What people use this for
- Getting a first AI policy in place before something goes wrong
- Answering a client or insurer asking whether you have one
- Giving a team a clear answer to "am I allowed to paste this in?"
- Starting the internal conversation with a draft instead of a blank page
Most small businesses do not have an AI policy, and the reason is almost never that they do not care. It is that the page is blank and the topic is large, so it stays on the list. Meanwhile the team is already using AI, quietly, on personal accounts, with no shared idea of what is allowed. The generator above produces a first version in a couple of minutes — and a circulated first version beats a perfect one nobody wrote.
Why a small business needs one at all
A policy is not paperwork for its own sake. It answers a question your team is currently answering individually, inconsistently, and usually without telling you: can I paste this into an AI tool? Right now some of them are guessing conservatively and losing the benefit, and some are guessing liberally and creating exposure. Neither of them is wrong, because nobody told them.
What having one actually changes:
- People stop guessing about client data, which is where the real risk sits
- You can answer a client, an insurer, or a tender question in one line
- "Shadow AI" on personal accounts becomes visible rather than hidden
- Someone owns the question, so new tools get assessed instead of appearing
- When something does go wrong, there is a route that is not concealment
The five decisions that make up a policy
Strip away the formatting and every AI policy is the same five decisions. The generator asks them directly rather than burying them, because these are the ones you need to have actually made — the document is just where the answers get written down.
What can go in
The clause that does most of the work. Nearly every AI incident at a small business is a data-handling incident, not a model failure — someone pasted something they should not have, into a tool nobody had checked.
Who checks what comes out
Models are fluent when they are wrong, which is precisely why "someone will notice" is not a control. Write down who reads it before it goes anywhere, and what they are verifying.
Whether you tell people
Clients increasingly ask. The position you take matters less than being able to answer immediately and consistently when they do.
Whether the tool trains on your data
Consumer tiers frequently train on what you type; business tiers generally do not, and put it in the contract. This is a settings question with a legal answer, and it is worth ten minutes to check.
Which accounts are allowed
Personal accounts used for company work are the most common way a policy gets bypassed without anyone deciding to bypass it. Provision what people need, and they will not route around you.
What separates a policy people follow from one they ignore
Gets followed
- One page, in the language people actually use
- States what you may do, not only what you may not
- Names a person to ask when a case is not covered
- Provides the approved tools rather than only prohibiting others
- Makes reporting a mistake safe and fast
Gets ignored
- Eight pages of legal boilerplate nobody finishes
- Bans without alternatives, so people work around it
- No owner, so unanswered questions become precedent
- Written once and never revisited as tools change
- Punishes disclosure, which guarantees you find out last
Getting it adopted
The document is the easy part. Adoption is where these fail.
Circulate it as a draft, not a decree
Ask for objections. The objections are informative — they tell you what people are already doing, which is usually the thing you most needed to know.
Walk through three real examples
A client email, a spreadsheet of customer data, a job posting. Abstract rules do not transfer; worked examples do, and the disagreements surface immediately.
Provision the approved tools that week
Do not leave a gap between "stop using that" and "use this instead". The gap is where workarounds get established, and they are hard to undo.
Put a review date on it
Six months. The tools change faster than most policies do, and a policy that has visibly not been looked at in two years stops being taken seriously.
Does a small business really need an AI usage policy?
If anyone on your team uses AI for work, yes — and they almost certainly do, whether or not it has been discussed. The policy is not about controlling people; it is about answering "can I paste this in?" once and consistently, rather than having every person answer it differently. One page is enough for most businesses.
What should an AI usage policy include?
Five things: what data may be put into AI tools, who reviews output before it is used, whether AI use is disclosed to clients, whether tools may train on your inputs, and which accounts are permitted. Add a named owner and a review date. Anything beyond that is elaboration, and elaboration is what stops policies being read.
Can I use AI with client data?
It depends on your contracts, your regulator, and the tool's terms. Business and enterprise tiers generally do not train on your inputs and will say so contractually; consumer tiers often do. Check your client agreements for confidentiality clauses that cover disclosure to third-party processors, and check whether your sector restricts it specifically. If you are handling health, financial, or legal records, get advice rather than a template.
Is this policy legally binding or reviewed by a lawyer?
No. It is a template written to be a good, honest first version — the one that gets circulated and argued with. It is not legal advice and it is not a substitute for a lawyer where you are regulated or handling personal data at scale. Most small businesses are considerably better off with this than with the nothing they have now, and should still have a professional review it if the stakes warrant it.
How often should an AI policy be reviewed?
Every six months, and immediately whenever you adopt a new tool or a client imposes a restriction. The pace of change in AI tooling makes an annual cycle too slow — capabilities, pricing tiers, and data-handling terms all shift inside a year.
Is my information sent anywhere when I use this generator?
No. The document is assembled entirely in your browser. Nothing is submitted, stored, or transmitted — this site is static and has no server to receive it. There is no email gate, no account, and no copy of your answers anywhere but your own machine.
The short version
- Your team is already using AI. The only question is whether they know what is allowed.
- Every policy is five decisions: what goes in, who checks output, whether you disclose, training settings, and which accounts.
- One readable page beats eight pages of boilerplate, every time.
- Banning a tool without providing an alternative moves the activity out of sight rather than stopping it.
- Name an owner and a review date, or it becomes a document nobody has read since it was written.
