Guides · Updated 2026-09-06
AI Policy for Small Business: A 30-Minute Practical Guide
Small businesses adopt AI tools faster than large ones because there is nobody to say no. That is a strength until the day a client asks where their data went, an employee sends out a confidently wrong AI answer, or an insurer asks what controls you have in place. This guide is for owners and managers of companies with roughly five to fifty people who want a working AI policy without a project plan, a committee or a legal budget.
Why a 10-person company needs one
In a small team, one person handles sales, support and invoicing, and that person has ChatGPT open in another tab. The risks are not abstract. Customer lists get pasted into prompts to draft outreach. Contract clauses get summarised by a free tool whose terms allow training on inputs. A generated blog post cites a statistic that does not exist. None of these people are careless; they simply have not been told where the line is.
A policy also answers questions that now come from outside. Enterprise customers increasingly include AI usage clauses in supplier questionnaires. Cyber insurers ask about controls on data leaving the organisation. If you operate in the EU or serve EU customers, the AI Act already requires you to ensure staff have adequate AI literacy and to disclose AI use in certain interactions. A short written policy is the fastest way to answer all of these with a yes.
What to keep short
A small business policy should fit on four pages, with the first page being a summary of ten rules that a new starter can read in five minutes. Resist the temptation to copy the structure of an enterprise policy with its steering groups and quarterly attestations. If a section describes a process you will not actually run, delete it. A policy that promises reviews that never happen is a liability, not an asset.
Keep the definitions to a handful. Keep the approved tool list to the tools people really use, and put it in an appendix so it can change without re-issuing the whole document. Keep the data rules to three or four categories with a plain-English test for each. The one section that should not be cut is the incident reporting route, because the whole point is that people tell you when something goes wrong.
The 30-minute path to a policy
The first ten minutes are an inventory. Ask everyone which AI tools they use for work, including browser extensions and features built into products you already pay for. You will find more than you expect. Decide, for each tool, whether it is approved, approved on a company account only, or not approved. The second ten minutes are data. List the types of information the business handles, from public marketing to client financials to personal data, and decide which category may go into which tier of tool.
The final ten minutes are writing. Use a generator or a template to turn those decisions into a document, add your company name, the owner of the policy and a review date, and read the summary page aloud to check that it sounds like something your team would actually follow. The free generator at aipolicy.wizeb.com/generator takes the inventory and data answers as inputs and writes the rest, including an acknowledgement form and a one-page summary, which is why the whole exercise fits in half an hour.
- Minutes 0 to 10: list every AI tool in use and mark each as approved, approved on company account only, or not approved.
- Minutes 10 to 20: list your data categories and decide what may go where.
- Minutes 20 to 30: generate or fill in the document, name an owner, set a review date, and read the summary page aloud.
Enforcement without an HR department
Enforcement in a small company is mostly about clarity and example, not discipline. If the owner uses a personal AI account for client work, nobody else will follow the rule. Make the approved tools easy to access, pay for the company accounts, and make the unapproved path the harder one. Most breaches in small teams are convenience, not malice.
When something does go wrong, treat the first instance as a training moment and document it in a short note. Repeated or deliberate breaches, such as knowingly pasting restricted data into a public tool, should be handled under your existing disciplinary process, however informal that is. State this in the policy in one sentence so nobody can say they did not know it mattered.
Employee acknowledgement
Every person who works for you, including contractors, should sign a one-line acknowledgement that they have read the policy and will follow it. This can be a form, an email reply or a checkbox in your onboarding tool. Keep the acknowledgements in a single folder with the version of the policy that was signed. This is the evidence an insurer, a client auditor or a regulator will ask for first, and it takes minutes to collect.
Re-collect acknowledgements when the policy changes materially, and include the policy in your new starter checklist so it does not depend on anyone remembering.
Keeping the policy alive
Put a six-monthly review in the calendar of the policy owner. The review is short: check the tool list against what people are really using, check whether any incidents were reported, and check whether any new law or client requirement applies. Update the version number and date, and circulate the change in one paragraph.
The other habit that keeps a policy alive is talking about it. A two-minute item in a monthly team meeting, asking what AI tools people have tried and whether anything felt unclear, surfaces new tools before they become a problem and keeps the rules in everyday vocabulary.
Frequently asked questions
- We only have five staff. Is a written policy overkill?
- No. Five people can leak data as effectively as fifty, and a two-page policy takes less time to write than a single client complaint takes to handle. Keep it proportionate, but write it down.
- Can I just ban AI tools instead?
- You can, but it will not work. Staff will use the tools on personal accounts where you have no visibility. A permissive policy with clear data rules gives you more control than a ban.
- Who should own the policy in a small company?
- The owner, a director or the most senior person responsible for operations or IT. What matters is that one named person is accountable for the review date.
- Do we need a lawyer to review it?
- For most small businesses a generated or template policy is adequate as a starting point. If you handle health, financial or children's data, work in a regulated profession, or have contractual AI restrictions with clients, a short legal review is worth the cost.
- What if an employee refuses to sign?
- Treat it as you would refusal to sign any workplace policy. Explain the reasons, and make clear that compliance is a condition of using company systems and data. In practice refusals are rare once people see the policy is permissive and short.
Generate your own in about four minutes
Spend ten minutes with the free generator and walk away with a policy, a one-page summary and an acknowledgement form your team can sign today.
Generate my policy freeRelated guides
This guide is general information, not legal advice.