← All posts
aisecuritypolicy

Do You Need an AI Use Policy? (Short Answer: Yes)

Your staff are already pasting company data into public chatbots. Here's what a small-business AI use policy should cover, plus a starter template.

Dustin Blad

If you run a small business and you don’t have an AI use policy, you don’t have “no AI use.” You have unmanaged AI use. Your team is already using these tools — for emails, for summarizing documents, for writing code, for cleaning up spreadsheets. The only question is whether anyone’s told them where the lines are.

I bring this up with almost every client now, because the risk is quiet and easy to miss. Nobody’s being reckless on purpose. Someone just pastes a customer list into a chatbot to reformat it, because it’s faster, and now that data has left your building.

The shadow-AI problem

“Shadow AI” is the same idea as shadow IT: staff using tools the business never approved or reviewed. It happens for a good reason — the tools genuinely help — which is exactly why banning them outright rarely works. People route around a blanket ban.

Here’s the specific concern. Many free, consumer-tier AI chatbots can use whatever you type as training data or keep it for review. When an employee pastes in a contract, a patient record, source code, a customer database, or an unreleased financial figure, you’ve potentially handed sensitive information to a third party under terms nobody at your company read. Depending on your industry, that can also put you offside with regulations you’re required to follow.

The fix isn’t fear. It’s a short, clear policy that tells people how to use these tools safely, so they can keep the speed without the exposure.

What a policy should cover

You don’t need a 30-page document. You need a one-pager people will actually read. Cover these:

Allowed and banned tools

Name them. List the specific tools your team may use and the ones they may not. Vague guidance (“use good judgment”) gives people nothing to act on. “Use the company account on these two tools, don’t use anything else for work data” is something they can follow.

What never gets pasted in

Be concrete about the data that must never go into a public AI tool. Usually: customer and employee personal information, anything covered by an NDA, passwords and keys, source code you don’t want public, financials before they’re announced, and anything regulated in your field. Give examples from your actual business — it lands better than a category name.

Approved business-tier tools

This is the part that makes the whole policy workable. Most major AI vendors sell business or enterprise tiers that contractually do not train on your data and give you admin controls. Standardize on one or two of those, pay for them, and give staff real accounts. Now the fast tool and the safe tool are the same tool, and you’ve removed the reason to go around you.

Disclosure

Decide when people should say AI was involved — in client deliverables, in published content, in code. You don’t need to label every email, but agree on where honesty matters to your customers and your team. And require that a human reviews AI output before it goes out. These tools are confidently wrong on a regular basis.

A starter policy you can copy

Here’s a plain template. Fill in the brackets, cut what doesn’t fit, and put it somewhere everyone can find it. It’s a starting point, not legal advice — if you’re in a regulated field, have counsel look it over.

[Company] AI Use Policy

Why this exists
AI tools help us work faster. This policy keeps us fast without
putting our data, our customers, or our business at risk.

Approved tools
- Use only these tools for work: [Tool A — business tier],
  [Tool B — business tier].
- Always sign in with your company account, never a personal one.
- Want to use a different tool for work? Ask [name] first.

Never paste this into any AI tool
- Customer or employee personal information
- Anything under an NDA or marked confidential
- Passwords, API keys, or access tokens
- Source code we haven't chosen to make public
- Financials or plans before they're announced
- [Anything regulated in our industry: ___]

Human review
- A person reviews AI output before it reaches a customer,
  goes public, or ships in our product. AI is a draft, not a
  final answer.

Disclosure
- Tell the client/reader when AI did meaningful work on
  [deliverables / published content / code], per our norms.

Questions
- Not sure if something's okay? Ask [name/channel] before you
  paste. Asking is always fine.

Where I land on this

You want your team using AI. It’s a real productivity gain, and pretending otherwise just pushes the usage into the shadows where you can’t see it. The goal of a policy isn’t to slow anyone down — it’s to make the safe path the easy path, so people don’t have to choose between doing their job well and protecting the business.

Get the business-tier accounts, write the one-pager, spend ten minutes walking the team through it, and revisit it a couple times a year as the tools change. That’s most of the work.

If you want help picking tools, setting up a policy that fits how your team actually works, or building AI into your own product safely, that’s a lot of what we do — see AI and automation, or get in touch and we’ll talk through your setup.