Bottom line: most small businesses have no written AI policy, yet almost every member of staff is already using AI tools on company laptops, often with client information pasted straight into the box. The fix isn't banning AI, it's writing four pages that tell people what's fine, what's not, and what happens with client data. You can do it in an afternoon, and you should do it this week.
The bit nobody flags until it's too late
I was working with a recruitment agency in Manchester last year, fourteen staff, decent business, been going eleven years. Their office manager was brilliant, on top of everything, and she'd taken to using ChatGPT to summarise candidate CVs and speed up shortlisting emails to clients. Sensible on the surface. Except she was also pasting in the client contract terms so the AI could "write it in their tone", which meant confidentiality clauses, rate cards and one client's entire notice period language were sitting inside a free ChatGPT account with no enterprise settings, no data retention controls, nothing.
Nobody told her not to. Nobody told her she could either. There was no conversation at all. That's the actual problem in most small businesses right now: not reckless staff, just an total absence of guidance.
Microsoft's Work Trend Index has repeatedly found that a large majority of knowledge workers already use AI tools at work, and a big chunk of them are using tools their employer never approved or even knows about. That second stat is the one owners skip past. It's not that your team might start using AI one day. They started months ago, on their own logins, with their own judgement calls about what's safe to paste in.
The uncomfortable part most advice avoids
Here's what a lot of AI safety content won't say plainly: banning ChatGPT at work does not stop people using ChatGPT at work. It just moves it to their personal phone, on their own account, where you can't see it, can't audit it, and definitely can't recover anything if it goes wrong. A blanket "no AI tools" policy feels responsible and does almost the opposite of what you want. It removes your visibility at the exact moment you need it most.
I've seen this play out with a marketing consultancy client of mine who banned AI outright after a scare story in the trade press. Within a month her copywriter was using her own ChatGPT Plus subscription on her iPhone during work hours, still doing exactly the same drafting work, just now completely outside company oversight, on a personal account with no way to trace what data had gone where. The ban didn't reduce risk. It hid it.
The businesses that manage this well don't try to stop AI use. They channel it, the same way you'd channel a team that's already using their own Google Docs and Dropbox before you ever bought them proper software.
What needs to be in an AI policy
You don't need forty pages or a lawyer on retainer, though if you're handling health, financial or legal data, get a lawyer to check the final version. For most small businesses, four sections cover it.
1. What can go into an AI tool, and what absolutely can't
- Fine: generic drafting, brainstorming headlines, summarising publicly available information, editing your own already-approved copy
- Never: client names paired with contract terms, pricing, personal data of customers or candidates, anything covered by an NDA, unpublished financials, staff performance details
Write it as a simple test, not a legal clause: "if you wouldn't paste this into a public Facebook post, don't paste it into a free AI tool." That one line does more work than three pages of policy language.
2. Which tools are approved and which accounts to use
A ChatGPT Plus account on a company email with business data settings turned on is a very different risk profile to a free personal account. Decide which tools people are allowed to use, get business-tier subscriptions where the budget allows (ChatGPT Team runs around 25 to 30 dollars per user a month, Claude for Work is similar), and say so in writing. If you can't afford business accounts for everyone yet, say that too, and set the boundary lower until you can.
3. Who checks AI output before it goes out
This is the one most policies skip. AI drafts a client email, an invoice query response, a job description. Someone still has to read it before it's sent. Not because AI is unreliable in some vague sense, but because it will confidently invent a detail, a date, a figure, that sounds completely plausible and is completely wrong. I've had AI tools invent a case study result that never happened and state it as fact, in a tone so measured I almost sent it. One human check, every time, non-negotiable.
4. What happens when someone breaks the rules
Not instant dismissal for a first mistake, that just teaches people to hide it better next time. A conversation, a note in writing, retraining. Save the serious consequences for repeat or deliberate breaches, particularly anything involving client confidentiality, where you may also have obligations under UK data protection law to tell affected clients something happened.
How to write it in an afternoon
I've done this with several small business clients now, and the pattern that works is short and boring, on purpose.
- Step one: list every AI tool anyone on your team already uses, even the ones you've only heard about secondhand. Ask directly, and don't be surprised by the answers.
- Step two: sort your business data into three piles, public, internal, confidential. Client contracts, personal data and pricing go straight in confidential. Everything else gets discussed.
- Step three: write the four sections above in plain English, one page each, no legal jargon.
- Step four: put it in your team handbook or onboarding pack, and walk through it in a fifteen-minute team meeting, not a memo nobody reads.
- Step five: revisit it every six months, because the tools change faster than most policies do.
That's the whole process. A whole afternoon, most of it spent on step one, because that's where the surprises live.
Where this connects to your marketing, not just your risk register
Once the policy exists, the more interesting question is what your team does with AI once it's sanctioned rather than sneaked. This is where most small businesses waste the opportunity. They write a policy purely to avoid disaster and never think about using AI for growth. Brands that get real value from AI treat it as part of a consistent voice and process, the same discipline you'd see in how the GoPro marketing strategy kept every piece of content, however small the team producing it, sounding like the same brand. Consistency was a rule, not an accident, and the same needs to apply to AI-assisted content leaving your business.
Want AI doing the heavy lifting in your marketing?
I build the systems that handle the boring 80 percent, so you get your week back. Done properly, with the human kept in.
Content discipline is also the throughline in Joe Pulizzi's business lessons, where the point that sticks with me is that a content plan only works if everyone touching it follows the same standard, whether they're writing it themselves or drafting with a tool. If your AI policy stops at "don't leak data" and never touches "here's the tone we want", you'll end up with technically safe output that reads like nobody in particular wrote it.
The same applies to platform-specific work. Before anyone lets AI draft captions, worth looking at how deliberately the Instagram marketing strategy behind a strong account is built, because a policy that only says what's forbidden and never says what good looks like will produce safe, forgettable content forever.
Teams working across shared design and content tools face the same question from a different angle, and it's part of why collaborative platforms in the Figma marketing strategy put so much weight on shared standards rather than individual taste. Shared tools always need shared rules, AI included.
When it's worth bringing someone in
If you're past ten or fifteen staff, several client accounts and multiple AI tools already in daily use with no oversight, this stops being a one-afternoon job and starts being worth outside help. I've written before about what that costs and what you get for the money on my page about how much an AI consultant costs, and the short version is that a proper audit of who's using what, with what data, usually pays for itself the first time it stops a genuine leak rather than a near miss.
Email is often where the gaps show up first, since so much client-sensitive content flows through it daily, and the same discipline that built trust in the Mailchimp marketing strategy, clear rules about what goes to whom and how, is exactly the mindset your AI policy needs for outbound client communication.
What I'd tell you if you only read one paragraph of this
Your team is not going to stop using AI because you're uncomfortable with it. They're going to keep using it whether you write anything down or not, so the only real choice is whether they're doing it inside your visibility with rules you set, or outside it on personal accounts you'll never see. Write the four pages. Have the fifteen-minute meeting. It's the cheapest insurance policy your business will buy this year.
Frequently asked questions
Do small businesses need a written AI policy?
Yes, if more than one person handles client, financial or personal data and has access to any AI tool, which describes most small businesses in 2026. A written policy doesn't need to be long, four short sections covering allowed tools, banned data types, human checks before sending, and consequences for breaches is enough for most teams under twenty people.
What's the biggest risk of staff using AI without guidance?
Confidential data, client names paired with contract terms, pricing, or personal information, ending up inside a free AI account with no enterprise data controls, where it can be retained or used to train the model. The second biggest risk is AI-invented facts going out to clients unchecked, because output can read as confident and accurate when it's neither.
Should I just ban AI tools until I've worked out a proper policy?
No, a blanket ban usually pushes staff onto personal devices and personal accounts, which removes your ability to see or audit what's happening at all. It's better to set clear rules quickly, even simple ones, than to ban AI and lose visibility entirely.
How much does it cost to get outside help with AI policy and data risk?
For a small business audit and policy build, costs typically range from a few hundred pounds for a light-touch review to a few thousand for a full audit across several teams and tools, depending on how many systems and how much client data are involved.
Related reading: What Your AI Meeting Notetaker Is Doing With Your Client Calls and Why Every AI-Written Newsletter Sounds the Same (And What I Changed In Mine).