A usable AI policy fits on one or two pages and answers three questions: which tools are approved, what data can never go into any of them, and who to tell when something goes wrong. Skip the philosophy section. Most businesses do not need a written AI policy because a lawyer said so; they need one because 66% of employees already use AI tools their employer never approved, according to a 2026 PagerDuty survey. Suvysoft builds these guardrails into every AI setup we deploy, not as a separate document nobody reads.
Most AI policy templates online are written for a company with a dedicated legal and IT team to fill in the blanks: definitions sections, governance committees, bias review boards. A five-person shop does not have any of that, and does not need it to get the actual risk under control.
Why does a small business need a written AI policy at all?
Because employees are already using AI, whether or not there is a policy telling them how. PagerDuty's 2026 Shadow AI Workplace Survey found that two-thirds of office professionals have used an AI tool at work that they believed was not permitted under company policy. That number comes from a survey of 1,250 professionals at larger organizations, but the underlying behavior, pasting a document into a free AI tool to save ten minutes, does not require a big company to happen. It requires a laptop and a deadline.
ISACA's 2026 AI Pulse Poll of 3,400 digital trust professionals puts a number on the gap between that behavior and formal governance: 90% say employees at their organization use AI tools, but only 38% of organizations have a formal, detailed AI policy, up from 28% the year before. One in four have no policy at all. A policy does not stop employees from using AI. It decides whether that use follows rules anyone wrote down, or none.
What does it actually cost when this goes wrong?
Enough to make a short document worth the hour it takes to write. IBM's 2026 Cost of a Data Breach Report found that breaches traced back to unsanctioned "shadow AI" tools added roughly $670,000 to the average cost of an incident compared to the cross-industry baseline, took longer to detect, and were more likely to expose customer data than an average breach. Among organizations that reported any AI-related breach, IBM found 92% had no proper AI access controls in place at all, which is a governance gap, not a technology one. We cover the mechanics of a related failure, a chatbot talked into leaking data it should have withheld, in what prompt injection actually risks.
None of that requires a malicious employee. The realistic failure mode is someone pasting a customer list into a free AI tool to reformat it, or dropping a draft contract into a chatbot to get a summary, with no idea that the tool's terms of service allow that input to train the next version of the model.
What should the policy actually say?
Three tiers cover almost every real situation, and a table like this is the part employees will actually remember:
| Data tier | Examples | AI tool rule |
|---|---|---|
| Green | Public info, general research, brainstorming | Any approved AI tool, no restriction |
| Yellow | Internal drafts, non-sensitive business data | Approved tools only, no free consumer accounts |
| Red | Customer PII, financial records, health data, contracts | Never enters a public AI tool, sanctioned or not |
Write the policy around that table, not around the technology. Name two or three approved tools by category (a writing assistant, a coding assistant, an internal chatbot if you have one) instead of trying to list every AI product that exists, since that list is out of date within a quarter. Then write the Red row's prohibition as a specific sentence employees can actually apply: do not paste a customer's name, account number, medical detail, or contract terms into any AI tool that has not been reviewed and approved for that data type. A vague instruction to "use good judgment" is why the gap exists in the first place.
Which data should never go into a public AI tool?
Anything you would not want printed on a public bulletin board with your company's name on it. In practice that means customer PII (names tied to account numbers, health information, financial details), anything covered by a signed NDA, unreleased financial results, and source code or trade secrets that give you a competitive edge. Free consumer accounts on most AI tools reserve the right to use submitted content to improve their models unless the account is on a business or enterprise tier with that setting explicitly turned off. Check that setting before approving a tool, not after.
Does AI-generated content actually belong to your business?
Only the parts a person meaningfully shaped. The U.S. Copyright Office's March 2023 policy statement reaffirmed that human authorship is required for copyright protection, and that purely AI-generated material, with no meaningful human creative control over the expressive elements, cannot be copyrighted at all. That matters if your business publishes marketing copy, product descriptions, or blog content drafted heavily by AI: the specific words a model generated without substantial human editing and judgment are not protected the way content your team wrote and revised would be. A registration applicant even has to disclose and exclude the AI-generated portions of a work. The practical fix is not avoiding AI drafting tools, it is having a person actually edit and take responsibility for what ships, which is also good writing practice regardless of the copyright question.
Do AI rules get stricter if you use AI to screen job applicants or employees?
Yes, and this is the part most generic AI policy templates skip entirely. If your business uses software to score, rank, or filter job candidates or employees, and any of those people live in New York City, NYC Local Law 144 requires an independent bias audit of that tool within the past year, a public summary of the audit results, and at least 10 business days' notice to candidates before it is used to evaluate them. Non-compliance is enforced per day the tool is used without an audit, not per candidate, at up to $500 for a first violation and up to $1,500 for each one after. Separately, the EEOC has confirmed that Title VII's existing ban on employment discrimination reaches an employer's use of AI tools in hiring decisions, meaning a vendor's claim that its tool is "bias-free" does not transfer legal responsibility away from the business using it. If your hiring process uses any AI resume screening, ranking, or scoring tool, this section of your policy needs to name that tool specifically and confirm who checked it.
How do you actually roll this out to a team that is already using AI informally?
Skip the all-staff training deck and start with the approved-tools list, since that alone removes most of the shadow AI problem. Tell employees what they can use today, not just what they cannot. Pair the policy with one specific example of what a Red-tier violation looks like in your business (a client's tax return, a patient's chart, an employee's SSN) so the rule is concrete rather than abstract. Ask people to flag any AI tool they are already using that is not on the approved list, without punishing the disclosure itself, since the goal in month one is visibility, not enforcement. Review the list quarterly. It will be wrong by then regardless of how careful you were when you wrote it.
If you want the guardrails built into the AI systems themselves rather than left to a document employees may or may not read, that is the difference between a policy and an actual setup. Our AI setup and deployment work configures access controls and data boundaries directly into the tools your team uses, and our internal copilots wire AI into Slack, your CRM, and your documents with those same boundaries built in from day one, so the Red-tier rule is enforced by the system instead of relying on someone remembering to follow it. Get in touch if you want a second set of eyes on what your team is already doing with AI.
Frequently asked questions
Do we need a lawyer to write an AI usage policy?
Not for the first version. The core of a usable policy, an approved-tools list, a data-tier table, and an incident-reporting line, is something a business owner can draft in an afternoon. A lawyer becomes worth the cost once your business uses AI in a regulated decision (hiring, lending, healthcare) or handles data covered by a specific compliance framework like HIPAA, where the stakes of getting the language wrong are higher than a general office policy.
What is "shadow AI" exactly?
Shadow AI is employees using AI tools for work without the business knowing or approving it: a personal consumer AI chatbot account, a free browser extension that reads email, or an AI note-taker added to a client call without review. It is the same underlying problem as shadow IT from a decade ago, unapproved software connecting to company data, just faster to adopt because most AI tools require no installation and no approval workflow.
Can we just ban AI tools instead of writing a policy?
You can try, but PagerDuty's survey data suggests it will not work: two-thirds of employees at organizations with policies in place already used unapproved AI tools anyway. A ban with no approved alternative pushes the same behavior further underground, where it is harder to see and audit. Naming a few approved tools removes the reason to reach for an unapproved one.
How often should we update the policy?
Review it quarterly at minimum, and immediately after adopting any new AI tool company-wide. The approved-tools list and the specific product names in a policy go stale fast; the data-tier rules and reporting process underneath them change far less often, which is why the policy should separate the two rather than mixing them into one paragraph.
Does this apply to AI tools built into software we already use, like a CRM's AI features?
Yes. A built-in AI feature in your CRM, help desk, or email platform is still an AI tool processing your data, and it deserves the same data-tier check as a standalone chatbot: confirm what the vendor's terms say about using your data to train models, and whether that setting can be turned off. Many vendors added AI features to existing products in 2025 and 2026 without a corresponding change to their data-use terms, so an older contract may not reflect what the AI feature actually does with your data today.
What happens if an employee violates the policy?
That depends on what was exposed and how, but the policy should say something rather than leaving it unstated. A first-time Yellow-tier mistake, drafting an internal memo in an unapproved tool, usually warrants a conversation and a reminder. A Red-tier violation involving customer PII or contract data should trigger the same review process as any other data exposure incident, including notifying whoever handles your business's data breach obligations, since several states require disclosure regardless of how the data was exposed.
