Operations
AI policy template for a small business: the one-page version
A fill-in-the-blank AI policy you can copy in ten minutes. Eight lines, written for a business with no IT department and no HR department.

The AI policy templates written for companies with an IT department are easy to spot. They open by telling you to form a working group. Somewhere further down they assume you have a general counsel.
You have eleven people, a part-time bookkeeper, and a service manager who answers the phone while eating lunch.
So here's the short version, and it is free and not behind a form.
What a one-page policy is actually for
Not compliance theater. It does three jobs you can check by walking around the building.
It tells your people which tools they're allowed to use for company work, so nobody has to guess. It names what never goes into one of those tools. And it names a person to ask, so that nobody is deciding "can I paste this in?" alone at seven at night.
Copy the whole thing below and change the brackets. That's the job, and it is genuinely the whole job for six of the eight lines. Nothing here is behind a form, we don't want your email for it, and there is no PDF, because a PDF is how a one-page policy becomes a thing nobody opens.
The eight lines
Replace everything in brackets. Keep the numbering, because people will say "line 3" out loud when they talk about it, and that is the entire reason the numbering is there.
-
Approved tools. The only AI tools approved for [company] work are [list them]. To use something else for work, ask [name] first.
-
Accounts. Use the account [company] gives you. Don't use a personal AI account for company work.
-
Never goes in. Never paste any of these into an AI tool.
- Customer names together with addresses or phone numbers.
- Card or bank details, and any password.
- [The thing your business can't afford to leak. See the notes below.]
- Anything a customer or a supplier marked confidential.
-
Checked before it leaves. Anything an AI tool wrote gets read by a person before a customer, a supplier or an inspector sees it. Prices, dates, measurements and promises get checked against the original.
-
Say so when you're asked. If a customer asks whether AI was involved, answer honestly. If a contract or a client agreement says what you can use, that comes first.
-
Who to ask. [Name] answers questions about this page. Asking is always fine. Guessing isn't.
-
If a rule gets broken. Tell [name] the same day. Nobody is in trouble for telling. [Owner: what happens after that is yours to write, and it is the one line on this page nobody outside your business should draft.]
-
Review. Last reviewed [date] by [name]. Review again on [date], or sooner if a new tool gets added.
That's the page. Six of the eight lines you can fill in over a coffee. Two of them need a decision, and those two are the rest of this article.
Filling in line 1, the approved list
Name the tools, not the categories. "ChatGPT and the one inside our field software" beats a paragraph about approved generative AI platforms, because a paragraph about platforms is a paragraph nobody can follow.
The problem is that you probably don't know what your people are using.
Then put every one of those on line 1 unless you have a specific reason not to. Starting with a short list that's true beats starting with a short list that's aspirational, because the aspirational one gets ignored in week two and then the whole page is optional.
What you're finding out in that week is three things, and none of them needs a security review. Who owns the company. Which plan your person signed up on, personal or paid. And whether your customers' details would end up in it, which is usually answered by watching somebody use it for two minutes rather than by reading anything.
New tools then get added to line 1 with the date they went on. That's how a page written once stays true, and it's also how you find out in March that four people have quietly been using something since November.
Filling in line 3, what never goes in
This is the line that changes by trade, and the line every generic template gets wrong, because they all write it for an office that doesn't exist.
| If you run | Line 3 is | The one people forget |
|---|---|---|
| Plumbing, HVAC, electrical | A customer's name with their address, and that nobody's home till six | The gate code, sitting in the job notes |
| A dental or medical practice | Patient information of any kind. See below, this one is different | A photo of the schedule on the front desk screen |
| An agency or consultancy | Unreleased client work, client numbers, the client list | A pitch deck for a client who hasn't signed |
| A shop or small manufacturer | The drawing, the supplier's price, the margin you quoted | The drawing, because it looks like a picture |
The medical row is genuinely different rather than just higher stakes, and we write it the same way every time: no patient information of any kind. A practice occasionally asks us to soften it and we don't, because the softening would be the one sentence on their page that nobody qualified had looked at. Your compliance person can tell you in about a minute whether it moves. Until they do, write it as it stands.
The judgment calls underneath this, the ones your people will get wrong in good faith, are in what your team can safely put into ChatGPT. That article is the long version of line 3.
Who the named person should be
Every template tells you to name somebody. Not one of them tells you who, and the obvious answer is wrong.
It should be whoever already gets asked when something is broken and nobody knows what to do. In a lot of shops that is the office manager or the service manager rather than the owner, and it works better than the owner, because they are reachable at ten past four on a Tuesday.
They need three things to do the job, and they are all cheap.
- Say out loud, in front of everybody, that they can answer for the business on this.
- Agree that "not yet, let me check" is an answer they're allowed to give.
- Give them twenty minutes with you whenever they want to escalate something.
- Put the approved list somewhere they can edit it without asking you.
That fourth one is the one people skip, and it is the one that turns the page from a document into a thing that runs.
The line nobody writes
Go and read three other AI policy templates after this one. Every one of them tells your staff what they can't do. Not one of them tells you how a new tool gets approved.
So line 6 does more work than line 3. One named person, a yes or a not yet, and the answer written on the list with a date. Line 3 stops the thing you already thought of; line 6 is the only line on the page that handles the thing you haven't. That asymmetry is why it is worth spending real thought on who that name is, which is the section above, rather than filling it in with whoever is nearest.
Figure 1 / Flow
Every request ends in the same place: a dated line on the approved list, whether the answer was yes or not yet.
How a new tool gets approved
Needs a person
Someone wants a new tool
Line 1 says to ask first.
Needs a person
They ask the named person
Asking is always fine. Guessing isn't.
Needs a person
Yes, or not yet
A "not yet" is a complete answer.
Affirmed
It goes on the list, dated
The approved list is line 1 of the policy.
- Needs a person
- Affirmed
"Not yet, ask me again when I've found out where the data goes" is a complete answer and it leaves a record. A silent no is the one that drives people underground.
And when the answer is yes, the tool goes on line 1 that day rather than at the next review. A policy that lags the business by three months is a policy people route around.
The two blanks, and why they stay blank
Six of the eight lines we will hand you finished. Two are blank on purpose, and they are the two that look like we ran out of effort.
Line 3 is the easy one. The thing your business can't afford to leak is specific to your building and your contracts, and a stranger filling it in produces a page that is technically a policy and practically a form letter. The Compare table above gets you most of the way there in about four minutes.
Line 7 is the one worth stopping on. Here is the half of it we do write, because this half is ours: tell the named person the same day, and nobody is in trouble for telling. That sentence is doing more work than anything else on the page.
What happens next, though, is a rule about a person rather than a rule about a tool, and we have never written one into a client's page. Not out of caution. It's that a consequence written by somebody who doesn't work there reads exactly like what it is, and the page's whole job is to make asking easy.
One more, and then this section is over. If the page is heading into a handbook, an employment agreement, or anything your people put a signature on, whoever owns your handbook reads it before that happens. Not because the page is dangerous. Because a signed document and a pinned-up document are not the same object, and only one of them is what we build.
What the page can't tell you
Here's the limit of the thing you just copied.
It says what's allowed. It doesn't tell you whether anybody reads AI output before a customer sees it. It doesn't tell you whether the work it describes is written down anywhere. You can have a flawless policy sitting on top of a business where neither of those is true, and that business is in worse shape than it looks on paper.
The free AI readiness check asks twenty questions, one tap each, about four minutes. Your finding and all five areas show up on screen when you finish. Two of the five are documentation and checking, and a policy can't close either one.
Figure 2 / Boundary
A page settles what is allowed and cannot settle whether anybody does it.
What the page can't close
Settled
Which tools are allowed
The approved list, with a date on every addition.
What never goes in
It changes by trade.
Who to ask
Asking is always fine. Guessing isn't.
What gets checked before it leaves
Prices, dates, measurements and promises.
What you say when a customer asks
Answer honestly.
Still open
Whether anybody reads the output
Before a customer sees it.
Whether the work is written down anywhere
The consequence line
That one belongs to the owner. It is the only line we will not draft.
Whether a vendor's compliance claim is true
Ask for it in writing, with the regulation named.
The lineA rule is real when a person is named and the output gets checked.
What to do with the page once it's written
Three moves, in order, and the first one is the one that decides whether the other two matter.
Read it out loud at a Monday morning meeting. Not emailed. Out loud, and then stop talking and let people argue about line 3. The person who argues is usually the person who was about to paste something, which is exactly the conversation you wanted.
Pin it where the work happens. Break room, van, front desk. Not a shared drive, because a policy in a folder is a policy nobody has read.
Then teach the two lines that need judgment. Line 3 and line 4 are the ones people get wrong in good faith, and a page nobody understands is a page nobody follows. There's a first-month plan for that in how to get a small team using AI properly.
And if the real problem turns out to be that the procedure only exists in one person's head, the page can wait. Start with writing the work down instead, because a rule about a process nobody can describe is a rule about nothing.
Figure 3 / Sequence
Three moves in order, and the first one is reading it out loud to people who can argue with it.
What to do with the finished page
Read it out loud at a Monday meeting
Not emailed. The person who argues is the person who was about to paste something.
Pin it where the work happens
Break room, van, front desk.
Teach the two lines that need judgment
Lines 3 and 4 are the ones people get wrong in good faith.
The part you can do without us
We train teams on exactly this. We build the check into the process. Or we run it for you. Those are the three routes, and this page is free either way.
The policy itself you can do this afternoon without us, and you should. What's worth paying somebody for is the thing after it, which is whether anybody actually does what the page says.
