AI Acceptable Use Policy: What a Small Firm Needs

7 min read

An AI acceptable use policy tells staff which AI tools they may use for work, what information must never go into them, and who checks AI output before it reaches a client. For a business of 5-20 people it should fit on one page and cover eight clauses. It only works if the business gives staff an approved tool first.

Why does a small business need an AI acceptable use policy?

A small business needs an AI acceptable use policy because its staff are almost certainly using AI for work already, with no rules about what goes in. The policy turns private habits into a shared, safe way of working.

The scale is large. Microsoft’s October 2025 survey of 2,003 UK employees found 71% have used unapproved consumer AI tools at work, and 51% do so every week. The same research found 28% said their employer offers no approved option.

The legal exposure sits with the business. Under UK GDPR, the firm stays accountable for client and staff data, whichever tool an employee chose. The ICO’s guidance on accountability and governance in AI is clear that this responsibility cannot be handed to a supplier.

If you have not yet checked which tools are in use, start with our guide on how to find the AI tools your staff use. The policy is easier to write once you know what it has to cover.

What must an AI acceptable use policy cover?

An AI acceptable use policy for a small firm must cover eight clauses, each one short enough to read in under a minute. Free templates online often run to ten pages, and staff stop reading after the first. The wording below is a starting point you can adapt.

  1. Purpose. “This policy lets us use AI to save time while keeping client and staff information safe.” One sentence is enough.
  2. Approved tools. “Use only the AI tools on the approved list, signed in with your work account.” Name each tool and the account type, for example “ChatGPT Business, firm account”.
  3. Data rules. “Never put red data into any AI tool. Amber data goes only into approved tools on a work account.” The traffic light table in the next section defines each colour.
  4. Human check. “You are responsible for anything AI helps you produce. Check every fact, figure, name and reference before it leaves the business.”
  5. Client disclosure. “If a client contract or regulator requires us to say when AI was used, say so.” Some contracts already contain this, so check your largest three.
  6. No decisions about people. “AI may draft, summarise and suggest. It may not decide who is hired, disciplined, refused credit or charged more.”
  7. New tools. “To use a new AI tool, ask [named person] first. We aim to answer within five working days.” A slow answer sends people back to personal accounts.
  8. Mistakes and review. “If you put the wrong data into an AI tool, tell [named person] the same day. You will not be in trouble for reporting it.” The policy is reviewed every six months.

Clause 8 matters more than it looks. Staff hide mistakes they expect to be punished for. A firm that hears about a slip on day one can often delete the chat, change a password or warn a client before any harm is done.

Which data should staff never put into AI tools?

Staff should never put data into an AI tool that would cause harm if a stranger read it, and the clearest way to set that rule is a three-colour traffic light. Each colour names real examples, because “sensitive data” means different things to different people.

ColourWhat it coversExampleWhere it can go
GreenPublic or general informationA blog draft, a job advert, a public price listAny approved AI tool
AmberInternal business information with no personal detailRotas without names, process notes, anonymised figuresApproved tools on a work account only
RedPersonal, client-confidential or security dataClient names and case details, staff health records, bank details, passwordsNo AI tool, unless the owner has approved that exact use in writing

Anonymising moves data down a colour. “A client is disputing last month’s invoice” is amber. The same sentence with the client’s name and invoice number is red.

The red row has one exception on purpose. A business may decide that its Microsoft Copilot account can handle client documents, because the contract covers it. That should be a written decision by the owner, recorded on the approved list, never an individual’s judgement call.

Why does the policy depend on which AI account staff use?

An AI policy depends on the account because the same chatbot handles data under different terms depending on who pays for it. A personal ChatGPT account and a firm’s ChatGPT Business account look identical on screen.

The terms behind them differ. OpenAI states it does not train on data from ChatGPT Business, Enterprise or the API by default. On consumer accounts, training is on unless the user switches it off. Microsoft’s documentation says Copilot prompts, responses and data accessed through Microsoft Graph aren’t used to train foundation models.

That is why clause 2 names the account as well as the tool. A rule that says “ChatGPT is allowed” lets staff use their personal login. A rule that says “ChatGPT Business, firm account” closes that gap. Our piece on keeping company data out of AI model training covers the vendor terms in more depth.

What does the human check clause protect you from?

The human check clause protects a business from sending out confident, wrong work with its name on it. AI tools invent facts, figures and references that read as real, and a client cannot tell the difference.

The UK High Court showed the cost in June 2025. In Ayinde v Haringey, heard with Al-Haroun v Qatar National Bank, one witness statement cited 45 authorities and 18 of them did not exist. The client said he had used public AI tools. The solicitor had not checked them.

The court’s finding is the lesson for any owner: the professional who signs the work owns it. The judgment also says that issuing guidance alone is not enough to stop misuse. A policy needs a named check, done by a person, before work leaves the building.

In practice that means one line per job type. Quotes are checked against the price list. Letters are checked for names and dates. Anything with a legal or financial figure is checked against its source.

How do you roll out an AI policy so staff follow it?

You roll out an AI policy by giving staff the approved tool on the same day as the rules, then walking through the policy in a 20-minute team meeting. A policy that only removes options gets ignored.

Follow this order:

  1. Set up business accounts for the AI tool most staff already use.
  2. Fill in the approved list and the traffic light with your own examples.
  3. Run a 20-minute meeting and ask each person to name one job they use AI for.
  4. Ask everyone to sign or reply to confirm they have read it.
  5. Put a review date in the diary for six months’ time.

The examples from step 3 are valuable. They show you which jobs staff already trust AI with, and those jobs belong on your approved list with clear data rules.

Loading the approved tool with your firm’s own context makes it more useful than a personal account, which removes the main reason to go elsewhere. The Business Brain is built to give a small team that setup.

Should you write the policy before choosing your AI tools?

A small business should choose its AI tools before finalising the policy, because the policy describes how chosen tools are used. Writing rules first produces a document about tools nobody has picked.

This is the diagnose-first view Bedrock AI takes. Map which jobs in the business AI could help with, choose the accounts that fit those jobs, then write the one-page rules around them. The policy then reflects real work rather than a generic template.

For the wider picture of who owns AI decisions in a small firm, read our piece on AI governance for small businesses.

FAQ

Is an AI acceptable use policy a legal requirement in the UK? An AI acceptable use policy is not a specific legal requirement in the UK. Under UK GDPR, though, a business must protect the personal data it holds and show how it does so. A written AI policy is one of the simplest ways to evidence that.

How long should an AI acceptable use policy be for a small business? An AI acceptable use policy for a business of 5-20 people should fit on one page, plus a short approved tools list. Staff read and remember one page. Ten-page templates tend to be signed and forgotten.

Can staff use their personal ChatGPT account under an AI policy? Most small business AI policies should ban personal accounts for work. A personal ChatGPT account follows consumer terms, where chats can be used for training unless the user opts out. A firm-owned business account keeps the data under the business’s contract.

How often should a small business update its AI policy? A small business should review its AI acceptable use policy every six months, and sooner when it adds a new AI tool. AI products change their features and terms often, so the approved list goes out of date faster than most policies.


Get ahead with AI by getting The Business Brain | Would rather talk it through? Book a free 15-minute call

Keep reading

More for owners

All articles
Shadow AI Shadow AI: How to Find the AI Tools Your Staff Use Shadow AI is any AI tool staff use for work without your sign-off. Here are the five places to find it in an afternoon and a rule for what to keep. / 7 min AI strategy How to Keep Company Data Out of AI Model Training Company data stays out of AI model training through vendor contract terms, routing and data classification, not a single settings toggle. / 7 min Consulting The Consulting Staffing Pyramid Problem, Explained Why the senior partner in the pitch meeting rarely does the diagnostic work, and what AI is doing to the pyramid model that made this normal. / 6 min
Book a free call