What should an AI acceptable-use policy cover in a small company?
Your employees are already using AI at work — some of it unapproved. A one-page acceptable-use policy with seven sections covers the risk without hiring a compliance department.
Your employees already use AI at work, and a chunk of it is unapproved. A one-page acceptable-use policy covering approved tools, data tiers, output review, disclosure, security, incident reporting, and one named owner handles the risk without a compliance department.
What should an AI acceptable-use policy cover?
An AI acceptable-use policy for a company under 200 people needs seven things: an approved-tool list, data classification rules with examples, output verification requirements, disclosure rules, security basics, an incident reporting path, and one accountable owner. That's it. Not a 20-page legal document — one page your team will actually read, reviewed once a year.
Why can't you just ban AI tools at work?
Because banning doesn't work, and the data proves it. A September 2025 Cybernews survey of over 1,000 U.S. employees found 59% used AI tools not approved by their employer — and 75% of those users admitted sharing potentially sensitive information with them. The LayerX Enterprise AI and SaaS Data Security Report (2025) found that of employees using generative AI at work, 77% paste company data directly into prompts, and 82% of those pastes happen on personal, unmanaged accounts rather than enterprise-secured software.
A ban drives usage underground. What actually reduces leakage is giving people sanctioned tools with enterprise data protection, plus clear rules about what can go into them.
What data rules should the policy include?
Data classification is the heart of the policy. Don't write "no confidential information" — employees can't apply that. Use four tiers with concrete examples:
- Public information — marketing copy, published pricing, anything already on your website. Fine in any approved tool.
- Internal business information — project plans, internal docs, meeting notes. Approved enterprise tools only.
- Confidential and personal information — customer data, employee records, candidate details. Prohibited unless specifically approved and contractually protected.
- Regulated, credentials, and trade secrets — API keys, passwords, source code, legal privilege, payment or health data, unreleased product plans. Prohibited by default, no exceptions.
The last tier is where the real damage happens. Credentials and API keys pasted into a consumer chatbot are the most common serious leak, and the OmniGPT breach in 2025 showed what's at stake: 34 million chat lines, API keys, and confidential business documents were exposed when a third-party AI wrapper used by employees was breached.
Which AI tools should employees be allowed to use?
The ones with contractual data protection. The difference between consumer tiers and business tiers is not the model — it's the contract:
- ChatGPT Enterprise and Team: OpenAI's business terms commit to not using your business data (prompts, files, responses) to train their models.
- Microsoft Copilot with commercial data protection: for users signed in with a Microsoft Entra ID, Microsoft commits that prompts and responses are not saved and not used to train foundation models.
- Gemini for Workspace/Enterprise: Google's service terms include a training restriction — customer data isn't used to train or fine-tune models without your permission.
Consumer free tiers carry no such guarantee. Your policy should say: work happens in company accounts on approved plans, never personal accounts. Cyberhaven's 2025 AI Adoption and Risk Report found 71.7% of AI tools actively used by employees are rated high or critical risk — most of that risk is consumer-tier tools on personal accounts.
Should employees have to verify AI output?
Yes, and the policy should say where the bar is higher. At minimum, no AI output goes to a customer, into a contract, or into a decision about a person without a human checking it. AI-drafted customer emails, quotes, and legal or financial documents need named human review. IBM's Cost of a Data Breach 2025 report found that 1 in 5 organizational breaches now involves unsanctioned "shadow AI," adding an average of $670,000 to breach costs — and fabricated output sent to a customer is its own category of damage.
What about disclosing AI use?
Require disclosure when AI materially contributed to customer-facing work product: proposals, deliverables, communications. Internal brainstorming doesn't need a stamp. If you operate in the EU or serve EU customers, transparency obligations around AI-generated content exist under the EU AI Act — and small-company status is not a blanket exemption, so a quick applicability check before deploying AI in hiring, credit, or essential-services decisions is cheap insurance.
How do you keep the policy alive?
Three mechanics, not more:
- One owner. A named person — usually ops or IT lead in a company this size — owns the policy, the approved-tool list, and the review calendar.
- A fast request path. If an employee wants a new tool, there's a same-week answer, not a quarterly committee. Slow approval is how shadow AI starts. The SBE Council's March 2026 survey found 82% of small businesses use at least one AI tool, with a median of five — the tools are coming in either way.
- An amnesty incident route. Anyone who pastes something sensitive into the wrong tool reports it without fear. Fast reporting limits damage; fear hides it until it's a breach.
Review the policy annually or when a major tool or regulation changes. Keep it to one page plus the approved-tool list. If it's longer, nobody reads it — and an unread policy protects nothing.
What's the minimum viable version?
If you do nothing else this week: list your approved tools and plans, ban credentials and personal data from prompts in writing, require human review of anything customer-facing, and name one owner. That four-line policy eliminates most of the real-world leakage risk from the statistics above. Everything else is refinement.
If you want a second pair of eyes on yours, we review AI tool stacks and policies for companies this size every week - book a call and we'll pressure-test your draft in 30 minutes.
Frequently asked questions
- What should an AI acceptable-use policy include?
- An AI acceptable-use policy should include an approved-tool list, data classification rules with concrete examples, output verification requirements, disclosure rules for customer-facing work, security basics like managed accounts, an incident reporting path, and one named accountable owner. For a company under 200 people, this fits on one page.
- Should small businesses ban AI tools at work?
- No. Surveys consistently show a majority of employees use unapproved AI tools regardless of bans - a Cybernews survey found 59% used unapproved tools and 75% of them shared sensitive information. Banning drives usage underground. Providing sanctioned tools with enterprise data protection reduces leakage more effectively.
- What data should employees never put into AI tools?
- Credentials and API keys, source code, customer and employee personal data, regulated data like payment or health information, legal privileged material, and unreleased product plans should never go into AI tools without specific approval. These categories carry the highest leak and breach costs.
- Do enterprise AI plans like ChatGPT Team stop your data training their models?
- Yes. ChatGPT Enterprise and Team, Microsoft Copilot with commercial data protection (Entra ID sign-in), and Gemini for Workspace all contractually commit to not using your business data to train their models. Free consumer tiers do not offer this guarantee, which is why work should happen in company-managed accounts.
- How often should a small business review its AI policy?
- Review it at least annually, and immediately after a major tool change or new regulation that affects your operations. The policy owner should also keep the approved-tool list current, since employees adopt new AI tools faster than annual cycles.