A small business AI usage policy should fit on one page and answer five questions: which AI tools are approved, what information can and can't go into them, who checks the output before it goes out, how to handle client or customer data, and who to ask when something's unclear. Below is a plain-language template you can copy, fill in, and send to your team today. Adjust it for your industry, and have your lawyer look it over if you work with regulated data.

Why you need one now

Your team is probably already using AI. The risk isn't the tool, it's the account: someone pastes a client's contract into a personal ChatGPT or Claude account, where the vendor may be allowed to use it for training and you have no admin control. A one-page policy fixes most of that by pointing people to the approved business accounts and telling them what not to paste.

A policy also protects the quality of your work. AI tools make confident mistakes, so someone has to check the output before it reaches a customer.

The template

Copy everything between the lines. Replace anything in square brackets.


[Company name] AI Usage Policy

Effective [date]. Owner: [name and role]. Applies to all employees, contractors and interns.

1. Why we use AI

We use AI tools to save time on drafting, summarizing, research and analysis. AI helps us do our work. It doesn't replace our judgment, and we're responsible for everything we send, whether AI helped or not.

2. Approved tools

Use only these tools for company work, signed in with your company account:

  • [Tool, for example Claude Team, ChatGPT Business or Microsoft 365 Copilot]
  • [Tool]

Don't use personal AI accounts (free or paid) for company or client work. If you want to try a new tool, ask [name] first.

3. What you can put into approved tools

  • Your own drafts, notes and general questions
  • Company information that isn't confidential
  • [Client or customer information, only if your business plan and client agreements allow it. Delete this line if not.]

4. What you must never put into any AI tool

  • Passwords, access codes or API keys
  • Bank account, credit card or Social Security numbers
  • [Health information about patients or employees]
  • [Information a client has told us not to share, or anything covered by a confidentiality agreement that doesn't allow it]
  • Anything you wouldn't be comfortable seeing on the front page of the newspaper

When in doubt, leave it out, or remove names and identifying details first.

5. Check everything before it goes out

AI can be wrong, make things up, or miss context. Before anything AI-assisted goes to a client, customer or the public:

  • Read it all yourself
  • Check facts, numbers, names, dates and quotes against the source
  • Make sure it sounds like us and says what we mean

You're responsible for the final version.

6. Be honest about AI use

Don't present AI output as someone's personal expert opinion without reviewing it. [If clients ask, tell them how we use AI.] [If your industry or contracts require telling clients when AI is used, say so here.]

7. Settings

Don't change privacy or data-sharing settings on company AI accounts. Don't use the thumbs up or thumbs down feedback buttons on client work, since feedback can let the vendor use that conversation.

8. Questions and mistakes

If you're not sure whether something is allowed, ask [name] before you do it. If you think confidential information went into the wrong tool, tell [name] right away. We'd rather fix it early than find out later.

9. Review

We'll review this policy every [six] months, or sooner when our tools change.


How to roll it out

  1. Fill in the brackets. Keep it to one page. If it gets longer, people won't read it.
  2. Set up the business accounts first. The policy only works if the approved tools exist and people can sign in to them. On business plans, Claude Team, ChatGPT Business and Microsoft 365 Copilot don't train on your data by default. Personal accounts don't give you that guarantee.
  3. Walk through it in a 15-minute meeting. Show one good example and one thing not to paste. Answer questions.
  4. Have everyone acknowledge it. A signed copy or an email reply is enough.
  5. Revisit it. AI tools change every few months. Put the review date in your calendar.

Adjustments by industry

  • Law firms: add a line on client confidentiality and consent that follows your bar's guidance, including ABA Formal Opinion 512. See is Microsoft Copilot safe for client data.
  • Accounting and tax: address tax return information and client consent specifically, since IRS Section 7216 rules on disclosure can apply.
  • Healthcare: patient information needs a tool covered by a HIPAA business associate agreement. Most standard business plans aren't covered. Check with the vendor before anything clinical goes in.
  • Everyone: if you sign contracts that restrict how you handle customer data, check them against section 3.

When to call someone

This template covers most small businesses. It's worth getting help when you handle regulated data, when client contracts have AI or data clauses you're not sure about, or when you need the tools set up so the policy is enforced by settings rather than trust.

Our AI advisory includes a privacy review, the right plans and settings, a policy written for your business, and team training, at a fixed price. If you're still choosing a tool, start with Claude vs ChatGPT vs Copilot, and for the people side, see how to roll out AI so your team uses it.

This template is general information, not legal advice.

Sources: Anthropic Privacy Center, Is my data used for model training?; OpenAI Help Center, How your data is used to improve model performance; Microsoft Learn, Enterprise data protection in Copilot.

Written by Tapestries Bot, the AI writing assistant at Tapestries Group.