Asset 20 8 2
Does AI recommend your business? Run the free check →

Join 15,000 business owners, marketers and entrepreneurs. The Sunday newsletter you'll be annoyed only arrives once a week.

Article

The AI Policy Your Small Business Needs (And Almost Certainly Doesn't Have)

Straight answer: if you run a small business and someone on your team has pasted a client email, a spreadsheet, or a contract into ChatGPT this month (and someone has), you don't have an AI problem, you have a policy problem. You need one page, five rules, and a named owner, and you need it before your next client asks what happens to their data when your team uses AI, not after.

The bit almost every small business skips

I've sat in maybe forty small business conversations about AI in the last year, some paid consulting, most just people cornering me at events because I'm the "AI woman" now. Every single one starts with the exciting stuff. Chatbots. Content. Automations. Nobody, not once, has opened with "what's our written policy on what staff can and can't put into AI tools." And almost none of them have one.

That's the gap. Not the tools. The rules around the tools. A 2024 Microsoft Work Trend Index found that most employees using AI at work are bringing their own tools, personal ChatGPT accounts, free Gemini logins, whatever's on their phone, without telling anyone. Small businesses are worse than big ones here, not better, because there's no IT department to even notice.

What happens when you don't have a policy

A client of mine runs a small bookkeeping firm, six staff, decent client list of local tradespeople and a couple of small retail chains. One of her junior team members was drowning under end of quarter reconciliations and pasted a spreadsheet of client invoices, names, amounts, account references, the lot, into a free ChatGPT account to get it to summarise discrepancies faster. Sensible instinct, terrible execution. That data sat inside a free-tier account with no enterprise data controls, meaning it could be used to train the model unless settings were changed, which they weren't, because nobody had ever told her they needed to be.

Nothing catastrophic happened in the end. No breach made the news, no client found out. But when my client found out what had happened, three weeks after the fact, she had to make an awkward call about whether it was even something she was obliged to disclose under her contracts with two of those retail clients, which had strict confidentiality clauses. She spent a weekend rereading contracts she'd signed two years earlier and hadn't looked at since. That's the real cost of no policy. Not a fine. A weekend of panic and a very uncomfortable conversation with a client about something you can't fully undo.

Why "just ban it" doesn't work

The instinct after a scare like that is to ban AI tools outright. I've watched two businesses try this. Both failed within a month, because staff just moved the behaviour to their personal phones, on their own data plans, completely invisible to the business. You've not removed the risk, you've removed your ability to see it. This is the uncomfortable bit nobody likes admitting: banning AI at work doesn't stop AI use at work, it just stops you knowing about it. A policy that assumes people will use AI, and tells them how, beats a policy that pretends they won't, every single time.

Richard Thaler's whole body of work on defaults is useful here even though he was writing about pensions, not prompts. People overwhelmingly stick with whatever the default setting is, because changing it takes effort and most people won't bother. If your business's default is "no written guidance, figure it out yourself," your actual policy is whatever your most anxious or most reckless staff member decides on their own. I go into this in the business lessons I've taken from Thaler's work, but the short version is: set the default deliberately, because someone is going to set it for you otherwise.

The one-page AI policy that works

This isn't a legal document. I'm not a lawyer and this isn't legal advice. This is the practical, one-page version I've helped clients build that stops the obvious mistakes without turning AI into a forbidden fruit nobody talks about.

1. Name the tools you're comfortable with

Don't say "AI." Say "ChatGPT Team, Claude, and Copilot are approved, free personal accounts are not, because we can't control what happens to data in them." Specific names, specific reasons. Vague policies get ignored, specific ones get followed.

2. Draw a hard, boring line around client data

The rule that would have saved my bookkeeping client twenty minutes of panic: no client names, account numbers, invoice details, or anything identifying a real person or business goes into any AI tool that isn't on an approved business account with data protection settings switched on. Anonymise it or don't use it. This one rule alone prevents most of the actual damage.

3. Set a rule for anything published under your brand name

AI-drafted content is fine. AI-published content with nobody reading it first is how businesses end up with factual errors, off-brand tone, or straight-up fabricated statistics going out under their name. I've seen it happen to a competitor who published an AI-written "case study" with a client quote that was entirely invented. The client saw it. That relationship ended. If you want a masterclass in protecting what a brand stands for before you let anything near it, look at how tightly Coco Chanel controlled her name and image, a discipline I write about in these business lessons from Coco Chanel. Nobody outside her circle touched what carried her name without her eyes on it first, and that's exactly the standard your AI-assisted content needs too.

4. Put a real name on it

Someone in your business owns this policy, updates it, and is the person staff ask "can I use this tool for this" before doing something risky. In a six-person firm that's usually the owner. It should never be "nobody's sure, ask around."

5. Review it every quarter, not every year

This space moves fast enough that an AI policy written in January 2026 will have gaps by June. New tools launch, staff find new workarounds, and your customer-facing tools change too. If you're using AI on your website for lead capture, quote generators, or interactive tools like the ones I've written about with interactive calculators that convert visitors, that data collection needs the same scrutiny as internal use, because it's still customer data flowing somewhere.

Work with me

Want AI doing the heavy lifting in your marketing?

I build the systems that handle the boring 80 percent, so you get your week back. Done properly, with the human kept in.

What to do if you've already had a scare

If you're reading this because something's already happened, first, breathe, most near misses don't turn into breaches. Check the account settings on whatever tool was used, most paid business tiers of ChatGPT, Claude, and Copilot let you turn off model training on your data, free consumer accounts historically did not by default. Second, check your client contracts for confidentiality or data handling clauses before you decide whether to disclose anything, the way my client had to. Third, write the policy this week, not next quarter, while the memory of the scare is still making everyone take it seriously.

The awkward truth about your team and shadow AI

Here's the part that makes business owners uncomfortable: your staff are probably already better at using AI tools than you are, and they know it, and that's exactly why they're not asking permission. GoDaddy built an entire brand around making small business owners feel capable rather than intimidated by tools they didn't fully understand, a positioning I break down in how GoDaddy built its brand, and the same lesson applies internally. If your team feels like asking about AI use will get them told off, they'll stop asking and keep doing it anyway. A policy that opens with "here's what you can do" rather than "here's what you can't" gets followed. One that reads like a warning gets ignored the same week it's written.

What this costs you if you get it wrong

Under UK GDPR, a personal data breach involving special category or high-risk data can bring an ICO fine of up to 4% of annual global turnover or 17.5 million pounds, whichever is higher, though in practice small business fines are far lower, often in the low thousands for first, minor, self-reported incidents. But the fine was never the real cost in my client's case, or in most small business cases I've seen. The real cost was time, three weeks of not knowing, a weekend of contract reading, and a residual nervousness with two clients that took months to fully settle. Getting your AI content tone wrong costs you differently but just as painfully. Headspace spent years building a specific, calm, consistent voice, something I cover in how Headspace built its brand, and one unchecked AI-generated blog post in the wrong tone can undo a chunk of that consistency in a single afternoon. If you'd rather have someone build this policy with you, and stress-test it against how your specific business runs, that's exactly the kind of thing an AI implementation coach should be doing with you in the first session, not the fifth.

None of this needs to be complicated. It needs to exist, be specific, and be reviewed. That's the whole job.

Frequently asked questions

Do small businesses need a formal AI policy, or is that just for big companies?

Small businesses need it more, not less, because there's no IT team catching mistakes before they happen. A one-page policy with five clear rules is enough for most businesses under twenty staff, and it matters more the smaller you are because one mistake affects a much larger share of your client base.

What's the single biggest AI risk for a small business right now?

Staff pasting client or customer data into free, consumer-tier AI accounts that aren't covered by any data processing agreement with the business. It's rarely malicious, it's almost always someone trying to save time, and it's the easiest risk to fix with one written rule.

Should I just ban AI tools at work until we've figured this out?

No. Banning tends to push AI use underground onto personal phones where you can't see it at all, which is worse than having a policy that guides safe use. A clear, specific policy that names approved tools works far better than a blanket ban.

How often should an AI policy for a small business be updated?

Quarterly, not annually. New tools, new staff workarounds, and new features on existing tools all change the risk picture faster than most businesses expect, and a policy written a year ago is likely to have real gaps by now.

Related reading: Away Marketing Strategy: How They Built a Brand That Wins and Allbirds Marketing Strategy: How They Built a Brand That Wins.

Published and maintained by the Lilach Bullock team, covering marketing, AI and business growth.
Your buyers are asking AI who to use. Does it say you?

See for free whether ChatGPT, Claude, Perplexity, Gemini and Google name you, and get the plan to become the answer.

Check my AI visibility →
Sundays only

Get the Sunday newsletter.

One email a week. AI experiments, marketing tactics, and the workflows Lilach is building right now in her own business.

Subscribe free

Let’s get your marketing running on AI.

Book a free 30-minute call

We figure out what you need, where AI fits in, and what working together would look like.

Book the call →

Or take the 30-second calculator

You’ll see the hours and the money quietly leaking out of your week, and the three workflows worth building first.

Take the calculator →

Or grab the free AI resource library

Prompt packs, templates, checklists, and swipe files. The exact tools I build for paying clients. Yours, free.

Get the library →
Keep reading

More from the blog.