Insights
How to Write a One-Page AI Policy Without a Legal Team
A small business does not need a legal department to use AI safely. It needs one page. Cover what is safe to put into AI tools, what must stay out, and a few plain guardrails. One public AI mistake can sink you. Write the page before you scale use.
Why does a small business need an AI policy at all?
One public AI failure can do real damage: a client's private data pasted into a tool, a confident wrong answer sent as fact, a biased output in your name. A large company absorbs that. A small one might not. A one-page policy is cheap insurance against an expensive mistake.
What's safe to put into AI tools?
Plenty of work is low-risk and fair game. Make the green list explicit so people use AI freely where it is safe:
- Public information and published material
- Draft content you will review before it ships
- General questions, research, and brainstorming
- Anonymised or made-up examples in place of real data
What must stay out?
The red list matters more. Name what never goes into a public AI tool:
- Client personal data and anything confidential
- Passwords, financial details, and contracts
- Anything you would not email to a stranger
- Unreviewed AI output sent as final or as fact
What guardrails keep you clear?
A few plain rules cover most of the risk:
- A human reviews anything client-facing before it goes out.
- Real data is anonymised before it touches a public tool.
- Approved tools only, so use stays in known places.
- When unsure, ask before pasting.
Four rules, one page, no lawyer required.
How do you keep the policy alive?
A policy no one reads protects no one. Keep it to one page in plain language, walk the team through it once, and revisit it when your tools change. Short and used beats thorough and ignored. The goal is a document people follow.
I cover this in my in-person AI Mini MBA, where you write your one-page AI policy in the room and walk out covered. Get in touch at megan@clockwiseco.com for upcoming dates and details.
Frequently asked questions
Do I need an AI policy as a small business?
Yes. The smaller you are, the less you can absorb a public mistake. One page that says what stays out of AI tools and who reviews output prevents the failures that hurt most.
What's the single most important rule?
Keep client and confidential data out of public AI tools. Most serious AI incidents trace back to sensitive information pasted where it should not have gone.
How often should I update the policy?
Review it whenever you add or change tools, and at least twice a year. Tools shift fast. A quick check keeps the page current without a full rewrite.