Plainstart Back to the kit

Article

Free AI Policy Template: What to Include and How to Use One

If you run a business and your team uses AI tools, you need a written AI policy. This article explains what a good one covers, who needs one, and how to adapt a template to your situation.

Why a Written Policy Matters

Most small businesses have no written rules around AI use. Staff make their own decisions about which tools to use, what data to paste in, and what output to publish. That is not a criticism. It is simply what happens when no one has written anything down.

The problem is exposure. Confidential client data pasted into a public AI tool. A contract drafted by a chatbot and sent without review. A job rejection that turns out to be partly automated. These are not hypothetical situations. They are happening now, in businesses of every size.

A written policy does three things. It sets clear expectations for staff. It reduces the risk of accidental data exposure or legal misstep. And it gives you a record that you took reasonable steps to govern AI use, which matters if something goes wrong.

A policy does not need to be long. It needs to be specific and actually used.


Who Needs an AI Policy

You need one if any of the following is true.

  • Your staff use AI tools at work, even informally.
  • You handle personal data belonging to clients, customers, or employees.
  • You work in a regulated sector such as finance, healthcare, legal services, or education.
  • You have clients who ask about your data handling practices.
  • You produce written content, code, or analysis that goes out under your name.

The size of your business does not change this. A five-person agency that handles client data has the same exposure risk as a fifty-person firm. The policy just looks different in scale and complexity.


What a Good AI Policy Includes

A useful AI policy covers seven areas. Here is what each one should do.

1. Scope

State clearly which tools and which people the policy covers. Named tools you have approved. A process for requesting approval of new ones. Whether contractors and freelancers are included.

A vague scope is almost useless. "All AI tools" without a list leaves staff guessing. Name the tools your team currently uses and note that any new tool requires sign-off before use.

2. Permitted and Prohibited Uses

Be specific about what staff can do with AI tools. Drafting internal documents is usually fine. Pasting in a client's personal data usually is not. Automating a hiring decision without human review is a clear no.

List a few examples in plain language. Do not try to cover every scenario. Cover the most common ones and add a default rule for everything else: "If you are unsure, ask before using."

3. Data Rules

This is the section most templates miss or handle badly. It should answer these questions plainly.

  • What categories of data must never be entered into an AI tool? (Personal data, client-confidential information, commercially sensitive material.)
  • Which tools have been reviewed for data storage and processing practices?
  • Does the tool use your input to train its model? (Many free-tier tools do. Business tiers often do not.)

Check the terms of service for each tool you approve. Note the relevant finding in the policy or in a separate data governance document. This is not something to guess at.

4. Human Review Requirements

State which outputs require human review before use. This should be a firm rule, not a suggestion. AI tools produce confident-sounding errors. A human who understands the context needs to check the output before it goes to a client, gets published, or influences a decision.

Be specific. "All client-facing content must be reviewed and approved by a named staff member before sending." That is a rule. "Please review AI output carefully" is not.

5. Disclosure Rules

When must you tell someone that AI was used? Your policy should give a clear answer. Some sectors have legal or regulatory requirements here. Beyond compliance, there is a straightforward honesty question: if a client would reasonably want to know, you should probably tell them.

Set a default position and note any sector-specific exceptions you are aware of. Take professional advice if you are unsure what your sector requires.

6. Intellectual Property and Ownership

AI output is not automatically yours to use freely. Ownership rules vary by tool, jurisdiction, and context. Your policy should acknowledge this and require staff to check the terms of any tool before publishing output commercially.

A conservative default: treat AI output as a starting draft that a human substantially revises, rather than finished work you own outright.

7. Breach and Review

What happens if someone breaks the rules? A policy without consequences is a suggestion. You do not need a heavy disciplinary framework. You do need a sentence that says breaches will be addressed under your existing conduct policy.

Also state when the policy will be reviewed. AI tools change fast. A policy written today may need updating in six months. Set a review date, assign a named owner, and stick to it.


How to Adapt a Template

A template gives you structure. It does not give you a finished policy. Here is how to turn one into something your business can actually use.

Step 1. Read the whole template before editing anything. Understand what each section is trying to do. Some clauses will be irrelevant to you. Some will need significant expansion.

Step 2. List the AI tools your team currently uses. Go section by section through the template with that list in hand. Name specific tools where the template has placeholders. Remove sections that do not apply.

Step 3. Fill the data rules section carefully. Check the terms of service for each tool you have listed. Note whether your data is used for training, whether it is retained, and where it is processed. If you handle personal data under GDPR or a similar framework, take advice from a qualified professional on what your obligations are. This article is general guidance and does not constitute legal or compliance advice.

Step 4. Write the permitted and prohibited uses in your own words. Copy the structure, not the language. Write examples that your staff will recognise. "Do not paste client contact lists into any AI tool" is clearer than "avoid inputting personally identifiable information into unapproved systems."

Step 5. Put a named person against each responsibility. Who approves new tools? Who handles a breach? Who owns the next review? Unnamed responsibilities do not get actioned.

Step 6. Send a draft to two or three people who will use it. Ask them to read it and flag anything unclear or unworkable. A policy your staff find confusing will not be followed.

Step 7. Publish it, brief your team, and set a review date. A policy that stays in a folder is not a policy. Brief staff verbally when you publish it. Keep the document somewhere they can find it.


Common Mistakes in AI Policies

Too long, too vague. A five-page policy full of legal-sounding language that nobody reads achieves nothing. Keep it short enough to read in ten minutes.

No data rules. Many template policies focus on outputs and ignore inputs. The data you put into an AI tool is often the higher-risk area.

No human review requirement. Stating that staff "may use AI tools responsibly" and leaving it there puts all the risk on staff judgment. Specify where human review is mandatory.

Set and forget. A policy written in 2023 and never updated is likely to be out of date. Tools change. Regulations are catching up. Build in a review cycle.

Not actually distributed. Write it, brief on it, and make it findable. All three.


Get the Free Plainstart AI Usage Policy

Plainstart publishes a free AI Usage Policy template written in plain language for small and medium businesses. It covers all seven sections above, with guidance notes on how to adapt each one.

You can download it at no cost. No credit card, no sales call.

If you want more than a policy, the Plainstart AI Adoption Kit ($149) includes a data governance checklist, 90-day adoption plan, tool scorecard, prompt libraries, ROI tracker, and a staff one-pager alongside the policy. The prompt libraries are also available separately for $39.

Download the free AI Usage Policy from Plainstart

AI adoption, done properly.


Frequently Asked Questions

Is a free template good enough, or do I need a lawyer? A well-written template is a reasonable starting point for most small businesses. If you operate in a regulated sector, handle significant volumes of personal data, or have clients with specific contractual requirements, take professional advice. The template gives you a working document. A qualified professional tells you whether it is sufficient for your specific situation.

Does an AI policy need to be a separate document? Not necessarily. Some businesses add AI rules to an existing acceptable use or IT policy. Either approach works. The important thing is that the rules exist, are written down, and staff know where to find them.

How often should we update it? Review it at least once a year. Also review it when you adopt a significant new tool, when a relevant law or regulation changes, or when something goes wrong.

What if we are a very small team, say two or three people? Keep it short. A one-page document covering the seven areas above is enough. The goal is not a comprehensive compliance manual. The goal is shared, written expectations.

Do contractors need to follow the same policy? If they are doing work for you and accessing your systems or your clients' data, yes. Include a line in your contracts requiring compliance with your AI policy, and make sure they have actually seen it.


This article is general business guidance only. It is not legal, compliance, or professional advice. If you need advice specific to your business, your sector, or your data obligations, consult a qualified professional.

Free download

The AI Usage Policy your team can actually follow

One page, plain language, ready to put in front of staff today. No cost, no catch.

Get the free policy