AI policy · practical guide
A practical AI policy checklist for a small business.
An AI policy does not need to be a heavy legal document. It should help people make good decisions when they use AI, protect information and know when to stop and ask.
Why have a policy at all?
Most businesses already have people experimenting with AI. The risk is rarely that someone uses it; it is that each person makes up their own rules about confidential information, customer communication and accuracy.
A proportionate policy gives the team permission to use AI where it helps, while setting boundaries that keep the business and its customers protected.
The six decisions to make first
You can create a useful first version by answering these practical questions.
- Which tools are approved for business use, and who can approve a new one?
- What information must never go into an AI tool — for example customer data, passwords, financial details or confidential contracts?
- Which tasks may AI assist with, and which require a human to do the work or approve the result?
- How should staff check facts, calculations, legal claims and customer-facing content?
- When should people tell a customer that AI has been used?
- Who should be contacted if an output looks wrong, biased, unsafe or exposes information?
Keep the policy usable
A policy that is too long will be ignored. A short set of plain-English rules, paired with a simple list of approved tools, is often a far better starting point.
Use examples from the work people actually do. For example: ‘You may use an approved tool to draft an internal meeting summary, but do not paste customer names or sensitive details into a public AI tool.’
Make human checking explicit
AI can sound convincing when it is wrong. Any output that affects a customer, a contract, pricing, compliance, recruitment or a meaningful business decision should be checked by someone who understands the subject.
The aim is not to slow everything down. It is to match the level of checking to the potential impact if the answer is wrong.
Review it as your use changes
Set a date to revisit the policy after the first few months. You will learn which tools are genuinely useful, where people get stuck and what new risks or opportunities have appeared.
If your business handles sensitive personal data, regulated decisions or high-risk use cases, take specialist legal, data-protection or security advice before relying on AI.