Skip to content
Back to insights

Article

What should a small business AI policy actually contain?

Bill Coombes · · 7 min read

A workable small-company AI policy is short — a few pages — and answers seven questions: which tools are approved, what data may and may not go into them, when a human must review output, when AI use has to be disclosed, who decides on a new tool, what happens when something goes wrong, and who reviews the policy and how often. It is a decision record, not a legal essay. If your team cannot find the answer to "can I paste this client email in?" in under a minute, the document has failed regardless of how thorough it is.

The seven sections

  • Approved tools. A named list, with the accounts in the company's name. Anything unlisted is a request, not a choice.
  • Data classes. Which categories of information may be entered, which may not, and the one or two examples people actually run into.
  • Human review. Which outputs a person must check before they leave the building, and who that person is by role.
  • Disclosure. When clients, candidates or regulators are told AI was involved. Silence here is itself a position, and rarely the one you'd choose deliberately.
  • New tool intake. How someone asks for a tool, who answers, and roughly how long that takes. Without this, adoption goes underground.
  • When something goes wrong. Who is told, how fast, and what happens next. Written before you need it.
  • Review. A named owner and a date. An AI policy is stale in months.

Why a template is the wrong start

A downloaded policy is a set of answers to someone else's questions. The value is not in the prose — it's in a small group of people arguing through the data classes and the disclosure line for your business and then agreeing. That argument is the artefact. The document is just where it gets recorded.

Templates also encourage scope inflation: twelve pages covering model risk management at a 60-person firm, which nobody reads and which therefore governs nothing.

Structural, not just legal

This is the part most policies skip. A policy that says only what is forbidden pushes people to unapproved tools on personal accounts, which is worse for you than the thing you banned. Pair every restriction with the approved way to do the same job.

The test to apply before you sign it

Give it to someone whose work it governs, ask them a real question from their week, and time how long the answer takes to find. Then give it to your counsel. If both are satisfied, it's short enough and clear enough. That's the standard the work aims at: a governance position your counsel can approve in an hour, not a document that impresses nobody and protects nothing.

Governance your counsel can sign →

Start with a conversation.

Thirty minutes on what you have already bought, who is using it, and what is actually in the way. If I am not the right person, I will say so.