AI Security Policy Template for Small Businesses
What this means
A practical AI security policy template small businesses can adapt — approved tools, data you must not paste, human checks, and a one-week adoption list.
Note: This site may show light ads and occasional affiliate links. How that works.
Small businesses are already using AI — for drafts, summaries, support replies, and “quick research.” Most don’t have a policy. This template gives you wording you can adapt in an afternoon, without sounding like a Fortune 500 legal department.
How to use: Copy into your staff handbook or shared drive. Delete sections that don’t apply. Have an owner approve it. Revisit when you adopt a new AI tool. Template only — not legal advice. For regulated sectors, ask your adviser.
Why a short policy beats a long silence
Without guidance, staff invent their own rules. Some paste customer emails into public chatbots. Others hide useful tools because they fear looking wrong. A short, plain policy makes expectations visible and keeps good tools in the open.
Related reading: Before You Paste It Into the Bot · Shadow AI.
AI Security Policy — template
1. Purpose
[Organisation name] allows approved AI tools to improve drafting, research, and routine tasks. This policy protects customers, staff, and the business from accidental data exposure, unreliable outputs, and unsupervised actions.
2. Scope
Applies to all employees, contractors, and volunteers using AI for work on company or personal devices.
3. Approved tools
List tools approved for work use: [e.g. Microsoft Copilot in our tenant / ChatGPT Team / …]
- Personal free accounts are not approved for company or customer data.
- New tools need owner approval before staff put work data into them.
4. Data you must not paste
- Customer personal data (names with contact details, IDs, health, financial identifiers)
- Full card numbers, authentication codes, passwords, private keys
- Confidential contracts, unpublished pricing, or staff HR records
- Anything you’d be unhappy to see in a data-breach headline
If you can anonymise a question (remove names and identifiers), prefer that — or use an approved business tool with a clear data-handling stance.
Stop! Pause! Before you paste into any bot: Is it urgent? Do you know who owns this data? Would you be happy if a stranger read it tomorrow? If not sure — strip names and numbers first, or don’t paste at all.
5. Human responsibility
- AI drafts are starting points. Staff remain responsible for accuracy before sending to customers.
- Do not rely on AI for legal, tax, medical, or safety-critical decisions without a qualified human check.
- If a tool can send, pay, or change settings on your behalf, keep a human confirm step. Know how to disconnect it.
6. Customers and transparency
- When AI materially drafts customer-facing replies, follow our tone of voice.
- Do not present AI fiction as verified fact.
- If a customer asks whether AI helped, answer honestly per manager guidance.
7. Reporting problems
If you pasted something sensitive by mistake, or an AI tool behaved oddly (unexpected sends, strange access prompts), tell [role/email] promptly. Early reporting is valued.
8. Review
This policy is reviewed at least annually, or when we adopt a major new AI product.
One-week adoption checklist
- Owner names an AI contact person
- Approved-tool list published in the staff channel
- 15-minute walkthrough of “what not to paste”
- Link this policy next to your password / phishing guidance
Broader SMB baseline: Small Business Cybersecurity Checklist 2026. Hub: AI, human risk & scams. Align staff habits with NCSC staying-secure tips.
A self-check
Can every person on your team name one approved AI tool — and one thing they must never paste into it? If not, the policy isn’t live yet. That’s a fifteen-minute conversation worth having this week.
