Your team already uses AI. Somebody pasted a client contract into a chatbot last week to get a summary, and nobody asked whether that was allowed. An AI usage policy is not bureaucracy for its own sake; it is the difference between useful adoption and an accidental data leak. Fortunately, one good page beats a forty-page framework nobody opens.
Why an AI usage policy matters now
Three risks arrive together. First, confidentiality: customer data, unreleased figures and material under NDA can leave your control in one paste. Second, quality: a confident, wrong answer sent to a client damages trust far more than a slow reply. Third, obligation — European rules increasingly expect transparency when customers interact with AI, as we set out in our piece on the EU AI Act for small businesses. Meanwhile insurers and enterprise customers now ask whether you have a policy at all.
What to put on the page
- Approved tools, by name. List which assistants are allowed and on which plan, because business tiers usually promise that your inputs are not used for training. Consumer tiers often do not.
- Data that never goes in. Customer personal data, credentials, payment details, unpublished financials, source code you do not own, anything under NDA.
- Where review is mandatory. Anything customer-facing, anything legal or financial, and all code before it merges.
- Disclosure rules. When you tell a client that AI helped, and when a human must be in the conversation.
- Accountability. The person who sends the work owns it — “the AI wrote it” is not a defence.
- A review date. Revisit every six months, because the tools change faster than your handbook.
If you want a structured way to think about risk levels, the NIST AI Risk Management Framework is a sober, vendor-neutral reference. Borrow its structure, not its length.
Make the safe path the easy path
Here is the practical bit most policies miss. If you ban AI without providing an approved tool, people use their personal accounts on their phones, and you lose all visibility. Therefore buy a business plan, add everyone, and say clearly which tasks it is for. Then train the team with real examples from your own work — a good prompt for a quotation, a bad one for a legal clause. As a result, adoption goes up and shadow usage goes down. Our comparison of Claude, ChatGPT and Gemini helps with the choice.
Then extend it to your systems
Chat is only the beginning. Once assistants connect to your tools and can act — the shift we described in the Model Context Protocol — your policy needs two more lines: which systems an assistant may reach, and which actions require a human click. In addition, log those actions, because oversight without records is a feeling rather than a control. The reasoning behind that sits in what AI safety means for your business.
Write the first version this week, keep it to one page, and circulate it for comment rather than approval. A living AI usage policy that people read beats a perfect one filed away. If you would like ours as a starting template, ask us — we will send the version we use ourselves.



