// Blog / Guide

Writing an AI acceptable-use policy for your team

Share

Your team is already using AI, whether or not you have said they can. Someone is pasting a client email into a chatbot to draft a reply; someone else is using it to clean up a spreadsheet. That is mostly a good thing, but with no ground rules it is also how sensitive information quietly leaks. An acceptable-use policy fixes that, and it does not need to be a legal document. One clear page that people actually read beats ten pages nobody opens.

Why one page, not ten

The goal of an AI policy is behaviour, not paperwork. A long policy signals "cover the company" and gets filed and forgotten; a short, plain one signals "here is how we use this well" and gets followed. Aim for a single page a new hire can absorb in five minutes. If a rule does not change what someone actually does on a Tuesday afternoon, it does not belong in the small business version.

The one rule that matters most

If your policy says only one thing, make it this: never paste sensitive or confidential information into a public, consumer AI tool. Client personal data, financial details, contracts, passwords, or anything you would not want to leak should not go into a free personal account, because on those tiers your inputs can be retained and used to train the model. The fix is to give the team an approved tool on a business tier (for example Copilot inside a paid Microsoft 365 plan) where the provider commits not to train on your data, as our AI data privacy guide explains. Get this one rule understood and most of the risk disappears.

What a good one-pager covers

  • What AI is for here. A short, encouraging line: we use AI to work faster on drafting, summarising, and research, and we treat its output as a draft to check, not a final answer.
  • Which tools are approved. Name the ones you have blessed and, briefly, why. This stops "shadow AI," where people quietly use random free tools you have never vetted.
  • The data rule. The line above: what must never go into a public tool, stated plainly with a couple of concrete examples.
  • Always verify. AI can state something false with total confidence. Nobody sends AI output to a client, or acts on a number it produced, without a human check.
  • Be transparent where it counts. If AI meaningfully drafts something a customer relies on, or you use it in a decision about a person, be honest about it. This is where the coming rules are heading.
  • Who to ask. One named person to approve a new tool or answer a question. That single line prevents most freelancing.

Make it easy to follow

A policy only works if the right thing is also the easy thing. If you tell people not to use free tools, give them a good approved one, or they will quietly go back to the free one. Walk the team through the page once rather than emailing it into the void, and revisit it when your tools change. The point is a shared understanding, not a signature on file.

Where the policy fits

An acceptable-use policy is the day-to-day, staff-facing layer. If you grow into needing more structure, an inventory of where AI is used, a way to review new use cases, a light risk process, that is a full AI governance program, and this one-pager becomes its front door. For most small businesses, though, the page is enough to start, and starting is what matters.

Want a one-page AI policy that fits how your team really works?

Talk to us

Related