A ready-to-adapt acceptable-use policy for a small business, covering the clauses that matter: the approved-tool list, the data rule, the verification expectation, disclosure, and the named owner. It is the practical companion to Writing an AI Acceptable-Use Policy.
The template is deliberately short. A policy that fits on a page is a policy people remember, and the objective is compliance rather than documentation.
A policy is a control, not a document. It works when someone owns it and everybody has read it.
Before you use this template
Four things must be specific to your business, because a template cannot supply them.
- The approved-tool list. Named tools, not categories.
- The prohibited-data list. Categories relevant to what your business actually holds.
- The named owner and approver. A person who answers questions, and an executive who approves.
- The review date. Six months from adoption, at most.
Everything else in the template can be adopted largely as written.
Section 1 — Purpose and scope
This policy sets out how [Business Name] permits the use of AI tools in company work. It applies to all employees, contractors and volunteers, and to all work produced on behalf of the business.
It does not replace existing policies on data protection, confidentiality, information security or professional conduct. Where those policies are stricter, they apply.
Section 2 — Approved tools
The following AI tools are approved for company work:
- [Tool name] — approved for [categories of use].
- [Tool name] — approved for [categories of use].
Any other AI tool may not be used for company work without written approval from [Owner Name/role].
Using a personal account for company work is not permitted, including where the tool itself is approved.
Section 3 — Prohibited data
The following must never be entered into any AI tool, including an approved one, unless it has been explicitly approved for that category:
- Client confidential information, and anything covered by a confidentiality agreement.
- Personal or employee data, including contact details, contracts and records.
- Regulated records — financial, health or legal.
- Credentials, keys and access secrets.
- Anything covered by a contractual restriction on processing or sub-processing.
If you are unsure which category applies, treat the material as prohibited and ask [Owner Name].
Section 4 — Verification
AI output is a draft. Before any AI-assisted output is used, a named person must verify:
- Every figure, against the system of record or an identified source.
- Every claim, against evidence.
- Every citation, by opening the source.
- Every commitment, confirming the business can and intends to deliver it.
The check must be recorded — a tick in the checklist, a version note, or an approval in the system.
Section 5 — Disclosure
Where AI assisted in producing work delivered to a client, [state your position: e.g. “the firm may state that AI assisted with drafting and that a named person verified the output”].
Where a contract, a client or a regulation requires disclosure of AI use, follow that requirement.
Where a customer interacts with an AI system directly, [state your position: e.g. “the interaction will be identified as AI-assisted, and a route to a person will be provided”].
Section 6 — Accountability
[Owner Name/role] owns this policy, maintains the approved-tool list, and answers questions about it. The policy is approved by [Approver Name/role].
Where an AI error or incident occurs, report it to [Owner Name] and follow the incident process in [document reference]. Raising a problem is expected, not penalised.
Section 7 — Review
This policy is reviewed at least every six months, and after any material change in the tools used or the regulatory position. Staff will be told of material changes.
Version: [x] · Adopted: [date] · Next review: [date]
How to roll it out
A policy nobody has read is worse than no policy, because it creates the appearance of control without the substance.
- Circulate it with a short note explaining what changes in practice.
- Walk through sections 2, 3 and 4 in a fifteen-minute session, with examples from your own work.
- Confirm receipt, so the business can show that staff were told.
- Put it where the work happens — a link in the tools, a note in the shared drive.
Frequently asked questions
How long should an AI policy be?
About a page. Length is not the measure; whether it is read and applied is.
What must be customized in this template?
The approved-tool list, the prohibited-data list, the named owner and approver, the disclosure position, and the review date.
Who should approve the policy?
An executive, because the policy will eventually constrain someone senior. The day-to-day owner can be anyone reachable and able to update it.
Should the policy ban unapproved AI tools?
It should require approval before use on company work, and prohibit the listed data categories in anything unapproved. An outright ban is usually unenforceable and drives use underground.
How often should it be reviewed?
Every six months, and after any material change in tools or the regulatory position.
Does this make us compliant?
It closes most of the practical risk for a small business. Compliance with specific regulatory or contractual obligations depends on your situation; confirm that with qualified counsel.
Next step
Adapt the seven sections, name the owner and approver, and circulate it with a walkthrough of sections 2, 3 and 4. See Data Security and Confidentiality in AI Tools and AI Disclosure, or book an AI adoption call and we will review your draft.
Sources
- Policy structure reflects the five controls set out in this program: an acceptable-use policy, data rules, verification, tool due diligence and incident response.
- NIST AI Risk Management Framework; EU AI Act; ABA Formal Opinion 512; ICMCI Code of Ethical Conduct — reference frameworks for governance content.
No statistic in this asset is invented. This template is general information, not legal advice; confirm your specific obligations with qualified counsel.