How to write an AI policy for a small business

An AI policy for a small business fits on one page: which tools staff may use, what never gets pasted in, who checks the output, and who to ask.

Most owners I talk to around Cork have skipped this, and not out of carelessness. A policy sounds like something for a company with an HR department. Meanwhile three of your staff are using ChatGPT on their phones, one is pasting in customer emails, and nobody has said whether that is grand or a serious problem. It is the conversation you have not had, written down once so you stop having it badly.

This is general information, not legal advice. If you are in a regulated trade, or handle health records or data about children, have someone qualified read whatever you end up with.

Does a small business really need an AI policy?

Yes, and not mainly for compliance reasons. Without one you get the worst of both: the careless using AI in ways you would never sanction, and the careful not using it at all because nobody told them they could.

Silence is not neutral. It reads as permission to one half of your team and disapproval to the other. That is how you end up with a receptionist running every complaint through a free chatbot while your best writer types from scratch, having assumed it was off limits.

There is a mild legal nudge too. The EU AI Act expects organisations using AI to make sure the people operating it have a basic grasp of what they are doing. A one-page policy and twenty minutes explaining it is a reasonable answer for a business of eight. I wrote up the rest of the Act in plain English here.

The four rules an AI acceptable use policy needs

Four, not fourteen. An AI acceptable use policy running to six pages gets signed by everyone and read by nobody, and an unread policy protects you from nothing.

  1. Which tools are approved. Name them. “Use the company ChatGPT account” is a rule. “Use AI responsibly” is a wish. If somebody wants a tool that is not listed, fine, they ask first.
  2. What never goes in. The short list of things nobody pastes into any AI tool, ever: customer names and contact details, anything medical or financial, passwords, signed contracts, staff records, anything a client gave you under an NDA.
  3. A person checks it before it leaves. Nothing generated goes to a customer, a supplier, Revenue or the internet without someone reading it and standing over it. The name on the email is still yours.
  4. Who to ask. One named person, usually you. The point is that a question has somewhere to go, because the alternative to asking is guessing.

Those four cover most of what goes wrong. The rest is detail you add the first time you need it.

Writing staff AI rules people can actually recall

The test for staff AI rules is not whether they are complete. It is whether the part-timer working Saturday can remember them without looking anything up. What helps:

  • Write it in your own words. If you would not say the sentence out loud in the kitchen, cut it.
  • Give the reason, briefly. “Don’t paste customer details in, because we can’t promise where they end up” sticks. A bare prohibition gets worked around by whoever is in a hurry.
  • Say what is encouraged, not only what is banned. Drafting, summarising a long email thread, a first pass at a job ad. People follow a policy that gives them something.
  • Use examples from your own business. A café’s version names a supplier email and a review reply. A physio clinic’s names patient notes. Generic examples get generic compliance.
  • One page. If it does not fit, you are writing a manual, and nobody reads manuals.

Then say it out loud once, to everybody, in a ten-minute meeting. A policy that arrives only as an attachment has not really arrived.

AI policy Ireland: where the law comes into it

Two bodies of law matter at your size, and neither needs the document to look official.

GDPR is the one with teeth day to day. Customer and staff personal data going into an AI tool is processing of that data, and the free consumer tiers are not built for it. The fix is usually a business account with training on your inputs switched off, plus the never-paste list above. Fuller version in my note on putting client data into AI tools.

The EU AI Act is the other, and for ordinary tools it lands lighter than the headlines suggest: mostly transparency, and making sure staff know what they are using. The exception worth naming is hiring. Screening CVs with AI is treated far more seriously than drafting a newsletter, so if anyone is tempted, the policy should say to come to you first.

Neither is satisfied by having a document. They are satisfied by the document being true. A policy saying nobody pastes client data in, while everybody does, is worse than none, because you have written down a standard you are visibly failing.

A one-page AI policy you can copy

Fill in the brackets, delete what does not apply, keep it to a page.

  • Why we use AI. One sentence: we use AI to cut repetitive writing and admin, so we spend more time on [the actual work].
  • Tools you may use. [Named tools and accounts.] Anything else, ask first.
  • Never put these into an AI tool. [Customer names and contact details, payment details, medical or financial records, passwords, contracts, staff files, anything under an NDA.]
  • Always check before it goes out. Send it only if you would have been happy to write it. Verify any figure, date, name, price or legal point yourself.
  • Tell people where it matters. [Where you disclose AI use. For example: no AI-drafted reply to a complaint goes out unread.]
  • If something goes wrong, tell [name] the same day. Nobody is in trouble for flagging it early.
  • Questions: [name, and how to reach them].

That last rule does more work than it looks. The failure you want to avoid is a wrong figure sitting in a customer’s inbox for a fortnight because whoever sent it hoped nobody would notice.

How to stop it going stale

Put a review date on it, six months out, and keep it. Most reviews change one line: a tool added, a tool dropped, one new example of something that went sideways. The other half is using it. When somebody asks whether they can run the newsletter through Claude, answer from the policy rather than off the cuff, and if it does not cover that, add the line this week.

Most of this you can do in an hour on a wet Tuesday, and you should. If you would rather somebody looked at what your team is already using and told you where the real exposure sits, that is part of what the AI Assessment covers: a straight read of how your week runs, and a plain plan for what to fix first. Either way, write the page. The version in your head does not count.

Book the AI Assessment

The assessment is credited in full if you go on to a build, and if I can’t find you five hours a week you pay nothing. See how it works.