Your employees may already be using artificial intelligence at work—even if your company has never officially approved it.
They may use an AI assistant to rewrite an email, summarize meeting notes, research a prospect, analyze a spreadsheet or draft customer-facing content. These uses can save time, but they can also expose confidential information, introduce inaccurate claims and create uncertainty about who is responsible for the final result.
The answer is not a blanket ban. Employees will either stop benefiting from useful tools or continue using them without guidance. A better approach is a short, understandable AI acceptable use policy that explains:
- Which AI tools are approved
- What information employees may enter
- Which tasks are permitted or restricted
- What must be reviewed by a person
- Who is accountable for the final output
- How employees should report a mistake or security concern
This guide explains those controls and includes a copy-and-customize policy template for small businesses.
Important: This template is general educational information, not legal advice or a guarantee of compliance. Have it reviewed against your contracts, privacy obligations, employment practices, industry rules and applicable laws before adoption.
What Is an AI Acceptable Use Policy?
An AI acceptable use policy is an internal set of rules governing how employees, contractors and other authorized users may use AI for company work.
It does not need to become a 40-page governance manual. For many small businesses, the first version can be two to four pages if it answers the operational questions employees face every day.
A useful policy should cover:
- Scope: Who and what the policy applies to.
- Approved tools: Which AI services, accounts and features employees may use.
- Data rules: Which information may never be entered into an unapproved AI tool.
- Permitted uses: Low-risk activities employees may perform.
- Restricted uses: Activities requiring management, security, legal or privacy approval.
- Human review: The checks required before relying on or publishing AI output.
- Accountability: The person—not the AI tool—responsible for the final decision or work product.
- Incident reporting: What to do when sensitive information is exposed or harmful output is produced.
The objective is safe adoption, not paperwork. If employees cannot understand the policy, it will not control real-world behaviour.
Why Small Businesses Need AI Rules Now
AI risk is no longer limited to companies developing their own models. Any organization using public chatbots, AI-enabled office software, automated agents or connected AI applications can face risk.
Confidential data may leave the approved environment
An employee might paste a customer complaint, contract, source-code fragment or financial report into a public AI service without understanding its retention or data-use terms. The Government of Canada’s guidance for federal institutions instructs public servants not to enter personal information into publicly available generative AI tools because the provider may retain it. That rule is specific to federal institutions, but the underlying control is sensible for businesses: do not put protected information into a system unless its use has been assessed and approved.
AI output can sound confident and still be wrong
AI can invent facts, citations, calculations, product capabilities or legal interpretations. Fluency is not evidence. A plausible-looking answer can become a customer commitment or business decision if nobody verifies it.
Ownership and accountability become unclear
If an AI-generated proposal contains a false claim, the tool is not accountable to the customer. The employee and organization remain responsible. A policy should make this explicit.
Different uses create different levels of risk
Drafting an internal meeting agenda is not equivalent to screening job applicants, recommending credit decisions or sending an autonomous message to a customer. One universal rule—“AI is allowed”—is too vague. Controls should increase with the potential impact.
The NIST AI Risk Management Framework offers a voluntary approach organized around four functions: Govern, Map, Measure and Manage. Small businesses do not need to reproduce the entire framework, but they can adopt its core idea: understand the context and impact of an AI use before deciding how it should be controlled.
Classify Information Before Entering It Into AI
The easiest rule for employees to remember is: classify before you copy and paste.
Use a simple traffic-light model:
| Classification | Examples | Public or unapproved AI tool |
|---|---|---|
| Green: Public | Published website text, public press releases, public product descriptions, general brainstorming prompts | Usually permitted, subject to normal review |
| Amber: Internal | Draft procedures, internal meeting notes, non-public plans, internal presentations | Use only in an approved business account and for an approved purpose |
| Red: Confidential or regulated | Customer records, employee data, health or financial information, credentials, contracts, source code, trade secrets, legal advice | Prohibited unless the specific system and use case have received written approval |
This table is a starting point. Your organization may need more detailed categories.
Do not assume that removing a person’s name always makes data safe. A combination of job title, location, transaction, complaint details or other attributes may still identify someone. Canadian privacy regulators recommend limiting the sharing of personal, sensitive or confidential information and using generative AI tools in ways that respect applicable privacy laws and best practices.
Examples of Generally Permitted AI Uses
When performed in an approved tool without protected data, lower-risk uses may include:
- Brainstorming titles, questions or campaign ideas
- Rewriting non-sensitive text for clarity or tone
- Creating a draft meeting agenda
- Summarizing documents already approved for that tool
- Producing a first draft of internal training material
- Generating spreadsheet formulas using fictional sample data
- Translating public content, followed by qualified review where accuracy matters
- Research assistance when the employee independently verifies the sources
- Creating outlines, checklists or interview questions
Permission does not remove the need for review. An AI-generated customer email still needs a person to confirm its facts, tone and commitments.
If employees are unfamiliar with the difference between traditional, generative and agentic systems, start with Traditional, Generative and Agentic AI Explained.
Prohibited or Restricted Uses
Unless the organization has specifically assessed and approved the system and use case, employees should not use AI to:
- Enter passwords, API keys, access tokens or security answers
- Upload personal information about customers, employees or applicants
- Share confidential contracts, pricing, source code or trade secrets
- Make final hiring, dismissal, promotion, credit, insurance, legal, health or safety decisions
- Impersonate a person or create deceptive media
- Send messages, change records or execute transactions autonomously
- Produce fake reviews, references, citations or testimonials
- Bypass copyright, licensing, privacy, security or records-management obligations
- Publish claims that have not been checked
- Connect an AI tool to business systems without authorization
Connected tools deserve extra scrutiny because their potential impact extends beyond the prompt. An AI assistant with access to email, cloud storage, a CRM or an MCP server may be able to retrieve sensitive information or take actions. For technical background, see How to Add an MCP Server to ChatGPT, but treat connection approval as a security and governance decision—not merely a setup step.
Required Human Review
“Human in the loop” is meaningless unless the policy defines what the person must do.
Before an AI-assisted output is used externally or for a material decision, the reviewer should:
- Verify factual claims. Check names, dates, statistics, product details and source links against reliable evidence.
- Recalculate important numbers. Confirm formulas, totals, rates and financial projections independently.
- Check completeness. Look for missing conditions, exceptions and context.
- Review for harmful bias. Consider whether the output treats people unfairly or relies on inappropriate assumptions.
- Confirm confidentiality. Ensure the output does not reveal protected information from prompts, connected sources or previous context.
- Assess intellectual-property risk. Confirm the organization has the right to use images, text, code or other material.
- Approve the final result. Record the responsible person when the use is high impact.
The person approving the work should have enough subject knowledge and authority to detect a failure. Asking a junior employee to approve specialized legal analysis they cannot evaluate is not meaningful oversight.
Copy-and-Customize AI Acceptable Use Policy
Replace the bracketed text before adoption.
1. Purpose
[Company Name] supports the responsible use of artificial intelligence to improve productivity, quality and innovation. This policy establishes requirements for using AI while protecting confidential information, personal information, intellectual property, security and the interests of our customers, employees and partners.
2. Scope
This policy applies to all employees, contractors, temporary workers and other authorized users who use AI systems for work performed for or on behalf of [Company Name]. It applies to standalone AI services and AI features embedded in other software.
3. Approved Tools and Accounts
Users may use only AI tools, accounts, models, connectors and extensions approved by [Responsible Role or Department].
The current approved tools are listed at [Location of Approved Tool Register]. Approval of one feature does not automatically approve every integration, connector, plug-in or autonomous capability offered by the same vendor.
Personal accounts and free public accounts must not be used for company work unless specifically approved in writing.
4. Data Protection
Users must classify information before entering, uploading or connecting it to an AI system.
The following information must not be entered into an unapproved AI system:
- Passwords, credentials, API keys or security configurations
- Customer, employee, applicant or other personal information
- Confidential contracts, pricing, financial data or business plans
- Proprietary source code, trade secrets or unpublished intellectual property
- Information restricted by law, contract, client requirement or company policy
Protected information may be used only when [Responsible Role or Department] has approved the specific system, account configuration and business purpose.
5. Permitted Uses
Subject to this policy, users may use approved AI tools for low-risk activities such as brainstorming, outlining, rewriting non-sensitive text, summarizing approved content, drafting internal materials and research support.
All AI-generated work must be reviewed for accuracy, appropriateness and confidentiality before use.
6. Restricted and Prohibited Uses
Without written approval, users must not use AI to:
- Make final decisions about employment, eligibility, credit, legal rights, health, safety or other high-impact matters
- Communicate externally without required human review
- Create deceptive, discriminatory, unlawful or harmful content
- Impersonate a person or misrepresent AI-generated material as verified evidence
- Connect to company systems, retrieve company data or execute actions
- Circumvent security, privacy, licensing, records-management or access controls
7. Accuracy and Human Oversight
AI output must be treated as unverified draft material. The user is responsible for checking facts, citations, calculations, completeness, bias, intellectual-property concerns and suitability for the intended audience.
A qualified person must approve any externally published, customer-facing, safety-related, financially material or otherwise high-impact output.
8. Transparency
Users must disclose material AI assistance when required by law, contract, client instruction, professional standard or [Company Name] procedure. Users must not make false claims about how content or decisions were created.
9. Intellectual Property
Users must respect copyright, trademark, confidentiality, licensing and ownership requirements. AI-generated content must not be assumed to be original, exclusive or free of third-party rights.
10. Security and Incident Reporting
Users must immediately report suspected exposure of protected information, unsafe AI behaviour, unauthorized access, deceptive output or other incidents to [Contact or Reporting Channel].
Users should stop using the affected system and preserve relevant details, including the tool, date, prompt, output and information involved, unless instructed otherwise.
11. Training and Monitoring
Users must complete required AI training before using approved tools. [Company Name] may monitor AI use on company systems as permitted by law and company policy.
12. Violations
Violations may result in removal of AI access and other corrective or disciplinary action consistent with applicable law and company policy.
13. Policy Review
This policy will be reviewed at least [quarterly/semi-annually/annually] and when there is a material change in AI tools, business uses, laws, contracts or risk.
Policy owner: [Name or Role]
Effective date: [Date]
Next review date: [Date]
Approved by: [Name or Role]
How to Implement the Policy in Five Steps
Step 1: Inventory current AI use
Ask employees which tools they use, for what tasks, with what data and through which accounts. Do not begin with punishment; you need an accurate picture of shadow AI before you can control it.
Step 2: Create an approved-tool register
For each tool, record the business owner, account type, approved uses, prohibited data, enabled integrations, retention settings and review date. A roundup such as 25 Best AI Tools for Productivity in 2026 can help identify options, but popularity is not a security assessment.
Step 3: Customize the policy
Replace vague placeholders with actual roles, reporting channels and examples from your business. If a rule cannot be applied to a real task, improve it.
Step 4: Train employees with scenarios
Use short examples: “Can I paste this customer email?” “May I summarize this contract?” “Can the tool send a follow-up automatically?” Scenario-based training is more useful than asking employees to acknowledge a document they did not understand.
Step 5: Review use and incidents regularly
Update the policy when tools, terms, integrations, regulations or business processes change. NIST’s Generative AI Profile provides additional voluntary risk-management considerations for organizations that need a deeper review.
Frequently Asked Questions
Can employees use free ChatGPT, Gemini or other public AI accounts?
Only if the business has evaluated and approved that account type and the intended data. A consumer account may have different administrative controls, contractual protections, retention options or data-use terms than a business plan. Tool names alone are not enough; document the exact plan and configuration.
Can AI summarize customer documents?
Potentially, but only when the customer document is permitted in that specific system and account. Check contractual confidentiality, privacy, data location, retention, provider use of content, access controls and deletion options first.
Who owns AI-generated content?
The answer can depend on jurisdiction, tool terms, source material and the amount of human authorship. Do not promise ownership or exclusivity without appropriate review. Employees should also avoid requesting close imitation of protected works or living creators’ distinctive material.
Should employees disclose AI use?
Disclosure should be required when law, contract, client instruction, professional standards or company policy demand it—and whenever omission would mislead the audience about authorship, evidence or decision-making. Not every spelling correction requires a label, but material AI involvement in important work may.
How often should the policy be reviewed?
Quarterly is a reasonable starting point during rapid adoption. At minimum, trigger a review when the business approves a new tool, enables a connector, introduces autonomous actions, handles a new data type or experiences an incident.
Final Takeaway
A useful AI policy is not a ceremonial document. It is a decision tool employees can apply before they paste data, trust an answer or allow software to act.
Start with four non-negotiable questions:
- Is this tool and account approved?
- Is this information allowed in the tool?
- What must a qualified person verify?
- Who is accountable for the result?
If your policy answers those questions clearly, you have established a practical foundation. The next step is to evaluate individual AI tools with the same discipline before purchasing or connecting them to company systems.
