The one-page AI policy every small business needs should answer four questions: which tools are approved, what information must never go into a prompt, who checks the output before it reaches a customer, and who employees ask when they are unsure. That is enough to give people a usable boundary without burying them in legal language.
Write the policy for the work your team does today. A real estate office, a coaching practice, and a local service company may all use AI, but they do not handle the same records. Start by naming the tasks and information that matter in your business. For financial workflows, compare the review habits in this guide to AI bookkeeping tools for small businesses before you approve a tool that sees transaction data.
Section one: approved tools and approved work
List the tools your business has chosen and the jobs each one may support. For example, an approved assistant might help draft a public blog outline, summarize an internal meeting, or turn a confirmed set of notes into a first draft. The list should also say whether a personal account is allowed. If your business cannot control the account, access, or retention settings, do not treat it as an approved place for company information.
Keep the language concrete. “Use AI responsibly” sounds pleasant but does not help someone decide what to do at 4:45 p.m. “Use the company account for draft outlines and internal summaries. Do not paste customer records into an unapproved tool” gives a person a decision they can follow.
- Name each approved tool or tool category.
- Describe the tasks it may support.
- Say whether personal accounts are prohibited for company work.
- Require a manager or owner to approve a new tool before use.
Section two: information that stays out of prompts
Make a short protected-data list. It may include passwords, payment details, private health information, identity documents, confidential contracts, unpublished financial records, customer contact details, or anything covered by a promise you made to a client. The exact list should reflect your business and agreements.
Do not make employees guess whether removing a name makes a document safe. A file can still identify someone through a phone number, address, account number, dates, or a combination of details. When in doubt, remove the sensitive material, use a company-approved environment, or ask the person named in the policy.
Your policy should also explain what to do with data that is public but still valuable. A public pricing page may be fine for an outline, while an unreleased offer may not be. The difference is business context, not just whether someone could find a related fact online.
Section three: human review before delivery
Every output that can affect a customer, employee, payment, contract, or public claim needs a human review step. The reviewer checks facts, names, numbers, promises, tone, permissions, and whether the draft actually answers the person’s question. The reviewer owns the final decision even when AI produced the first version.
Assign the review by job, not by vague hope. The person responsible for client communication may review a draft email. The person who manages finances may review a payment explanation. A qualified professional should handle legal, tax, medical, or other specialized decisions when those issues arise.
- Read the entire output, not only the first paragraph.
- Check every number, date, name, link, and claim against a source.
- Remove private information that is not needed in the final message.
- Ask whether the wording promises more than the business can deliver.
- Save the approved version where your team can find it.
This review rule matters for automated front-door systems too. Before you approve an AI answering service, decide which calls can receive a routine response and which calls must reach a person. The cost comparison in AI answering service versus receptionist work is useful only after you define that boundary.
Section four: the person who answers questions
Name one owner for the policy. That person does not need to approve every prompt, but they should maintain the approved-tool list, collect questions, record incidents, and update the page when the business changes. If the owner is unavailable, name a backup.
Give the team a simple question path: stop, save nothing sensitive, and ask. People are more likely to follow a policy when asking is treated as good judgment rather than failure. You can keep a small log of questions and use repeated questions to improve the policy.
What the one-page document can look like
Purpose: We use approved AI tools to support defined business tasks. A person remains responsible for the final work.
Approved tools: [List tools and allowed uses.] Personal accounts may not be used for company information unless the owner approves them.
Protected information: Do not enter passwords, payment details, identity documents, private customer records, confidential contracts, or other information listed by the owner.
Review: A named person checks facts, privacy, tone, links, numbers, and promises before AI-assisted work reaches a customer, employee, or public channel.
Questions: Ask [name and contact] before using a new tool or sending uncertain content.
Review date: The owner reviews this policy on [date] and after a material change.
That draft is short enough to read and specific enough to use. Replace the brackets with your own information. Do not copy a policy from another company and assume it fits your data, contracts, or clients.
How to introduce the policy
Share the page in the same place where your team keeps other operating rules. Walk through two examples: one allowed task and one protected-data situation. Then invite questions. A ten-minute conversation can reveal a gap that a polished document hides.
Connect the policy to the rest of your operating system. If AI will help sort receipts, your bookkeeping process should say who reviews the result. If AI will help plan follow-up, your customer process should say which messages require approval. If setup work is growing, separate the one-time design cost from the monthly running cost with this practical AI automation cost guide.
Finally, explain that the policy is not a ban on useful tools. It is a shared agreement about trust, privacy, and responsibility. A clear page lets your team move faster on safe work because they know where the line is.
Keep the page visible after launch. A policy that sits in a forgotten folder cannot guide a rushed decision, while a short document that gets discussed can become part of how the business works.