Skip to main content

Operations

AI policy template for a small business: the one-page version

A fill-in-the-blank AI policy you can copy in ten minutes. Eight lines, written for a business with no IT department and no HR department.

A man pinning a printed sheet to a noticeboard on a tiled wall above a kitchen counter, a wall lamp lighting the board.

The AI policy templates written for companies with an IT department are easy to spot. They open by telling you to form a working group. Somewhere further down they assume you have a general counsel.

You have eleven people, a part-time bookkeeper, and a service manager who answers the phone while eating lunch.

So here's the short version, and it is free and not behind a form.

What a one-page policy is actually for

Not compliance theater. It does three jobs you can check by walking around the building.

It tells your people which tools they're allowed to use for company work, so nobody has to guess. It names what never goes into one of those tools. And it names a person to ask, so that nobody is deciding "can I paste this in?" alone at seven at night.

Copy the whole thing below and change the brackets. That's the job, and it is genuinely the whole job for six of the eight lines. Nothing here is behind a form, we don't want your email for it, and there is no PDF, because a PDF is how a one-page policy becomes a thing nobody opens.

The eight lines

Replace everything in brackets. Keep the numbering, because people will say "line 3" out loud when they talk about it, and that is the entire reason the numbering is there.

  1. Approved tools. The only AI tools approved for [company] work are [list them]. To use something else for work, ask [name] first.

  2. Accounts. Use the account [company] gives you. Don't use a personal AI account for company work.

  3. Never goes in. Never paste any of these into an AI tool.

    • Customer names together with addresses or phone numbers.
    • Card or bank details, and any password.
    • [The thing your business can't afford to leak. See the notes below.]
    • Anything a customer or a supplier marked confidential.
  4. Checked before it leaves. Anything an AI tool wrote gets read by a person before a customer, a supplier or an inspector sees it. Prices, dates, measurements and promises get checked against the original.

  5. Say so when you're asked. If a customer asks whether AI was involved, answer honestly. If a contract or a client agreement says what you can use, that comes first.

  6. Who to ask. [Name] answers questions about this page. Asking is always fine. Guessing isn't.

  7. If a rule gets broken. Tell [name] the same day. Nobody is in trouble for telling. [Owner: what happens after that is yours to write, and it is the one line on this page nobody outside your business should draft.]

  8. Review. Last reviewed [date] by [name]. Review again on [date], or sooner if a new tool gets added.

That's the page. Six of the eight lines you can fill in over a coffee. Two of them need a decision, and those two are the rest of this article.

Filling in line 1, the approved list

Name the tools, not the categories. "ChatGPT and the one inside our field software" beats a paragraph about approved generative AI platforms, because a paragraph about platforms is a paragraph nobody can follow.

The problem is that you probably don't know what your people are using.

Then put every one of those on line 1 unless you have a specific reason not to. Starting with a short list that's true beats starting with a short list that's aspirational, because the aspirational one gets ignored in week two and then the whole page is optional.

What you're finding out in that week is three things, and none of them needs a security review. Who owns the company. Which plan your person signed up on, personal or paid. And whether your customers' details would end up in it, which is usually answered by watching somebody use it for two minutes rather than by reading anything.

New tools then get added to line 1 with the date they went on. That's how a page written once stays true, and it's also how you find out in March that four people have quietly been using something since November.

Filling in line 3, what never goes in

This is the line that changes by trade, and the line every generic template gets wrong, because they all write it for an office that doesn't exist.

The thing your business can't afford to leak
If you runLine 3 isThe one people forget
Plumbing, HVAC, electricalA customer's name with their address, and that nobody's home till sixThe gate code, sitting in the job notes
A dental or medical practicePatient information of any kind. See below, this one is differentA photo of the schedule on the front desk screen
An agency or consultancyUnreleased client work, client numbers, the client listA pitch deck for a client who hasn't signed
A shop or small manufacturerThe drawing, the supplier's price, the margin you quotedThe drawing, because it looks like a picture
Write one of these into line 3 in your own words. The right-hand column is there because it is the one that actually happens.

The medical row is genuinely different rather than just higher stakes, and we write it the same way every time: no patient information of any kind. A practice occasionally asks us to soften it and we don't, because the softening would be the one sentence on their page that nobody qualified had looked at. Your compliance person can tell you in about a minute whether it moves. Until they do, write it as it stands.

The judgment calls underneath this, the ones your people will get wrong in good faith, are in what your team can safely put into ChatGPT. That article is the long version of line 3.

Who the named person should be

Every template tells you to name somebody. Not one of them tells you who, and the obvious answer is wrong.

It should be whoever already gets asked when something is broken and nobody knows what to do. In a lot of shops that is the office manager or the service manager rather than the owner, and it works better than the owner, because they are reachable at ten past four on a Tuesday.

They need three things to do the job, and they are all cheap.

Give the named person these before you put their name on line 6
  • Say out loud, in front of everybody, that they can answer for the business on this.
  • Agree that "not yet, let me check" is an answer they're allowed to give.
  • Give them twenty minutes with you whenever they want to escalate something.
  • Put the approved list somewhere they can edit it without asking you.

That fourth one is the one people skip, and it is the one that turns the page from a document into a thing that runs.

The line nobody writes

Go and read three other AI policy templates after this one. Every one of them tells your staff what they can't do. Not one of them tells you how a new tool gets approved.

So line 6 does more work than line 3. One named person, a yes or a not yet, and the answer written on the list with a date. Line 3 stops the thing you already thought of; line 6 is the only line on the page that handles the thing you haven't. That asymmetry is why it is worth spending real thought on who that name is, which is the section above, rather than filling it in with whoever is nearest.

Figure 1 / Flow

Every request ends in the same place: a dated line on the approved list, whether the answer was yes or not yet.

How a new tool gets approved

  1. Needs a person

    Someone wants a new tool

    Line 1 says to ask first.

  2. Needs a person

    They ask the named person

    Asking is always fine. Guessing isn't.

  3. Needs a person

    Yes, or not yet

    A "not yet" is a complete answer.

  4. Affirmed

    It goes on the list, dated

    The approved list is line 1 of the policy.

  • Needs a person
  • Affirmed
RunSimpler

"Not yet, ask me again when I've found out where the data goes" is a complete answer and it leaves a record. A silent no is the one that drives people underground.

And when the answer is yes, the tool goes on line 1 that day rather than at the next review. A policy that lags the business by three months is a policy people route around.

The two blanks, and why they stay blank

Six of the eight lines we will hand you finished. Two are blank on purpose, and they are the two that look like we ran out of effort.

Line 3 is the easy one. The thing your business can't afford to leak is specific to your building and your contracts, and a stranger filling it in produces a page that is technically a policy and practically a form letter. The Compare table above gets you most of the way there in about four minutes.

Line 7 is the one worth stopping on. Here is the half of it we do write, because this half is ours: tell the named person the same day, and nobody is in trouble for telling. That sentence is doing more work than anything else on the page.

What happens next, though, is a rule about a person rather than a rule about a tool, and we have never written one into a client's page. Not out of caution. It's that a consequence written by somebody who doesn't work there reads exactly like what it is, and the page's whole job is to make asking easy.

One more, and then this section is over. If the page is heading into a handbook, an employment agreement, or anything your people put a signature on, whoever owns your handbook reads it before that happens. Not because the page is dangerous. Because a signed document and a pinned-up document are not the same object, and only one of them is what we build.

What the page can't tell you

Here's the limit of the thing you just copied.

It says what's allowed. It doesn't tell you whether anybody reads AI output before a customer sees it. It doesn't tell you whether the work it describes is written down anywhere. You can have a flawless policy sitting on top of a business where neither of those is true, and that business is in worse shape than it looks on paper.

The free AI readiness check asks twenty questions, one tap each, about four minutes. Your finding and all five areas show up on screen when you finish. Two of the five are documentation and checking, and a policy can't close either one.

Figure 2 / Boundary

A page settles what is allowed and cannot settle whether anybody does it.

What the page can't close

Settled

  • Which tools are allowed

    The approved list, with a date on every addition.

  • What never goes in

    It changes by trade.

  • Who to ask

    Asking is always fine. Guessing isn't.

  • What gets checked before it leaves

    Prices, dates, measurements and promises.

  • What you say when a customer asks

    Answer honestly.

Still open

  • Whether anybody reads the output

    Before a customer sees it.

  • Whether the work is written down anywhere

  • The consequence line

    That one belongs to the owner. It is the only line we will not draft.

  • Whether a vendor's compliance claim is true

    Ask for it in writing, with the regulation named.

The lineA rule is real when a person is named and the output gets checked.

RunSimpler

What to do with the page once it's written

Three moves, in order, and the first one is the one that decides whether the other two matter.

Read it out loud at a Monday morning meeting. Not emailed. Out loud, and then stop talking and let people argue about line 3. The person who argues is usually the person who was about to paste something, which is exactly the conversation you wanted.

Pin it where the work happens. Break room, van, front desk. Not a shared drive, because a policy in a folder is a policy nobody has read.

Then teach the two lines that need judgment. Line 3 and line 4 are the ones people get wrong in good faith, and a page nobody understands is a page nobody follows. There's a first-month plan for that in how to get a small team using AI properly.

And if the real problem turns out to be that the procedure only exists in one person's head, the page can wait. Start with writing the work down instead, because a rule about a process nobody can describe is a rule about nothing.

Figure 3 / Sequence

Three moves in order, and the first one is reading it out loud to people who can argue with it.

What to do with the finished page

  1. Read it out loud at a Monday meeting

    Not emailed. The person who argues is the person who was about to paste something.

  2. Pin it where the work happens

    Break room, van, front desk.

  3. Teach the two lines that need judgment

    Lines 3 and 4 are the ones people get wrong in good faith.

RunSimpler

The part you can do without us

We train teams on exactly this. We build the check into the process. Or we run it for you. Those are the three routes, and this page is free either way.

The policy itself you can do this afternoon without us, and you should. What's worth paying somebody for is the thing after it, which is whether anybody actually does what the page says.

Questions and answers