Skip to content

AI policy

An AI acceptable-use policy for staff

Your staff are already using AI tools, whether or not the company has approved any. A short written policy turns that from a quiet risk into a managed one. It does not need to be long. It needs to answer five questions: what data may go in, which tools, who checks the output, when to tell people, and what to keep.

Why write one now

The common failures are ordinary: a client contract pasted into a free chatbot, an AI-written proposal sent with an invented statistic, a meeting recorded without anyone being told, a customer email that went out unread. A policy prevents most of them by making the rules explicit and giving people an approved tool so they do not reach for an unapproved one.

This page offers a practical outline, not legal advice. Employment, privacy and industry rules vary by state and sector. Have a lawyer review your final policy.

1. Classify the data

Most of the policy hangs on one table. Staff decide what they may paste into a tool by the class of the data, not by guessing at the risk each time.

ClassExamplesAI use allowed
PublicPublished marketing copy, public website text, press releasesAny approved tool
InternalInternal memos, process documents, general emailApproved business-plan tools only
ConfidentialClient files, contracts, financials, pricing, employee recordsApproved tools with a contract that bars training and sets retention
RestrictedHealth records, payment card data, Social Security numbers, passwords, anything under an NDA that forbids itNo AI tool unless specifically approved for that data

Check client contracts. Some already forbid sending their data to third-party services, and an AI vendor is a third party. Where data must never leave your systems, a local model may be the answer; see running AI on your own hardware.

2. Approve the tools

  • Keep a short list of approved tools, each with the data classes it is cleared for. Everything else is not approved for company data.
  • Prefer business or enterprise plans. They usually offer terms that exclude your data from model training, admin controls, single sign-on and retention settings that personal plans lack.
  • Require work accounts, not personal ones, so the company can remove access when someone leaves.
  • Review AI features inside software you already use. New features often switch on through an update.
  • Name one person who approves new tools and keeps the list current.

3. Require human review

AI output can be fluent and wrong. It invents facts, citations, case law and figures, and it states them with confidence. The rule: a named person is responsible for anything AI produces that leaves the building or drives a decision, and that person reads it first.

  • Check every fact, number, quote and citation against a source.
  • Do not let AI make or recommend decisions about hiring, firing, pay, credit or housing without a documented human review. Several jurisdictions regulate automated decisions in these areas.
  • Review AI-written code before it runs in production, as you would a new developer's.
  • Do not use AI output as legal, tax or medical advice.

4. Disclose where it matters

  • Tell people when a meeting or call is recorded or transcribed. See AI notetakers.
  • Tell callers and chat users when they are dealing with an automated agent. See AI receptionists.
  • Follow client and publisher rules on AI-generated work; some contracts require disclosure or forbid it.
  • Do not use AI to imitate a real person's voice or likeness without their written permission.

5. Keep records

  • Keep the approved tools list, with the date each was reviewed and who approved it.
  • Treat prompts, outputs and transcripts as business records under your normal retention schedule. They can be requested in litigation.
  • Keep a simple register of AI uses that affect customers or employees: what the tool does, what data it uses, who reviews it.
  • Record incidents: data pasted where it should not have been, harmful output sent. Fix the process, not only the person.

Using the NIST AI Risk Management Framework

The NIST AI Risk Management Framework (AI RMF 1.0, published in January 2023) is a free, voluntary US framework for managing AI risk. It is organized around four functions: Govern (policies, roles and accountability), Map (understand where and how AI is used and what could go wrong), Measure (test and track the risks) and Manage (act on them). NIST has also published a companion profile for generative AI.

A small business does not need to adopt it formally. It is a useful checklist: the policy above covers most of Govern, the tool list and use register cover Map, and human review and incident records start on Measure and Manage. If a large customer asks how you manage AI risk, pointing to the framework gives a common vocabulary.

Hardware that fits the policy

On-device AI features on new laptops can capture screens and audio. Decide your settings before rollout; see AI PCs. For local models and servers, browse the AI hardware directory.

Before you publish the policy

  1. Survey staff on which AI tools they already use. Expect surprises.
  2. Build the data-class table and check it against client contracts.
  3. Pick approved tools on business plans, with training on your data turned off.
  4. Set the human-review rule and name who owns outputs.
  5. Add disclosure rules for recording, automated agents and client work.
  6. Set retention for prompts, outputs and transcripts.
  7. Have a lawyer review it, train staff, collect acknowledgments, and diary a six-month review.