AI GUY OFFICIAL

THE AI GUY · BLOG

Small Business AI Policy: Rules Your Staff Can Use

Build a small business AI policy with approved accounts, customer data rules, named reviewers, a task card and practical staff rehearsal exercises.

By James Hill · October 4, 2026 · 12 min read

A small business AI policy should tell employees which tool and account they may use, what information may go into it, and who must check the result before anyone relies on it. Give each approved task a short decision card with an owner, input examples, a reviewer and a clear stop rule. Practise the awkward cases so staff can apply the policy while doing real work.

Key Takeaways

  • Approve a specific task, account and input together.
  • Use allowed, approval-needed and excluded examples to remove guesswork.
  • Keep output on hold until the assigned reviewer approves its intended use.
  • Give staff a named contact for mistakes and exceptions.

What problem should the staff decision sheet solve?

It should answer the question an employee faces just before pasting information or sending a draft: “Am I allowed to do this here?” A general instruction to use AI responsibly leaves that decision to each person's interpretation.

The demand is concrete. In “Concerns with employees using AI?”, an owner asks how to allow useful AI work while preventing accidental uploads of proprietary or customer information. A separate discussion about employees using AI at work raises expectations about employee effort and output quality. These are observed owner questions, not evidence of how often incidents happen or how any provider protects information.

Build the sheet around decisions people can demonstrate. “Draft a general appointment reminder from approved public wording” is a defined task. “Use AI for customer service” leaves open which records, promises and actions are allowed.

This guide proposes an operational starting point, not a legal template or compliance certification. Adapt it to your contracts and obligations with qualified help where needed. The NIST AI Risk Management Framework is voluntary guidance for managing AI risks; borrowing its ideas does not certify your policy.

How should personal accounts, company accounts and restricted tasks compare?

Separate permission to use an account from permission to perform a task. The table below offers starting rules to adapt, not descriptions of universal product features.

Use scenarioApproved inputAccount requirementReviewerException route
Personal-account usePublic or fictional material only after a narrow exceptionExact tool and account recorded in the exceptionNamed task reviewer before business useOwner decides before work starts; no automatic transfer of approval
Approved company accountOnly material listed on the task cardNamed company workspace with reviewed terms, settings and accessPerson qualified to check that taskTask owner reviews a new input, feature or destination
Restricted taskNo real input while the task is excludedNo account type overrides the restrictionOwner and relevant specialist assess any proposed changeFormal task review before permissions change

A company account is not a privacy guarantee. Before approving it, assign someone to check the applicable terms, data use, retention, access permissions and connected services. Record what was checked and when. If a needed answer is unclear, leave the proposed input unapproved.

For personal accounts, decide whether any work use is permitted at all. If you allow public-material brainstorming, spell out that it does not cover internal documents or access to business systems. Employees should not have to infer permission from a colleague's habits.

Restricted tasks might include approving refunds, evaluating job applicants or giving specialist advice. These are suggested policy boundaries to assess for your business, not claims that every such use is prohibited by law. Keep them outside routine staff permission until a separate review establishes suitable controls.

How do you build the policy around actual staff work?

Use the following procedure to produce a task inventory, permission decisions and rehearsal records. It is an original working method for this guide, not a report of a completed client test.

  1. Inventory actual staff AI tasks. Ask employees to describe what they already do or want to try, including AI features inside software they already use. Collect task descriptions without asking them to forward real customer records. Write down the input, expected output, intended recipient and whether the tool can take action.

Split broad requests into separate tasks. Drafting a reusable email outline differs from summarizing a customer complaint, and both differ from sending a reply. Start with a task whose result someone can inspect. The guide to which business tasks to automate with AI first can help you choose that starting scope.

Your completion check is a list the staff recognize. If someone cannot point to the row covering their proposed work, that work is not yet approved.

  1. Name approved accounts and task owners. Record the tool, workspace, sign-in method and responsible person for each task. Tell employees how to recognize the approved workspace before entering information. Make access individual and accountable rather than telling everyone to share a password.

Assign the task owner responsibility for the permission decision. Assign an administrator to verify the available account controls. The same person may fill both roles in a small business, but write down both responsibilities. Approval should also state whether uploads, browser extensions and connections to business apps are permitted.

Verify this step by having an employee locate the correct workspace and explain which features they may use. A familiar logo alone is not your approval record.

  1. Classify sample inputs as allowed, approval-needed or excluded. Create examples from fictional material. Allowed could mean your published service description or an invented appointment request. Approval-needed could mean an internal procedure with information about a supplier. Excluded could mean credentials, payment details or identifiable customer records under your starter policy.

Define approval-needed as “wait for a recorded decision before entering anything.” Define excluded as “do not submit under this task card.” For a mixed document, tell staff to stop if any part falls outside the approved class. They should not decide that a small amount of excluded content is harmless.

Check that employees can classify the entire proposed input, including attachments and copied conversation history. If your approved task uses a prepared business knowledge source, follow the separate guidance on training an AI assistant on business information. That preparation does not authorize unrelated customer uploads.

  1. Assign an output reviewer for each task. Choose someone with the knowledge and authority to check the result against the original source. For a generic service email, that might be the office manager. For a technical explanation, assign someone qualified in the subject. “A human checks it” is incomplete until the human and the checks are named.

Put acceptance criteria on the card: facts match the source, commitments are authorized, recipient details are correct, and unsupported additions are removed. State what counts as release, such as sending, publishing, importing or using the result to make a decision. Keep draft creation separate from permission to release it.

Name a backup reviewer. If neither person is available, hold the draft or use the established manual process. Urgency should not quietly remove the review requirement.

  1. Rehearse accidental-upload and uncertain-answer scenarios. Use pretend incidents and fictional files. Tell an employee they selected the wrong attachment, then ask them to show the reporting route. The expected response is to stop the task, contact the named incident owner and describe the tool, account, time and information involved without spreading the material further.

Have the incident owner demonstrate how they would coordinate containment with the administrator or provider and obtain qualified advice where needed. Do not treat a deleted conversation as proof that the incident is resolved. Record what remains uncertain and who will follow up.

For the uncertain-answer rehearsal, supply a draft with an unsupported promise. The employee should hold it, compare it with approved source material and ask the reviewer. Asking AI whether its own statement is correct does not satisfy the human review rule you have set.

  1. Set a review date and a route for exceptions. Put an actual next-review date and owner on each card. Also require review when the task, tool, permissions, source material or intended use changes. A calendar reminder alone does not handle a new connection to a customer system.

Make exception requests specific: describe the task, proposed input category, account, expected benefit, reviewer and requested duration. Use a fictional example in the request. Record whether permission is granted, its limits and when it expires. No reply means the work stays on hold.

At review, ask what employees found unclear, which outputs were rejected and whether an exception should become a permanent rule. NIST's AI RMF Core treats risk management as continuous and organizes it around Govern, Map, Measure and Manage. This procedure adapts that general direction; it is not NIST's prescribed sequence.

What should a fill-in AI task card contain?

Keep the card where employees start the task. Fill every permission field before marking it approved, and use names rather than an unnamed “management” contact. A blank field means the decision is still open.

AI task card

Task and purpose: __________

Task owner: __________

Approved tool, account and workspace: __________

Allowed features and connections: __________

Allowed input example: __________

Approval-needed input example: __________

Excluded input example: __________

Approved source used to check the answer: __________

Output reviewer and backup: __________

Checks required before release: __________

Permitted destination or action after approval: __________

Stop condition and manual fallback: __________

Incident contact and reporting route: __________

Exception approver and route: __________

Approval date, version and next review date: __________

Here is a hypothetical way to complete its central decision. The task is drafting a generic appointment reminder. Allowed input is the business's public opening hours and an invented appointment example. Actual customer messages need a separate decision; customer records and access credentials are excluded from this task.

The office manager reviews the wording against the approved service information. Staff add real recipient details later in the established business system. The card authorizes a reviewed text draft, with no automatic sending or account connection. A request to turn that draft into an automated campaign requires a new task review.

Keep the approved card in a shared location staff can access, with a clear current version. When a rule changes, replace obsolete copies and tell affected employees what decision changed. Saving another policy file without withdrawing the old instructions leaves competing answers.

If the plan expands into shared knowledge sources or connected business applications, carry these task boundaries into the technical design. MetaTechAi's AI infrastructure service is relevant to that implementation discussion: bring the account, input and review decisions so they can be considered alongside access and system design.

How can you test whether employees understand the rules?

Use a teach-back exercise: ask the employee to explain the decision in their own words and demonstrate the next action. A signed acknowledgement shows receipt of the policy; this exercise checks whether the person can apply it.

Prepare fictional material labeled for training. Include a public service description, an internal note with an unclear classification and a mock customer record. Give the employee the actual task card and ask them to identify the approved account, classify each input and name the reviewer.

Then change one condition. Say the reviewer is absent, the tool asks to connect a mailbox, or the draft promises something the source never offered. Ask the employee to show where the card tells them to stop and how they would request help. Do not coach them through the decision before recording their explanation.

Use these acceptance checks for the rehearsal:

  • The employee selects the approved workspace and checks the whole input.
  • Unclear material is held for approval; excluded material is not submitted.
  • The employee identifies the source and reviewer required before release.
  • A new connection or action triggers a fresh decision.
  • A pretend accidental upload reaches the named incident contact promptly.

Record the scenario, the explanation, any unclear rule and the correction needed. This is a proposed exercise, not a claim of measured training results. If the employee guesses, revise the card with a concrete example and repeat the relevant scenario. Make asking for help an accepted way to finish the exercise correctly.

What FAQs should the policy answer?

Can employees use personal AI accounts for work?

Make the answer explicit in your policy. A practical starting rule is no work use through personal accounts unless the owner approves a narrow task using public or fictional material. Never let that exception authorize customer records, connected business apps or a different task.

Does an approved company account make customer uploads acceptable?

No. Require separate approval for the task, the input and the account configuration. Check the relevant provider terms and business obligations before permitting customer information. If a task card does not clearly allow the proposed input, staff should hold it for review.

Who should check an AI draft before a customer sees it?

Name someone who understands the work, can consult the source material and has authority to approve the result. Give that person specific checks for facts, promises, recipient details and unsupported additions. Name a backup, and keep the draft on hold when neither reviewer is available.

What should staff do after an accidental upload?

Stop the task and report the tool, account, time and type of information to the named incident contact immediately. Avoid copying the sensitive material into the report. Let that contact coordinate containment and qualified review of any further obligations; do not assume deleting visible history resolves the incident.

What should you put into practice first?

Choose a routine task, complete its card and rehearse it with the employee who performs it. Approve the task only when the input boundary, account, reviewer and stop rule are clear. Expand the inventory as you resolve further tasks rather than treating the first approval as permission for everything.

If you want help turning existing staff habits into practical permissions, contact AI Guy about approved AI tasks and review rules. Bring task descriptions and fictional examples so the discussion can focus on useful work, clear responsibility and decisions your team can follow.