Generators

AI Usage Policy Generator

Answer seven questions and leave with a policy you can circulate today.

Free · no signup Reviewed yearly

Used in the document. Never sent anywhere.

A role, not a name — roles survive turnover. A policy with no owner is a suggestion.

What can go into an AI tool?

The clause that does most of the work. Almost every AI incident at a small business is a data-handling incident.

Who checks the output?

AI is confidently wrong often enough that "someone read it" has to be written down, not assumed.

Does AI use get disclosed?

The clause clients ask about. Being able to answer it quickly is worth more than the position you take.

Training on your data

Consumer tiers often train on what you type. Business tiers usually do not. This is a settings question with a contractual answer.

Which accounts may be used?

Shadow AI — personal accounts used for work — is the most common way a policy gets quietly bypassed.

Anything else to cover?

Add only what applies. A policy nobody finishes reading is not one.

Your policy
AI USAGE POLICY — YOUR ORGANISATION

This policy covers how everyone at Your organisation uses AI tools for work: large language
models, AI assistants, and AI features built into software we already run. It applies
to everyone, including contractors and anyone working on our behalf.

The principle behind all of it: AI is a tool, and the person using it is accountable
for what comes out. Nothing below changes who is responsible for the work.

──────────────────────────────────────────────────────────────────────

WHAT YOU MAY PUT INTO AN AI TOOL

Do not put client information, personal data, financial records, credentials, or anything covered by a confidentiality agreement into an AI tool. Public information and your own draft writing are fine. If you are unsure whether something counts, it counts — ask before you paste.

CHECKING THE OUTPUT

Every piece of AI-assisted work is read end to end by the person responsible for it before it goes anywhere — internally or externally. Facts, figures, names, dates, quotations, and citations are verified against a source, not accepted because they look right. The reviewer owns the output as if they had written it themselves, because as far as anyone receiving it is concerned, they did.

TELLING PEOPLE

We tell clients when AI has been used materially in work delivered to them. "Materially" means it shaped the substance — drafted the analysis, produced the copy, generated the code — not that it fixed the spelling. Where a client has asked us not to use AI on their work, we do not.

TOOL SETTINGS

Approved tools must be configured so that our inputs are not used to train the provider's models, and we use business or enterprise tiers where that is what makes the guarantee contractual. Free and personal accounts are not used for company work. Anyone setting up a new tool confirms this setting before the first real task goes through it.

ACCOUNTS AND ACCESS

Company work goes through company-provisioned accounts. Personal AI accounts are not used for company work, and company material is not put into them. If a tool you need is not provisioned, ask for it rather than working around it — a request we can approve is far better than a workaround we cannot see.

WHEN SOMETHING GOES WRONG

If confidential information is entered into a tool it should not have been, or AI-generated material containing an error reaches a client, tell the policy owner the same day. There is no penalty for reporting quickly and honestly; there is one for concealment. Speed is what limits the damage, and people only move fast when they are not afraid of the conversation.

QUESTIONS AND CHANGES

[NAME A ROLE HERE] owns this policy. Ask them if a situation is not covered
here — an unanswered question is how policies get quietly ignored. This policy is
reviewed every six months, because the tools change faster than most policies do.

──────────────────────────────────────────────────────────────────────

Owner: [NAME A ROLE HERE]
Review: every six months

Generated with the AI policy generator at https://tekstudio.ai/tools/ai-policy-generator

Starting point This is a template, not legal advice, and it is not a substitute for a lawyer where you are regulated or handling personal data at scale. It is written to be a good first version — the one that gets circulated and argued with, which is worth considerably more than the perfect one that never gets written. Edit it to match how your business actually works.

What people use this for

  • Getting a first AI policy in place before something goes wrong
  • Answering a client or insurer asking whether you have one
  • Giving a team a clear answer to "am I allowed to paste this in?"
  • Starting the internal conversation with a draft instead of a blank page

Most small businesses do not have an AI policy, and the reason is almost never that they do not care. It is that the page is blank and the topic is large, so it stays on the list. Meanwhile the team is already using AI, quietly, on personal accounts, with no shared idea of what is allowed. The generator above produces a first version in a couple of minutes — and a circulated first version beats a perfect one nobody wrote.

Why a small business needs one at all

A policy is not paperwork for its own sake. It answers a question your team is currently answering individually, inconsistently, and usually without telling you: can I paste this into an AI tool? Right now some of them are guessing conservatively and losing the benefit, and some are guessing liberally and creating exposure. Neither of them is wrong, because nobody told them.

What having one actually changes:

  • People stop guessing about client data, which is where the real risk sits
  • You can answer a client, an insurer, or a tender question in one line
  • "Shadow AI" on personal accounts becomes visible rather than hidden
  • Someone owns the question, so new tools get assessed instead of appearing
  • When something does go wrong, there is a route that is not concealment

The five decisions that make up a policy

Strip away the formatting and every AI policy is the same five decisions. The generator asks them directly rather than burying them, because these are the ones you need to have actually made — the document is just where the answers get written down.

  1. What can go in

    The clause that does most of the work. Nearly every AI incident at a small business is a data-handling incident, not a model failure — someone pasted something they should not have, into a tool nobody had checked.

  2. Who checks what comes out

    Models are fluent when they are wrong, which is precisely why "someone will notice" is not a control. Write down who reads it before it goes anywhere, and what they are verifying.

  3. Whether you tell people

    Clients increasingly ask. The position you take matters less than being able to answer immediately and consistently when they do.

  4. Whether the tool trains on your data

    Consumer tiers frequently train on what you type; business tiers generally do not, and put it in the contract. This is a settings question with a legal answer, and it is worth ten minutes to check.

  5. Which accounts are allowed

    Personal accounts used for company work are the most common way a policy gets bypassed without anyone deciding to bypass it. Provision what people need, and they will not route around you.

What separates a policy people follow from one they ignore

Gets followed

  • One page, in the language people actually use
  • States what you may do, not only what you may not
  • Names a person to ask when a case is not covered
  • Provides the approved tools rather than only prohibiting others
  • Makes reporting a mistake safe and fast

Gets ignored

  • Eight pages of legal boilerplate nobody finishes
  • Bans without alternatives, so people work around it
  • No owner, so unanswered questions become precedent
  • Written once and never revisited as tools change
  • Punishes disclosure, which guarantees you find out last
The provisioning point is the important oneA policy that forbids personal accounts without providing company ones does not stop anybody — it just moves the activity somewhere you cannot see it. If you ban a tool people find genuinely useful, provide the sanctioned equivalent in the same week, or you have written a document that makes your exposure worse while appearing to reduce it.

Getting it adopted

The document is the easy part. Adoption is where these fail.

  1. Circulate it as a draft, not a decree

    Ask for objections. The objections are informative — they tell you what people are already doing, which is usually the thing you most needed to know.

  2. Walk through three real examples

    A client email, a spreadsheet of customer data, a job posting. Abstract rules do not transfer; worked examples do, and the disagreements surface immediately.

  3. Provision the approved tools that week

    Do not leave a gap between "stop using that" and "use this instead". The gap is where workarounds get established, and they are hard to undo.

  4. Put a review date on it

    Six months. The tools change faster than most policies do, and a policy that has visibly not been looked at in two years stops being taken seriously.

Does a small business really need an AI usage policy?

If anyone on your team uses AI for work, yes — and they almost certainly do, whether or not it has been discussed. The policy is not about controlling people; it is about answering "can I paste this in?" once and consistently, rather than having every person answer it differently. One page is enough for most businesses.

What should an AI usage policy include?

Five things: what data may be put into AI tools, who reviews output before it is used, whether AI use is disclosed to clients, whether tools may train on your inputs, and which accounts are permitted. Add a named owner and a review date. Anything beyond that is elaboration, and elaboration is what stops policies being read.

Can I use AI with client data?

It depends on your contracts, your regulator, and the tool's terms. Business and enterprise tiers generally do not train on your inputs and will say so contractually; consumer tiers often do. Check your client agreements for confidentiality clauses that cover disclosure to third-party processors, and check whether your sector restricts it specifically. If you are handling health, financial, or legal records, get advice rather than a template.

Is this policy legally binding or reviewed by a lawyer?

No. It is a template written to be a good, honest first version — the one that gets circulated and argued with. It is not legal advice and it is not a substitute for a lawyer where you are regulated or handling personal data at scale. Most small businesses are considerably better off with this than with the nothing they have now, and should still have a professional review it if the stakes warrant it.

How often should an AI policy be reviewed?

Every six months, and immediately whenever you adopt a new tool or a client imposes a restriction. The pace of change in AI tooling makes an annual cycle too slow — capabilities, pricing tiers, and data-handling terms all shift inside a year.

Is my information sent anywhere when I use this generator?

No. The document is assembled entirely in your browser. Nothing is submitted, stored, or transmitted — this site is static and has no server to receive it. There is no email gate, no account, and no copy of your answers anywhere but your own machine.

The short version

  • Your team is already using AI. The only question is whether they know what is allowed.
  • Every policy is five decisions: what goes in, who checks output, whether you disclose, training settings, and which accounts.
  • One readable page beats eight pages of boilerplate, every time.
  • Banning a tool without providing an alternative moves the activity out of sight rather than stopping it.
  • Name an owner and a review date, or it becomes a document nobody has read since it was written.