Straight answer: if you run a small business and have not written down what your team can and cannot put into AI tools, someone has already pasted something they shouldn’t have, and you just don’t know about it yet. A one-page AI policy, written this afternoon, fixes most of the risk. You don’t need a lawyer or a 40-page document to start.
The email that made me write this
Last October, a client of mine, a PR consultant running a four-person agency near Bristol, called me in a bit of a panic. One of her account managers had taken a client’s unreleased product launch brief, embargoed press release and all, and pasted the whole thing into ChatGPT to “tidy up the tone.” Nothing malicious. She just wanted a faster first draft.
The problem wasn’t that the AI leaked anything (it didn’t, and the free consumer version of ChatGPT doesn’t train on your inputs by default anymore, which most people still don’t know). The problem was that my client had no idea it had happened until the account manager mentioned it in passing three weeks later. If that brief had contained financial figures, or a client’s confidential customer data, she would have had a genuine disclosure problem and no idea it existed until it was too late to fix quietly.
She didn’t have a policy. She had assumed her team would use common sense. Common sense is not a policy, it’s a hope.
Most small businesses have no policy, and that silence is itself a policy
I run a small community for business owners experimenting with AI, and I asked 92 of them a blunt question in January: “Do you have a written policy for what your team can put into AI tools?” Sixty-one said no. Of those 61, only four said they’d ever discussed it out loud with their staff at all.
Here’s the uncomfortable bit nobody wants to say plainly: not having a policy doesn’t mean AI isn’t being used at your business. It just means you’ve delegated the decision about what’s safe to whoever on your team is boldest and least worried about asking permission. That’s usually your most enthusiastic, most junior person. Not because they’re careless, but because nobody ever told them where the line was.
Banning AI outright doesn’t fix this either. I’ve spoken to three business owners in the past year who “banned” AI tools at work, and in every single case their staff kept using it on personal phones, personal logins, outside any company oversight. A ban without a plan just moves the risk somewhere you can see even less of it.
What needs to be in a one-page AI policy
You don’t need this to sound like a legal document. You need it to sound like something a human would read in ninety seconds and remember. Here’s the structure I give clients, and you can copy it word for word:
- What tools are approved. Name them. “ChatGPT (business plan only, not personal accounts), Claude, Gemini.” If you haven’t picked, pick this week, not “eventually.”
- What can never go in, full stop. Client contracts, unreleased pricing, anything with a person’s full name plus financial or health information together, unpublished financial results, anyone’s ID documents.
- What’s fine to put in. Draft blog posts, generic email templates, competitor research from public sources, meeting notes you wrote yourself.
- Who to ask when unsure. One named person. Not “management,” a name.
- What happens if someone gets it wrong. Say plainly that mistakes get reported, not hidden, and that reporting early is never a punishment. This one line does more work than the rest of the document combined, because it’s the reason my client found out three weeks late instead of three minutes late.
The one-hour version, step by step
- Block out 60 minutes this week, not “sometime this month.”
- List every AI tool anyone on your team has mentioned using, even in passing. Ask them directly, don’t guess.
- Pick your approved list. For most small businesses that’s one general chat tool on a paid business or team plan (never free consumer accounts for anything client-facing) plus whatever’s built into tools you already pay for, like the AI features inside Mailchimp for subject lines or Canva for design copy.
- Write the five sections above in plain English. Read it aloud to yourself. If it sounds like a compliance manual, cut it in half.
- Send it, don’t file it. Put it in the same place as your holiday request form, somewhere people already look.
- Put a 15 minute review in your calendar for three months’ time. Policies written once and never touched again are the ones nobody follows by month four.
The settings most owners never check
If your team is using ChatGPT, Gemini, or Claude on personal or free accounts, there’s a data control setting most people never open. On ChatGPT’s free and Plus tiers, there’s a toggle under Settings, Data Controls, that stops your conversations being used to train future models, but it’s off by default for a lot of accounts and buried in a menu nobody visits twice. Business and Enterprise tiers handle this differently and generally exclude training by default, which is one honest reason to pay for a proper business seat rather than let staff run on personal logins. It costs roughly £20 to £25 per user per month for a decent business tier across the major tools. That’s cheaper than one afternoon of a solicitor’s time if something goes wrong.
The other thing worth doing: turn off “memory” features on shared or work-purpose accounts unless you’ve decided as a business that you want AI tools remembering client names and preferences across sessions. Convenient, yes. Also a quiet way for sensitive detail to accumulate somewhere you never asked it to.
Where this shows up in marketing work
This isn’t only a legal-risk conversation, it’s a quality one too. I see agencies feeding entire client brand documents into AI tools to write social captions, then wondering why the output sounds like nobody in particular. The businesses that get AI-assisted marketing right, the ones I studied when writing about how Airbnb built consistency across a huge, messy platform or how Figma kept its brand voice tight while scaling fast, treat AI as a drafting tool inside a system with clear rules, not a replacement for judgement. A policy that says what goes in and what doesn’t also, quietly, protects your brand voice, because it forces someone to think before pasting the whole client history into a prompt and hoping for magic.
The same logic applies to social. If your team is drafting posts for a client’s Instagram strategy using AI, unreleased campaign dates and influencer contract terms are exactly the kind of thing that should sit on your “never” list, even though a caption draft is perfectly fine to run through a chatbot.
I’d also say this plainly, because it’s the part most guides skip: your AI policy is not really about AI. It’s about the fact that you probably don’t have a clear data-handling habit at all, AI just made the gap visible. If you’ve never had a clean answer to “where does client information live and who can see it,” writing the AI policy is often the moment you notice that gap for the first time. Use it as the excuse to fix both.
What to do if you find out something’s already gone wrong
My Bristol client’s story ended fine, in the end. She checked with the client, confirmed nothing commercially damaging had been exposed (the embargoed release wasn’t published anywhere and the account manager hadn’t shared outputs outside the team), tightened her settings that afternoon, and had her one-page policy written and sent to her team within 48 hours. The client never found out there’d been a wobble at all.
If you’re in that position now, don’t skip the awkward step of checking with the affected client or partner if there’s any real chance something sensitive left the building. Silence feels safer in the moment. It very rarely is, if it surfaces later through someone else.
None of this needs to be dramatic. It needs to be written down, sent to real people, and revisited on a date that’s already in your calendar. That’s the whole job. If you want someone to sit down with you and build this alongside your wider AI setup rather than bolting it on as an afterthought, this is exactly the kind of groundwork an AI implementation coach walks through in the first week, before touching a single marketing tactic.
Businesses that treat decisions like this the way Alex Hormozi talks about making decisions fast and cheap early, then correcting course, tend to do this well: write the imperfect policy today, improve it in three months, rather than waiting for the perfect version that never gets written at all.
Free resource: The Pricing Page Copy Prompt Pack.
Frequently asked questions
Do I need a lawyer to write an AI policy for a small business?
No, not for a first version. A clear one-page document covering approved tools, what data can never be entered, and who to ask when unsure covers most small business risk. Get a solicitor to review it once your team is over roughly 15 people or you’re handling regulated data like health or financial records at scale.
Is it safe to use the free version of ChatGPT for client work?
It’s riskier than a paid business account, mainly because free and personal accounts are easier to leave on default settings that use conversations for training, and because there’s no company-level oversight of what’s being entered. For anything touching client information, a paid business or team tier with data controls checked is worth the roughly £20 to £25 a month per person.
What’s the single biggest mistake small businesses make with AI and data?
Assuming staff will use common sense without ever telling them where the line is. Most people using AI carelessly aren’t being reckless, they simply were never told what counts as sensitive in your specific business, because nobody wrote it down.
How often should an AI policy be updated?
Every three months is a sensible starting rhythm for a small business, since the tools and their settings change faster than most policies do. Put the review date in your calendar the same day you write the first version, or it won’t happen.
Related reading: AI Meeting Notetakers Are Quietly Costing You Client Trust and Notion Marketing Strategy: How They Built a Brand That Wins.