Most small businesses don’t have an AI policy because nobody has asked for one yet. Staff aren’t waiting for permission though. Someone in the team is already pasting a client email into ChatGPT to draft a reply, or running numbers through an AI tool nobody in the business has looked at. That’s not a hypothetical risk to plan around, it’s what’s already happening quietly on laptops across the country. The CIPD’s research on AI at work found that the share of employers who had worked on a generative AI policy in the past year rose to 31%, up from 16% the year before, which also means the majority still hadn’t written anything down.
A policy isn’t the same thing as an AI strategy, and it doesn’t need a consultant, a committee or a six-week project to produce. It needs to exist, it needs to be a page long enough that people actually read it, and it needs an owner. This is what to put in it.
Why this can’t wait for a full AI strategy
A lot of AI governance advice is written for organisations with a compliance team and a board to report to. A small business doesn’t need that scale of process, but it does need the same basic questions answered: which tools are staff allowed to use, what shouldn’t go into them, and who’s responsible if something goes wrong. Waiting until you have a complete strategy before writing any of that down just means more months of staff making those calls themselves, tool by tool, with no guidance either way.
The risk isn’t abstract. UK GDPR still applies to whatever gets typed into a public AI tool, and most consumer AI products aren’t built to keep client names, financial details or personnel records confidential once they’re submitted. The ICO’s guidance on AI and data protection sets out how UK GDPR’s existing principles, lawfulness, data minimisation, security, apply to AI use exactly the same way they apply to anything else. A one-page policy is mostly just that guidance translated into plain instructions for your team.
What a practical policy actually needs to cover
Skip the legal boilerplate. A policy that gets read and followed covers five things:
- Approved tools. Name the AI tools the business has actually looked at and is comfortable with staff using for work. Anything not on the list needs a quick check with you first, not a blanket ban that nobody follows anyway.
- What can’t go in. Client data combined with financial or personal details, anything covered by an NDA, passwords, and anything you wouldn’t want to see forwarded to a stranger. This is the section people actually need to read.
- An owner. One named person who keeps the tool list current and answers questions when someone isn’t sure. In a small business that’s usually you, and that’s fine, as long as it’s written down rather than assumed.
- A review point. A date to revisit it, twice a year is enough for most small teams. AI tools change fast enough that a policy written in January can be quietly out of date by the summer.
- What happens if something goes wrong. Who gets told if sensitive data ends up somewhere it shouldn’t, and what the first step is. Even a two-line answer beats no answer.
The template
Here’s a starting point you can copy into a document and adapt. It’s deliberately short, a policy nobody reads doesn’t protect anybody.
[Business name] AI use policy
Approved tools: [list the specific tools staff can use for work, e.g. “Microsoft Copilot (company account only)”]
Before using anything else: Ask [owner name] first. This isn’t about slowing you down, it’s about knowing what’s in use.
Never enter into any AI tool: client names alongside financial or personal information, anything under an NDA, passwords or login details, or anything you wouldn’t want a competitor to read.
If something goes wrong: Tell [owner name] straight away. Speed matters more than getting the wording right.
Reviewed: [date]. Next review: [date, six months later].
That’s genuinely most of what a small business needs on paper. It’s not a governance framework and it isn’t trying to be one, it’s a guardrail that stops the biggest, most avoidable mistakes while everyone works out what AI is actually going to do for the business.
If you want a more structured version to work from, the government’s AI Management Essentials tool is a free self-assessment built for exactly this size of business, and it’s worth ten minutes even if you never touch the fuller version.
Where policies fail in practice
Three mistakes show up over and over:
- Written once, never revisited. A policy from a year ago that still names a tool nobody uses anymore, and doesn’t mention two tools everyone does, isn’t protecting anyone. Put the review date in a calendar the day you write it.
- Too long to read. A twelve-page policy modelled on a corporate template gets skimmed once and ignored. One page, plain language, wins every time.
- No real owner. “IT will handle it” isn’t an owner if there’s no IT department. Name an actual person, even if that person is you.
None of these are complicated fixes. They’re the difference between a document that exists and a document that does anything.
When it’s time for AI governance consulting, not just a policy
A one-page policy covers the basics: what’s allowed, what isn’t, who to ask. It doesn’t cover building an actual AI strategy, working out which processes are worth automating, or installing the tools and agents that make that strategy real. That’s a different job, and it’s worth knowing where one stops and the other starts.
If you’re past the point of “what should staff not paste into ChatGPT” and into “what should I actually be building with AI,” that’s the audit-first work I do through the AI Makeover: a full look at your marketing and processes first, so you know what’s worth building before anything gets touched, then the agents and automation installed against your real workflow. I’ve written before about what that kind of engagement covers and what it costs, and the case studies show the same audit-first approach applied to real client work, with the figures attached.
A policy is a page you can write this afternoon. Everything past it, what to build, in what order, and who builds it, is worth a proper conversation rather than a template. A consultation call is free, thirty minutes, and the right place to start that conversation once the one-pager is sorted.


