A usable AI policy for a small team fits on one page and answers five questions: which tools are approved, what can never be pasted into them, what a human has to check before it goes out the door, who to ask when it is unclear, and what happens when something goes wrong. Start by naming an owner and writing those five decisions in plain language. Use the page as a working team rule, and get qualified advice where client contracts or regulated data require it.
What Five Questions Does a One-Page AI Policy Need to Answer?
Before drafting any explanation, put the five answers on the page first. Everything else in this article exists to help you fill in the brackets and defend the choices you made.
Our AI Use Policy
- Approved tools: [tool names, and whether each is a personal account or a business/team account]
- Never paste into any AI tool: [customer identifiers, regulated records, credentials, anything under an NDA]
- A human must review before it goes out: [customer-facing messages, anything tied to money, anything published publicly]
- If you are not sure, ask: [name or role], by [phone, Slack, or email], and wait for a yes before proceeding
- If something goes wrong: [stop, tell the escalation contact the same day, document what was exposed, decide on notification]
Print it, pin it in the team channel, and hand it to anyone new on day one. The sections below explain the reasoning behind each line so you can answer follow-up questions without improvising.
Which AI Tools Should a Small Team Approve?
Approve a specific tool and account type, not just a brand name. Check whether conversations may be used for model training, how long data is kept, and who can access it. Before you approve a tool, open its admin settings and confirm the training and retention defaults, then write down what you found next to the tool's name. Do not rely on a general impression of the brand; confirm the setting for the specific account your team uses.
Once you know which tools are approved, decide what each one is for. A tool that drafts a first pass of a task is a different risk than a tool that acts on your behalf inside a customer system. If you have not sorted out which repetitive tasks are worth handing to AI, working through which business tasks to automate with AI first will help you scope the approved-tools list to real work. And if your team is choosing between a drafting tool and something closer to an autonomous agent, the difference between AI agents and automation tools changes what review step you need, since an agent that takes action needs a tighter human-review line than a tool that only produces a draft.
What Should Never Be Pasted Into an AI Tool?
Vague language like "keep things confidential" does not tell anyone what to do at the moment they are about to paste something. A never-paste list built around specific identifiers and regulated records is something a team can actually follow. A workable starting list:
- Social Security numbers, driver's license numbers, and full payment card numbers
- Health records or anything covered by a client's own privacy obligations
- Login credentials, API keys, and access tokens
- Unreleased financial figures or anything under a signed NDA
- A customer's full name paired with an account number or balance
Deliberately teaching an AI assistant about your own business is a different activity from pasting a customer's private data into a general-purpose chat tool, and it deserves its own guardrails. How to train an AI assistant on your business information covers doing that part safely, which is worth reading before you decide what belongs on the never-paste list versus what belongs in an approved knowledge base.
When Does a Human Have to Check AI Output Before It Goes Out?
Scope the review rule narrowly enough that people will actually follow it: anything customer-facing, and anything that touches money. That covers emails to clients, proposals, invoices, contract language, ad copy, and social posts. An internal brainstorming draft may need a lighter review, but check any output used for decisions about staff, customers, or finances.
The review step matters most for claims. The FTC's general advertising guidance requires that marketing claims be truthful and substantiated, and its endorsement guidance addresses when a stated experience or result has to be genuine rather than invented. An AI tool can draft a sentence claiming a result, a rating, or a level of experience nobody verified, and if that sentence ships in an ad or on your site, your business is the one that has to stand behind it, not the tool. A human checking AI output before it goes out is the step that catches an invented number before a customer sees it.
Who Does a Team Member Ask When It Is Unclear?
Name one person on the page, not a department. On a small team, that is usually the owner or whoever runs operations. Give a channel (a Slack message, a text, a specific email) and a plain expectation: no one should have to wait more than a business day for an answer, and the default while waiting is to hold off, not to guess and proceed. A policy that names an escalation path but no timeline turns back into an unwritten policy the first time someone is in a hurry.
What Happens When Something Goes Wrong?
Keep this section short enough that someone under stress can still follow it. Use these four steps as your initial response: stop using that tool for that task, tell the escalation contact the same day rather than waiting to see if it matters, write down exactly what was pasted and into which tool, and decide with the escalation contact whether a client or vendor needs to be told. That last decision depends on what was exposed and what obligations your business already has. Check the affected contracts and applicable notification requirements with qualified help. Removing a conversation from visible history does not establish that all copies have been deleted.
What Do Small Teams Usually Forget to Cover?
Check that your draft covers two additional situations. The first is AI note takers on customer or prospect calls. A note-taking tool that joins a call to transcribe and summarize it is processing another person's words through a third-party system they did not necessarily agree to. The policy should require telling the other party the tool is running and confirming any required consent before recording, and the resulting transcript should flow through the same never-paste and review rules as any other customer record, not get treated as a casual internal note.
The second is representing AI output as independently verified expertise or a personal result. For advertising endorsements, the FTC guidance linked above requires honest opinions and experiences. As an internal team rule, label AI-assisted drafts so reviewers know to check their claims. This labeling recommendation is a workflow choice, not a general FTC requirement to label all AI-assisted work.
How Does This Page Map to a Real Risk Management Framework?
The NIST AI Risk Management Framework playbook organizes suggested actions around Govern, Map, Measure, and Manage. The framework is voluntary. Here is a practical way to borrow those ideas for this page: name an accountable owner for governance; list tools, tasks, and affected data to map risks; test sample outputs and review incidents to assess risks; and use those findings to change permissions, review steps, or approved tools. This is an editorial adaptation, not a claim that a one-page policy satisfies the full framework. Review the page every quarter or after adding a tool, and keep the findings with it so future changes have a clear reason.
How Do You Roll Out a One-Page AI Policy?
Announce it once in writing, in whatever channel the team already uses daily, so no one can say they missed it. Walk through it live in one short meeting, set aside ten to fifteen minutes to start, and use that time for questions rather than reading the page aloud. Have each person acknowledge they have seen it, even something as simple as a reply in the channel. Then put a recurring reminder on the calendar to review the page every quarter, and revisit it immediately if you add a new tool or something goes wrong before the next scheduled review. If your team is also handing off a broader AI automation project to an outside vendor, MetaTechAi's AI automation handover checklist covers the operational side of that handoff, which is a useful companion once your internal policy is in place.
If you want more background on who is behind this kind of practical, no-legal-department guidance, see the About page.
What FAQ Answers Help Small Teams Apply an AI Use Policy?
Do I need an AI use policy if I only have three employees?
Yes. If people already use AI tools for email or drafts, an unwritten policy already exists, it is just whatever each person happens to be doing. One page replaces guessing with a rule everyone can point to.
Should I just ban consumer AI accounts outright?
If you prohibit consumer accounts, also explain the approved alternative and how staff can request access. A clear rule names which tools are approved on a business or team account and treats an unapproved consumer account the same as any other never-paste violation.
How do I handle a team member who already broke the rule before the policy existed?
Handle the exposure first: find out what was pasted, into which tool, and whether it can be deleted from that tool's account settings. Then clarify the rule with everyone and review what training or access changes are needed. Handle any personnel decision through your normal process with the facts of the incident in hand.
Do AI note takers on customer calls need their own rule?
Yes. An AI note taker on a call is processing another person's words through a third-party tool they did not necessarily expect. Tell the other party it is running and confirm any required consent before recording. Route the transcript through the same never-paste and review rules as any other customer record.