For small businesses

Small businesses need clear AI rules, not an enterprise manual.

Start with a short policy that fits in day-to-day work, then add process only where your risks require it.

Start here: for most small businesses, a two-page policy can establish approved tools, prohibited data, human review and one accountable owner.

Keep the first version practical

Your staff should be able to answer three questions in seconds: may I use this tool, may I paste this information, and who checks the final output? If the policy does not answer those questions, it will not change behaviour.

Minimum viable policy

  1. Name the people covered, including contractors.
  2. List approved AI tools and how new ones are reviewed.
  3. Ban passwords, payment data and confidential client information from public tools.
  4. Require human checks before publishing, sending or deciding.
  5. Name one person to answer questions and log incidents.

When a short policy is not enough

Get specialist advice before adopting a generic template if you process health data, payment information, children’s data, legal documents, regulated financial records or sensitive employee information.

Build, test, review

Generate the first draft, ask the people who use AI each day to identify unclear moments, then update it. A policy that has been tested in real work is more valuable than a long document copied from a competitor.