Sensible AI Rules for a Business of Thirty People
Last updated:
The risk is already live
Your team is already using AI tools, whether or not you have a policy. The question is only whether they are doing it with guidance.
The main exposure is not a rogue integration. It is someone pasting a client contract into a consumer account because it was quicker.
What the one page says
- Approved tools — the specific accounts to use, and that personal accounts are not for work
- Never paste — client confidential material, personal data, credentials, unpublished financials
- Always review — anything reaching a customer, anything financial, anything with a number in it
- Always disclose — where a client or regulator would expect to know
- Who to ask — a named person, for anything unclear
Five points, one page, written in plain language. A twelve-page policy is a policy nobody has read and therefore nobody follows.
Approve tools rather than banning them
Blanket bans move usage into personal accounts where you have no visibility and no terms. Providing approved business accounts is both safer and cheaper than the alternative.
Business tiers also give you the no-training and retention terms that consumer accounts do not.
Keep a short register
- What AI is in use, and for what
- What data each one touches
- Who owns it
- When it was last reviewed
Four columns in a spreadsheet. It answers most of a security questionnaire and it takes an hour to start.
Review twice a year
Tools change, terms change and usage spreads. Half an hour twice a year keeps the page true.
That is the whole governance requirement for most businesses of this size, and doing it properly is far better than doing something elaborate once.
Frequently asked questions
Do we legally need an AI policy?
What about clients asking whether we use AI?
Should we ban personal accounts entirely?
Who should own this?
No AI policy and a team already using it?
One page covers it. Happy to share the structure we use with clients.