AI Policy Starter Guide
Once staff are using AI tools — and in most businesses they already are — the rules need writing down. A short, plain-English AI policy tells everyone which tools are approved, what data must stay out of prompts, and who to ask when something is unclear. This guide walks through the decisions to make first, gives you a section-by-section structure to write from, and explains how to roll the policy out so it is actually read and followed. You do not need a lawyer or a twenty-page document to start.
An AI policy is not a legal document to frighten staff — it is a short set of working rules that makes the safe way of using AI the obvious way. The businesses that get this right keep the policy to one or two pages, write it in the language their staff actually use, and treat it as a living document that changes as the tools change.
Why write it down at all?
- Staff are almost certainly using AI already — a policy replaces guesswork with clear expectations.
- Without written rules, every member of staff invents their own, and the riskiest habits spread quietest.
- Customers, insurers and larger clients increasingly ask whether you have an AI policy.
- A written policy protects staff too: nobody gets blamed for breaking a rule that was never stated.
- It is far easier to update a short document than to correct habits that formed in a vacuum.
Step 1: Decide who owns the policy
Every policy needs a named owner — a person, not a committee. In a small business this is usually the owner, a director or an office manager. The owner keeps the approved tool list current, answers day-to-day questions, receives reports when something goes wrong, and triggers the periodic review. Name them in the policy itself.
Step 2: Make the six core decisions
Most of the writing is easy once these decisions are made. Discuss them with whoever helps run the business before drafting anything.
| Decision | Question to answer |
|---|---|
| Approved tools | Which AI tools and accounts may staff use, and for what work? |
| Data boundaries | Which categories of data must never be entered into an AI tool? |
| Acceptable use | What is AI encouraged for, allowed with care, and not acceptable for? |
| Checking | What must be verified, and by whom, before AI output is used or sent? |
| Disclosure | When do customers, clients or colleagues need to know AI was involved? |
| Mistakes | How are errors and near-misses reported, and what happens when they are? |
Step 3: Write from this structure
The sections below make a complete starter policy. Write one short paragraph or a handful of bullet points under each heading — if a section runs past half a page, it is probably trying to do too much.
- Purpose — one or two sentences on why the policy exists: to help staff use AI well, not to ban it.
- Who it applies to — usually all staff and contractors, on any device used for work.
- Approved tools — the named tools and accounts staff may use, and how to request a new one.
- Data rules — the categories that never go into a prompt: customer personal data, employee and HR data, passwords and security details, contracts and pricing.
- Acceptable use — what AI is encouraged for, what needs care, and what it must not be used for.
- Checking outputs — every AI answer is a draft; facts, figures and links are verified before use, with specialist review for legal, financial, HR or safety content.
- Disclosure — when AI assistance is declared, and a reminder to check client contracts for AI restrictions.
- Reporting mistakes — who to tell, the same-day rule for data entered in error, and the promise that honest reports are safe.
- Ownership and review — the named owner and the next review date.
Borrow the rules you have already seen
The data rules, acceptable-use table and checking habits in our staff-facing guide slot straight into the matching policy sections — you do not need to invent them from scratch:
Step 4: Keep the language plain
- Write rules staff can repeat from memory: 'no customer data in prompts' beats a paragraph of qualifications.
- Prefer 'never', 'always' and 'ask first' over 'where appropriate' and 'in general'.
- Give one concrete example per rule — examples are what people remember.
- Avoid vendor names in the rules themselves; keep the tool list separate so it can change without rewriting the policy.
- If a sentence needs reading twice, rewrite it.
Step 5: Roll it out properly
A policy emailed as an attachment is a policy unread. Introduce it in a short team conversation: explain the reasoning, walk through the rules, and invite questions — especially about the tools people are already using. Then ask each person to confirm they have read and understood it, and keep a simple record of who has.
Step 6: Review it regularly
- Put a review date in the policy — every three to six months suits most small businesses.
- Review sooner when a new tool is adopted, an AI feature appears in software you already use, or a mistake exposes a gap.
- Treat repeated questions from staff as a sign a rule needs rewording, not that staff need reminding.
- Date each version so everyone knows they are reading the current one.
Common mistakes to avoid
- Banning AI outright — staff use it anyway, just without telling you.
- Copying a long corporate template that nobody reads or follows.
- Writing rules for specific products that are out of date within months.
- Publishing the policy without a named owner to answer questions.
- Treating the first version as final — the first version is a starting point.
Plain-English Takeaway
A good small-business AI policy is one to two pages, written in plain English, with a named owner. Decide the approved tools, data boundaries, acceptable uses, checking habits, disclosure rules and reporting route first — then write short sections, introduce the policy in person, and review it every few months.
Downloadable guide
Download the AI Policy Starter Template
A printable one-page worksheet with the six core decisions and the section-by-section structure, ready to fill in as you draft your policy.
Download PDFFree download. No email address required.
Related Knowledge Centre resources
Safe Use of Generative AI at Work
Simple rules to help staff use AI tools without exposing business or customer data.
View guideAI Readiness Checklist
Check whether your business is ready to adopt AI tools safely and usefully.
View guideAI Answer Verification Checklist
Check factual claims, sources, assumptions and approval before using or publishing an AI-generated answer.
View guideQuestions to Ask Before Buying an AI Tool
The practical questions that separate useful AI tools from expensive experiments.
View guide