- Learn
- AI Automation for Small and Mid-Sized Businesses
- AI use policy template for SMBs
AI use policy template for SMBs
A copy-ready employee AI-use policy: approved tools, data rules, review requirements — and the reasoning behind each section so you can adapt it to your business.
Your employees are already using AI at work. The only question is whether they're doing it under rules you wrote or rules they're making up — pasting who-knows-what into who-knows-which chatbot on a personal account. An AI use policy isn't about banning tools; it's about steering use you can't stop into paths you can defend. Here's the policy, section by section, with the reasoning behind each part so you can adapt it instead of copying it blindly. One note before the template: this is a template, not legal advice — have counsel review the final version, especially if you operate in a regulated industry.
The policy, section by section
1. Purpose and scope. One paragraph: this policy governs the use of AI tools — chatbots, assistants, code and content generators, transcription — by anyone doing work for the company, on any device, on any account. The "any account" part carries the weight: quiet use on personal accounts is exactly what the policy exists to bring into the open.
2. Approved tools. A short, named list of the AI tools the company allows, and at which subscription level — because the business tier of a tool and its free consumer tier have completely different rules about your data. Include the request path: how an employee proposes a new tool, and who decides. A policy without a request path teaches people not to ask.
3. Data rules. The most important section in the document. Define what may never be pasted, uploaded, or dictated into an AI tool outside your approved, contracted tiers: customer names and contact details, anything covered by an NDA, credentials and keys, financial records, employee personal data, unreleased plans and pricing. Set the rules by how much you trust the tool — what's allowed in the company-paid tier, where the vendor has agreed not to train on your data, is different from what's allowed in a free chatbot, which for confidential data is nothing.
4. Human review. AI drafts, humans ship. Anything that leaves the company — an email, a proposal, a contract clause, code in production, a social post — gets reviewed by the person responsible before it goes. The clause is a quality check, not a loyalty test: the person who ships it owns it, however it was drafted.
5. Disclosure. When work is AI-assisted, when does anyone need to know? A sane SMB default: internal use needs no disclosure; client deliverables follow whatever the client contract says; and nobody presents AI output as an expert's independent judgment where that judgment was the thing being bought.
6. Accounts and access. AI tools are used through work accounts with two-step sign-in (MFA) — not personal logins — so access ends when employment does and there's a record of who used what. No shared accounts: with a shared login, nobody can tell whose bad paste it was.
7. Enforcement and review. Breaking the rules is handled the same way as breaking any other workplace policy. The policy itself is reviewed on a schedule — every six months is realistic while the tool landscape is moving this fast — and the approved-tools list can change between reviews without re-issuing the whole policy.
Why each section is there
The data rules are the whole ballgame for an SMB. Almost every real-world AI incident at small-business scale is a data-handling incident: the customer list summarized in a free chatbot, the contract pasted in for a redline, the credentials in a debugging prompt. Sections 2 and 6 exist to make section 3 enforceable — you can't say where data is going if you don't know which tools are in use and whose accounts they're on. And tool tiering beats a blanket ban every time: banning AI outright doesn't stop usage, it just moves it to phones and personal laptops where none of your rules reach.
If you're in a regulated industry
This template is the floor, not the ceiling. A healthcare or dental practice needs the policy plus the practical controls HIPAA actually requires — signed BAAs, a vendor promise not to train on your data, a log of everything the AI looked at, rules on how long data is kept — which is a different document with different stakes: the HIPAA-compliant AI guide covers that checklist. Law and accounting firms carry confidentiality duties that make the data rules stricter by default — the professional services guide goes deeper. And to be precise about what a policy buys you: a policy is not compliance. Compliance lives in how tools are actually set up and used; the policy is what makes that possible.
The policy is step one, not the strategy
Writing the policy usually surfaces a bigger question: which of these tools is actually worth anything to the business? That's a different exercise — looking at where the hours go and what's worth automating properly, versus what's just novelty. The policy makes experimentation safe; an assessment makes it deliberate (ours, Edgerton, measures the real workday for ten business days and reports where the hours go). For the wider picture of what AI adoption looks like at small-business scale — beyond individual chatbot use, toward systems that actually carry work — start with the rest of this pillar.
Frequently asked questions
Brian Kelly
Founder, Automated Edge
Brian spent twenty-plus years running IT and security for small and mid-sized businesses as a managed service provider. Automated Edge brings that same discipline to AI: Edgerton measures where the hours go, then Edgekeeper, a private AI brain on a server we run for you, does the work — and what it learns is yours.
More in this series
How much do managed AI services cost? (2026 ranges)
Real 2026 market ranges by provider type — DIY subscriptions, automation shops, AI consultancies, managed AI retainers — what drives the spread, and the six questions that make any quote comparable.
AI audit for small business: what it actually covers
What an AI audit looks at in a small business — tools in use, data exposure, where the hours go — plus a DIY checklist, and when a measured assessment like Edgerton pays for itself.
Talk to a MAISP, not a consultant.
Thirty minutes with the engineers who'll build and operate your AI — not the SDR queue. We listen, then we tell you the truth about whether AI fits.
Book a Strategy Call