AI Acceptable Use Policy Template for Small Business
Your staff are already using AI. The question is whether anyone has told them what is allowed. Below is a policy you can copy, adapt and issue this week — free, no form, no email address required.
Why one page and not twenty
A policy nobody finishes reading is not a control. The twenty-page version exists to protect the company in a dispute; the one-page version exists to change what someone does at 4pm on a Tuesday. You want the second one. If you need the first as well, write it afterwards.
A policy that simply says “do not use AI” is worse than no policy, because it pushes the activity onto personal accounts and personal devices where you have no visibility at all.
The template — copy everything in this box
[COMPANY] — Acceptable Use of AI Tools
Effective [DATE] · Owner: [NAME, ROLE] · Review: annually
1. Why this exists. AI tools are useful and we want people using them. This page says which ones, with what information, and who to ask. It applies to everyone, including owners and contractors.
2. Approved tools. Only these, and only signed in with your work account:
- [e.g. Microsoft Copilot — business tier]
- [e.g. ChatGPT Business — company workspace only]
- [e.g. approved meeting note-taker]
Personal accounts are not approved for work, even for the same tool. If a tool is not on this list, ask before using it for anything work-related.
3. Never put this into any AI tool.
- Anything that identifies a customer, client or patient
- Passwords, keys, or anything from the password manager
- Payment card, bank or payroll details
- Employee records, HR matters, medical or disciplinary information
- Signed contracts, or anything covered by an NDA
- [add anything specific to this business]
4. Recording and meetings. Do not let an AI assistant record a meeting without telling everyone present and giving them a chance to object. Florida requires consent from every participant. Never record conversations covered by privilege, HR matters, or anything involving patient information.
5. Connecting AI tools to company systems. Do not grant an AI tool access to company email, files, calendars or chat without approval from [NAME]. That permission usually has no expiry and is invisible once granted.
6. You are responsible for the output. AI drafts; a person checks. Anything that goes to a customer, a regulator or into a legal or financial document is checked by a human first. If it is wrong, that is on the person who sent it, not the tool.
7. Tell us when something goes wrong. If you pasted something you should not have, say so the same day. Nobody is disciplined for reporting it quickly. That is the whole point of this paragraph.
8. Questions. Ask [NAME] — including “can I use this new thing I found?” The answer is often yes.
Three things to do before you issue it
1. Fill in section 2 honestly
Approve at least one tool people actually want. A list containing nothing they find useful will be ignored, and you will have taught your staff that the policy is decoration.
2. Find out what is already connected
This is the step almost everyone skips, and the policy is much weaker without it. Tools granted access months ago keep it indefinitely — there is no expiry and no alert. When we ran this check on our own Microsoft 365 tenant we found ChatGPT holding permission to read every file we owned, and a meeting recorder with calendar access across the organisation. Nobody had done anything wrong; someone had clicked Accept once. The full story is here.
Changing a setting does not revoke what was already granted. Existing permissions have to be removed deliberately.
3. Decide who owns it
One name in section 1, and that person answers the “can I use this?” questions. Without a name it is nobody’s job and it goes stale in a quarter.
If you are in a regulated business
Medical, dental and behavioural health practices: standard consumer AI tools are not suitable for anything containing patient information, and a vendor handling it is a business associate who needs an agreement in place first. Tax and accounting firms: the same information you protect under the FTC Safeguards Rule does not stop being protected because it went into a chat window. Law firms: confidentiality obligations follow the information wherever it goes.
In each case the fix is the same — an approved tool on the right tier, with an agreement, and section 3 of the policy written to match what you actually hold.
Want someone to check the second step for you?
We run an audit against your Microsoft 365 tenant that reports which AI tools already hold access, exactly what each can reach, and who approved it. It takes about ninety seconds to run. If it comes back clean we will say so plainly — that happens, and it is a legitimate result.
Get in touch — (321) 221-7117, Monday to Friday, 8am to 6pm. More on how we approach AI consulting, and why the recording clause in section 4 matters in Florida.
This template is general information, not legal advice. It is a starting point written for small businesses — have counsel review it if your situation warrants.