Plainstart Back to the kit

Article

How to Write an AI Policy for Your Business

A plain, step-by-step guide for small and medium businesses that want to use AI without the guesswork.

AI tools are already inside most businesses, whether management has approved them or not. Staff use ChatGPT to draft emails, Grammarly to edit reports, and Copilot to summarise meetings. Without a written policy, you have no way to set expectations, protect client data, or stay on the right side of your obligations.

This guide walks you through how to write an AI policy for your business, section by section. It covers what to include, what to leave out, and the mistakes that make most policies useless the moment they are published.

This article is general business guidance only. It is not legal, compliance, or professional advice. If your business operates in a regulated industry, or handles sensitive personal data at scale, get a qualified professional to review your final policy.


What an AI Policy Actually Is

An AI policy is a short, written document that tells your team three things:

  1. Which AI tools they are allowed to use, and for what
  2. What information they must never put into an AI tool
  3. What to do when something goes wrong

That is it. A good AI policy is not a legal manifesto. It is not a philosophy statement. It is a practical document that a new staff member can read in ten minutes and actually follow.

Target length: 600 to 1,200 words for most small and medium businesses. If yours runs to 4,000 words, it will not be read.


Before You Start Writing

Do two things before you open a blank document.

Talk to the people who do the work. Ask staff which AI tools they are already using, what they use them for, and what they are unsure about. You will find things you did not expect. That information shapes your policy far better than a generic template can.

Write down your actual risk areas. Every business is different. A law firm has different risks to a marketing agency. A medical clinic has different obligations to a software company. List the types of data you handle, the clients you serve, and any regulatory requirements that apply to you. Your policy needs to address your situation, not a hypothetical average business.


The Sections to Include

1. Purpose and Scope

Start with one short paragraph. Say why the policy exists and who it applies to.

Example framing: "This policy applies to all staff, contractors, and freelancers who use AI tools while working for [Business Name]. Its purpose is to set clear expectations about safe and appropriate use."

Scope should specify: employees, contractors, and any third parties who access your systems. If the policy only covers full-time staff, say so, and be aware of the gap that creates.

2. Approved Tools

List the AI tools your business has reviewed and approved. Be specific. "AI tools" is not a useful category. "ChatGPT (GPT-4, browser version), Microsoft Copilot (M365 integration), and Grammarly Business" is useful.

For each tool, note:

  • What it is approved for
  • Any restrictions on how it can be used
  • Whether output must be reviewed before it goes to a client

If a tool is not on the approved list, the default answer should be: ask before using it. Say that explicitly.

3. Data Rules

This is the most important section. Be direct and specific.

State clearly what must never be entered into an AI tool. Common categories for most businesses:

  • Full names combined with contact details, financial information, or health information
  • Client files, case notes, or anything shared in confidence
  • Passwords, API keys, or internal system credentials
  • Commercially sensitive information such as pricing models, acquisition plans, or unreleased product details
  • Any data that belongs to a third party and was shared under an agreement

Also address the question of AI tools that train on your inputs. Some free-tier tools use your prompts to train their models. Staff need to know this and know what it means for the data they enter.

4. Acceptable Use

Describe what staff can use AI for, positively. Do not make this section entirely a list of prohibitions.

Typical approved uses for most businesses:

  • Drafting internal documents, then reviewing and editing them before use
  • Summarising long documents or meeting notes
  • Writing first drafts of marketing copy, then editing for accuracy and tone
  • Research assistance, with the expectation that claims are verified from primary sources
  • Generating code, with the expectation that a qualified person reviews it before deployment

5. Quality and Accuracy Standards

AI tools produce confident-sounding output that is sometimes wrong. Your policy needs to say what standard of checking applies before AI-assisted work leaves the building.

A simple rule that works: anything that goes to a client, gets published, or informs a business decision must be verified by a person who has the knowledge to check it. "The AI said so" is not an acceptable source for client-facing work or decisions with real consequences.

6. Intellectual Property

Two issues to cover. First: who owns content created with AI assistance? Check the terms of service for each tool you use. Ownership rules vary. Second: do not feed someone else's copyrighted material into an AI tool and use the output commercially without understanding the risk. This is an unsettled area of law in most countries. Flag it, and suggest staff check with a professional if they are uncertain.

Note: this is general guidance only. Intellectual property questions specific to your business and jurisdiction need qualified legal advice.

7. Responsibility and Breach

Be clear about who is responsible for AI-assisted work. The person who produces and submits the work is responsible for it, not the tool that helped them.

State what happens if the policy is breached. You do not need to be heavy-handed, but you do need to say something. "Breaches will be treated in line with our existing conduct policies" is enough if you have those in place.

8. Review Date

AI tools change quickly. Set a review date, typically every six to twelve months, and name who owns that review. A policy that has not been looked at in two years is worse than no policy, because it creates false confidence.


Common Mistakes That Make AI Policies Useless

Writing it in legal language. If your staff cannot read it without a dictionary, they will not read it at all. Plain English throughout.

Banning everything as a default. Blanket bans do not stop tool use. They drive it underground, where you have even less visibility. Set real rules for real situations instead.

Ignoring tools that are already in use. If your staff are already using a tool and your policy pretends it does not exist, your policy is disconnected from reality on day one.

No data guidance at all. Many policies address tone and quality but say nothing about what data is safe to enter. The data rules are the most important part. Do not skip them.

One-and-done publication. Publishing the policy once and never returning to it. Set a calendar reminder for your review date before the document is even finalised.

Not telling staff it exists. A policy in a shared drive folder that nobody knows about changes nothing. Brief your team, answer their questions, and make it easy to find.


How Long Will This Take?

For a small business with straightforward operations, writing the first version of an AI policy typically takes two to four hours. That includes the conversation with staff, the draft, and a final read-through.

If you are starting from a clear template, you can cut that time significantly.


Start With the Free Template

Plainstart's AI Usage Policy template is free to download. It follows the structure above, uses plain language throughout, and is designed so that a non-technical business owner can fill it in and have a working policy the same day.

It covers all eight sections in this guide, with guidance notes inside each section explaining what to write and why.

[Download the free AI Usage Policy template]

If you want to go further, the full Plainstart AI Adoption Kit includes a data governance checklist, a 90-day adoption plan, a tool scorecard, prompt libraries, and an ROI tracker. Everything your business needs to bring AI in properly, at $149.

[See the full AI Adoption Kit]


Plainstart is a digital-product brand owned by Sypher Limited. All content on this site is general business guidance only and does not constitute legal, compliance, financial, or professional advice. AI adoption, done properly.

Free download

The AI Usage Policy your team can actually follow

One page, plain language, ready to put in front of staff today. No cost, no catch.

Get the free policy