home / guides / AI Acceptable Use Policy for Small Business

Guide

AI Acceptable Use Policy for Small Business

The 11 sections to cover, a copy-ready starter template, and how to roll it out so people actually follow it.

Updated 2026-09-27 · 9 min read · yforest AI Labs

Key takeaways

  • Most employees already use AI tools at work whether or not the company approved them — an acceptable use policy turns that "shadow AI" into something you can see and manage.
  • A working policy covers 11 areas: purpose, definitions, approved tools, data rules, human review, disclosure, IP, prohibited uses, incident reporting, training, and review cadence.
  • The single highest-risk gap is customer data going into public AI tools — names, health details, financials, and passwords should never be typed into a consumer chatbot.
  • A one-page, plain-language policy that people actually read beats a 12-page document that sits in a shared drive.
  • Have a qualified attorney review the final policy before you roll it out — this guide gets you a strong draft, not legal sign-off.

If you haven't written an AI acceptable use policy yet, your team has probably already written one for you — just not on paper. Someone in accounts payable is pasting invoice details into a chatbot to draft a collections email. Someone in sales is uploading a call transcript to summarize it. Someone in HR is asking a public AI tool to screen resumes. None of it is malicious. All of it is happening without rules.

Why you need an AI acceptable use policy

This pattern has a name: shadow AI. It's the AI equivalent of shadow IT — tools employees adopt on their own because they're useful, fast, and free, without going through any approval process. The numbers back up what most owners already suspect is happening inside their own walls.

FindingSource
More than 80% of workers use AI tools their employer never approvedUpGuard, reported by Cybersecurity Dive, Nov 2025
Fewer than half of workers say they understand their company's AI policiesUpGuard, reported by Cybersecurity Dive, Nov 2025

Put those two numbers together and you get the real problem: adoption is running far ahead of governance. Employees aren't waiting for permission, and even where a policy exists, most people don't know what it says. That gap is where the damage happens — a customer's Social Security number pasted into a public chatbot, a draft contract uploaded to get a "second opinion," a screenshot of financial results dropped into a tool that trains on user input.

A written policy doesn't stop people from using AI. It tells them which tools are fine, what never leaves the building, and who to ask when they're not sure. That's the whole job of the document — not to slow your team down, but to give them a clear lane so they can move fast without creating a problem you find out about later.

Why this can't wait

You don't need a big rollout to have exposure. One employee, one chatbot, and one pasted customer record is enough to create a real problem. The policy is cheap. The incident isn't.

The 11 sections a policy should include

A useful AI policy is short enough to read in ten minutes and specific enough that an employee can act on it without asking a follow-up question. The structure below follows the shape recommended by HR and workplace-policy practitioners, including the AI policy template guidance published by AIHR, and it lines up with the function-level controls in the NIST AI Risk Management Framework — govern, map, measure, and manage AI risk.

1. Purpose and scope

One paragraph on why the policy exists and who it covers — employees, contractors, and any vendor with access to your systems or data.

2. Definitions

Plain-language definitions of "AI tool," "generative AI," and "approved tool," plus a short list of what counts (chatbots, image generators, AI features built into software you already use, AI note-takers on calls).

3. Approved tools list

The specific tools your team is allowed to use, and how a new tool gets added to the list. Without this, "ask before you use something new" never actually happens.

4. Data rules — what never goes into public AI

This is the section that matters most. Spell out, in a list, exactly what can never be typed, pasted, or uploaded into a public AI tool:

  • Customer names, addresses, or contact details tied to an account
  • Financial records — invoices, bank details, pricing under negotiation
  • Health information of any kind, about customers or employees
  • Passwords, API keys, or login credentials
  • Trade secrets, unreleased product details, or signed contracts
Tip

If a piece of information would be a problem to text to a stranger, it's a problem to paste into a public AI tool. Same rule, same reason: once it leaves your systems, you don't control where it goes.

5. Human review requirement

Anything AI drafts that reaches a customer, a regulator, or a legal document needs a person to read it first. State plainly that AI output is a draft, not a finished product.

6. Disclosure

When does the business need to tell a customer that AI was involved — in a support chat, a marketing email, a generated image? Set the rule once so nobody has to guess.

7. Intellectual property and copyright

Cover two directions: don't feed a public AI tool content you don't have the rights to use, and don't publish AI-generated material without checking it isn't a close copy of someone else's copyrighted work.

8. Prohibited uses

A short, specific list: no AI-only hiring or firing decisions, no AI-generated legal or medical advice presented as final, no using AI to impersonate a real person, no bypassing security controls.

9. Incident reporting

Tell people exactly what to do if they realize they pasted something they shouldn't have — who to tell, and that reporting it quickly is the right move, not a punishable one.

10. Training

Every employee gets a short walkthrough of the policy when they join and whenever it changes. A policy nobody was trained on isn't a policy — it's a document.

11. Review cadence

Set a date — quarterly or twice a year — to revisit the approved tools list and the rules themselves. AI tools change fast; a policy written once and never touched again goes stale within months.

Copy-ready starter policy template

Below is a plain-language starting point. Fill in the bracketed sections for your business, then send it to your attorney for review before you roll it out.

AI Acceptable Use Policy — starter template
1. Purpose and scope This policy explains how employees, contractors, and vendors at [COMPANY NAME] may use artificial intelligence (AI) tools in their work. It applies to everyone with access to company systems, data, or customers. 2. Definitions "AI tool" means any software that generates text, images, audio, code, or decisions using machine learning, including chatbots, AI writing assistants, AI features inside other software, and AI meeting-note tools. 3. Approved tools The current approved AI tools are: [LIST TOOLS]. To request a new tool be added, contact [NAME/ROLE]. Do not use an AI tool that is not on this list for company work. 4. Data rules Never enter the following into a public or unapproved AI tool: customer names or contact details, financial records, health information, passwords or login credentials, trade secrets, or unreleased business information. When in doubt, leave it out and ask [NAME/ROLE]. 5. Human review All AI-generated content that will reach a customer, appear in a contract, or represent the company publicly must be reviewed and approved by a person before it is sent or published. 6. Disclosure [COMPANY NAME] will tell customers when AI was used to generate content or handle a request, in the following situations: [LIST SITUATIONS]. 7. Intellectual property Do not upload copyrighted material you don't have rights to into an AI tool. Review AI-generated content for originality before publishing it. 8. Prohibited uses AI tools may not be used to: make final hiring or firing decisions, provide legal or medical advice presented as final, impersonate a real person, or bypass any security control. 9. Incident reporting If you accidentally enter restricted information into an AI tool, report it to [NAME/ROLE] immediately. Reporting quickly is expected and will not result in disciplinary action for the honest mistake itself. 10. Training All employees complete AI policy training within [TIMEFRAME] of joining and whenever this policy is updated. 11. Review This policy is reviewed every [QUARTER/6 MONTHS] by [NAME/ROLE] and updated as tools and risks change. Last reviewed: [DATE] Policy owner: [NAME/ROLE]

How to roll it out

A policy that arrives as a surprise email attachment gets ignored. A policy that's introduced well gets followed. A short rollout sequence works better than a big announcement:

StepWhat to do
1. Draft with inputShare the draft with a few employees from different roles before it's final — they'll spot gaps you won't.
2. Legal reviewHave an attorney review the final draft, especially the prohibited-uses and disclosure sections.
3. Short live walkthroughFifteen minutes, in person or on a call, covering the data rules and how to report a mistake.
4. Put it somewhere people will actually see itLink it from wherever employees already look — the handbook, the onboarding checklist, the internal wiki.
5. Set the review datePut the next review on the calendar before you move on, so it doesn't quietly go stale.

Common mistakes

  • Writing a policy nobody reads. Ten dense pages of legal language get skimmed once and forgotten. One page in plain language gets followed.
  • Banning AI outright. A flat ban doesn't stop shadow AI — it just pushes it further out of sight, since employees will keep finding it useful and keep using it quietly.
  • Skipping the approved-tools list. Without a concrete list, "ask before using a new tool" is a rule nobody can follow, because nobody knows where the line is.
  • No incident-reporting path. If reporting a mistake feels like confessing to a firing offense, people won't report it — and you'll find out about the exposure much later, if at all.
  • Treating it as a one-time document. AI tools change every few months. A policy without a review date is a policy that's already out of date.

◆ Small Business AI Kickstart

Get AI ready today.
Before it's too late.

yforest AI Labs comes to your company, trains your team, and ships your first tools.

FAQ

Do we really need a written AI policy if we're a small team?

Yes. Policy size doesn't need to scale with team size — even a five-person company has customer data, financial records, and a reputation to protect. A one-page policy takes an afternoon to write and closes the biggest gap: employees using AI tools with no guardrails.

What's the single most important rule to include?

The data rule: never put customer PII, financial details, health information, passwords, or trade secrets into a public AI tool. Most AI-related incidents trace back to someone pasting information into a tool that wasn't built to keep it private.

Should we just ban AI tools instead of writing a policy?

A ban doesn't remove the risk — it removes your visibility into it. Employees who find a tool useful tend to keep using it quietly, which is worse than an approved, monitored list of tools with clear data rules.

Who should own the policy inside the company?

Pick one person or role — often an owner, office manager, or IT lead — to own the approved-tools list, the review cadence, and incident reports. Shared ownership tends to mean no ownership.

How often should the policy be updated?

Review it at least twice a year, or sooner if you adopt a new AI tool or a major platform changes its data-handling terms. AI tools evolve quickly enough that a policy older than a year is worth a fresh look.

Sources

  1. UpGuard shadow AI research, reported by Cybersecurity Dive (Nov 2025)
  2. NIST AI Risk Management Framework
  3. AIHR — AI Policy Template for HR

This guide is general information, not legal advice. Have a qualified attorney review any policy before you adopt it.