Knowledge Centre
AI GuidesGuide and Template

AI Policy Starter Guide

8 minutes to completeEvergreen guide — kept up to date

Once staff are using AI tools — and in most businesses they already are — the rules need writing down. A short, plain-English AI policy tells everyone which tools are approved, what data must stay out of prompts, and who to ask when something is unclear. This guide walks through the decisions to make first, gives you a section-by-section structure to write from, and explains how to roll the policy out so it is actually read and followed. You do not need a lawyer or a twenty-page document to start.

An AI policy is not a legal document to frighten staff — it is a short set of working rules that makes the safe way of using AI the obvious way. The businesses that get this right keep the policy to one or two pages, write it in the language their staff actually use, and treat it as a living document that changes as the tools change.

Why write it down at all?

  • Staff are almost certainly using AI already — a policy replaces guesswork with clear expectations.
  • Without written rules, every member of staff invents their own, and the riskiest habits spread quietest.
  • Customers, insurers and larger clients increasingly ask whether you have an AI policy.
  • A written policy protects staff too: nobody gets blamed for breaking a rule that was never stated.
  • It is far easier to update a short document than to correct habits that formed in a vacuum.

Step 1: Decide who owns the policy

Every policy needs a named owner — a person, not a committee. In a small business this is usually the owner, a director or an office manager. The owner keeps the approved tool list current, answers day-to-day questions, receives reports when something goes wrong, and triggers the periodic review. Name them in the policy itself.

Step 2: Make the six core decisions

Most of the writing is easy once these decisions are made. Discuss them with whoever helps run the business before drafting anything.

DecisionQuestion to answer
Approved toolsWhich AI tools and accounts may staff use, and for what work?
Data boundariesWhich categories of data must never be entered into an AI tool?
Acceptable useWhat is AI encouraged for, allowed with care, and not acceptable for?
CheckingWhat must be verified, and by whom, before AI output is used or sent?
DisclosureWhen do customers, clients or colleagues need to know AI was involved?
MistakesHow are errors and near-misses reported, and what happens when they are?

Step 3: Write from this structure

The sections below make a complete starter policy. Write one short paragraph or a handful of bullet points under each heading — if a section runs past half a page, it is probably trying to do too much.

  • Purpose — one or two sentences on why the policy exists: to help staff use AI well, not to ban it.
  • Who it applies to — usually all staff and contractors, on any device used for work.
  • Approved tools — the named tools and accounts staff may use, and how to request a new one.
  • Data rules — the categories that never go into a prompt: customer personal data, employee and HR data, passwords and security details, contracts and pricing.
  • Acceptable use — what AI is encouraged for, what needs care, and what it must not be used for.
  • Checking outputs — every AI answer is a draft; facts, figures and links are verified before use, with specialist review for legal, financial, HR or safety content.
  • Disclosure — when AI assistance is declared, and a reminder to check client contracts for AI restrictions.
  • Reporting mistakes — who to tell, the same-day rule for data entered in error, and the promise that honest reports are safe.
  • Ownership and review — the named owner and the next review date.

Borrow the rules you have already seen

The data rules, acceptable-use table and checking habits in our staff-facing guide slot straight into the matching policy sections — you do not need to invent them from scratch:

Safe Use of Generative AI at Work

Step 4: Keep the language plain

  • Write rules staff can repeat from memory: 'no customer data in prompts' beats a paragraph of qualifications.
  • Prefer 'never', 'always' and 'ask first' over 'where appropriate' and 'in general'.
  • Give one concrete example per rule — examples are what people remember.
  • Avoid vendor names in the rules themselves; keep the tool list separate so it can change without rewriting the policy.
  • If a sentence needs reading twice, rewrite it.

Step 5: Roll it out properly

A policy emailed as an attachment is a policy unread. Introduce it in a short team conversation: explain the reasoning, walk through the rules, and invite questions — especially about the tools people are already using. Then ask each person to confirm they have read and understood it, and keep a simple record of who has.

Step 6: Review it regularly

  • Put a review date in the policy — every three to six months suits most small businesses.
  • Review sooner when a new tool is adopted, an AI feature appears in software you already use, or a mistake exposes a gap.
  • Treat repeated questions from staff as a sign a rule needs rewording, not that staff need reminding.
  • Date each version so everyone knows they are reading the current one.

Common mistakes to avoid

  • Banning AI outright — staff use it anyway, just without telling you.
  • Copying a long corporate template that nobody reads or follows.
  • Writing rules for specific products that are out of date within months.
  • Publishing the policy without a named owner to answer questions.
  • Treating the first version as final — the first version is a starting point.

Plain-English Takeaway

A good small-business AI policy is one to two pages, written in plain English, with a named owner. Decide the approved tools, data boundaries, acceptable uses, checking habits, disclosure rules and reporting route first — then write short sections, introduce the policy in person, and review it every few months.

Downloadable guide

Download the AI Policy Starter Template

A printable one-page worksheet with the six core decisions and the section-by-section structure, ready to fill in as you draft your policy.

Download PDF

Free download. No email address required.

Still unsure what applies to your business?

Ask the IT Club Advisor about Microsoft 365, browsers, cyber security, productivity or any everyday technology problem.

Ask Your IT Question

Free to ask. No credit card. No sales pressure. Fair usage applies.