Home  ›  Blog  ›  Risk and Compliance
Risk and Compliance

Does My Small Business Need an AI Policy?

Short answer

Yes, and one page is enough. Your team is already using AI, so the policy's job is to name approved tools and accounts, list what information may never be pasted in, require a named human to review anything customer-facing, set your disclosure rule, and give people one person to ask when something looks wrong. Writing it takes about an hour.

Key Takeaways
  • No federal law requires a small business to have an AI policy, but existing advertising, employment, and privacy law fully applies to what AI produces on your behalf.
  • Fortune's coverage of MIT's 2025 study reported employees at roughly 90 percent of surveyed companies use personal AI chatbots for work, usually without telling anyone.
  • A workable policy has seven short sections: approved tools, what never goes in, what is fine, human review, accuracy and claims, disclosure, and who to ask.
  • Pay for sanctioned business accounts before you publish restrictions, because prohibition without an alternative just hides the behavior from you.
  • Keep a simple inventory of every AI use with owner, data touched, and failure consequence, and review it with the policy twice a year.
  • The NIST AI Risk Management Framework's four functions (govern, map, measure, manage) are the plain structure behind all of this.

Does your small business need an AI policy? Yes, and it should fit on one page. Not because a regulator is coming for your six-person shop, but because your team is already using AI whether you have said anything or not, and the difference between "helpful" and "expensive incident" is a few sentences about what may be pasted into a chatbot, who checks the output before it goes out, and who to ask when something looks wrong. A one-page policy takes about an hour to write and prevents the two failures that actually happen: confidential information leaving the building, and wrong information going out with your name on it.

Below is what to put in it, which parts are genuinely required by law, how to roll it out without making your team hide their tools, and a template you can adapt today.

What Is an AI Policy, and Why Does a Small Team Need One?

An AI policy is a short written statement of which AI tools your business allows, what information may and may not go into them, who reviews AI output before it reaches a customer, and who is accountable. That is it. It is a use policy, not a technical document, and it should read like something a new hire can follow on day one.

The reason you need one now is simple: adoption already happened. According to Intuit QuickBooks' April 2025 survey of more than 2,200 US businesses with up to 100 employees, 68 percent use AI regularly. And in coverage of MIT's 2025 study of generative AI in business, Fortune reported that employees at roughly 90 percent of the companies surveyed said they use personal AI chatbots for work, mostly without telling their technology teams. That gap has a name: shadow AI. Your policy's real job is to close it by making the sanctioned path easier than the unsanctioned one.

What goes wrong without a policy, in the order we see it:

  • Someone pastes a customer list, a contract, or a patient schedule into a free consumer chatbot account to "clean it up."
  • An AI-written estimate, quote, or medical or legal-sounding answer goes to a customer with a confident error in it.
  • Marketing copy claims capabilities the business does not have, or describes the product as AI-powered when it is not.
  • A manager uses a tool to screen applicants and nobody can explain what it screened on.
  • Two employees build automations nobody else understands, then one of them leaves.

What Goes in a One-Page AI Policy?

Seven sections, a few sentences each. Write it in your own words, put a date on it, and hand it to every employee including part-time and seasonal staff.

  1. Approved tools. Name them. "ChatGPT Team, Microsoft Copilot in our Microsoft 365 account, and the AI features inside QuickBooks and our scheduling app." Then the rule: anything else needs a yes from the owner before business information goes into it. Approving specific accounts matters more than approving brands, because a business or team account and a free personal account handle your data differently.
  2. What may never go in. Be concrete for your business: customer credit card or bank information, Social Security numbers, driver license numbers, medical information, employee records, passwords or API keys, signed contracts, and anything a customer gave you in confidence. If you are in a regulated field, say so explicitly.
  3. What is fine. Say this out loud or people will assume everything is banned and go underground. Drafting copy, summarizing your own notes, rewriting a policy, brainstorming, writing formulas, explaining an error message, translating, and cleaning up anonymized text are all fine.
  4. The human review rule. Nothing written by AI goes to a customer, a lender, an insurer, or the public without a named person reading it first. State who that is by role.
  5. Accuracy and claims. Facts, prices, dates, measurements, legal statements, and medical or safety information must be verified against a source before they go out. AI drafts. People confirm.
  6. Disclosure. Decide when you tell customers AI is involved. Our standing rule: disclose when a customer might reasonably think they are talking to a person, and never let an AI assistant claim to be human.
  7. Who to ask, and what to do when it goes wrong. One name, one email address, and one instruction: report it the same day, do not try to quietly fix it. The reporting line is the part most policies forget and the part that saves you.

Add a version date at the bottom and a line saying the policy will be reviewed every six months. That single line is what keeps it from becoming a fossil.

Hard lesson: The most common breach in a small business is not a hacker. It is a good employee pasting a spreadsheet of customer names, addresses, and payment history into a free chatbot account at 10 p.m. to build a mailing list faster. Give your team a paid business account with training turned off and tell them plainly which columns to strip first. Prohibition without a sanctioned alternative just moves the behavior somewhere you cannot see it.

Which AI Rules Are Actually Required by Law?

No federal law requires a small business to have an AI policy. What existing law does require is that the outcomes of your AI use are lawful, which is a different and more demanding thing. Three areas apply to almost every business.

Advertising and Claims

Consumer protection law applies to what you say about AI and to what you say using AI. The Federal Trade Commission has told businesses directly to keep their AI claims in check, and through its Operation AI Comply enforcement sweep it has brought cases against companies whose AI claims or AI-enabled conduct harmed consumers, including cases involving deceptive promises sold to small businesses. In July 2026 the FTC also sought public comment on a policy statement addressing AI accuracy, which tells you where regulatory attention is pointed. Practical translation: do not describe your product as AI-powered if it is not, do not let AI invent capabilities, guarantees, or results in your marketing, and do not publish AI-generated reviews or testimonials.

Hiring and Employment

If AI touches hiring, promotion, scheduling, or discipline, employment law follows it. Under Title VII, a neutral-seeming practice that disproportionately screens out a protected group is unlawful unless it is job related and necessary to the business, and the EEOC applies that standard to employment tests and selection practices regardless of who or what performs them. On the wage side, the Department of Labor's guidance on AI in the workplace is clear that automated monitoring and timekeeping systems require human oversight and that the employer remains responsible for paying for all hours worked. A growing number of states and cities also regulate automated employment decision tools directly, and those rules keep changing.

Privacy and Confidentiality

Your existing obligations travel with the data. Health information, financial account information, student records, and anything covered by a client confidentiality agreement or a professional licensing rule does not become fair game because a chatbot is convenient. If you signed a contract promising a client that their information stays with you, pasting it into a third-party tool may breach that contract on its own.

For the structure behind all of this, the NIST AI Risk Management Framework is the reference most auditors, insurers, and larger clients now point to. It is voluntary, and it is organized around four functions: govern, map, measure, and manage. In small-business language: decide who is accountable, write down where AI is used and what could go wrong, check whether it is working, and keep checking. Your one-page policy is the govern function. The rest of this post is the other three.

What Does This Look Like for a Business Here?

Picture a two-location dental practice in Elkhorn with eighteen employees, a front desk that fields sixty calls a day, and a practice manager who discovered that three people were already using AI tools for different things.

Their one-page policy came out like this:

  • Approved: Microsoft Copilot inside their Microsoft 365 business account, the AI features inside their practice management and scheduling software, and a transcription tool that signed a business associate agreement. Nothing else without the practice manager's approval.
  • Never goes in: patient names, dates of birth, chart numbers, insurance identifiers, images, or anything from a chart. The rule was written as "no patient information of any kind, including first names," because a rule with an exception is a rule nobody follows.
  • Fine: drafting the newsletter, rewriting appointment reminder templates, summarizing a vendor contract, generating social captions from photos with no patients in them, and writing job posts.
  • Review: the practice manager reads anything patient-facing before it sends. Clinical content gets a dentist's sign-off, always.
  • Disclosure: the website chat assistant opens with a line saying it is an automated assistant and offers a phone number in the first message.
  • Report to: the practice manager, same day, no blame for reporting.

Two things made it stick. First, the practice paid for real business accounts, so nobody had a reason to use a personal login. Second, the policy was one page and was read aloud in a fifteen minute staff meeting rather than emailed as a PDF nobody opened. If you want the deeper version of the data question, our post on whether it is safe to put customer data into AI tools covers the settings that actually matter.

How Do I Roll It Out Without Killing Momentum?

Lead with permission, not prohibition. A policy that reads like a list of ways to get in trouble produces silence, and silence is where the risk lives. The order that works:

  1. Ask first, in a meeting, with no consequences. "What AI tools are you already using and what for?" You will learn more in ten minutes than in a month of guessing.
  2. Buy the sanctioned accounts before you publish the rules. Give people the safe option on the same day you take away the unsafe one.
  3. Read the page out loud together. Fifteen minutes. Take questions. Sign a one-line acknowledgment and keep it with the employee file.
  4. Give three worked examples from your own business. One clearly fine, one clearly not, one genuinely gray. The gray one teaches the most.
  5. Name the person to ask. Then actually answer quickly when someone asks, because the first slow answer teaches everyone to stop asking.

Training and policy are the same project, really. Our guide on training your team on AI without chaos pairs with this one, and doing both in the same month is far easier than doing either alone.

How Do I Keep the Policy From Going Stale?

Put a standing 30 minute review on the calendar twice a year and keep a simple inventory alongside the policy. The inventory is one row per AI use: what it does, which tool, who owns it, what data it touches, and what happens if it is wrong. Ten rows is normal for a small business.

Review these five things at each check:

  1. New tools. What appeared in the last six months, including AI features quietly added to software you already pay for. Those turn on by default more often than people expect.
  2. Departed employees. Whose accounts and API keys are still active, and which automations were built by someone no longer here.
  3. Errors and near misses. Every reported incident, what caused it, and whether the policy would have prevented it.
  4. Vendor changes. Terms of service, data training defaults, and pricing. Vendors change data handling in updates, and the default is not always the one you chose.
  5. Law changes. Ask your attorney once a year whether anything in your state or industry has moved. This is a short conversation and a cheap one.

Do This This Week

  1. Ask your team, without consequences, which AI tools they already use and for what. Write the answers down.
  2. List every place AI is already inside software you pay for, and check whether its data training setting is on or off.
  3. Buy or upgrade one sanctioned business account so people have a safe place to work.
  4. Draft the one-page policy using the seven sections above, in your own words, with a date on it.
  5. Write your never-goes-in list for your specific business, naming the actual data types you handle.
  6. Name one person to ask and one place to report problems, and tell everyone both.
  7. Read the page aloud in a fifteen minute meeting, collect signed acknowledgments, and put the next review on the calendar six months out.

Where to Go From Here

The decision is not whether to have an AI policy. Your team has one already; it is just unwritten, inconsistent, and invisible to you. Writing it down costs an hour and turns a set of private guesses into a shared standard, which is the entire point. Keep it to one page, make the sanctioned path the easy path, and review it twice a year.

If you would rather see the whole picture first, where AI is already running in your business, what it touches, and which uses carry real risk, our AI automation work for Lake Geneva small businesses starts with that inventory before anything gets built or connected. The policy tends to write itself once you can see the list.

Sources and Further Reading

  1. AI Risk Management Framework. National Institute of Standards and Technology, 2026.
  2. Keep your AI claims in check. Federal Trade Commission, February 2023.
  3. Operation AI Comply: continuing the crackdown on overpromises and AI-related lies. Federal Trade Commission, September 2024.
  4. FTC Seeks Public Comment on Policy Statement Addressing AI Accuracy. Federal Trade Commission, July 2026.
  5. Prohibited Employment Policies/Practices. U.S. Equal Employment Opportunity Commission, 2026.
  6. Artificial Intelligence. U.S. Department of Labor, 2026.
  7. The 'shadow AI economy' is booming: Workers at 90% of companies say they use chatbots, but most of them are hiding it from IT. Fortune, August 2025.
  8. Survey Reveals Small Businesses Are Using AI to Boost Productivity. Intuit QuickBooks, June 2025.
Questions

Frequently Asked

Is a small business legally required to have an AI policy?

No federal law requires one for a small business. What the law does require is that outcomes are lawful: advertising claims must be truthful, hiring practices cannot disproportionately screen out protected groups without job-related justification, and confidential or regulated data must stay protected. A written policy is how you make those outcomes likely, and it is what a client, insurer, or regulator will ask to see.

What should employees never put into an AI tool?

Customer payment and bank information, Social Security and driver license numbers, medical information, employee records, passwords and API keys, signed contracts, and anything a client gave you under a confidentiality agreement. Write the list in terms of the actual data your business handles rather than in general categories, because vague rules produce confident mistakes.

Do I have to tell customers when I use AI?

There is no blanket federal requirement, but the safe standard is to disclose whenever a customer could reasonably think they are talking to a person, and to never let an automated assistant claim to be human. Set the rule in your policy and apply it consistently across your website chat, your text replies, and your email autoresponders.

How often should we update our AI policy?

Twice a year, plus any time you adopt a significant new tool. Check what new AI features turned on inside software you already pay for, whose accounts and automations belong to departed employees, every reported error, vendor changes to data handling defaults, and whether anything in your state or industry has changed legally.

No Cost · No Obligation

See Exactly Where You Stand Online

Get a free Lake Geneva Local Visibility Audit. We will show you where you stand on Google, AI search, listings, reviews, and social, plus what to fix first.