Safety & governance

How to Create an AI Policy for Your Business

Hands writing on a sheet of paper at a warm wooden desk beside an open laptop.

An AI policy is a short document that tells your team which AI tools they may use, what data they may put into them, and when a human must review the output. You do not need a legal department to write one — you need to answer a handful of practical questions. Below is a template you can adapt in an afternoon.

Why even a small business needs one

Your team is almost certainly already using AI, whether or not anyone decided they should. Without a policy, that means employees may be uploading confidential information to public tools, relying on inaccurate outputs, or using AI to support decisions that really need human judgment. An AI policy does not slow that down — it turns unmanaged risk into a known, agreed process. It is one of the cheapest risk-reduction steps a business can take.

The template: seven sections

A workable AI policy for a small or mid-sized business is short — one to two pages. These are the sections, and what to write in each:

  1. Purpose and scope. One paragraph: why the policy exists, and who it applies to (usually everyone who uses AI for work, including contractors).
  2. Approved tools. List the AI tools the business permits, and at which tier. Being specific here is what prevents shadow use — "the approved tools are X business tier and Y" is far more useful than "use good judgment."
  3. What data may and may not go in. The most important section. Name clearly what must never be entered into a public AI tool — customer and personal data, contracts, financials, credentials, anything regulated — and what is fine.
  4. Human review. State what always requires a person before it goes out or takes effect: anything sent to a customer, anything published, any financial action, any decision about an individual. AI outputs are drafts until a human approves them.
  5. Accuracy and accountability for output. Make clear that AI can be confidently wrong, so the employee using it remains responsible for checking the result. AI is a tool, not an authority.
  6. Ownership and questions. Name who owns AI use in the business and who to ask when something is unclear. A policy with no owner is a document nobody follows.
  7. Review date. AI tools change fast. State when the policy will be reviewed — quarterly is sensible — so it does not quietly go out of date.
That is the whole thing. Seven short sections, most of them a few sentences. A policy your team will actually read beats a twenty-page document nobody opens.

The three rules that matter most

If you do nothing else, put these three in writing and make sure everyone knows them:

  • Never paste confidential data into a public AI tool. This single rule prevents the most common and most damaging kind of AI data leak.
  • A human approves anything with consequences. Sending, publishing, paying, or any decision about a person goes through a human before it is final.
  • Someone owns it. One named person is responsible for AI use — for keeping the approved-tools list current and answering questions.

Turning a policy into practice

A policy tells people what to do; a well-built system makes the safe path the easy one. When AI is deployed into your operations with least-privilege access, business-tier tools, human approval steps and logging built in, most of the policy is enforced by the system itself rather than relying on everyone remembering the rules. That is the difference between a policy on paper and safety in practice.

This template is a starting point, not legal advice — adapt it to your own obligations and, where a sector rule applies, take proper guidance. If you want help turning an AI policy into systems that actually enforce it, that is part of what we do; a free AI Opportunity Scan is the place to start. You may also find our guide on whether business data is safe with AI useful alongside this.

Questions

Common questions

How do I create an AI policy for my company?

Write a short one-to-two page document with seven sections: purpose and scope; approved tools and tiers; what data may and may not go into AI; what always requires human review; accountability for accuracy; who owns AI use and answers questions; and a review date. You do not need a legal department — you need to answer these practical questions clearly. A policy your team will actually read is more effective than a long document nobody opens.

What should an AI policy include?

An effective AI policy includes the approved tools and tiers employees may use, a clear list of what data must never be entered into AI (customer and personal data, contracts, financials, credentials, regulated information), the actions that always require human review before taking effect, a statement that employees remain responsible for checking AI output for accuracy, a named owner of AI use, and a regular review date. The three rules that matter most are: never paste confidential data into public tools, a human approves anything with consequences, and one person owns it.

Does a small business really need an AI policy?

Yes. A small business needs an AI policy because its employees are almost certainly already using AI, and without a policy that use is unmanaged — risking confidential data being uploaded to public tools, reliance on inaccurate outputs, and AI being used for decisions that need human judgment. A short policy turns that unmanaged risk into an agreed process, and it is one of the cheapest and fastest risk-reduction steps a business can take.

Keep reading

More from the blog

A person watching a task complete by itself on a laptop at a sunlit desk.
AI basics · 6 min read

AI Agent vs AI Chatbot: What's the Difference?

A chatbot has a conversation. An AI agent takes actions across your systems and completes a task end to end. That difference decides whether you are buying a tool that deflects questions or one that removes work — and most businesses buy the wrong one.

Read the post →

A small brass padlock resting on a closed folder beside a laptop in warm light.
Safety & governance · 7 min read

Is Your Business Data Safe With AI?

The risk is not AI in the abstract — it's an employee pasting confidential data into a public tool whose terms let it be stored. Safety is a set of choices, not a property of the technology. Here's how to make the right ones.

Read the post →

Get started

Find the first AI system worth building.

Show us where your business is losing time, revenue, capacity or visibility. We will help determine whether AI can solve it — and what the first practical step should be.

hello@askgeeks.ai · Vancouver, BC · remote across Canada & the US