AI Use Policy Template for Small Business
Educational starting template — not legal, compliance, or cybersecurity advice. Review and adapt this document with a qualified professional before adopting it as an official company policy. Last reviewed: .
1. Purpose
This policy sets out how employees at [Company Name] may use AI tools (such as ChatGPT, Claude, Gemini, or similar) for work, so the business can benefit from these tools while reducing avoidable risk to customers, employees, and the business itself.
2. Approved AI Tools
Employees may use the following AI tools for work purposes: [list approved tools, e.g., "ChatGPT (business/team plan only)," "Claude," etc.]. Tools not on this list require approval from [name/role] before use with any company information.
3. Prohibited Information
The following must never be entered, typed, uploaded, or pasted into any AI tool, approved or otherwise:
- Customer or client personal information (names, contact details, financial or account information, health information, etc.)
- Confidential or proprietary business information (financials, contracts, trade secrets, unreleased plans)
- Employee personal or HR information
- Passwords, access keys, or credentials of any kind
- Any information the business is contractually or legally required to keep confidential
4. Customer / Client Data
Customer and client data must be handled according to [Company Name]'s existing privacy and data-handling commitments. When in doubt about whether information relating to a customer or client may be used with an AI tool, employees should ask [name/role] before proceeding, not after.
5. Confidential Business Information
Information not yet public — financial results, strategic plans, unreleased products, internal communications marked confidential — should not be used as input to any AI tool unless a business-tier agreement with specific data-handling terms has been reviewed and approved.
6. Document Uploads
Before uploading any document to an AI tool, employees should confirm the document does not contain the categories of information listed in Section 3. When unsure, ask first.
7. Account & Security Requirements
Any AI tool account used for work must use a unique password (not reused from another account), and multi-factor authentication must be enabled where the tool offers it. Personal AI accounts should not be used to store or process company information.
8. Human Review of AI Output
AI-generated content must be reviewed by a qualified employee before it is sent externally, published, used in a customer-facing context, or relied upon for a business, legal, financial, or compliance decision. AI output should be treated as a draft or a starting point, not a final answer.
9. Incident / Reporting Process
If an employee believes confidential, customer, or personal information may have been entered into an AI tool in error, or that an AI account may have been compromised, they should report it immediately to [name/role/contact] so the situation can be assessed and addressed.
10. Policy Ownership
This policy is owned by [name/role], who is responsible for keeping it up to date and answering employee questions about approved AI use.
Template provided by Smarter AI Use for general educational purposes. It is not a substitute for advice from a qualified attorney, compliance professional, or security advisor familiar with your business, industry, and jurisdiction.