Most AI policies fail for the same reason most acceptable use policies fail. They are written to satisfy an auditor rather than to be read by the person who is about to paste a customer list into a chatbot at half past four on a Friday.
A useful AI policy for a small business is one page. It answers five questions in language a new starter understands, and it lives somewhere they will actually see it. Here is what belongs on it.
Section one: which tools are approved
Name them. Not categories, not principles, actual product names and actual plan tiers, because the tier is where the risk lives.
The consumer tier of a tool and its business tier are different products with different contracts. Business and enterprise plans of Microsoft 365 Copilot, ChatGPT Business and Claude for Work exclude your prompts from model training and keep processing inside terms you can hold someone to. The free tier of the same brand may not. A policy that says ChatGPT is approved without naming the plan has approved the wrong thing.
Keep the list short. Three or four tools that everyone uses well beats twelve that nobody has been trained on.
Section two: what data may go in
This is the part people get wrong, usually by writing something so cautious it is ignored. Be concrete. A three-tier rule works for most businesses:
- Green — fine. Anything already published, anything you wrote yourself, generic questions, draft marketing copy, code you own.
- Amber — approved tools only, never a personal account. Internal documents, project notes, anonymised customer scenarios, financial figures with names removed.
- Red — never. Named customer records, health data, payroll, card details, passwords and credentials, anything under an NDA that names the counterparty, anything a client contract specifically restricts.
Give two or three worked examples from your own business. Examples are what people remember when the policy itself has been forgotten.
Section three: who checks the output
The rule that prevents almost every embarrassing AI incident is this: a named human is accountable for anything that leaves the business, whether or not AI helped write it.
Write it as a positive obligation rather than a prohibition. You own what you send is a rule people follow. AI output must be validated in accordance with the quality framework is a rule people skim.
Add a specific instruction about numbers. Any figure, date, price, legal reference or statistic produced by an AI tool must be checked against the source before it goes out. Invented specifics are the single most common failure mode and they are also the easiest to catch.
The policy is not there to stop people using AI. It is there so that when they do, nobody has to guess where the line is.
Section four: telling customers
There is no blanket UK disclosure law in 2026, but two obligations bite. UK GDPR requires transparency about how personal data is processed, so if AI touches customer data your privacy notice must say so. And consumer protection rules mean you must not pass off an AI response as a human one where that would mislead somebody into a decision.
In practice, most small businesses land on a sensible middle position: AI-assisted drafting needs no announcement, an AI system that replies to customers directly does and anything that makes or materially influences a decision about a person needs both disclosure and a route to a human.
Section five: what to do when it goes wrong
Name a person and a route. If somebody realises they have pasted something into the wrong tool, the whole game is whether they tell you in ten minutes or in ten days, and that depends entirely on whether the policy reads as help or as a disciplinary trap.
Say explicitly that reporting a mistake promptly will not be treated as misconduct. Then honour it. One punished self-report and you will never hear about the next one.
What to leave out
Resist the urge to include a definition of machine learning, a philosophical section on the future of work or a list of prohibited model architectures. None of it changes behaviour, and every paragraph you add reduces the odds anyone reads the four that matter.
Also leave out promises you cannot keep. If your policy says all AI use is logged and reviewed monthly, somebody needs to be doing that. An unfollowed control is worse than no control at all in an audit, because it shows you knew the risk and did not manage it.
Making it stick
A policy becomes real through three unglamorous mechanisms. Put it in the induction pack so every new starter reads it in week one. Reference it when you buy a tool, so procurement and policy stay in step. And review it every six months with a diary reminder, because the products it names will have changed.
If you would like a hand adapting this into something specific to your business, including the supplier due diligence that sits behind it, our IT consultancy team does exactly this work for UK businesses. We can also make sure the technical controls underneath match what the policy promises, through our security solutions service. Get in touch and we will start with the one page.








