Skip to content
NextGen Code
// AI Strategy

AI Policy Template: How to Write a Company AI Policy

Free AI policy template for small businesses: a copyable AI acceptable use policy, the 12 sections to include, a two-week rollout plan, and the laws to know.

NextGen Code TeamPublished 14 min read

An AI policy template is a ready-made set of rules for how employees use AI tools such as ChatGPT, Claude, Gemini, and Microsoft Copilot: which tools are approved, what information can go into them, and who checks the output. Copy the small-business AI acceptable use policy below, replace the bracketed fields, and you can have a working policy in place within two weeks.

You need one because your team is probably using AI already, approved or not. Without written rules, customer data ends up in personal accounts, unchecked AI errors reach clients, and nobody knows who is accountable when something goes wrong.

This guide is written for businesses with roughly 5–500 employees. It isn't legal advice, so have an attorney review your final version, especially in a regulated industry.

Why every company using AI needs a written policy

Any company whose employees use AI tools needs a written policy, because the risk comes from everyday use, not from big AI projects. A sales rep pastes a customer list into a free chatbot. A bookkeeper asks an assistant to summarize a client's tax return. None of them is being reckless; they're getting work done without rules.

Three things go wrong without a policy:

  1. Data leaks into accounts you don't control. Free and personal AI accounts may use conversations to improve the vendor's models, depending on settings, and you can't audit or delete what employees put there.
  2. Errors reach customers. AI tools sometimes produce confident, wrong answers, often called hallucinations. If nobody is required to check, those errors end up in proposals, emails, and contracts.
  3. Nobody owns the outcome. When a mistake surfaces, "the AI wrote it" isn't an answer a customer, regulator, or court will accept.

A policy also speeds up adoption, because people who know the rules stop guessing. Governance is one of the five pillars in our AI readiness framework, and it's usually the quickest pillar to improve.

Example: Consider a 15-person accounting firm where three staff members draft client emails in personal chatbot accounts. With a policy, the firm moves everyone to one business account with training on company data turned off, bans tax IDs and bank details from prompts, and requires a partner to review AI-drafted advice.

What should an AI policy include?

A complete company AI policy covers 12 topics, and a small business can handle most of them in a few sentences each. Here's what each section answers and a sensible default:

SectionThe question it answersSmall-business default
1. Purpose and scopeWho and what does this cover?All staff and contractors, and every AI tool, including AI features inside software you already use
2. Approved tools and accountsWhich tools, and which accounts?A named list; company-managed business accounts only
3. Data classificationWhat can go into AI tools?Four levels: Public, Internal, Confidential, Restricted
4. Prohibited usesWhat's off-limits?Unreviewed decisions about people, fake reviews, impersonation, deception
5. Human review and accountabilityWho checks the output?The user owns the result; high-stakes work gets a second reviewer
6. Disclosure to customersWhen do we say AI was involved?Chatbots identify themselves; disclose when it matters to customers or the law requires it
7. Intellectual propertyWho owns AI-assisted work?The company; people add real creative input to anything you need to own
8. Security and vendor reviewHow does a new tool get approved?The policy owner checks data use, retention, access controls, and contracts
9. TrainingWhat must people learn?A session at onboarding and a yearly refresher
10. Incident reportingWhat if something goes wrong?Report within 24 hours, with no penalty for prompt, good-faith reports
11. EnforcementWhat happens if rules are broken?The same process as other company policies
12. Review cadenceHow does the policy stay current?Tools list quarterly, full policy yearly

Four of these sections need the most thought. The template covers the rest.

Approved tools and accounts

Name specific products and plans, because the same AI product can carry very different data terms depending on the plan. Business plans from the major vendors don't use your company data to train models by default; consumer plans may, unless the user changes a setting. Vendors revise these terms, so confirm the current version before you approve a tool.

Keep an approved AI tools register, and include AI features inside software you already pay for, such as meeting transcription and CRM email drafting, because they handle the same data.

Data classification: what can and can't go into AI tools

Data rules are the heart of an AI acceptable use policy. The template uses four levels: Public information can go anywhere; Internal information only into approved business tools; Confidential information, such as customer details, pricing, and financials, only into tools approved for it; and Restricted information, such as Social Security numbers, card numbers, passwords, and patient records, only with written approval for a specific tool.

Two habits make these rules workable. Strip identifying details before prompting, since "a client in the restaurant business" works as well as the client's name for most drafting. And when in doubt, treat information at the higher level. Healthcare practices should allow patient information only in tools covered by a signed HIPAA business associate agreement (BAA).

Prohibited uses and human review

Ban the uses that are off-limits in any tool: unreviewed decisions about hiring, pay, credit, housing, insurance, or health care; impersonation and realistic fakes of real people; misleading claims; and fake reviews. The FTC's rule on consumer reviews, in effect since October 2024, explicitly covers AI-generated fake reviews.

The core accountability rule is that the person who uses AI is responsible for the result as if they had written it. Scale review to the stakes. Customer-facing content needs the author to verify every fact, figure, and quote, while contracts, financial statements, medical or safety information, pricing commitments, and production code need a second qualified reviewer.

AI agents, meaning AI systems that take actions such as sending emails or updating records, need extra rules: named approval, only the permissions they need, and a log of what they did.

Disclosure and intellectual property

Disclose AI when a reasonable customer would want to know, and always when a law or contract requires it. In practice, chatbots say they're AI and offer a way to reach a person, and AI-generated images don't misrepresent your products or work.

For intellectual property, state that AI-assisted work belongs to the company and require real human creative input for logos and other work you need to own. The U.S. Copyright Office has said material generated entirely by AI isn't protected by copyright without sufficient human authorship.

AI laws and frameworks to know (as of October 2026)

No US law requires every private business to have an AI policy, but several laws regulate specific AI uses, and a written policy is the simplest way to show you manage them. Here's what's in effect or scheduled as of October 2026.

The NIST AI Risk Management Framework. The NIST AI Risk Management Framework is a free, voluntary framework released in January 2023, with a Generative AI Profile added in July 2024; NIST is revising it under the White House AI Action Plan. Its four functions translate well for a small business: Govern (this policy and a named owner), Map (an inventory of where you use AI), Measure (review, testing, and an incident log), and Manage (fixing problems and updating the rules).

The Texas Responsible Artificial Intelligence Governance Act (TRAIGA). House Bill 149 took effect January 1, 2026, and reaches anyone who does business in Texas or serves Texas residents. For private companies, it mainly prohibits developing or deploying AI intended to encourage self-harm, harm to others, or crime; to unlawfully discriminate against a protected class; to infringe constitutional rights; or to produce child sexual abuse material. Government agencies must tell consumers when they're interacting with AI, and licensed health care providers must disclose AI use in a patient's care.

The Texas attorney general enforces the act, must give a 60-day cure period before suing, and can demand documentation of an AI system's purpose, data, outputs, and safeguards. The act also lists substantial compliance with NIST's Generative AI Profile, or another recognized AI risk management framework, among the circumstances that protect a company from liability. A written policy and an inventory of AI uses are the start of that documentation.

Colorado's AI law. The requirements in Colorado's original AI Act never took effect. In May 2026 the state replaced it with Senate Bill 26-189, which applies from January 1, 2027, to automated decision-making technology used in consequential decisions about employment, housing, lending, insurance, health care, education, and government services. Companies that deploy it must give consumers notice, explain adverse outcomes, and offer data correction and human review.

Other rules that touch AI. Illinois has regulated AI in employment decisions since January 1, 2026, New York City requires bias audits of automated hiring tools, and California has rules on automated decision systems in employment. Existing laws still apply, including the FTC Act, HIPAA, the Gramm-Leach-Bliley Act (GLBA), state privacy laws, and copyright. Companies with EU customers or staff also face the EU AI Act, which phases in over several years.

Federal policy is unsettled. A December 2025 executive order directed the Justice Department to challenge state AI laws the administration considers burdensome, but as of October 2026 Congress hasn't passed a law preempting them, so state laws still apply.

Small-business AI acceptable use policy template

Copy the policy below into your handbook or document system. Replace everything in brackets, delete rules that don't apply, and add your industry's requirements. It's written for a company of 5–500 people without full-time compliance staff.

Template · AI acceptable use policy (small business)

[Company Name] AI Acceptable Use Policy

Effective date: [Date] · Policy owner: [Name, Title] · Version: [1.0]

1. Purpose

This policy explains how people at [Company Name] may use artificial intelligence (AI) tools for company work, so we get the benefits of AI while protecting customer and company information. A person stands behind everything we deliver.

2. Scope

This policy applies to all employees, contractors, and interns who work for [Company Name], on any device. It covers standalone AI tools, AI features inside software we already use (such as email, documents, CRM, and meeting tools), and AI agents that can take actions on our behalf.

3. Approved tools and accounts

  • Use only the AI tools listed in the Approved AI Tools Register, kept by [Policy Owner] at [location].
  • Use company-managed accounts for company work, never personal or free accounts.
  • To request a new tool or feature, tell [Policy Owner] what it is, what you want to use it for, and what data it would touch. Don't use it until it's approved.
  • Don't connect AI tools, browser extensions, or agents to company email, files, financial accounts, or systems without approval.

4. Data rules

Before you enter information into any AI tool, classify it:

LevelExamplesApproved AI toolsOther AI tools
PublicPublished website content, public product informationAllowedAllowed
InternalProcedures, general meeting notes, drafts without customer detailsAllowedNot allowed
ConfidentialCustomer names and contact details, pricing, contracts, financial reports, employee informationOnly tools approved for Confidential data, using the minimum neededNot allowed
RestrictedSocial Security numbers, bank and card numbers, passwords and API keys, health information, [other regulated data]Only with written approval from [Policy Owner] for a specific tool and purposeNot allowed

When in doubt, treat information as the higher level, remove names and identifying details, or ask [Policy Owner].

5. Prohibited uses

Don't use AI to:

  • Make or finalize decisions about hiring, firing, pay, promotion, credit, housing, insurance, or health care for any person without documented review by a qualified person.
  • Create fake reviews, testimonials, endorsements, or social media engagement.
  • Impersonate a real person, or create realistic images, audio, or video of a real person without their permission.
  • Mislead customers about what a product or service is, does, or costs.
  • Create discriminatory, harassing, or sexually explicit content, or get around security controls.
  • Record, transcribe, or summarize calls or meetings without the notice required by law and by [Company Name].
  • [Add industry-specific prohibitions.]

6. Human review and accountability

  • You're responsible for any work you produce with AI, as if you created it yourself.
  • Check AI output before you use it. Verify facts, figures, citations, quotes, and legal or technical statements against a reliable source.
  • A second qualified person reviews the following before they go out: [contracts and legal language; financial statements; medical or safety information; pricing commitments; code released to production].
  • AI agents that send messages, change records, or spend money need approval from [Policy Owner], only the permissions they need, and a log of their actions.

7. Disclosure

  • AI chat assistants and automated messages that customers interact with say they're AI and offer a way to reach a person.
  • Tell customers when AI plays a significant role in work they pay for if they would reasonably expect to know, or when a contract or law requires it.
  • Don't present AI-generated work as the personal work or opinion of a named person who didn't review it.
  • [Add industry requirements, for example: "Licensed clinicians disclose AI use in patient care as Texas law requires."]

8. Intellectual property and confidentiality

  • Work you create with AI for [Company Name] belongs to [Company Name], like any other work product.
  • Don't enter material we don't have the right to use, and don't use AI to copy protected work.
  • Material generated entirely by AI may not be protected by copyright. For logos, brand assets, and other work we need to own, a person makes a substantial creative contribution.
  • AI-generated code goes through our normal review, testing, and license checks.

9. Security and vendor review

Before approving a tool, [Policy Owner] confirms whether the vendor trains models on our data and whether that can be turned off; how long data is kept and whether we can delete it; admin controls, single sign-on, and multifactor authentication; where data is stored; and any agreement regulated data requires, such as a HIPAA business associate agreement.

10. Training

Everyone completes AI training within [30] days of starting and a refresher every [12] months.

11. Reporting problems

Report to [contact or channel] within [24 hours] if:

  • Confidential or Restricted information went into a tool that isn't approved for it.
  • AI output with a significant error reached a customer or the public.
  • An AI tool or agent behaved unexpectedly, such as following instructions hidden in a document, email, or website.
  • You believe someone is misusing AI.

Prompt, good-faith reports won't be punished. We'd rather know early.

12. Enforcement

Violations are handled like violations of other company policies and may lead to loss of tool access or disciplinary action, up to and including termination. [Company Name] may monitor company accounts and tools as the law allows.

13. Review

[Policy Owner] reviews the Approved AI Tools Register every quarter and this policy at least once a year, and after any significant incident, new legal requirement, or new type of AI use. We'll tell everyone what changed.

Appendix: Approved AI Tools Register

Tool and planHighest data levelApproved usesOwnerNext review
[e.g., ChatGPT Business][Confidential][Drafting, research, analysis][Name][Date]
[e.g., AI meeting notes in our video-call tool][Internal][Internal meeting summaries][Name][Date]

Acknowledgment

I have read the [Company Name] AI Acceptable Use Policy and agree to follow it.

Name: [Employee name] · Signature: [Signature] · Date: [Date]

How to roll out your AI policy in two weeks

You can go from no policy to a trained team in 10 working days if one person owns the project. Here's the schedule we recommend.

Week 1: decide

  1. Day 1: Name the owner. Pick one person with authority to approve tools and enforce the rules, usually the owner, COO, or IT lead.
  2. Days 1–3: Inventory current AI use. Send a short, no-blame survey asking which AI tools people use, for which tasks, and with what data. Check which AI features are already on in your email, CRM, and meeting software.
  3. Day 4: Choose approved tools. Standardize on one or two business-tier assistants that fit your software, set up company accounts with single sign-on, and confirm training on your data is off.
  4. Day 5: Draft the policy. Fill in the template and add examples of Confidential and Restricted data from your own business.

Week 2: launch

  1. Day 6: Review. Leadership signs off, and an attorney reviews it if you're regulated.
  2. Day 7: Publish. Put the policy and the approved tools register where people will find them, and move everyone off personal accounts.
  3. Days 7–8: Train. Run a 60–90 minute session for each team using real tasks from their work. Our AI training and adoption services can run these sessions for you.
  4. Day 9: Collect acknowledgments. Every employee signs, and the policy becomes part of onboarding.
  5. Day 10: Hold office hours. Answer questions, turn them into an FAQ, and set the first quarterly review date.

How to keep your AI policy current

An AI policy goes stale quickly because tools, vendor terms, and laws change every few months. Put the upkeep on a calendar:

  • Quarterly: review the approved tools register, vendors' data terms, and any new AI features in software you already use.
  • On a trigger: update the policy when you adopt a new kind of AI use (such as an agent with access to customer records), when a vendor changes its terms, when a law starts to apply to you, or after an incident.
  • Yearly: do a full review, refresh training, and collect new acknowledgments.

Keep a one-page change log and track the share of staff trained, open tool requests, and incidents reported. The free AI readiness assessment is a quick way to re-check your governance score each year.

When you move on to bigger AI projects, such as agents or AI features for customers, extend the policy into a fuller governance program. Our AI strategy and consulting services cover that work, and our guide to AI for small business shows where a policy fits in a broader adoption plan.

Frequently asked questions

Does a small business need an AI policy?

Yes, if anyone on your team uses AI tools for work, and most teams already do. A short written policy tells people which tools are approved, what data must never go into them, and who checks AI output before it reaches a customer. Without one, employees make those calls on their own, often in personal accounts you can't see or control. A policy of one to three pages, a list of approved tools, and an hour of training cover most of the risk for a business with 5–100 employees.

What is the difference between an AI policy and an AI acceptable use policy?

An AI acceptable use policy is the employee-facing part of a broader AI policy. It covers day-to-day rules: approved tools, data limits, prohibited uses, human review, disclosure, and reporting. A broader AI governance policy adds how the company chooses AI projects, assesses risk, reviews vendors, and documents the AI systems it builds or offers to customers. Most small businesses should start with an acceptable use policy, like the template in this article, and add governance sections as their AI use grows.

Can employees use ChatGPT at work?

Yes, if your policy approves it and they use a company-managed business account. Business plans such as ChatGPT Business or Enterprise, Claude Team or Enterprise, Microsoft 365 Copilot, and Gemini in Google Workspace don't use your company's data to train models by default, and they give administrators control. Free or personal accounts may use conversations for training, depending on settings, and you can't manage or audit them. Check each vendor's current terms before you approve a tool.

Is there a law that requires a company AI policy?

No US law requires every private business to have an AI policy as of October 2026, but laws do regulate specific uses. Texas's Responsible Artificial Intelligence Governance Act, in effect since January 1, 2026, prohibits certain harmful uses of AI and requires health care providers to disclose AI use to patients. Colorado's rewritten AI law adds notice duties for AI used in consequential decisions from January 1, 2027, and HIPAA, the FTC Act, and employment laws still apply. This isn't legal advice.

How often should an AI policy be updated?

Review the list of approved AI tools every quarter and the full policy at least once a year. Update it sooner when you adopt a new kind of AI use, such as an AI agent that can send emails or change records, when a vendor changes its data terms, when a new law starts to apply to you, or after an incident. Keep a short change log, tell employees what changed, and have them acknowledge major revisions.

Who should own the AI policy in a small company?

One named person with authority to approve tools and enforce the rules, usually the owner, COO, operations manager, or IT lead. Owning the policy means keeping the approved tools list current, answering questions, reviewing incidents, and scheduling reviews. Regulated businesses should involve their compliance lead or attorney. Avoid ownership by committee: when everyone owns the policy, nobody updates it. Larger companies can add a small review group from legal, IT, and operations.