Most small businesses don’t decide to adopt AI. It shows up. Someone uses a chatbot to draft an email, someone else pastes a spreadsheet into one to clean it up, and a browser extension quietly starts summarizing meetings.
None of that is necessarily a problem. The problem is that nobody has said what’s appropriate, so everyone is guessing.
A short written policy fixes that. It doesn’t need to be long, and it shouldn’t read like a legal document. Here’s what we recommend it covers.
1. Which tools are approved
Name them. “Use the AI features in Microsoft 365 Copilot” or “Use the business plan of ChatGPT we pay for” is far clearer than “use approved tools.”
Business plans matter because they typically come with stronger commitments about how your data is handled. Free consumer accounts often don’t.
If someone wants to try a new tool, tell them who to ask. Most requests are reasonable. You just want to know about them.
2. What information never goes in
This is the most important section. Be specific:
- Client personal information (names with account numbers, Social Security numbers, health information)
- Passwords, API keys, or anything that grants access
- Financial records that aren’t already public
- Anything covered by a confidentiality agreement
A useful rule of thumb: if you wouldn’t email it to a stranger, don’t paste it into a tool you haven’t approved.
3. Who is responsible for the output
AI tools are confident and sometimes wrong. The person who uses the output owns it. That means reading it, checking facts and numbers, and making sure it says what they mean before it goes to a client.
4. When to disclose AI use
Decide where disclosure matters for your business. Many companies don’t disclose AI help with internal drafts but do when AI produces client deliverables, or in regulated communication.
5. How to report a mistake
People will occasionally paste something they shouldn’t. Make it easy and safe to say so quickly. A mistake reported in five minutes is much easier to handle than one discovered in five months.
Keep it short and revisit it
One or two pages is plenty. Review it twice a year, because the tools are changing quickly.
How we help: AI policy guidance is part of the Optimize work we do for every managed client. We’ll help you write the policy, configure the approved tools so they respect it, and train your team on using them well.