Your Employees Are Already Using AI. Here’s the Policy That Should Have Existed First

team discussion whiteboard

Whether or not your business has officially adopted AI, your employees have. Somebody in your office is pasting text into a free chatbot right now. Drafting an email, summarizing a document, maybe rewriting a proposal. They’re doing it on a personal account, on the free tier, with no record of what went in, and with the best of intentions.

That’s shadow AI, and it’s the default state of every organization that doesn’t have a policy. The risk isn’t hypothetical either. Free consumer AI tools may retain whatever users type into them, and once client information or anything under NDA goes in, you can’t get it back. You also can’t manage what you can’t see.

An AI acceptable use policy isn’t about slowing anyone down. It’s about taking something that’s already happening and moving it into a lane you can actually see.

Employee using an AI chatbot on a laptop

Why banning AI backfires

The instinctive response is “no AI tools, period.” It’s also the one policy that reliably fails. A ban doesn’t stop the usage. It just moves it to personal phones and personal accounts, where you have zero visibility and zero control. And the people using AI are usually your most productive employees trying to work faster. Take away the sanctioned path and they’ll find an unsanctioned one. They always do.

The organizations that handle this well do the opposite. They name an approved tool, draw clear lines around data, and make the rules easy to follow. You prohibit the behavior you actually fear, which is sensitive data leaving the building. Not the technology.

What a good small business AI policy covers

You don’t need fifteen pages. You need one page that answers six questions.

Which tools are approved. Name them, including which account to use. “The company Microsoft 365 Copilot license” is a rule people can follow. “Approved AI tools” is not. And if you prohibit free consumer tools, you have to provide an alternative. A prohibition with no sanctioned option is just a ban wearing a policy costume.

What data never goes in. This is the section that matters most. The usual no-go list: customer and client personal information, employee records, passwords and credentials, financial and payroll data, anything covered by an NDA, health information, and proprietary business information like pricing models or client lists. The simplest way to draw the line: if you wouldn’t email it to a stranger, don’t paste it into an AI tool the company hasn’t approved.

Who owns the output. AI produces drafts. A human reviews, corrects, and takes responsibility for anything that goes out the door. “The AI wrote it” is never an explanation for a mistake a client sees. This one expectation prevents most AI-related quality problems on its own.

When to disclose. Decide where your organization stands on telling clients that AI assisted with their work, and write it down. There’s no universal right answer here. There is a wrong one, though: each employee guessing for themselves.

How to request a new tool. New AI tools show up every month. Give employees a two-sentence path, something like “send the tool name and what you want to use it for to this person,” so the policy bends instead of getting ignored.

When the policy gets reviewed. AI moves too fast for a write-once policy. Commit to revisiting it every six months and put a date on it.

The mistakes I see most often

Copy-pasting an enterprise policy. A 40-page framework written for a 5,000-person company will not be read by anyone at a 20-person firm, and an unread policy protects no one.

Writing it once and forgetting it. A policy that names tools that no longer exist tells everyone that nobody is minding this.

All prohibition, no path. Rules about what’s forbidden, silence about what’s allowed. People need a yes, not just a list of nos.

Emailing it instead of explaining it. A policy nobody discussed is a policy nobody follows.

The template

Here’s a starting point sized for small and mid-size businesses. Replace the bracketed text, cut what doesn’t apply, and have your attorney look it over before you adopt it, especially if you’re in a regulated industry. This is a practical starting point, not legal advice.


[Company Name] Artificial Intelligence Acceptable Use Policy

Effective date: [date] | Next review: [date + 6 months] | Policy owner: [name/role]

1. Purpose. [Company Name] supports the responsible use of AI tools to improve how we work. This policy defines which tools may be used, what information may be shared with them, and the responsibilities of every employee who uses them.

2. Scope. This policy applies to all employees and contractors using AI tools for any work-related purpose, on any device.

3. Approved tools. The following tools are approved for business use, under company-provided accounts only: [list tools and account types, for example “Microsoft 365 Copilot under your company login”]. Personal accounts on any AI service may not be used for work-related tasks. Tools not listed here require approval under Section 7.

4. Prohibited data. The following may never be entered into any AI tool, including approved ones, unless [role, for example the policy owner] has confirmed in writing that the specific tool is authorized for it: customer or client personal information; employee personal information; passwords, credentials, or access keys; financial, payroll, or banking data; any information covered by a confidentiality agreement; health information; and proprietary business information including pricing, contracts, and client lists.

5. Responsibility for output. AI-generated content is a draft. The employee who uses it is responsible for reviewing it for accuracy, appropriateness, and confidentiality before it is used or sent. Errors in AI-assisted work are the responsibility of the person who produced the work.

6. Client disclosure. [Choose one: “Employees must disclose material AI assistance in client deliverables when asked.” / “AI assistance in client deliverables must be disclosed proactively as follows: …” Set your standard here.]

7. New tools. To request approval of a new AI tool, send the tool name and intended use to [name/email]. Do not use unapproved tools while a request is pending.

8. Violations. Violations of this policy, particularly Section 4, are treated as seriously as any other mishandling of confidential information and may result in disciplinary action.

9. Acknowledgment. I have read and understood this policy.

Signature: ______________________ Date: ____________


Small business team reviewing an AI acceptable use policy together.

How to roll it out

Don’t email the PDF and call it done. Hold a 30-minute meeting. Explain why the data rules exist. One concrete story about pasted client data does more than any policy language. Demo the approved tool so people see the sanctioned path, collect signed acknowledgments, and put the six-month review on the calendar before the meeting ends.

Want a second opinion?

If you want help adapting this to your organization, choosing the right approved tools, tightening the data rules for your industry, or figuring out whether something like Copilot is worth deploying at all, that’s exactly what I do. I’m vendor-neutral. I don’t resell any AI platform, so the advice is only ever about what fits your business.

Book a free 30-minute call and we’ll talk through where AI does and doesn’t belong in your operation.

Scroll to Top