Free Resource

AI Usage Policy Template for Small Business

A concise, copy-pasteable AI usage policy covering all the essentials — data handling, approved tools, human review, client disclosure, incident handling, retention, and ownership. Adapt it in under an hour.

Free to use & adapt 7 sections, ~600 words SMB-focused, plain language
Full Governance Pack — Done For You

Want the full governance pack — risk register + mitigation playbook, done for you in 5 business days?

The AI Policy & Compliance Builder gives you a complete foundation: five policy documents, a risk register identifying the top AI risks for your business, and a client-facing governance pack you can use in sales and compliance conversations. Fixed price, fixed timeline.

Get the AI Policy & Compliance Builder — $299 →

[Company Name] — Internal Policy

AI Usage Policy

Version 1.0 · Effective August 2025 · Owner: Operations Lead

Review annually or after any incident

Purpose. This policy sets out how [Company Name] staff, contractors, and agents may use artificial intelligence (AI) tools in their work. It exists to protect client data, manage operational risk, maintain quality standards, and ensure we can answer questions about our AI usage confidently and accurately.

Scope. This policy applies to all AI tools used for business purposes — including large language models, image generators, coding assistants, and AI-powered SaaS features — whether accessed via a web browser, API, or integrated software.

1.

Data Handling

  • 1.1Only anonymised or synthetic data may be submitted to external AI services unless the vendor has a signed Data Processing Agreement (DPA) in place.
  • 1.2Client personally identifiable information (PII), financial records, and any data covered by an NDA must not be entered into public-facing AI tools (e.g. ChatGPT free tier, consumer chatbots).
  • 1.3Staff who need to use client data with an AI tool must first obtain written authorisation from their line manager and confirm that the tool's DPA or enterprise terms cover the relevant data category.
  • 1.4All data entered into AI systems must be logged with the tool name, purpose, and date. The log must be retained for 12 months.
2.

Approved Tools & Models

  • 2.1Only tools on the Approved AI Tools List (maintained by the Operations Lead) may be used for business purposes.
  • 2.2Consumer or free-tier versions of AI services are approved for non-sensitive, non-client tasks only (e.g. internal drafting, ideation, research summaries).
  • 2.3Enterprise or API-tier versions with a signed DPA are approved for tasks involving business-sensitive information, subject to the data handling rules above.
  • 2.4Staff must not use unapproved AI tools. Requests to add a tool to the approved list must be submitted via the standard software-procurement process.
3.

Human Review Requirements

  • 3.1All AI-generated content that will be shared externally — including emails, reports, proposals, and marketing copy — must be reviewed and approved by a qualified staff member before sending.
  • 3.2AI-generated analysis or recommendations that inform a material business decision (pricing, hiring, contracts, legal matters) must be reviewed by someone with domain expertise before acting on it.
  • 3.3Staff are responsible for the accuracy of any output they use or share, regardless of whether it was AI-assisted.
  • 3.4When AI assistance is material to a deliverable, it should be noted internally so reviewers know to apply appropriate scrutiny.
4.

Client Disclosure

  • 4.1We will disclose AI usage to clients when AI has materially contributed to a deliverable — for example, AI-drafted contract language, AI-generated analysis, or AI-produced content they are paying for.
  • 4.2Disclosure language: "[Company] uses AI-assisted tools to support this work. All AI outputs are reviewed and approved by a qualified team member before delivery."
  • 4.3We will not misrepresent AI-generated work as solely human-produced when asked directly by a client.
  • 4.4Client contracts may include specific AI usage restrictions; staff must check the relevant contract before using AI tools on that account.
5.

Incident Handling

  • 5.1An AI incident is any situation where AI use results in a material error, privacy breach, client complaint, reputational issue, or regulatory concern.
  • 5.2Incidents must be reported to the Operations Lead within 24 hours of discovery.
  • 5.3The Operations Lead will assess impact, determine if client notification or remediation is required, and update the Risk Register.
  • 5.4Root-cause findings from incidents will be used to update this policy and the Approved AI Tools List within 30 days.
6.

Data Retention & Deletion

  • 6.1Prompts and outputs that contain business-sensitive or client data must not be retained in AI tool histories longer than operationally necessary.
  • 6.2Staff must turn off or clear conversation history when using AI tools that store prompts by default, unless retention is required for audit purposes.
  • 6.3AI-generated outputs retained as business records are subject to the same retention and deletion schedules as other business documents.
  • 6.4If a vendor notifies us of a data breach involving AI-processed data, the incident response process in Section 5 applies immediately.
7.

Intellectual Property & Ownership

  • 7.1AI-generated content created in the course of work for clients is owned by the client or treated as a work-for-hire, consistent with the terms of the relevant contract.
  • 7.2AI-generated content created for internal use belongs to [Company Name] subject to applicable law and the terms of the AI tool's vendor agreement.
  • 7.3Staff should not enter proprietary company IP — trade secrets, unpublished product details, source code under NDA — into AI tools unless the tool is running entirely on company infrastructure or a private deployment with a signed enterprise agreement.
  • 7.4Third-party IP (copyrighted text, trademarks, licensed materials) must not be submitted to AI tools in ways that would violate the underlying licence.

Approved by

_________________________

Title

_________________________

Date

_________________________

Next review

_________________________

How to adapt this template

01

Customise placeholders

Replace [Company Name] throughout, set the effective date, and name the Operations Lead or equivalent owner.

02

Build your Approved Tools List

List your actual approved tools — ChatGPT Enterprise, Claude API, GitHub Copilot, etc. — and note the DPA status for each.

03

Review with your team

Share a draft with staff before publishing. The human-review and disclosure rules work best when people understand the reasons, not just the rules.

04

Get sign-off

Have a founder, legal counsel, or senior leader approve it. Date and version it. Set a calendar reminder to review it annually or after any AI incident.

What this template doesn't cover

This template gives you the core policy. A mature AI governance foundation also includes a risk register that maps your specific workflows to AI risk categories (data, quality, compliance, reputational), a mitigation playbook with concrete controls per risk, and client-facing governance copy you can use in proposals, sales calls, and contracts.

Those take significantly more time to build correctly — which is exactly what the AI Policy & Compliance Builder covers.

Full Governance Pack — Done For You

Want the full governance pack — risk register + mitigation playbook, done for you in 5 business days?

The AI Policy & Compliance Builder gives you a complete foundation: five policy documents, a risk register identifying the top AI risks for your business, and a client-facing governance pack you can use in sales and compliance conversations. Fixed price, fixed timeline.

Get the AI Policy & Compliance Builder — $299 →
Not ready to buy yet?

Leave your email and we'll follow up.

Questions about the AI Policy & Compliance Builder, or want to talk through whether it fits your situation? Drop your details and we'll get back to you within one business day.