Guide · AI governance
AI acceptable use policy template for small businesses
A plain-English, copy-pasteable AI policy. Covers approved tools, data privacy, and when a human has to review AI output. Written for teams under 100 people — no legalese, no filler.
Why you need one
Without a written policy, employees paste customer data, contracts, and source code into public AI tools by default. That's a data-leak incident waiting to happen, and most cyber-insurance policies now ask about your AI usage rules. A short, clear document beats a 40-page one nobody reads.
The template (copy & paste)
Replace [Company Name], [Approver], and the tool list to fit your organization.
AI ACCEPTABLE USE POLICY — [Company Name]
Effective: [Date] · Owner: [Approver] · Review cadence: every 6 months
1. PURPOSE
This policy sets the rules for using AI tools (LLMs, image/audio/video
generators, coding assistants, and any product that uses them) at
[Company Name]. Goals: protect customer data, meet our legal
obligations, and ship high-quality work.
2. WHO THIS APPLIES TO
All employees, contractors, and interns — on company devices, personal
devices used for work, and any account tied to a company email.
3. APPROVED TOOLS
You may use:
• [ChatGPT Team / Enterprise]
• [Claude for Work]
• [GitHub Copilot Business]
• [Add others here]
Any tool not on this list requires written approval from [Approver]
before use. Free/consumer tiers of the above are NOT approved for
work data — use the paid business tier only.
4. PROHIBITED DATA
Never paste, upload, or type the following into any AI tool:
• Customer PII (names + emails, phone numbers, addresses, IDs)
• Payment or banking details
• Passwords, API keys, tokens, or credentials
• Health information
• Signed contracts, NDAs, or unreleased financial data
• Proprietary source code (unless in an approved coding assistant)
• Anything covered by an NDA with a third party
If you're not sure, ask [Approver] before sending it.
5. HUMAN-IN-THE-LOOP REVIEW
AI output must be reviewed by a qualified human before:
• It is sent to a customer, prospect, or partner
• It is published on the website, social media, or a press release
• It is used to make a hiring, firing, pricing, or legal decision
• It is committed to a production code repository
• It is used as evidence in a regulated report
The reviewer is responsible for accuracy, tone, and legal risk. "The
AI wrote it" is not a defense.
6. TRANSPARENCY
Disclose AI use when a customer would reasonably expect a human
(support chats, personalized proposals, hiring communications).
Don't claim AI-generated content is original human work when asked
directly.
7. INTELLECTUAL PROPERTY
• Assume AI-generated text and images may not be copyrightable.
• Do not upload third-party copyrighted work (books, articles,
proprietary code) to train or fine-tune models without a license.
• Code suggestions must be reviewed for license contamination
before merging.
8. SECURITY
• Use SSO where available; never share AI tool accounts.
• Enable chat history opt-out or zero-retention settings on all
approved tools where offered.
• Report a suspected data leak to [Security Contact] within 24 hours.
9. NEW TOOL APPROVAL PROCESS
To request a new AI tool:
1. Email [Approver] with the tool name, vendor, and use case.
2. Include the vendor's data-processing addendum and security page.
3. Wait for written approval before signing up or paying.
Typical turnaround: 5 business days.
10. VIOLATIONS
First violation: written warning and mandatory retraining.
Repeat or severe violations (leaking customer data, ignoring human
review on customer output): up to and including termination.
11. QUESTIONS
Direct questions to [Approver] at [email].
Acknowledged by: ______________________ Date: ____________How to roll it out in a week
- Day 1: Fill in the blanks. Pick one owner (usually the ops lead or CTO) as [Approver].
- Day 2: Confirm your approved tool list is on business/enterprise tiers with data-retention controls enabled.
- Day 3–4: Share with leadership for a quick read. Cut anything that doesn't apply to your team.
- Day 5: Send to the whole team with a 15-minute walkthrough. Require an acknowledgement signature.
- Ongoing: Re-review every 6 months, or the same day you approve any new AI tool.
Common mistakes to avoid
- Banning AI entirely. Staff use it anyway, on personal accounts, with no visibility. Approve a safe tool instead.
- Copy-pasting a Fortune 500 policy. Enterprise policies assume a legal team you don't have. Keep it under two pages.
- No approval process. If there's no way to request a new tool, "shadow AI" fills the gap.
- Skipping human review on customer output. One hallucinated fact in a proposal can lose a contract.
FAQ
Does a small business really need an AI policy?
Yes. Even a two-page policy protects customer data, sets expectations, and satisfies most vendor and insurance questionnaires. Without one, employees will paste sensitive data into public AI tools by default.
What should an AI acceptable use policy include?
At minimum: approved tools, prohibited data, a tool-approval process, human-review requirements for customer-facing output, and consequences for violations.
How often should we update the policy?
Every 6 months, and whenever a new tool is approved, a new law takes effect, or an incident occurs.