Skip to content
Contact Me
SEOOrganic search strategy, technical fixes, links and local listings.AEOGet cited by ChatGPT, AI Overviews and Perplexity when buyers ask.PPC AdsGoogle & Microsoft Ads managed end to end, from structure to landing page.Social MediaOrganic growth and paid campaigns on LinkedIn, Meta and YouTube.Web DesignHigh-converting sites built SEO-first, from brief through to go-live.
Not sure where to start? The AI Makeover converts your website into an AI-driven system.Get An AI Makeover
All articles
Sep 14, 20267 min readConsulting & Adoption

A Practical AI Policy for Small Businesses (With a Template You Can Use)

Staff are already using AI at work, policy or no policy. Here's what a one-page AI policy needs to cover, a template to copy, and where a written policy stops and proper AI governance consulting starts.

Harry HawkinsHarry H — AI Consultant & Developer
A one-page policy document next to a checklist of approved AI tools and data rules, representing a written AI policy for a small business

Most small businesses don’t have an AI policy because nobody has asked for one yet. Staff aren’t waiting for permission though. Someone in the team is already pasting a client email into ChatGPT to draft a reply, or running numbers through an AI tool nobody in the business has looked at. That’s not a hypothetical risk to plan around, it’s what’s already happening quietly on laptops across the country. The CIPD’s research on AI at work found that the share of employers who had worked on a generative AI policy in the past year rose to 31%, up from 16% the year before, which also means the majority still hadn’t written anything down.

A policy isn’t the same thing as an AI strategy, and it doesn’t need a consultant, a committee or a six-week project to produce. It needs to exist, it needs to be a page long enough that people actually read it, and it needs an owner. This is what to put in it.

Why this can’t wait for a full AI strategy

A lot of AI governance advice is written for organisations with a compliance team and a board to report to. A small business doesn’t need that scale of process, but it does need the same basic questions answered: which tools are staff allowed to use, what shouldn’t go into them, and who’s responsible if something goes wrong. Waiting until you have a complete strategy before writing any of that down just means more months of staff making those calls themselves, tool by tool, with no guidance either way.

The risk isn’t abstract. UK GDPR still applies to whatever gets typed into a public AI tool, and most consumer AI products aren’t built to keep client names, financial details or personnel records confidential once they’re submitted. The ICO’s guidance on AI and data protection sets out how UK GDPR’s existing principles, lawfulness, data minimisation, security, apply to AI use exactly the same way they apply to anything else. A one-page policy is mostly just that guidance translated into plain instructions for your team.

What a practical policy actually needs to cover

Skip the legal boilerplate. A policy that gets read and followed covers five things:

  • Approved tools. Name the AI tools the business has actually looked at and is comfortable with staff using for work. Anything not on the list needs a quick check with you first, not a blanket ban that nobody follows anyway.
  • What can’t go in. Client data combined with financial or personal details, anything covered by an NDA, passwords, and anything you wouldn’t want to see forwarded to a stranger. This is the section people actually need to read.
  • An owner. One named person who keeps the tool list current and answers questions when someone isn’t sure. In a small business that’s usually you, and that’s fine, as long as it’s written down rather than assumed.
  • A review point. A date to revisit it, twice a year is enough for most small teams. AI tools change fast enough that a policy written in January can be quietly out of date by the summer.
  • What happens if something goes wrong. Who gets told if sensitive data ends up somewhere it shouldn’t, and what the first step is. Even a two-line answer beats no answer.

The template

Here’s a starting point you can copy into a document and adapt. It’s deliberately short, a policy nobody reads doesn’t protect anybody.

[Business name] AI use policy

Approved tools: [list the specific tools staff can use for work, e.g. “Microsoft Copilot (company account only)”]

Before using anything else: Ask [owner name] first. This isn’t about slowing you down, it’s about knowing what’s in use.

Never enter into any AI tool: client names alongside financial or personal information, anything under an NDA, passwords or login details, or anything you wouldn’t want a competitor to read.

If something goes wrong: Tell [owner name] straight away. Speed matters more than getting the wording right.

Reviewed: [date]. Next review: [date, six months later].

That’s genuinely most of what a small business needs on paper. It’s not a governance framework and it isn’t trying to be one, it’s a guardrail that stops the biggest, most avoidable mistakes while everyone works out what AI is actually going to do for the business.

If you want a more structured version to work from, the government’s AI Management Essentials tool is a free self-assessment built for exactly this size of business, and it’s worth ten minutes even if you never touch the fuller version.

Where policies fail in practice

Three mistakes show up over and over:

  1. Written once, never revisited. A policy from a year ago that still names a tool nobody uses anymore, and doesn’t mention two tools everyone does, isn’t protecting anyone. Put the review date in a calendar the day you write it.
  2. Too long to read. A twelve-page policy modelled on a corporate template gets skimmed once and ignored. One page, plain language, wins every time.
  3. No real owner. “IT will handle it” isn’t an owner if there’s no IT department. Name an actual person, even if that person is you.

None of these are complicated fixes. They’re the difference between a document that exists and a document that does anything.

When it’s time for AI governance consulting, not just a policy

A one-page policy covers the basics: what’s allowed, what isn’t, who to ask. It doesn’t cover building an actual AI strategy, working out which processes are worth automating, or installing the tools and agents that make that strategy real. That’s a different job, and it’s worth knowing where one stops and the other starts.

If you’re past the point of “what should staff not paste into ChatGPT” and into “what should I actually be building with AI,” that’s the audit-first work I do through the AI Makeover: a full look at your marketing and processes first, so you know what’s worth building before anything gets touched, then the agents and automation installed against your real workflow. I’ve written before about what that kind of engagement covers and what it costs, and the case studies show the same audit-first approach applied to real client work, with the figures attached.

A policy is a page you can write this afternoon. Everything past it, what to build, in what order, and who builds it, is worth a proper conversation rather than a template. A consultation call is free, thirty minutes, and the right place to start that conversation once the one-pager is sorted.

Harry Hawkins
Harry HAI Consultant & Developer
Book a consultation call

Keep reading

What Does an AI Automation Consultant Do? A Plain-English Breakdown
Sep 28, 2026What Does an AI Automation Consultant Do? A Plain-English Breakdown
What a Marketing Automation Consultant Actually Builds
Sep 21, 2026What a Marketing Automation Consultant Actually Builds

Streamline your business with me.

WhatsApp Me
Harry HawkinsHarry H — AI Consultant & Developer