Guide - 7 min read

An AI policy for small business: the one-page version, and the version for teams already building

Most businesses need one page: which tools are approved, what never goes in, and that a person checks the output. Some teams have already moved past that and are building tools and agents other people rely on. This guide covers both, with a free template for the first and how we help with the second.

7 min read Written for Australian small business By Just AiDL

Two different things get called an "AI policy". The first is a use policy: rules for people using ChatGPT, Claude, Gemini or Copilot on their own work. The second is a build policy: rules for people making tools, agents and automations that other people in the business come to rely on. Most small businesses only need the first, and it fits on one page. If someone on your team has already built something the rest of the team uses, you need the second as well.

This guide gives you both. Part one is the one-page use policy with a copyable template and a never-paste list by industry. Part two is for teams that are already building, and what a tiered approach looks like.

Part one: the one-page AI use policy

An AI use policy is a short, written set of rules that tells staff which AI tools they can use for work, on which plan, what information they must never put in, and that a person checks AI output before it reaches a customer. It is not a legal contract, a technical standard or a ban. A good policy actively encourages staff to use AI for the safe, time-saving jobs, and draws a clear line around the few things that are off limits.

You only need to answer six questions clearly.

CoverWhat to write
Approved tools and plansName the tools and the plan. "ChatGPT Team" or "Claude for Work" is a rule; "ChatGPT" is not, because personal and free accounts handle data differently.
What never goes inThe never-paste list below, tailored to your industry. Keep it short enough to remember.
Who checks the outputAnything customer-facing, anything about money, anything that becomes a record: a named person reads and approves it first.
What we want you to use it forDrafting, summarising, tidying notes, first-draft content. Say it plainly so people are not nervous about using it at all.
What to do if something goes wrongWho to tell, the same day, without blame. Near misses are welcome; that is how the list gets better.
When we review thisOnce a year, or when a new tool, a new type of work or an incident changes the picture.

The never-paste list, by industry

This is the part staff most often get wrong without clear guidance. The baseline for every business: customer names paired with personal details, passwords and logins, payment details, anything under an NDA, and anything you would not want a competitor to read. Then add the sharper version for your trade.

Your industryAdd to the never-paste list
Trades and constructionTender pricing and margins, client contract terms, site safety incident records, subcontractor rates and personal details.
NDIS and careParticipant names and NDIS numbers, care and progress notes, health and medication details, incident reports, staff rosters with names.
Retail and servicesCustomer contact lists, loyalty and purchase histories, supplier pricing, staff pay details.
Professional servicesClient files and matter details, financial statements, advice in draft, anything covered by professional privilege or confidentiality.
The one-line test for staffWould the customer be upset to learn this went into an AI tool? If the answer is yes or maybe, it does not go in.

Zero data retention: why the plan matters more than the tool

The most common worry about AI tools is that your data is used to train the model. That worry is a few years out of date for business plans, and the policy should say so. Both OpenAI and Anthropic now offer zero data retention (ZDR) arrangements on their business and API plans: your prompts and outputs are not stored after the response comes back, so there is nothing kept to train on or leak. Their standard business tiers (ChatGPT Team and Enterprise, Claude for Work and Enterprise) do not train on your data by default.

Free and personal accounts generally do not carry these protections. That is the whole reason the first line of your policy names the plan and not just the tool. Put everyone on the business plan, turn on ZDR where it is offered, and the never-paste list gets shorter and easier to follow. Terms change, so check the provider's current data-use page once a year as part of the policy review.

Your one-page template (copy and adapt)

Copy this straight into a document and replace the [bracketed] parts. Keep it to a single page.

[Business name] AI use policy

  1. Approved tools. We use [tool and plan, e.g. Claude for Work] on business accounts only. Personal accounts are not used for work.
  2. Never paste. [Your never-paste list from above, five to eight items.]
  3. A person checks. Anything sent to a customer, anything about money and anything that becomes a record is read and approved by [role] first.
  4. Please use it for. Drafting replies, summarising, tidying notes, first-draft content and [your examples].
  5. If something goes wrong. Tell [name] the same day. Reporting a mistake is never a disciplinary matter.
  6. Review. [Name] reviews this policy every [12] months or when a new tool or type of work is added.

Have everyone acknowledge it once, then revisit it when something changes. That is genuinely enough for most small businesses. If you want it embedded rather than emailed, an AI workshop walks your team through the rules using their own work, so the "why" lands with the "what".

Part two: when your team is already building

At some point the use policy stops being enough. Someone builds a quoting helper the estimators start relying on. Someone wires an agent to the inbox. A spreadsheet macro turns into a small system with a model inside it. None of that is a problem, it is exactly what you want, but a use policy has nothing to say about it. What you need is a build policy: rules for what people make with AI, not just how they use it.

We help businesses develop a tiered approach: roles that give people a clear path from using AI, to trying ideas in a sandbox with safe data, to building tools others rely on; tiers that scale the checks to who depends on a tool and what it touches; and a short set of non-negotiables that never bend. The aim is that the sanctioned path is the fastest and best-supported way to build, so company data stays where it belongs and nothing useful gets built in the shadows.

Every business is different in how far along it is, so we build this with you rather than hand over a template. Start with the free fit call and we will tell you whether you need it yet.

How we help

Where you areWhat we do
Staff are using AI, nobody has written the rules downAn AI workshop: we build the one-page use policy with your team in the room, using their own tasks, and set up the approved plan with ZDR where it is offered.
People are already building tools and agents others rely onA strategic guidelines engagement: we work with you to set up the tiers, sandboxes and guardrails that fit how your business actually operates, then help the first tools through them.
A bigger team, several departments, procurement in the mixThe same model, scaled: an approved-services list with criteria so new tools can be assessed without rewriting the policy, an AI register covering built and bought, and induction by role.

Start with a free 30-minute fit call. We will tell you which of the three you need, and if the one-page template on this page is genuinely all it takes, we will say so.

Frequently asked questions

Do I need an AI policy for my small business?

If your staff are using AI tools like ChatGPT or Claude, and they almost certainly are, yes. For most small businesses a one-page use policy is enough: which tools are approved, what must never be pasted in, and that a person checks output before it reaches a customer.

What is the difference between an AI use policy and an AI build policy?

A use policy covers how people use AI tools on their own work. A build policy covers what people build with AI, the tools, agents and automations others come to rely on. Most small businesses only need the first. Once someone on the team is building things that other people depend on, you need the second.

What does zero data retention (ZDR) mean?

Zero data retention means the AI provider does not store your prompts or outputs after the response is returned, so there is nothing kept to train on or leak. OpenAI and Anthropic both offer ZDR arrangements on their business and API plans, and their business tiers do not train on your data by default. Personal and free accounts generally do not carry these protections, which is why a policy names the approved plan, not just the approved tool.

Can you help us write our AI policy?

Yes. You can copy and adapt the template on this page for free. If you want the rules embedded with your team, our AI workshop walks staff through them with their own work. If your business is already building tools and agents, we build the strategic guidelines with you: roles, tiers, non-negotiables and a register that fits how your team actually works.

Reduce the risk

Get clear AI rules before something goes wrong.

Book a free fit call and we'll help you put simple, plain-English AI rules in place that your team will actually follow.