Writing an AI policy for your team: a practical guide
By Keith Hamilton · · 5 min read
Your team is probably already using AI, whether or not you have agreed it. Writing an AI policy for your team turns that quiet experimentation into something safe, consistent and useful. This guide explains what a practical AI policy for a small business should cover, how long it needs to be, and how to keep it working once it is written.
Why does a small business need an AI policy?
Without a policy, each person makes their own decisions. One person pastes a customer complaint into a free chatbot to draft a reply. Another refuses to touch AI at all. A third uses it to write a quote and sends it without checking the figures.
None of them is being careless on purpose. They simply have no guidance. A short AI policy gives everyone the same rules, protects customer and staff data, and makes it easier to get real value from the tools you choose.
It also helps you meet your existing obligations. UK GDPR already applies to any personal data your team puts into AI tools, and a policy is one of the simplest ways to show you have thought about that.
What should an AI policy include?
Keep it short enough that people will actually read it. Two or three pages is often enough for a small business. The core sections are:
- Which AI tools are approved, and for what.
- What information must never go into public AI tools.
- How AI outputs must be checked before they are used.
- When and how you tell customers that AI is involved.
- Who to ask when someone is unsure.
- What training people will get.
- When the policy will be reviewed.
The rest of this article takes each of these in turn.
Approved tools and how to use them
List the tools staff may use for work, and the accounts they should use them through. Business accounts are usually safer than personal ones, because you control access, settings and what happens to the data.
For each approved tool, say what it is approved for. For example, a tool might be approved for drafting internal documents and summarising public information, but not for handling customer records. Make it clear that new tools need approval before anyone uses them for work, and explain how to ask.
What data must never go into public AI tools?
This is the most important section, so make it specific. A typical list includes:
- customer names, contact details, account numbers or order histories
- anything about health, finances or other sensitive matters
- staff records, including performance and absence notes
- passwords, access codes and system details
- confidential business information, such as pricing plans, contracts or supplier terms
- anything you have agreed to keep confidential for a client or partner
Give people a simple test they can remember. If you would not paste it into an email to a stranger, do not paste it into a public AI tool. Where staff do need AI help with this kind of material, point them to an approved tool that has been checked properly.
Checking AI outputs before they are used
AI tools can produce text that sounds confident and is wrong. Your policy should make clear that the person using the tool remains responsible for the result.
Set out a few plain rules:
- Check facts, figures, names and dates against a reliable source.
- Read customer-facing content in full before it is sent.
- Do not rely on AI for legal, financial or safety advice without proper review.
- Keep a person able to review any decision that significantly affects a customer or member of staff.
Checking takes a little time, but it is far cheaper than correcting a mistake after a customer has seen it.
Being open with customers
Decide how open you will be about AI, and write it down. Many businesses choose to tell customers when AI is used to answer queries, analyse calls or help with decisions about them. Your privacy notice should also explain how personal data is used.
Being honest about AI tends to build trust rather than lose it. A customer who later discovers that a reply was written by a machine, without being told, is more likely to feel misled.
Who to ask, training and keeping the policy current
Name one person as the go-to for AI questions. In a small business this might be the owner, the operations manager or whoever looks after data protection. People are far more likely to ask than guess when they know exactly who to ask.
Training does not need to be elaborate. A short session that walks through the policy, shows the approved tools and works through a few real examples is often enough. Repeat it for new starters.
Finally, set a review date. AI tools and their terms change often, so look at the policy at least once a year, and sooner if you adopt a new tool or something goes wrong. Ask the team what is working and what is unclear, then update it.
Frequently asked questions
How long should an AI policy be?
For most small businesses, two or three pages is about right. It should be short enough to read in one sitting and clear enough that people can find the answer to a common question quickly. Detailed procedures can sit in separate guidance if needed.
Should we ban AI tools altogether?
A blanket ban is hard to enforce and often pushes use out of sight, which is riskier. It is usually better to approve a small number of suitable tools, set clear rules on data and checking, and give people a safe way to experiment.
Who should own the AI policy?
One named person should own it, keep it up to date and answer questions. In a small business this is often the owner or a senior manager. They do not need to be a technical expert, but they do need the authority to approve tools and make decisions.
Where Forwardcycle fits
Our safe adoption service includes an AI Governance Pack covering an AI policy, data protection impact assessment, vendor checklist and staff guidance, written for how your team actually works. To see where you stand today, try the free AI Readiness Assessment or arrange a free call.