AI Policy Documentation for Small Businesses
Esperanza runs a 14-person home cleaning company in San Antonio. Last spring one of her cleaners used an AI photo tool on a client's phone to organize before-and-after photos for their portfolio. The client noticed, called to complain that a photo of their home interior had been uploaded to an AI service without permission, and threatened to leave a public review about the privacy violation. Esperanza had no written policy about AI tools and no clear answer for the client. She spent three days managing the situation. A one-page AI policy, written in advance, would have prevented all of it.
What an AI Policy Actually Is
An AI policy is a short document, typically one to three pages for a small business, that answers three questions for your employees and for yourself:
- Which AI tools are we allowed to use, and for which purposes?
- What information can and cannot be put into those tools?
- What happens when something goes wrong?
It is not a legal compliance document written by lawyers for regulators. It is a practical rulebook for your team, written in plain language, that prevents the kind of misunderstanding Esperanza ran into. Being a practical document does not make it a substitute for whatever obligations already apply to your business; it sits alongside them rather than in place of them, and Data Privacy Obligations for Small Businesses is where that separate question belongs.
Think of it like the dress code section of your employee handbook. The policy exists not because your team is untrustworthy, but because different people make different assumptions about what is acceptable, and a written rule removes the ambiguity. Esperanza's cleaner was not being careless by his own standards. He was applying a standard nobody had ever given him, which is what people do in the absence of one.
Those three questions are the whole scope, and it is worth resisting the urge to add more. A policy that also tries to explain how large language models work, or to anticipate every tool your team might encounter, becomes a document nobody finishes reading, and a document nobody finishes reading is functionally the same as not having one. The measure of success is narrow: can a member of your team, mid-shift, work out from it whether the thing they are about to do is allowed.
The Four Sections Every Small Business AI Policy Needs
Section 1: Acceptable Use
This section lists the AI tools your business has approved, what each one is approved for, and whether personal AI tools, such as a free account someone already has at home, may be used for work tasks. The second half of that sentence is the part most policies leave out, and it is the part that decides most real cases, because the tool an employee reaches for is usually the one already on their own phone.
Example language:
"Approved AI tools as of [date]: ChatGPT (for drafting client emails and internal communications only), Canva AI (for creating marketing graphics), and Jobber's built-in scheduling assistant. Team members may not use other AI tools for business tasks without manager approval. Personal AI accounts may not be used for any task involving client data or confidential business information."
The "approved as of [date]" framing matters more than it looks. AI tools change constantly, and a dated approval list signals that the policy is a living document that will be updated, rather than one claiming to cover every tool that will ever exist. It also gives you a clean answer when someone asks about a tool that is not on the list: the answer is not "no forever," it is "not yet, bring it to the review."
Notice that the approvals in that example are scoped to purposes rather than granted outright. One tool is approved for drafting emails and internal communications only; another for marketing graphics; a third is the scheduling assistant built into software the business already runs. Scoping matters because the risk lives in the combination of tool and task, not in the tool alone. The same assistant that is fine for a marketing paragraph is not fine for a document containing a client's address, and a list of names without purposes cannot express that difference.
Section 2: Data Handling Rules
This is the most important section, and it is the one that would have prevented the mistake Esperanza's cleaner made. It specifies what categories of information may and may not be uploaded to AI tools. A simple two-column split works well, and the value is in its bluntness: a rule an employee can apply while standing in a client's kitchen is worth more than a nuanced one they would have to interpret.
| Information | Rule |
|---|---|
| Client names, addresses, or contact information | Never |
| Photos of client homes, vehicles, or property | Never, without written consent |
| Employee Social Security numbers, bank details, or health information | Never |
| Passwords, API keys, or login credentials | Never |
| Any document marked "Confidential" | Never |
| Your own marketing copy and service descriptions | Acceptable |
| Generic business communications, not client-specific | Acceptable |
| Public information about your industry | Acceptable |
| Internal process documentation | Acceptable |
The logic behind the never column is that when you upload information to an AI tool, it travels to that company's servers and is no longer only in your possession. Many providers offer business or enterprise tiers whose terms state that your inputs are not used to train their models, but that depends on which account type you are on and how its settings are configured, the terms differ between providers, and they change over time. Check the terms for the specific tool and the specific tier your team is actually using rather than assuming the protection is there.
Team members using free personal accounts have no such protection. That is the single most useful sentence in this section, because it explains why the acceptable-use rule about personal accounts exists rather than simply asserting it. It is also why a clear never list beats a nuanced one: explaining data retention settings to every cleaner, technician or stylist on your team is a training programme, and a short list is a laminated card.
The photo row is the one that would have changed Esperanza's spring. Her cleaner was doing something reasonable on its face, which was organizing before-and-after photos for a portfolio, and the fault was not in the intention. It was that a client's home interior went to a third party without the client having agreed to it. Written consent is the exception the rule carries because there are legitimate reasons to use those photographs, and the difference between a portfolio and a complaint is whether the person whose home it is said yes first.
It is worth being explicit that the second column is a permission, not an afterthought. Marketing copy, generic business communications, public industry information and your own internal process documentation are the material your team can use AI on freely, and saying so removes the other failure mode, which is a policy so cautious that people quietly ignore it in order to get work done. A policy that only forbids things trains your team to treat it as an obstacle. One that also grants things gets read as guidance.
Section 3: Vendor Management
Before adding a new AI tool to your approved list, establish a simple review process. Most small business owners can handle this in about 30 minutes per tool, and the four questions below are the whole of it:
- Does the tool have a privacy policy you can actually find and read?
- Does a paid tier exist with data privacy protections, such as an opt-out from training data and data deletion rights?
- Is the company based in the US, the EU, or another jurisdiction with enforceable privacy law?
- What does the tool do with your data if you cancel?
You do not need a lawyer to answer these four questions. Most of the answers are findable on the vendor's website in under 10 minutes, and the exercise is as much about how hard they are to find as about what they say. If you cannot find a privacy policy at all, that is your answer, and the answer is not to use the tool. Treat each question as a signal rather than a guarantee: a satisfactory answer means the vendor has made a commitment you can point to later, not that nothing can go wrong.
The last of the four questions is the one owners skip most often, and it is the one that matters after the relationship ends rather than during it. What a tool does with your data if you cancel determines whether leaving a vendor is a clean exit or a permanent deposit. Ask it before you sign up, while you are still a prospect and the answer is easy to get, rather than at the point where you have already decided to leave and your leverage is gone.
Section 4: Incident Response
This section answers the question of what you do when something goes wrong. Something going wrong includes a client's data being accidentally sent to an AI tool, an AI-generated response saying something incorrect or harmful to a client, or a tool your team was using being found to have suffered a data breach. Naming those three cases in the document matters, because people report incidents they recognise as incidents.
The response steps for a small business are short:
- Stop using the tool immediately and document what happened, while the details are still accurate rather than remembered.
- Notify the business owner within 24 hours.
- If client data was involved, the owner decides how and when to tell the client, and checks whether the business has a notification obligation before treating that decision as purely discretionary.
- Remove the tool from the approved list until the issue is understood and resolved.
Having these steps written down means Esperanza's cleaner would have known to come to her immediately rather than hoping nobody noticed, which is the behaviour an unwritten policy reliably produces. And Esperanza would have had a decision framework for the client conversation instead of three days of improvisation, which is where most of the damage in that episode actually occurred.
The order of those steps is deliberate. Stopping first, before anyone tries to work out what happened, prevents a single incident from becoming a repeated one while it is being investigated, and it costs almost nothing to reverse if the alarm turns out to be false. Documenting second, before the notification, means the account the owner receives is written rather than remembered. Most incident processes that fail at small scale fail because someone tried to assess the severity before containing it.
How to Roll Out the Policy
A policy nobody has read is just a document. Schedule a 20-minute team meeting to walk through the key points, and for each section give a concrete example from your own business rather than a hypothetical one. Ask whether anyone has questions, and expect the useful ones to be about edge cases you had not considered, because your team meets the edges daily and you do not.
Then put the document somewhere everyone can find it: a shared drive folder, pinned in your team chat channel, or printed and posted in the break room. Which of those you choose matters less than whether someone standing in a client's home with a phone in their hand can check the rule in under a minute. That is the actual test of where a policy lives.
Review and update the policy annually, or whenever you add a significant new AI tool. Put the date in the document header and version it, in the form "AI Policy v1.2, updated June 2026". Versioning is not bureaucracy at this scale; it is how you tell whether the copy pinned in the break room is the same one you last emailed out.
One more thing belongs in the header alongside the date: a name. Annual review and the "whenever we add a significant new tool" trigger both describe work that somebody has to actually do, and in a small business that somebody is usually the owner by default and by omission. Writing the name down converts a good intention into an assignment. It also tells your team who to bring a new tool to, which is the mechanism that keeps the approved list current rather than merely dated.
Anti-Patterns
- Assuming shared standards exist. Esperanza's cleaner was not reckless by his own lights. Without a written rule, every member of your team applies their own, and the range is wider than you expect.
- Leaving personal accounts unaddressed. The tool an employee reaches for is the one already on their phone. A policy that lists approved tools without saying anything about personal accounts has not covered the most common case.
- Assuming a paid tier protects you automatically. Terms vary by provider, depend on the account type and settings, and change. Read the terms for the tier your team is actually on.
- Treating client notification as a pure judgement call. How and when to tell a client is a decision. Whether you have an obligation to tell them is a separate question, and it is not answered by deciding you would rather not.
- Emailing the policy instead of walking through it. An emailed file gets an acknowledgement, not an understanding. Twenty minutes with examples from your own business is what makes it stick.
- Writing it once. An undated, unversioned policy quietly becomes wrong as tools change, and nobody notices because there is no date to compare against.
Practice Prompts
- Draft your never list. "I run a [type of business] with [number] employees who do [describe the work]. List the categories of information my team routinely handles that should never be put into an AI tool, phrased plainly enough to apply while on a job."
- Write the acceptable use section. "Draft an acceptable use section for a small business AI policy. Approved tools are [list them] for [purposes]. Include a clear rule about personal AI accounts and a dated approval framing."
- Run a vendor review. "I am considering [tool] for [purpose]. Walk me through four checks: is the privacy policy findable, does a paid tier offer training opt-out and deletion rights, where is the company based, and what happens to my data if I cancel. Tell me what I must look up myself."
- Build the incident steps. "Write a four-step incident response section for a [type of business] covering client data sent to an AI tool by mistake, a harmful AI-generated response to a client, and a breach at a vendor we use. Keep it short enough to follow under pressure."
- Prepare the rollout meeting. "Turn this policy into a 20-minute team meeting agenda for [type of business], with one concrete example from my industry for each section and three questions to ask the team."
Reflection
- If a member of your team uploaded a client's photograph to an AI tool tomorrow, what written rule would they have broken?
- Which AI tools is your team actually using right now, as opposed to the ones you know about?
- Whose personal accounts are being used for work tasks in your business, and would you be able to say?
- If a client called to complain about how their information had been handled, who takes the call and what do they say first?
- When was your policy last dated, and does the copy your team can see match the one you think is current?
Glossary
- AI policy. A short internal document, typically one to three pages, setting out which tools are approved, what data may go into them, and what happens when something goes wrong.
- Never list. The blunt enumeration of information categories that must not be uploaded to an AI tool under any circumstances short of the stated exception.
- Written consent. A client's recorded agreement, required before their property or premises appear in material sent to an AI tool.
- Business tier. A paid account type whose terms may include commitments about training data and deletion, subject to the specific settings in use.
- Vendor review. The four-question check performed before a tool joins the approved list, covering privacy policy, paid-tier protections, jurisdiction and cancellation.
- Incident response. The written sequence when something goes wrong: stop, document, notify the owner, decide on client contact, remove the tool.
Related Lessons
- Data Privacy Obligations for Small Businesses covers the obligations that sit alongside this policy rather than being replaced by it.
- Creating Your Business AI Use Policy works through the drafting process in more detail.
- Vendor Risk Assessment for AI Tools extends the four-question review into a fuller assessment.
- Data Privacy Basics: What You Share with AI explains what actually happens to information you upload, which is the reasoning behind the never list.
- AI Tool Security: What Every Owner Must Know covers the credential and access side, including the rule about passwords and API keys.
- Transparency with Customers About AI Use addresses what you tell clients about your use of AI, as distinct from what your team is permitted to do.
Closing
Esperanza lost three days to a conversation she could not have because she had never decided the answer in advance. That is what this document is: a set of decisions made once, in calm conditions, so that nobody has to make them while a client is on the phone. One to three pages, four sections, a twenty-minute meeting and a date in the header. The version you write this month will be wrong within a year, which is why it carries a version number, and being wrong in a documented, reviewable way is a considerably better position than the one Esperanza was in.
Key Takeaways
- An AI policy answers three questions: which tools are allowed, what data may go into them, and what happens when something goes wrong. For a small business, one to three pages is enough.
- The never list is the most important part. Client data, photographs of client property, employee personal information, credentials and anything marked confidential are the highest-risk categories, and the rule works because it is blunt.
- Personal AI accounts used for business tasks leave a protection gap. Business tiers may carry commitments about training data, but only under the specific account type and settings in use, so check the terms rather than assuming.
- A four-question vendor review prevents most tool-selection mistakes. A tool with no findable privacy policy should not be on your approved list, and each answer is a signal rather than a guarantee.
- Incident response steps written in advance save days of improvisation. Most incidents escalate because nobody knew whose job it was to act.
- Notification is not purely discretionary. The owner decides how and when to tell a client, and separately checks whether an obligation to notify applies at all.
- Roll the policy out in a 20-minute meeting, not by emailing a file. Concrete examples from your own business stick; abstract documents do not.
- Date and version the document and review it annually. A living policy tells your team the rules will keep up with the tools.
Frequently Asked Questions
Do I really need a written policy for a business this small?
The size of the business is not what creates the need; the number of people applying their own judgement is. Esperanza has 14 employees, which is 14 sets of assumptions about what is acceptable to upload. One to three pages costs an afternoon to write, against the three days she spent on a single incident.
What if my team is already using AI tools I did not approve?
That is the normal starting position, and a reason to write the policy rather than to wait. Begin by asking what is already in use, without treating the answers as offences, because a list you can trust is worth more than a list that makes you comfortable. Then decide which of those tools go on the approved list, and for what.
Does paying for a business tier mean my data is safe?
It means the provider has made commitments you can point to, under a particular account type and a particular set of settings. Terms differ between providers and change over time, so read the terms for the tier your team is actually on. A free personal account carries no such commitments at all, which is why the personal-account rule sits in the acceptable use section.
A client's information went into an AI tool by accident. What do I do first?
Stop using the tool and write down what happened while the details are still accurate. The owner should know within 24 hours. Then decide how and when to tell the client, and separately establish whether you have any obligation to notify, because that is a different question from whether you would prefer to. Take the tool off the approved list until you understand what happened.
Skill.re