Skip to content
LAA Concierge Consulting

Adoption

A short AI usage policy for a small business, and why yours should be short

September 17, 2026 · 3 min read

A policy nobody reads is not control. Most of the AI policies in circulation are several pages of principles that no employee will consult at four in the afternoon when they are deciding whether to paste a customer's email into a chatbot. A small business needs one page, written for that moment.

What the policy is for

Its job is to make a handful of decisions once, so that nobody in the business has to make them alone under time pressure. Which tools may be used. What must never go into them. Which outputs a person must check before they leave the business. Who decides when something new comes up. That is the whole job.

The five sections

1. What you may use AI tools for

Say it positively and specifically. Drafting replies, summarizing documents, first drafts of proposals, cleaning up notes, answering internal questions from approved material. A list people can recognize their own work in.

2. What must never go into an AI tool

This is the section that matters most, and it should be a plain list: customer personal information, payment card details, health information, anything covered by a confidentiality agreement, passwords and credentials, unreleased financial information, and anything you would not want to see on the front page. If a task needs that data, it needs an approved tool with a contract that covers it — not a general-purpose one.

3. Which outputs need a human review before they leave the business

Anything sent to a customer. Anything with legal, financial, or employment consequences. Anything published. The rule is simple: an AI draft is a draft until a named person has read it.

4. Which tools are approved, and who approves new ones

Name the tools people may use today and one person who says yes or no to additions. Without this, everyone picks their own, and section two becomes unenforceable.

5. Where to ask

One name. If someone is unsure, they ask this person rather than guessing. That single line prevents more problems than the rest of the document.

A draft you can adapt

The text below is a starting point, not legal advice. Adapt it to your business and have your attorney review it before you adopt it, particularly the section on data.

AI tools at [Company]. You may use approved AI tools to draft replies, summarize documents, prepare first drafts, tidy notes, and answer internal questions from our own procedures. Never put the following into any AI tool: customer names with contact or account details, payment card or bank information, health information, anything covered by a confidentiality agreement, passwords, or unreleased financial figures. If a task needs that information, ask [Name] before proceeding. Anything an AI tool helps you write must be read by you before it is sent, and by [Name or role] before it goes to a customer, into a contract, or into a public post. Approved tools: [list]. To use a new tool, ask [Name]. If you are not sure whether something is allowed, ask [Name] — that is always the right answer.

What to leave out

  • Long statements of principle. They add length and remove nothing.
  • Tool-by-tool feature rules. They are out of date the week you write them.
  • Anything you cannot enforce. A rule that will be broken by lunchtime teaches people that the rest of the policy is optional too.
  • Threats. The policy is there to help people decide, not to catch them out.

How to roll it out

Read it aloud in a team meeting. Give two or three examples from your own business of what is fine and what is not. Ask what people are already using — you will learn something. Put the page where the work happens, not in a folder. Revisit it after a few months, when you know what actually came up.

Where the policy fits

A policy on its own does not make a team use a new system well. It is one of the four things that have to line up — owner, workflow, rules, measurement — and we wrote about the other three in why AI projects die in week three. But it is the one you can write this afternoon.

If you want the policy written for your specific tools and roles, alongside the training and follow-up that make it stick, that is part of AI training and adoption.

More articles