- Your team is already using AI, so a clear policy reduces risk rather than adding it.
- A simple green, amber and red rule tells staff what they may paste into AI tools.
- Anything that reaches a client needs a human check, and the person who sends it owns it.
- Give the policy one owner, review it quarterly and keep it to a single page.
Your team is already using AI tools. Some will have told you. Many will not. A sales executive pastes a customer email into a free chatbot to draft a reply. An accountant uploads a spreadsheet to summarise it. A marketing coordinator asks for ten caption ideas. Most of this is harmless and useful. Some of it quietly puts client data, pricing and contracts somewhere you have no control over.
The answer is not a forty-page policy that legal approves and nobody reads. It is one page, written in plain language, that tells people what they can do, what they cannot do and who to ask. Here is how to build one for a mid-sized business.
Why most AI policies are ignored
Policies fail for predictable reasons. They are too long, too vague or too strict. A document that bans all AI use pushes people towards personal accounts on their phones, where you have even less visibility. A document full of phrases like "use responsibly" gives no one a clear answer at the moment they need it. And a policy written once and never updated loses credibility the first time a new tool arrives.
A good policy is short enough to read in five minutes, specific enough to answer real questions, and owned by someone who will keep it current.
What may and may not go into AI tools
This is the heart of the policy. Most staff only want to know one thing: can I paste this in? Give them a simple traffic-light rule.
- Green, allowed: public information, your own rough drafts, general research questions, marketing ideas and internal templates with no names or figures.
- Amber, approved tools only: internal documents, anonymised customer queries, process notes and meeting summaries, used only in tools the company has approved and set up.
- Red, never: client personal data, patient or student records, passwords and access details, bank details, salary information, unsigned contracts and anything covered by a confidentiality agreement.
Add two or three examples from your own business. A clinic might write "never paste a patient's name alongside a symptom". A distributor might write "never paste a dealer's price list or credit terms". Real examples do more than any definition.
Approved tools and accounts
List the tools staff may use for work, and say clearly that company work goes through company accounts, not personal ones. Business accounts usually give you more control over how data is handled, who has access and what happens when someone leaves. Check the terms of each tool before approving it, and record what you checked.
Keep the list short. Two or three approved tools that people know how to use are better than ten that nobody understands. Include a simple route for requesting a new tool, so curiosity becomes a request rather than a workaround.
Human review and accountability
AI can draft, summarise and suggest. It should not have the final word on anything that reaches a client, a regulator or a bank. Your policy should name the outputs that always need a human check before they leave the building: quotes, proposals, contracts, financial figures, medical or legal information, and anything published under the company name.
State the principle plainly: the person who sends it owns it. Using AI does not move responsibility for an error from the employee to the tool.
A policy nobody reads protects nobody, so write the one page people will actually open.
Logging and client data
You do not need heavy monitoring, but you do need a record of how AI is being used in work that matters. Ask teams to note when AI helped prepare client-facing material, and keep a simple register of the AI tools in use, who approved them and what data they touch.
Client data deserves its own line. Some clients, particularly in banking, healthcare and government, will have contract terms that restrict how their information is processed. Your account managers should know which clients these are. If in doubt, the answer is no until someone checks.
Who owns the policy
Give the policy one owner, usually the operations head or a senior manager who understands both the business and the risks. Their job is to answer questions, approve new tools, review the policy every quarter and report to leadership on how AI is being used. In a family business, make sure the owner has the authority to say no, including to senior family members.
Pair the policy with a short training session. Walk through the traffic-light rule with real examples from each department, and invite questions. People follow rules they understand and helped to shape.
Getting it onto one page
A practical structure that fits on a single sheet:
- Purpose: one sentence on why the policy exists.
- The traffic-light rule: green, amber and red, with examples from your own business.
- Approved tools: the list, and how to request a new one.
- Human review: what must always be checked, and by whom.
- Owner and contact: who to ask, and when the policy is next reviewed.
Draft it, test it with five people from different teams, and fix whatever confused them. Then publish it where people actually look, whether that is the intranet, the staff WhatsApp group or the wall by the printer.
If you want help shaping a policy that fits how your business really works, our complimentary one-week Cost Review includes a look at how AI is already being used across your teams and where the gaps are, with a 90-day plan you can act on with or without us.
Want these insights applied to your business?
Our complimentary one-week Review finds your biggest leaks and gives you a 90-day plan, whether or not you work with us.






