Company AI Policy: What to Include + a Free Template for SMBs

In this article:
- Why Every SMB Needs an AI Policy Now
- What an AI Policy Is (and Where It Fits)
- What a Company AI Policy Should Cover
- Shadow AI: The Risk Your Policy Has to Address
- AI Data Privacy Rules for the Workplace
- How to Build and Maintain an Approved AI Tools List
- Free AI Policy Template for Small Business
- Three Example AI Policies by Scenario
- How to Roll Out Your AI Policy Without Resistance
- Keeping Your AI Policy Current
- Frequently Asked Questions
- Where to Go From Here
TL;DR: Your employees are already using AI: 78% of workers who use AI on the job bring their own tools rather than waiting for approved options. A written AI policy is what determines whether that use is safe productivity or invisible data leakage. A complete policy needs ten core components, from an approved tools list to data rules and enforcement, and the free template below covers them in plain language you can roll out this week.
According to Microsoft’s 2024 Work Trend Index, 78% of employees who use AI at work are bringing their own tools rather than using options their employer has vetted and approved. That number includes businesses with no policy at all and businesses where a policy exists on paper but was never communicated.
If your business doesn’t have a written AI policy, your employees are already making decisions: which AI tools to use, what data to input, and how to apply the outputs. Some of those decisions are benign. Others are silently exposing client data, violating confidentiality agreements, or creating compliance liability your business doesn’t know exists yet.
This article covers every component a company AI policy needs, flags the risks most SMB owners overlook, and closes with a free, editable template you can adapt and roll out this week.
Why Every SMB Needs an AI Policy Now
AI adoption has outpaced governance at virtually every organization that hasn’t actively gotten in front of it. Employees are already using ChatGPT, Microsoft Copilot, Google Gemini, and a growing catalog of AI-powered browser extensions, with or without IT approval. A written policy doesn’t change human behavior on its own, but it creates something essential: a documented standard your business can actually enforce.
Without that standard, you have no basis to act when an employee pastes a client contract into a consumer AI tool and the data leaves your environment. You cannot enforce what you haven’t defined.
SMBs face the same legal and compliance exposure as enterprises when a data incident occurs, but typically lack the in-house legal team or dedicated security staff to absorb the consequences. A single unauthorized disclosure of protected health information or nonpublic personal information can trigger regulatory action, breach notification obligations, and client-relationship damage. At a 50-person business, those consequences hit differently than they would at a large corporation.
A well-built AI policy does not block your team from using the tools that make them more productive. It channels that use: defining approved applications and protecting the business at the same time. Cyber insurers and regulators are already treating AI governance as a baseline expectation, not an advanced practice. A written policy is also step one of integrating AI into your business safely.
What an AI Policy Is (and Where It Fits)
A company AI policy is a written standard that defines which AI tools employees may use, for which tasks, with which data, and who is accountable for the output. It is not a separate governance universe. If your business already maintains an acceptable use policy for company technology, the AI policy is the next chapter of the same book: same enforcement mechanisms, same disciplinary procedures, applied to a category of tools that moves faster and touches more data than anything your AUP was written for.
What earns AI a standalone document is scope. These tools generate output your business acts on, which raises review, ownership, and disclosure questions a standard acceptable use policy never had to answer. Cross-reference the two documents, keep them in the same section of the employee handbook, and hold them to the same signature requirement.
What a Company AI Policy Should Cover
A complete AI policy addresses more than an approved tools list. These are the core components every business needs to include:
- Purpose and scope. Define which employees, which tools, and which business functions the policy governs. A policy that doesn’t define its own scope is unenforceable.
- Approved and prohibited uses. Specify the categories of tasks where AI is permitted (drafting internal communications, summarizing meeting notes, internal research) versus prohibited (inputting personally identifiable information, generating client-facing legal documents, making autonomous hiring decisions).
- Data handling rules. List the data types that may never be submitted to external AI tools: client information, financial records, protected health information (PHI), and trade secrets.
- Confidentiality and IP ownership of AI output. State that work product created with AI assistance on company time belongs to the business and carries the same confidentiality obligations as anything else an employee produces.
- Accountability standards. Define who reviews AI-assisted outputs before they reach clients or inform business decisions. “The AI generated it” is not a defensible review process.
- Disclosure rules. Define when clients, partners, or regulators are told that a deliverable was produced with AI assistance, and name who makes that call.
- Security requirements. Require company-provisioned accounts and multi-factor authentication for approved AI tools. A vetted tool accessed through an unsecured personal login is still an exposure.
- Compliance alignment. Map the policy to your existing obligations under HIPAA, the FTC Safeguards Rule, or PCI DSS. Businesses that already work with IT compliance services can treat the AI policy as an extension of existing data governance rather than a separate system to build from scratch.
- Consequences for violations. A policy without a defined disciplinary framework is a suggestion, not a standard.
- Review cadence. Schedule a review at minimum annually to revisit approved tools and update rules as AI capabilities and regulatory guidance evolve.
Shadow AI: The Risk Your Policy Has to Address
Shadow AI refers to AI tools employees install or use independently, without IT knowledge or approval. It’s the direct analog of shadow IT, and it’s already operating inside most organizations.
The exposure scenarios are concrete:
- An employee uses a personal ChatGPT account on a work laptop to summarize a client proposal.
- Someone pastes financial records into a free AI tool to build a spreadsheet faster.
- A browser extension with embedded AI connects to an external model provider without the user’s awareness.
In each case, data leaves your environment and enters a third-party system your business never evaluated.
A policy that only lists approved tools is insufficient. It must explicitly define what constitutes unauthorized AI use and set clear expectations about personal AI accounts on company devices. Violations also need a defined process: how they’re identified and how they’re handled.
Include a reporting mechanism. Employees who discover they have already used an unapproved tool need a clear path to self-report without facing immediate discipline. That mechanism surfaces risk before it becomes a breach, turning the policy from a static document into an operational safety net.
AI Data Privacy Rules for the Workplace
The most critical distinction your policy needs to establish is between internal AI tools and external ones. Internal tools, deployed within your managed environment, keep data in-network. External tools, which cover the majority of consumer and SaaS AI products, send prompts and data outside your organization’s control the moment an employee submits a query.
Your policy should explicitly prohibit submitting personally identifiable information, PHI, financial account data, or client-confidential content to any external AI tool not covered by a signed data processing agreement. That prohibition needs to be specific enough that an employee can apply it without calling IT to ask.
According to OpenAI’s data controls documentation, consumer-tier AI tools such as ChatGPT retain user prompts and use them for model training by default unless the user actively opts out. Employees need to understand that what they type into a free tool does not disappear when they close the browser tab.
If your business already has a data classification policy, cross-reference it in the AI policy. AI input restrictions should mirror the data handling tiers your team already works with. For regulated organizations, the liability is specific:
- HIPAA-covered entities face direct exposure when PHI reaches an external AI tool. The HIPAA Security Rule applies to AI tools just like any other system that touches PHI.
- FTC Safeguards-regulated businesses (including auto dealers, financial services firms, and certain law firms) face the same risk with nonpublic personal information.
How to Build and Maintain an Approved AI Tools List
The approved tools list is where policy becomes operational. Work through these steps to build and sustain one that holds up:
- Survey your team before drafting. Ask employees what AI tools they currently use. The results typically reveal shadow AI adoption already underway and give you a realistic baseline rather than an aspirational list no one is actually using.
- Evaluate each candidate against three criteria. Check the provider’s data handling terms (does the tool train on user inputs by default?), access controls (can your company enforce single sign-on or role-based permissions?), and vendor security posture (SOC 2 Type II, ISO 27001, or equivalent certification).
- Scope each approval to specific use cases. A tool approved for drafting internal communications is not automatically approved for processing client financial data. Tie each approval to a defined context and document it.
- Connect the tools list to your device program. Employees accessing approved AI tools from unmanaged personal devices creates a security gap even when the tool itself is vetted. A hardware as a service arrangement or managed device program closes this by ensuring AI activity happens on company-controlled endpoints.
- Assign a single accountable owner. Whether that’s your IT lead, office manager, or outside IT partner, someone needs to own updating the list when employees request new tools or approved vendors modify their data terms.
Free AI Policy Template for Small Business
The template below is written in plain language for businesses without in-house legal counsel or a dedicated HR specialist. Copy it into a document, fill in the bracketed fields, and require employee signatures before distributing.
A note for regulated industries: Businesses in healthcare, financial services, and legal should have legal counsel review the final policy before it goes into the employee handbook or is distributed to employees.
[COMPANY NAME]: Artificial Intelligence (AI) Acceptable Use Policy
Policy Version: [1.0] | Effective Date: [MM/DD/YYYY] | Last Reviewed By: [Name, Title]
1. Policy Purpose
This policy establishes guidelines for the responsible use of artificial intelligence tools by [Company Name] employees, contractors, and vendors. Its purpose is to protect company data, client confidentiality, and regulatory compliance while allowing employees to benefit from AI-assisted productivity.
2. Scope
This policy applies to all employees, contractors, and third-party vendors who access [Company Name] systems, data, or client information, regardless of device or location.
3. Definitions
- AI tool: Any software application that uses machine learning or generative AI to produce text, code, images, analysis, or decisions in response to user input.
- Generative AI: AI systems that generate new content from user prompts. Common examples include large language models such as ChatGPT, Microsoft Copilot, and Google Gemini.
- Shadow AI: Any AI tool used by an employee without IT knowledge or formal approval.
- External AI tool: Any AI tool that processes prompts or data outside the company’s controlled network environment.
4. Approved Uses
Employees may use AI tools for the following tasks, provided they use only IT-approved tools and do not input restricted data types:
- Drafting and editing internal communications and documents
- Summarizing meeting notes or internal research materials
- Writing, reviewing, or debugging non-client-facing code or scripts
- [Insert additional approved use cases relevant to your business here]
5. Prohibited Uses
Employees may not use any AI tool, approved or otherwise, to:
- Input personally identifiable information (PII), protected health information (PHI), or financial account data into any external AI tool not covered by a signed data processing agreement
- Input client-confidential information, trade secrets, or proprietary business data into any external AI tool
- Present AI-generated content to clients, partners, or regulators as human-authored without documented review and approval
- Make hiring, termination, or performance evaluation decisions based solely on AI-generated outputs
- Use personal AI accounts (e.g., a personal ChatGPT subscription) on company-issued devices or for any company-related work
6. Data Privacy and Confidentiality Rules
The following data types are prohibited from submission to any external AI tool under any circumstances:
- Client names, contact information, account numbers, or financial records
- Protected health information (PHI) as defined under HIPAA
- Nonpublic personal information (NPI) as defined under the FTC Safeguards Rule
- Employee records, payroll data, or HR documentation
- Trade secrets, unreleased product information, or proprietary processes
Employees should assume that any prompt entered into a consumer-tier AI tool may be retained by the provider and used for model training, regardless of the provider’s default settings. [Cite the compliance framework applicable to your industry, e.g., HIPAA, FTC Safeguards Rule, PCI DSS.]
7. Approved Tools List
The following tools are approved for the use cases and roles specified. Use of any AI tool not on this list requires prior written approval from [IT lead/manager name].
| Tool Name | Approved Use Cases | Approved Roles | Data Restrictions |
|---|---|---|---|
| [Tool Name] | [e.g., Drafting internal documents] | [e.g., All staff] | [e.g., No client data, no PII] |
| [Tool Name] | [Use Cases] | [Roles] | [Restrictions] |
8. Accountability and Output Review
All AI-generated content used in client deliverables, business decisions, regulatory submissions, or external communications must be reviewed and approved by [designated role or manager title] before use. The employee who submits the output is responsible for its accuracy and appropriateness, regardless of the source.
9. Disciplinary Framework
Violations of this policy may result in disciplinary action up to and including termination, consistent with [Company Name]’s existing disciplinary procedures. Violations that result in a data breach, regulatory notification obligation, or client contract breach will be escalated to [legal counsel/senior management] immediately.
Employees who become aware of an accidental policy violation, including their own, should report it to [IT contact or manager] promptly. Self-reporting will be taken into account in any disciplinary determination.
10. Policy Review and Version Control
This policy will be reviewed no less than [annually / every six months for the first year of implementation]. The next scheduled review date is [MM/DD/YYYY]. Questions about this policy should be directed to [IT lead/manager name or email address].
11. Confidentiality, Ownership, and Account Security
- All work product created with AI assistance in the course of employment is the property of [Company Name] and is subject to the same confidentiality obligations as any other company material.
- Client deliverables produced with AI assistance must be flagged to [designated role or manager title], who determines whether disclosure to the client is required.
- Approved AI tools must be accessed through accounts provisioned and managed by [Company Name], protected by multi-factor authentication where the tool supports it. Personal accounts may not be used for company work (see Section 5).
Employee Acknowledgment
By signing below, I confirm that I have received, read, and understood the [Company Name] Artificial Intelligence (AI) Acceptable Use Policy, and I agree to comply with its terms.
Print Name: ____________________
Signature: _____________________ Date: ___
Three Example AI Policies by Scenario
The same template produces very different policies depending on your risk profile. Three common postures:
The locked-down professional-services firm. A 30-person accounting or law firm handling client financials approves a single AI tool inside its managed environment and prohibits every external tool outright. No client data enters any AI tool, period. Every AI-assisted deliverable is flagged to the engagement lead before it ships, and legal counsel reviews the policy at each six-month cycle. Restrictive, but defensible: the firm can tell any client or regulator exactly where AI sits in its workflow.
The pragmatic mainstream SMB. A 50-person company approves two or three tools for drafting, summarizing, and internal research. Hard data rules: no client information, no financials, no employee records in any external tool. Manager review for client-facing output, a self-report path for accidental violations, and a six-month first review before moving to annual. This is the posture the template above defaults to.
The AI-forward shop. A marketing agency or software firm approves a broader list scoped by role, runs a fast-turnaround request process for new tools, and writes AI disclosure terms directly into client contracts. The trade for wider access is tighter accountability: documented human review on every client deliverable and more frequent tools-list updates, because this team adopts new tools faster than the other two profiles.
How to Roll Out Your AI Policy Without Resistance
A policy your team doesn’t understand rarely gets followed. These steps make rollout straightforward:
- Lead with the rationale, not the rules. Before distributing the document for signatures, explain the data privacy and compliance exposure behind it. Employees who understand why the policy exists follow it more consistently than those handed a form to sign without context.
- Add it to the employee handbook and new-hire onboarding. The AI policy belongs alongside your existing acceptable-use and data security policies, not as a standalone document that gets filed and forgotten.
- Require a signed acknowledgment. This creates a documented record that each employee received and read the policy, which matters if a violation occurs.
- Run a short training session. 15 to 30 minutes built around real scenarios: what employees can do with approved tools, what they cannot, and who to ask when they are unsure. Fold it into your existing security awareness training cadence.
- Create a formal request path for new tools. Giving employees an official channel to submit tool requests reduces shadow AI. It replaces the instinct to “just use it” with a structured alternative that surfaces needs before they create risk.
- Assign ongoing governance to an accountable owner. For businesses without an in-house IT director, virtual CIO services provide the governance infrastructure the policy requires: annual reviews, tool evaluations, and compliance alignment updates as regulations develop.
- Plan a six-month first review. AI tool terms, capabilities, and regulatory guidance are changing fast enough that waiting a full year for the first review leaves the policy stale. Review at six months, then move to annual once the program stabilizes.
Keeping Your AI Policy Current
The review cadence from the rollout plan (six months for the first review, then annually) handles routine drift. Four events should trigger an off-cycle update:
- An approved provider changes its data terms. Re-check the tools list and data rules against the new terms before continued use.
- A new tool category shows up in employee requests. Repeated requests for something the policy doesn’t address, like AI meeting recorders or coding assistants, mean the policy has a gap, not the employees.
- New regulatory guidance lands affecting HIPAA, the FTC Safeguards Rule, or your industry’s compliance framework.
- A violation or near-miss is self-reported. Every report is free intelligence about where the policy is unclear or unrealistic. Update the language, not just the discipline log.
When a material change happens, increment the version number, re-circulate the policy, and collect fresh acknowledgments. An outdated signature on an outdated version protects no one.
Frequently Asked Questions
What should a company AI policy include?
Ten core components: purpose and scope, approved and prohibited uses, data handling rules, confidentiality and IP ownership of AI output, accountability and output review standards, disclosure rules, security requirements, compliance alignment, consequences for violations, and a review cadence. The data rules are the heart of it: client information, PHI, and financial records never enter external AI tools.
Do small businesses need an AI policy?
Yes. 78% of employees who use AI at work bring their own tools, and SMBs face the same legal and compliance exposure as enterprises when data leaks, without the in-house legal or security staff to absorb the consequences. You cannot enforce what you haven’t defined, and a written policy is the documented standard that makes enforcement possible.
What is an AI acceptable use policy?
A written document that defines which AI tools employees may use, for which tasks, with which data types, and what happens when the rules are violated. It is the AI-specific extension of the standard acceptable use policy most businesses already maintain, and it belongs in the employee handbook alongside your existing data security policies.
Can employees use ChatGPT for work?
Yes, within defined limits. Consumer-tier ChatGPT retains prompts and uses them for model training by default unless the user opts out, so client information, PHI, and financial data must stay out of it. Most SMB policies permit approved accounts for internal drafting and research while prohibiting personal ChatGPT accounts on company devices.
Who should own the AI policy in a small business?
One accountable person: your IT lead, office manager, or outside IT partner. The owner maintains the approved tools list, fields new tool requests, and runs the review cadence. Businesses without an in-house IT director typically assign ownership to a virtual CIO or managed IT provider, because the policy goes stale quickly without a named owner.
Where to Go From Here
When an AI policy is working, the picture is clear. Your team moves faster on legitimate work, client data stays where it belongs, and you have a governance framework ready when cyber insurers, clients, or regulators ask. That outcome is achievable for a 50-person company with a clear policy, a maintained tools list, and consistent enforcement.
LeadingIT provides managed IT and cybersecurity services to businesses across the Chicagoland area. That includes compliance alignment, vCIO guidance, and the managed device infrastructure that makes AI governance enforceable at the endpoint level. We work with SMBs that need more than a template: they need the technical foundation to back it up.
AI governance is one component of your overall security posture. Schedule a free Cyberscore assessment to see exactly where your organization stands across every major risk category. You’ll leave with a prioritized action plan you can act on immediately.



