🔒 Free AI Policy Template

AI Usage Policy for Small Business

5 clauses. Approved tools, prohibited uses, and a human-in-the-loop rule. Copy it, adapt it, use it today.

Built from the exact Safe List, Never List, and human-in-the-loop framework in our Shadow AI Audit guide, not a generic template pulled off the internet.

Not legal advice. This is a starting template, not a substitute for a policy scoped to your sector's specific risk. Have a solicitor review it before adopting, especially if you handle health, financial, or legal client data.

1. Purpose & Scope

This policy sets out how [COMPANY NAME] expects artificial intelligence (AI) tools to be used by staff, contractors, and anyone processing company or client data on our behalf. It applies to every AI tool in use, whether officially provided by the business or found and used independently ("Shadow AI"). The goal is not to ban AI. It is to make sure every tool in use has been checked, and every output has a human behind it before it reaches a client.

2. Approved Tools (The Safe List)

Only the following are approved for business use: [LIST YOUR CHOSEN PAID, BUSINESS-TIER TOOL(S), e.g. ChatGPT Business/Enterprise, Claude for Work/Team, Gemini for Workspace, Copilot], not the free consumer version of any of these. Data training must be switched off in the admin settings for every approved tool, this is usually a single toggle, check it before rolling a tool out, not after. One approved tool per task type, if two tools do the same job, pick one and standardise on it.

Get the rest of the template

Enter your name and email to unlock the Never List, the human-in-the-loop clause, and the roles & review section. Free forever, no credit card.

No spam. Unsubscribe any time.

This template covers the policy. It doesn't tell you what your team is actually using right now. Read The Shadow AI Audit for the three-step process that finds out, before you finalise a policy built on guesswork.

AI policy template: quick answers

Is this AI policy template legally binding?

No, on its own it isn't legal advice and won't automatically make your business compliant. It's a practical starting point built from the same Safe List, Never List, and human-in-the-loop framework in our Shadow AI Audit guide. Have a solicitor review it before adopting, especially if you handle health, financial, or legal client data.

Is this specific to UK GDPR?

It's written with UK data protection obligations in mind, you're accountable for how personal data is processed even through a tool nobody approved, but it's a generic starting template, not scoped to your sector's specific risk. We build a fully scoped policy as part of our AI Strategy & Audit engagement.

How is this different from a generic AI policy I'd find online?

It's built directly from the three real risks and the exact framework in our Shadow AI Audit, a Safe List of approved tools, a Never List of strict prohibitions, and a human-in-the-loop clause, rather than boilerplate pulled off the internet with no context for why each rule exists.

Do I need to run a Shadow AI Audit before using this template?

It helps. The audit tells you what your team is actually using so the Safe List reflects reality instead of guesswork. You can still start from this template today and refine it once you've run the audit.

Want it scoped to your sector?

This template is the generic starting point. Our AI Strategy & Audit engagement runs the full Shadow AI Audit and scopes the policy to your sector's actual risk, not a template pulled off the internet.

BrightMind Studio