Skip to content
AI Board

Blog

AI policy example: a two-page policy for a small business

A copyable AI policy: which tools are allowed, which data stays out, who decides and how answers get checked. Two pages, written for small businesses.

By , founder of AI Board · ·

An AI policy settles four things: which AI tools your team uses, what data may go in, who decides, and how answers get checked. Below is a complete two-page example for a small business, ready to copy.

This piece is part of the guide how to implement AI in your business.

Why you need an AI policy

Your team probably uses AI already, with or without rules. Without a policy, every employee decides alone what goes into a chatbot. That is not bad intent. It is a gap in the rules.

There is also a legal side, and it depends on where you work. If your business uses AI in the EU, Article 4 of the EU AI Act has applied since 2 February 2025.

It requires providers and deployers of AI systems to "take measures to support the development of AI literacy of their staff". The law does not say which measures. A written policy is the simplest one to show.

Ordinary chatbots count. The European Commission says Article 4 applies when employees use ChatGPT for advertising copy or translation. Staff should then know the specific risks, such as hallucination.

Outside the EU? Article 2 also covers deployers elsewhere whose AI output is used in the EU. If you only use AI and none of that output reaches the EU, the AI Act does not apply.

Your own privacy and employment rules still do, and a policy remains the easiest way to show you took care. This article is not legal advice. If you are unsure about your situation, have a lawyer review the policy.

The example policy (copy it)

Below is the full policy, in nine articles. Fill in the text in [square brackets] yourself. If a rule does not fit your business, delete it.

The example assumes one approved business AI tool and no personal accounts for work. That is a defensible starting point. The next section shows how to adjust it.

AI policy of [Company name]

Version [1.0], adopted on [date] by [management]. Owner: [name, role].

Article 1. Purpose and scope

1.1 This policy sets out how we use AI tools in our work. The aim is to save time with AI without harming customers, colleagues or the company.

1.2 It applies to everyone who works for [Company name]: employees, interns, temporary staff and freelancers.

1.3 An AI tool is software that produces text, images, code or analysis. AI features inside software we already use count too, such as in email or accounting.

Article 2. Approved tools

2.1 For work, you only use these tools:

  • [Tool 1, business account] for [for example drafting, summaries and translation];
  • [Tool 2] for [tasks].

2.2 Want to use another tool? Ask the owner first. The owner decides within [five working days] and updates the list.

2.3 A tool is only added when we know where entered data is stored and whether the vendor trains on it. We must also be able to have it deleted.

Article 3. Data that never goes into an AI tool

3.1 Do not enter the following, unless the owner has approved a tool for it in writing:

  • personal data of customers, colleagues or applicants, such as names, addresses, ID numbers, health data or reviews;
  • customer contracts, quotes and anything covered by a confidentiality agreement;
  • non-public figures, such as revenue, margins, salaries and forecasts;
  • [add your own, for example source code, drawings or formulas].

3.2 Passwords, access codes, API keys and other credentials never go into an AI tool, not even an approved one.

3.3 Remove names and identifying details before you enter text. If the person is still recognisable, 3.1 applies.

3.4 In doubt? Do not enter it, and ask first.

Article 4. Business and personal accounts

4.1 For work, you only use a business account that [Company name] has set up.

4.2 You do not use a personal account for work, free or paid. The company has no agreement with that vendor about what happens to your input.

4.3 For every business account, the owner records whether the vendor trains on our data. The owner also records where the agreements are kept, such as the data processing agreement.

4.4 When someone leaves or changes role, [name or team] revokes access within [one working day].

Article 5. Checking and citing sources

5.1 AI can be wrong with great confidence. You remain responsible for everything you make with AI.

5.2 Check facts, figures, names and legal points against the source before you use them.

5.3 Does a text or analysis go to a customer, or support a decision? Then note which source the answer rests on. If the tool gives no source, look it up yourself.

5.4 Decisions about people, such as hiring, reviews or dismissal, are never made on AI alone. A person decides and can explain the decision.

Article 6. Responsibility and ownership

6.1 The owner of this policy is [name, role]. The owner keeps the tool list, answers questions and decides on exceptions.

6.2 Managers make sure their team knows this policy and follows it.

6.3 Every user is responsible for what they enter and for what they do with the result.

Article 7. Training and AI literacy

7.1 Everyone who works with AI gets an explanation that fits their role. It covers what the tools can do, where they go wrong and what must stay out.

7.2 New colleagues get that explanation in their first [two weeks].

7.3 The owner records who received which explanation, and when.

Article 8. Reporting incidents

8.1 Did you enter data from Article 3 by mistake? Or do you see an AI error that could cause harm? Report it straight away to [name], via [phone or email].

8.2 Report it when in doubt, too. Nobody is blamed for reporting.

8.3 The owner decides whether it is a personal data breach. [EU: a breach may have to be reported to the data protection authority within 72 hours. Elsewhere: add your local rule.]

8.4 The owner keeps a record of reports and what was done about them.

Article 9. Review

9.1 The owner reviews this policy every six months, in [month] and [month].

9.2 The review covers which tools are really used, which incidents occurred and whether the rules are workable.

9.3 The owner shares any changes with everyone this policy applies to.

Read and understood: [name], [date].

The 72-hour window in Article 8 comes from Article 33 of the GDPR. Not every incident is a reportable breach. That is why one person assesses it, not the person who reported it.

How to adapt it to your business

The example is a starting point. Three choices shape your version.

Choice 1: do you allow cloud tools?

A cloud tool processes your question on the vendor's servers. For a lot of writing that is fine, as long as you have a business account and know what the vendor does with your input.

So ask every vendor the same questions. Does my data leave my environment, do you train on it, and can I have it deleted? We list the full set, and our own answers, on our security page.

On Microsoft 365, Copilot surfaces what an employee already has permission to view. Folders shared too widely suddenly become findable. Read our honest Copilot comparison before you add it to the list.

That is why the example starts strict: personal data stays out of the cloud tool. Loosen it only for a tool where you know exactly where the data goes.

Choice 2: do you work locally on your own data?

The second route is AI that runs on your own laptop. With a local model, your questions and documents never leave the machine. You can then relax Article 3 for that one tool, for example for figures and contracts.

Name the trade-off honestly: local models are weaker than the best cloud models, and you notice it on heavy analysis. How this route works is explained in private AI on your own laptop.

Full disclosure: this is what we build. AI Board is your personal AI assistant that makes you AI-native: it runs on your own laptop, grounded in your company's data, and gets sharper as your knowledge grows.

With the Claude edition, processing of a question goes through Anthropic. With the local edition, that stays on your machine too. So state in Article 2 which edition you use.

Choice 3: who owns the policy?

A policy without an owner goes stale fast. Pick one person who keeps the tool list, answers questions and can say yes or no. In a small business, the obvious candidate is the managing director or operations lead.

Do not hand it to IT by default. IT can assess tools, but which data may go in is a business decision. If you have a data protection officer, involve them from the start.

Check this list before you send the policy out:

  • Company name, owner and date are filled in.
  • The tool list in Article 2 is complete, with account type or edition.
  • Article 3 includes the sensitive data specific to your sector.
  • The contact in Article 8 can be reached outside office hours.
  • The two review dates from Article 9 are in the calendar.
  • A lawyer has reviewed it, if you were in doubt.

AI policy vs AI strategy

Policy and strategy often get mixed up. The difference is simple: the policy says what is allowed, the strategy says where AI makes your business better.

AI policyAI strategy
QuestionWhat is and is not allowed?Which decisions do we prepare with AI?
AudienceEveryone who uses AIThe leadership team
FormRules in numbered articlesChoices about decisions, data and ownership
OwnerOne named personThe leadership team as a whole

Start with the policy, because your team already uses AI. Keep it short and sharpen it after the first review. By then you know which risks actually occur.

The strategy follows once leadership has hands-on experience with AI. For the adoption side, with an owner per seat and a weekly rhythm, read the SMB AI adoption playbook.

FAQ

Is an AI policy mandatory?

No law requires a document by that name. In the EU you must take AI literacy measures under the AI Act and protect personal data under the GDPR. An AI policy records both. Elsewhere, check your local rules.

How long should an AI policy be?

Short enough that everyone reads it. Two pages is enough for the rules. Put the tool list in an appendix if you like, because it changes more often than the rules.

Can you ban ChatGPT at work?

In most places, an employer can set rules about the tools used for work. In the Netherlands, for example, employees must follow the employer's instructions on how work is done, under Article 7:660 of the Dutch Civil Code.

A bare ban rarely works, though, because use moves to personal phones. Ban personal accounts instead and offer a business alternative. If you have a works council or union agreement, involve them in rules about monitoring staff.

What do you do about shadow AI?

Assume it is there. Ask without blame who uses which tools, and for what. Put what works on the tool list as a business version and stop the rest. Why banning rarely works is covered in the shadow AI economy.


A two-page policy that everyone reads protects more than twenty pages nobody opens. Start small, name an owner, and look at what actually happened six months from now.

Become AI-native before your competition does

Ride the AI wave instead of swimming behind it. Book a demo and we'll schedule your install.

Your company brain lives on your laptop. You choose if a question goes to a cloud model or stays fully local.