Skip to content
CharliezServices

Artificial Intelligence

The AI Use Policy for Small Business Teams That Gets Read

6 minute read

Staff paste client documents into free AI tools because nobody told them where the line sits. The fix is a one page rule set naming specific tools, specific tiers and the data that never leaves the building.

Someone on your team had a document due at four o'clock. They pasted it into a chat window, got something usable back in ninety seconds, and moved on. They did not experience that as a policy decision. They experienced it as finishing the job before the meeting started.

That is what shadow AI looks like inside a small company. Not a rogue employee exfiltrating data, just a capable person with too much to get through and no idea where the line sits. If you have never written anything down, the safe assumption is that this is happening right now, in personal accounts you cannot see, with whatever files happened to be open at the time.

The gap is guidance, not discipline

Ask around and you will usually find three or four tools in regular use that never went past anyone. A meeting recorder that joined a client call because someone forwarded the calendar invite. A browser extension that summarises inbound email. A free assistant tab that stays open all day next to the CRM. None of these arrived through a purchase order, so none of them got reviewed by anybody.

People are not being reckless. They are filling a vacuum. When there is no rule, everyone writes their own private one, and the private rule is almost always some version of "it is probably fine if it saves me an hour."

So the exposure you are carrying is not that your team uses AI. It is that you cannot describe, in one sentence, what has left the building. That is the thing that becomes uncomfortable when a client asks.

What actually walks out the door

Be specific about the material, because the abstract version of this conversation never lands. In a small services or trades business, the things most likely to end up pasted into a consumer tool are:

  • Client documents, briefs and contracts that arrived under an NDA
  • Customer records with names, addresses, phone numbers and order history
  • Unreleased financials, a pipeline spreadsheet, a draft board update
  • Source code and environment configuration, occasionally with a live API key still in it
  • Applicant CVs and internal notes about staff performance

All of that is ordinary work product. All of it is also material you would not email to a stranger. A chat window does not feel like emailing a stranger, and that mismatch between how it feels and what it is does most of the damage.

Retention is the part people skip. On a free consumer tier you generally have limited visibility into how long inputs are kept, whether they are used to improve the product, and which staff at the vendor can access them for abuse review. Those terms are published, they change, and almost nobody on your team has read them.

The contract clause most owners have not checked

The regulatory angle gets the attention, but the contractual one is usually closer to home. Look at the master services agreements you have already signed. Many contain a confidentiality clause that prohibits disclosing the client's information to any third party without prior written consent, and an increasing number now name AI tools explicitly or require you to maintain a list of subprocessors.

If a member of your team pastes that client's data into a tool you have not disclosed, you are in breach whether or not anything bad ever happens to the data. Under GDPR the same structure applies through Article 28: a processor cannot engage another processor without authorisation from the controller. In healthcare, a vendor without a signed business associate agreement is not somewhere protected health information may go, regardless of how good the output is.

You do not need a breach to have a problem. You need a client who asks the question and an answer you cannot give.

Four tiers, in words your team already uses

The reason most policies fail is that they classify information in language nobody uses at their desk. Keep it to four tiers and give a real example of each.

Public. Anything already on your website, in published marketing, or in a public filing. Fine to paste anywhere.

Internal. Process documents, meeting notes with no client named, draft copy, general questions about how to do something. Approved tools only.

Client confidential. Anything a client gave you, anything identifying a client, and anything covered by an NDA. Approved business tier tools only, and only where the contract permits it.

Regulated personal data. Health information, financial account details, government identifiers, children's data, anything in scope for HIPAA, PCI or similar. Not entered into a general purpose assistant at all, whatever the tier.

That last rule needs to be absolute, because tiered judgement calls under time pressure reliably go the wrong way.

Name the tool and the tier, never "AI tools"

A policy that says "do not put confidential data into AI tools" is unenforceable, because the tool is not the unit of risk. The account is.

The commercial tiers of the major assistants and the consumer ones are different products with different terms. Business and enterprise plans generally commit to not training on your inputs by default, and they add the things that make the rest of this workable: single sign on, an admin console, member management, and retention controls. Free consumer accounts sit outside all of that, and you have no view into who is signed in or what they sent.

So write the policy with names and versions in it. "Approved: Claude Team, ChatGPT Business, Microsoft 365 Copilot under our tenant, GitHub Copilot Business with the public code filter on. Not approved: personal accounts of any of the above, meeting recorders that are not on this list, browser extensions that read page content." Put the date the terms were checked at the bottom, and a note that it gets rechecked at renewal. Vendor terms move, and an undated policy quietly becomes wrong.

Buying seats is also the cheapest visibility you will ever get. A paid workspace gives you a member list and audit logs. A team on personal accounts gives you nothing.

What always gets a human before a customer sees it

Separate the data question from the output question, because they are different failure modes. Data going in is a confidentiality problem. Output coming out is an accuracy and liability problem.

Draw the review line where a mistake reaches someone outside the company. Anything quoted to a customer, anything with a price, date, dimension or legal term in it, anything that states a fact about a product, and any code that touches payments, authentication or personal data. A named person reads it before it goes out, and that person is accountable for what it says. Nobody gets to point at the tool afterwards.

Enforcement is a comprehension problem

A rule nobody enforces is worse than no rule, because it documents that you knew and did nothing. But enforcement in a small company is not surveillance. It is making the rule short enough to remember and sensible enough to respect.

The whole policy should fit on one page with four headings: approved tools and tiers, what may and may not be entered by tier, what requires human review before it leaves, and who to ask when a case is unclear. That last one matters more than it looks. Most violations are edge cases, and if the answer takes two days to arrive, people will guess.

Pair it with actual instruction on what the tools are good at. People follow rules they understand and route around rules that feel arbitrary, so a session of AI literacy training does more for compliance than a signature on an acknowledgement form. It also surfaces the repetitive copy and paste work that should never have been manual in the first place, which is a business automation job with a proper API, a signed data processing agreement and a log, not a person pasting a spreadsheet into a browser twice a day.

Banning it just moves it somewhere you cannot see

The instinct to prohibit the whole category is understandable and it does not work. Staff keep phones, deadlines do not move, and a blanket ban converts a visible, governable behaviour into an invisible one. You lose the audit trail and you keep the exposure.

An AI use policy for small business earns its place by being specific enough to follow and short enough to finish. Name the tools. Name the tiers. Say what never goes in. Say who signs off before it reaches a customer. Then say who to ask, and answer quickly when they do.

Related service

Want this handled for you?

Role specific, hands on training built around your real workflows, with a usable AI policy and a prompt library your team keeps.