Plainstart Back to the kit

Article

Why Your AI Policy Should Fit on One Page

A twenty-page AI policy is not a policy. It is a filing exercise. It sits in a shared drive, it gets forwarded to new starters, and it does not change how anyone in your business uses AI on a Tuesday afternoon.

If someone handed you a twenty-page document and asked you to enforce it, this article is for you.


The Problem Is Not the Content. It Is the Format.

Compliance research on workplace policy consistently finds the same pattern: documents longer than two pages are rarely read in full by the people they are meant to govern. People skim the first section, skip the definitions, and stop before the appendices. Then they do what seems reasonable in the moment.

This is not a criticism of your staff. It is how humans process documents that feel like they were written for lawyers rather than for them.

An AI policy that nobody reads does not reduce your risk. It creates a paper trail that suggests you tried, while the actual behavior in your business runs on informal habit and guesswork.

A one-page policy gets read. It gets pinned to noticeboards. It gets pasted into onboarding emails. It gets referenced in the moment someone is unsure. That is the only version of a policy that changes behavior.


What Enterprise Policies Get Wrong for Small Businesses

Enterprise AI policies are written by legal and compliance teams for organizations with dedicated data protection officers, procurement review panels, and IT departments that audit software deployments. They include:

  • Vendor approval workflows that assume a technology committee exists
  • Data classification frameworks requiring trained staff to apply them
  • Liability carve-outs written in the passive voice to protect the organization from its own employees
  • Definitions sections that run four pages before the rules even begin
  • Appendices covering edge cases that apply to one division of a multinational

None of that is wrong for the context it was written for. It is completely wrong for a ten-person accountancy firm, a regional logistics company, or a marketing agency with two AI enthusiasts and eight skeptics.

When a small or medium business inherits or copies an enterprise policy, it absorbs the weight without the infrastructure. The clauses that require a data protection officer to sign off become meaningless. The vendor approval process gets quietly ignored because there is nobody to run it. And the business is left with a document that implies governance without providing any.


What Actually Belongs on One Page

A single-page AI policy for a small or medium business needs to answer five questions clearly. Every clause earns its place by answering one of them.

1. What tools are approved? Staff need to know whether they can use ChatGPT, Claude, Gemini, or others, and under what conditions. A simple list with a note about how to request approval for a new tool covers this.

2. What must never go into an AI tool? This is the highest-stakes clause. It should name specific categories: client names and contact details, financial records, passwords and credentials, unpublished contracts, personal health information. Vague phrases like "confidential information" do not work. People disagree about what counts as confidential. Specific categories remove the ambiguity.

3. Who is responsible for reviewing AI output before it is used? The answer is always the person using it. State that plainly. AI output must be checked by the staff member before it is sent, published, or acted on. Errors are the responsibility of the person who used the output, not the tool.

4. What happens if something goes wrong? One line is enough: report it to the named person or role, and describe what you used and what the output was. That is the whole incident process at this scale.

5. When does this policy get reviewed? Quarterly works for most businesses. Set a date and name a person. Without this, the policy becomes outdated within months and loses credibility faster than it gained it.

Five answers, one page. Everything else is overhead.


Before and After: One Clause, Reduced

Here is an example of how this works in practice.

Before (from a typical inherited enterprise policy):

"Personnel must ensure that all information assets classified as Confidential or above, as defined in Schedule 3 of the Information Security Policy (version 2.1), are not inputted into any third-party generative artificial intelligence system unless such system has been formally assessed and approved through the Technology Risk Assessment Process as documented in the Vendor Management Framework, and a data processing agreement compliant with applicable data protection legislation has been executed with the relevant vendor. Breaches of this clause must be reported to the Chief Information Security Officer within 24 hours of discovery."

That is 92 words. It requires the reader to locate Schedule 3, understand what "Confidential or above" means in your classification system, know what the Technology Risk Assessment Process involves, and know who the Chief Information Security Officer is. In a business without a CISO, the clause becomes unenforceable on arrival.

After (one usable line):

"Do not paste client data, passwords, financial records, or unpublished contracts into any AI tool. If you are unsure whether something is sensitive, treat it as sensitive and ask [name or role] first."

That is 35 words. Any member of staff can read it, understand it, and apply it immediately. The behavior it produces is identical to the behavior the 92-word version was trying to produce.


What Belongs Behind the One-Pager

Cutting to one page does not mean discarding everything else. Some content genuinely needs more space. It just should not live in the front-facing policy.

A supporting document, linked from the one-pager, can hold:

Tool assessments. Notes on why each approved tool was chosen, what data processing agreement is in place, and what the renewal date is. This is reference material, not operating guidance.

Incident log template. A structured form for recording what happened when AI output caused a problem. This protects the business and helps identify patterns.

Prompt guidance by role. Specific examples of good and poor prompts for the roles in your business. This is training material, not policy.

Review history. A simple record of who reviewed the policy, when, and what changed. This matters for compliance purposes without needing to be read regularly.

Data protection notes. A brief explanation of how your AI use sits within your broader data protection approach. This is for your own reference and for any external audit.

Keep this document internal, keep it linked, and keep it short. Its job is to support the one-pager, not to replace it.


How to Cut an Inherited Policy Without Losing What Matters

If you have a twenty-page policy and need to reduce it, work through it clause by clause with one question: does this change what a staff member does tomorrow?

If the answer is yes, find the simplest version of that instruction and keep it.

If the answer is no because it describes a process that does not exist in your business, set it aside into the supporting document or remove it.

If the answer is no because it is a legal disclaimer rather than an instruction, move it to a footer or a legal notice rather than the operating policy.

You will find that most of the length disappears quickly. Definitions sections, recitals, approval workflows for non-existent committees, and cross-references to other policies you do not have: all of that can go. What remains is usually five to eight plain instructions that fit on a page.

Read the result aloud. If it sounds like a policy written for your business, it probably is.


A Policy Your Business Will Actually Use

The goal of an AI policy is not to exist. It is to change how people behave. A document that changes behavior has to be read, understood, and remembered. At twenty pages, none of those things happen reliably. At one page, they can.

If you want a starting point rather than a blank page, the Plainstart AI Usage Policy is free. It is written in plain language, fits on one page, and is designed for small and medium businesses rather than enterprise legal teams.

Download it at [plainstart.com]. General guidance, not professional advice. Review it with your own legal or compliance adviser if your situation requires it.


Plainstart. AI adoption, done properly.

Free, no email required

Build your own AI usage policy in about two minutes

Answer eight questions and the full policy writes itself around your business. Copy it, download it, put it in front of staff today.

Open the policy generator