewer than half asked for a signature or told staff what to do after a slip, and those two lines cost the least to write. Several of the templates were built to fit on one to two pages, and the ones that addressed rollout suggested adding the policy to the employee handbook, collecting signatures, and re-acknowledging it each year.

How to Write Your One Page in an Afternoon

Work in this order and you finish before dinner.

Start from what your team already does. Ask each person which AI tools they use and for what. You will likely find more use than you expected. That inventory becomes your approved list, and anything risky on it becomes a conversation.

Write the never-goes-in list in your own industry's words. A contractor's list mentions homeowner addresses and bids. A bookkeeper's mentions client ledgers and tax IDs. Specific examples stick; abstract categories get skimmed.

Add one line about telling clients. Decide now whether you mention AI assistance, and say so in the policy. Most owners settle on: we disclose when a contract requires it or when a client asks. Do you need your client's permission to use AI on their documents walks through the cases where asking first is the right call.

Keep the tone of a colleague. "Please don't paste customer records into free AI tools. Ask me first if you're unsure" carries the same content as three paragraphs of legal phrasing and gets read.

Have an attorney glance at it if you handle regulated data. Healthcare, legal, tax, and financial work carry their own rules. A one-page policy is a floor there.

Turn the Policy Into a Page Your Team Opens

Most policies fail at delivery. A Word file in a shared folder gets signed once and forgotten. Give the same words a design people want to look at: a clear title, the five parts in labeled blocks, the never-goes-in list in a box you can spot from across a room.

That is a job for DocsAura, an AI document design tool. Upload the policy as a DOCX or PDF and it returns a designed page in about two minutes, with the text left as you wrote it. It takes the file you already have and handles the layout. It writes no policy language for you, and that stays with you and your attorney. If you have employee-facing paperwork to organize alongside it, how to use AI to create an employee handbook shows where a policy page fits.

Roll It Out Without a Big Meeting

Fifteen minutes is enough. Show the page, read the never-goes-in list aloud, name who to ask, and collect signatures. Then put two things on the calendar: a check-in after 30 days ("what did you run into?") and a review in six months, because the tools change fast.

Treat the first version as a draft. A page that exists and gets revised beats a perfect page you never finish. If you are still deciding where to begin with AI at all, how to start using AI in your small business is the gentler on-ramp, and the policy is the second thing you do after the first tool.

The Bottom Line

The businesses that get the most from AI tend to be the ones whose people know the rules. A small company with a one-page policy, two approved tools, and a named person to ask is ahead of most: one survey of 211 respondents at 202 Northern Ireland organizations found 83% already use AI and 73% have no formal AI policy.[^4]

Write yours this week. Once it exists, try DocsAura, an AI document design tool, on that single file: drop in the one document you already have, see what comes back in about two minutes, and decide for yourself. There is nothing to set up and nothing to maintain afterward. Try it with one document.

[^1]: Founder Reports 2026 survey of 2,000+ U.S. workers, as reported by defend-id: https://blog.defend-id.com/2026/07/15/employee-ai-use-policy [^2]: BlackFog, "Shadow AI Statistics Every Security Leader Should Know In 2026": https://www.blackfog.com/shadow-ai-statistics [^3]: Verizon 2026 Data Breach Investigations Report, as summarized by defend-id: https://blog.defend-id.com/2026/07/15/employee-ai-use-policy [^4]: Galvia Digital and Belfast Chamber survey, "NI businesses embrace AI but 73% still operate without a formal AI policy": https://belfastchamber.com/ni-businesses-embrace-ai-but-73-still-operate-without-a-formal-ai-policy

Turn voice notes and screenshots into beautiful documents.

Status updates, proposals, case studies, SOPs — generated in minutes, not hours.

Try DocsAura Free
Published on September 29, 2026.
Dominik Szafrański
Dominik Szafrański
Founder

After years of freelancer and agency work—spending countless hours on proposals, case studies, and client documentation—Dominik decided to build a tool that helps agencies and freelancers create professional client documents in minutes, not hours.