business ai

A one-page AI use policy for a small business

Copy a one-page AI use policy for your small business: approved tools, data that never goes in, output checks, and one name for questions, with vendor facts.

Somebody on your team is already using ChatGPT. Maybe two people are, on their own accounts, and you have not decided what they may paste into it. A customer email, a price sheet, a draft contract, a spreadsheet of names: it all looks like text to a chatbot, and nobody has told staff where the line is. You do not need a governance program to fix that. An AI use policy for a small business can fit on one page, and you can hand it out this week. It says which tools and accounts are approved, what information never goes in, who checks the output, and who answers questions. The rest of this page gives you the policy to copy, the facts about how the major vendors handle your data, and the few cases where your industry changes the rules. It is general information, not legal advice.

Key Takeaways

Write the rule before you buy anything

A named list of approved tools, a never-enter list and one person to ask will do more than a new subscription. Ten minutes of asking staff what they use is the first step.

Not used for training is not the same as not stored

OpenAI, Microsoft and Anthropic all describe business plans that keep customer content out of model training, and all of them still retain chats, logs or files in some form.

A human owns every customer-facing answer

NIST and the FTC both point to the same habit: check important output against a trusted source, and never claim more than you can back up.

Sector rules apply to some businesses, not all

HIPAA, GLBA and state privacy laws change the policy only when your business falls under them, so send uncertain cases to one named contact.

The one-page policy you can hand to staff this week

Copy the table below into a document, replace the items in parentheses with your own names and tools, and send it today. It follows the order a staff member meets the questions: which tool, which data, what to check, who to ask. Every line is a rule a person can follow without reading a vendor's legal page in the middle of a customer email.

One-page AI use policy (copy and edit)
SectionRule for staff
Approved toolsUse only (tool names) with a company-managed account for work. Do not use a personal account for business information.
Never enterPasswords, payment card data, authentication codes, Social Security numbers, confidential contracts, trade secrets, unredacted customer records, patient information and nonpublic financial information.
Remove identifiersWhen a task needs real material, take out names, contact details and identifying facts first.
Check the outputA person reads and verifies AI output against the original records or a trusted source before it goes to a customer, an employee, a regulator, the website or an important record.
Customer-facing contentIf AI materially wrote or changed something a customer will read, and leaving that out would mislead them, say so. Ask (policy owner) when unsure.
Never doWrite fake reviews or testimonials, impersonate anyone, make claims about accuracy or results you cannot support, or let AI make a hiring, credit or similar decision on its own.
Questions and exceptionsAsk (policy owner). New tools, new uses and new data types need approval first.
If something goes wrongReport a wrong answer, an exposed file or a pasted secret to (policy owner) right away. Reporting is never punished.
ReviewThe policy owner reviews this page every (month or quarter), after any incident and when a new AI feature is added.
SectionApproved tools
Rule for staffUse only (tool names) with a company-managed account for work. Do not use a personal account for business information.
SectionNever enter
Rule for staffPasswords, payment card data, authentication codes, Social Security numbers, confidential contracts, trade secrets, unredacted customer records, patient information and nonpublic financial information.
SectionRemove identifiers
Rule for staffWhen a task needs real material, take out names, contact details and identifying facts first.
SectionCheck the output
Rule for staffA person reads and verifies AI output against the original records or a trusted source before it goes to a customer, an employee, a regulator, the website or an important record.
SectionCustomer-facing content
Rule for staffIf AI materially wrote or changed something a customer will read, and leaving that out would mislead them, say so. Ask (policy owner) when unsure.
SectionNever do
Rule for staffWrite fake reviews or testimonials, impersonate anyone, make claims about accuracy or results you cannot support, or let AI make a hiring, credit or similar decision on its own.
SectionQuestions and exceptions
Rule for staffAsk (policy owner). New tools, new uses and new data types need approval first.
SectionIf something goes wrong
Rule for staffReport a wrong answer, an exposed file or a pasted secret to (policy owner) right away. Reporting is never punished.
SectionReview
Rule for staffThe policy owner reviews this page every (month or quarter), after any incident and when a new AI feature is added.

Each row comes from a named source later on this page. The never-enter list and the approved-account rule come from the vendors' own data pages. The checking, ownership and incident rows come from NIST, and the claims, reviews and disclosure rows come from the FTC. If you only have time for one thing today, send the short version: use company-approved AI accounts for work, keep customer confidential information, passwords, payment data, health information and financial records out unless the business has approved that exact tool and use, check every output before it goes anywhere, and ask the named person when unsure.

A single printed sheet of paper with unreadable pencil marks lies on a wooden desk beside a closed laptop and a coffee mug.
One sheet, handed out this week, is a better start than a long document nobody reads.

Ten minutes of questions gives you the facts to fill in the blanks

A policy full of guesses about what your staff use will miss the real tools. The inventory below takes ten minutes and tells you which tools to approve, which accounts to move, and which data to name in the never-enter row.

  1. Ask each staff member which AI tools they use for work, including the ones built into apps they already have.
  2. Ask whether each account is personal, company-managed or shared.
  3. Write down the tool, the account email, the purpose, and whether files or customer data go in.
  4. List your highest-risk information: payment data, passwords, health information, financial records, identity documents, contracts, trade secrets and private customer messages.
  5. Choose one rule for what never goes into a chatbot, such as: never enter confidential customer or company information into an AI tool unless the company has approved the exact tool and use.
  6. Name one person who approves tools and answers questions.
  7. Tell staff to report any past accidental paste right away, with no blame attached.

Do the survey in a friendly way. Staff who think they are being audited will leave tools off the list, and you need the real list more than you need a clean one. If you want a cleaner count, you can also look at expense records and, where it is appropriate, browser or sign-in records. NIST describes keeping an inventory of AI use, documented roles and periodic review as part of managing AI risk, and your list is a small version of that.

A notebook with a short handwritten list of items sits open on a desk next to a closed laptop and a pen.
A list of who uses which tool, on which account, is the base the whole policy rests on.

Business plans and personal accounts do not handle your data the same way

This is the part of the policy where the details differ by vendor and plan, so your approved-tools row should name the plan, not just the brand. The short version is that the business plans of the four major vendors keep your content out of model training by default or by commitment, while personal accounts may not. The table gives each vendor's own statement. Vendor pages change, so confirm the plan you pay for in its admin settings before you rely on any line.

What each vendor says about business and personal data
VendorBusiness or work plansPersonal accounts
OpenAI (ChatGPT)ChatGPT Business and Enterprise data is not used to train models by default. Business includes roles, MFA, SSO, GPT controls and basic usage analytics. Chats stay saved until deleted unless a workspace policy applies.Free, Plus and Pro have model-improvement sharing on by default, with an opt-out setting.
Google (Gemini)Google says Workspace data is not used to train Gemini or foundational models without permission. Admins can restrict Gemini and control access to Drive and Gmail data. Prompts and outputs are not stored without permission in covered Workspace apps.Personal Gemini Apps activity may be used to improve services, including training, when Keep Activity is on.
Microsoft (Copilot)Copilot for Microsoft 365 and Copilot Chat provide commercial data protection, and prompts and responses are not used to train foundation models. Interactions may be logged for auditing and eDiscovery, and retention depends on the subscription and your organization's policies.Not covered in the commercial data protection description.
Anthropic (Claude)Anthropic acts as a processor for Team and Enterprise customers and says commercial customer data is not used to train generative models. Claude for Work keeps chats so users can continue conversations. API inputs and outputs are deleted from its backend within 30 days, unless an agreement, a legal requirement or a usage-policy investigation applies.Not covered in the commercial customer description.
VendorOpenAI (ChatGPT)
Business or work plansChatGPT Business and Enterprise data is not used to train models by default. Business includes roles, MFA, SSO, GPT controls and basic usage analytics. Chats stay saved until deleted unless a workspace policy applies.
Personal accountsFree, Plus and Pro have model-improvement sharing on by default, with an opt-out setting.
VendorGoogle (Gemini)
Business or work plansGoogle says Workspace data is not used to train Gemini or foundational models without permission. Admins can restrict Gemini and control access to Drive and Gmail data. Prompts and outputs are not stored without permission in covered Workspace apps.
Personal accountsPersonal Gemini Apps activity may be used to improve services, including training, when Keep Activity is on.
VendorMicrosoft (Copilot)
Business or work plansCopilot for Microsoft 365 and Copilot Chat provide commercial data protection, and prompts and responses are not used to train foundation models. Interactions may be logged for auditing and eDiscovery, and retention depends on the subscription and your organization's policies.
Personal accountsNot covered in the commercial data protection description.
VendorAnthropic (Claude)
Business or work plansAnthropic acts as a processor for Team and Enterprise customers and says commercial customer data is not used to train generative models. Claude for Work keeps chats so users can continue conversations. API inputs and outputs are deleted from its backend within 30 days, unless an agreement, a legal requirement or a usage-policy investigation applies.
Personal accountsNot covered in the commercial customer description.

Read the first two vendor rows slowly. OpenAI's own pages describe business data privacy and controls and how its Business workspace handles data and sharing, and they also describe an opt-out for training on personal accounts. Google describes its Workspace generative AI privacy commitments and, separately, how Gemini protects your data. Microsoft lays out its Copilot Chat privacy and protections, and Anthropic explains whether it acts as a data processor or controller and how long it stores organization data.

Two points belong in your policy because they change what staff should do. First, a business plan that does not train on your content can still retain chats, prompts, outputs, logs or files so the service works, so an audit can happen, or a legal obligation can be met. A business plan is better governed, but it does not make a pasted password or an unredacted customer record appropriate. Second, switching off training on a personal account addresses model improvement only. The service may still hold the data, and it can still be exposed through a compromised account, a connected app or a shared link. That is why the policy says company-managed accounts for work, not personal accounts with a setting changed.

Two identical metal filing boxes sit side by side on a shelf, one with a small padlock on its latch and one without.
Business plans add locks and an administrator; they do not change what belongs in the box.

NIST and FTC guidance turn into six rules staff can follow

You do not have to invent the rules from nothing. NIST AI RMF 1.0, released January 26, 2023, is voluntary and not specific to any sector. It describes trustworthy AI as valid and reliable, safe, secure and resilient, accountable and transparent, explainable, privacy-enhanced, and fair with harmful bias managed, and it organizes the work into four functions: Govern, Map, Measure and Manage. For a business with a handful of staff, the AI RMF core functions boil down to six staff rules.

  • Use AI for approved purposes: Staff pick up AI for work the business has approved, not for anything that seems convenient.
  • Enter only what is approved: Do not enter information unless the business has approved the tool and the data use.
  • Check important output: Compare it with the original records or a trusted source.
  • Keep a human responsible: A named person owns customer-facing, financial, legal, employment and safety-related decisions.
  • Record recurring workflows: Write down the tool, the purpose and the reviewer for any task done repeatedly.
  • Report problems promptly: Wrong, biased, unsafe or exposed information goes to the policy owner right away.

NIST also publishes a Generative AI Profile from July 2024 and an AI RMF Playbook if you ever want to go deeper. A small business can run on the six rules above.

The FTC covers the other half: what you tell customers. Its guidance on AI claims says claims must be truthful, non-deceptive and supported by competent and reliable evidence. In practice, staff should not say that AI-written content, automation or accuracy is better than the business can substantiate. The agency has also banned fake reviews and testimonials in a final rule from August 2024, including AI-generated ones that misrepresent a real customer experience. That is the reason the policy has a never-do row.

Sector rules change the policy only for businesses they cover

Most of the policy applies to every business. A few rules apply only if you handle certain kinds of information, and the answer for each depends on who you are. Treat the three below as questions to settle with the right professional, then add one line to your policy for each that applies.

Health information and HIPAA

HIPAA applies to covered entities and business associates, not to every business that touches health information. HHS explains who counts in its guidance on covered entities and business associates. A vendor that handles protected health information for a covered entity may be a business associate, and the covered entity generally needs a written business associate agreement with it, as HHS describes in its business associates guidance. HHS identifies an AI chatbot on a patient portal as a possible business associate when it accesses that information. If this is you, add a line that patient information stays out of general-purpose AI tools unless the use is approved, covered by contract and secured. Health information that falls outside HIPAA is still addressed in HHS and FTC guidance on collecting, using or sharing consumer health information.

Financial information and GLBA

A business covered by the Gramm-Leach-Bliley Act must protect nonpublic personal information and maintain an information-security program with administrative, technical and physical safeguards. The FTC explains this in its GLBA and Safeguards Rule guidance. If you are covered, add AI vendors and prompts to the same data-security and vendor review you already run for other tools.

State privacy laws

State laws vary by state, threshold and business activity. California's CCPA, for example, can create duties around notice, purpose limits, consumer rights, service providers, contractors, sensitive data and vendor contracts, and the regulations effective January 1, 2026 are the text to check there. Where you are unsure whether a law applies, use the strictest internal rule for sensitive customer data and send the question to your policy owner. Confirm the details with a qualified privacy attorney before relying on this policy for regulated work.

Customers, reviews and wrong answers need their own lines

A policy that only covers what goes into the tool misses what comes out of it. The four rows below take about five minutes to add and cover the situations a customer actually notices.

Start with accuracy. AI output sounds confident whether it is right or wrong, and a disclaimer does not move responsibility to the customer. The person who sends the message owns it, and anything uncertain goes to the policy owner. Next, disclosure: not every AI-assisted email needs a label, but where leaving out the AI's role would mislead the customer, say so, and remember that a disclosure does not make misleading content acceptable. Then reviews. The never-do row bans fake reviews and testimonials outright, which also covers AI-written ones that misrepresent a real customer experience.

If you run a customer-facing chatbot, it needs a defined knowledge source, an allowed-topics list and a way to hand a customer to a person. A chatbot that answers outside its approved material, with no escalation, is the kind of failure staff rules cannot fix on their own. Last, plan for the mistake. If someone pastes something they should not have, the steps are short: preserve the facts, tell the policy owner, follow the vendor's deletion and incident process, and check whether any contract or regulation required you to notify anyone. The size of that job depends on what was pasted and which sector you are in.

A pair of reading glasses rests on a stack of blank sheets of paper beside a pencil on a clean desk.
The last step before anything leaves the building is a person reading it.

A written rule comes before a new subscription

Do not start by buying anything. A ten-minute inventory, a never-enter list, human review and one approved low-risk use may solve the problem you have today. A managed plan makes sense when you need central accounts, access controls, retention settings, auditability or approved integrations, and it pays for itself only when it solves a problem you can name. It will not make an unsafe prompt appropriate, guarantee compliance, remove retention or replace the person who checks the answer.

Banning AI is rarely the practical answer either. If staff already use it for ordinary work, a narrow approved-use rule, a never-enter list and a reporting route give you more control than a ban that people quietly work around. Be wary of AI detectors as a way to police it. The FTC took action against one detector marketed as 98 percent accurate after alleging its performance was no better than a coin toss, as described in its Workado order.

Approving tools also means checking where staff get them. Fake lookalike tools exist, and our post on the one rule to give staff about fake ChatGPT custom GPTs covers it. If your plan is to build a tool of your own, what a custom GPT can and cannot do for your business is the better place to start than a subscription.

Check your AI policy knowledge

Pick an answer to begin.

1. A vendor says business plan data is not used for model training. What should your policy still assume?

2. Which accounts should staff use for work?

3. An AI-written reply is about to go to a customer. What does the policy require?

Frequently Asked Questions About ai use policy for small business

Can employees use ChatGPT for work?

Yes, if the business approves the tool and account, defines allowed uses and requires human review of output.

What should never go into an AI chatbot?

Passwords, payment data, authentication codes, confidential customer records, protected health information, nonpublic financial information, trade secrets and contracts the business has not approved for that tool.

Is a business plan automatically private?

No. Business plans offer stronger training defaults and admin controls, but retention, logging, sharing, connected apps and plan settings still matter, so confirm them in your own account.

Does not used for training mean not retained?

No. A provider may keep chats, prompts, outputs or logs to provide the service, support auditing or meet legal obligations.

Do I have to tell customers that AI wrote an email?

Not always. It depends on the use and on whether leaving it out would mislead the customer. Human review is required either way.

Can HIPAA information go into AI tools?

Only through an approved workflow with the right safeguards, permissions and any business associate agreement required.

Wrapping Up

A small business AI policy needs five things: approved tools on company-managed accounts, a never-enter list, a human check before output leaves the building, supported claims and genuine reviews, and one person to ask. Vendor business plans help with training and admin controls, but retention and sharing still apply, and sector rules such as HIPAA, GLBA and state privacy laws add lines only for businesses they cover.

With the sheet sent, the inventory done and a review date on the calendar, staff know what to do without guessing and you stop wondering which tools are in use. You can adjust the policy after the first month, after any incident and whenever a new AI feature shows up.

If you want help turning the inventory into an approved-tool list, account settings and a policy staff follow, Web Leveling can do that with you through our AI consulting work, and our AI automation team can build the approved workflows afterward. You can start this policy on your own in ten minutes, and if that is all you need, we will tell you so. We work with small and medium businesses across the country and overseas. Tell us which tools your staff use, and we will help you write the rules around them.

Terms

AI policy words in this post

Tap a term to see what it means.

AI use policy. A short written rule for staff that names approved tools, off-limits data, output checks and who to ask.

Company-managed account. A work account the business controls, so access and offboarding can be handled by an administrator.

Model training. Using customer content to improve the AI model itself, which business plans from the major vendors say they do not do by default.

Retention. How long a service keeps chats, prompts, outputs, logs or files, which is separate from whether they are used for training.

Business associate. Under HIPAA, a vendor that handles protected health information for a covered entity and generally needs a written agreement with it.

Nonpublic personal information. Customer financial information that GLBA-covered businesses must safeguard.