Think Build Implement Repeat
London, UK +44 7367 067226
WhatsApp FOLLOW f in X
AI Integration

Sensible AI Rules for a Business of Thirty People

Last updated:

The risk is already live

Your team is already using AI tools, whether or not you have a policy. The question is only whether they are doing it with guidance.

The main exposure is not a rogue integration. It is someone pasting a client contract into a consumer account because it was quicker.

What the one page says

  1. Approved tools — the specific accounts to use, and that personal accounts are not for work
  2. Never paste — client confidential material, personal data, credentials, unpublished financials
  3. Always review — anything reaching a customer, anything financial, anything with a number in it
  4. Always disclose — where a client or regulator would expect to know
  5. Who to ask — a named person, for anything unclear
Five points, one page, written in plain language. A twelve-page policy is a policy nobody has read and therefore nobody follows.

Approve tools rather than banning them

Blanket bans move usage into personal accounts where you have no visibility and no terms. Providing approved business accounts is both safer and cheaper than the alternative.

Business tiers also give you the no-training and retention terms that consumer accounts do not.

Keep a short register

  • What AI is in use, and for what
  • What data each one touches
  • Who owns it
  • When it was last reviewed

Four columns in a spreadsheet. It answers most of a security questionnaire and it takes an hour to start.

Review twice a year

Tools change, terms change and usage spreads. Half an hour twice a year keeps the page true.

That is the whole governance requirement for most businesses of this size, and doing it properly is far better than doing something elaborate once.

Frequently asked questions

Do we legally need an AI policy?

Not usually as a standalone requirement. Your existing data protection and confidentiality obligations already apply, and a policy is how you meet them in practice.

What about clients asking whether we use AI?

Increasingly common. Having a clear, honest answer ready is a competitive advantage rather than a liability.

Should we ban personal accounts entirely?

For work data, yes, and provide approved alternatives at the same time. A ban without an alternative is ignored.

Who should own this?

Whoever owns data protection today. It is an extension of what they already do, not a new discipline.

Keep reading

No AI policy and a team already using it?

One page covers it. Happy to share the structure we use with clients.

Book a free 30-minute call Get a project estimate WhatsApp us

Related services

What we build for problems like this one

AI IntegrationEnterprise AIAI Agents