AI Governance and Risk

Does a Small Business Need an AI Policy?

Yes, and it should fit on one page. Your staff are probably already using AI on personal accounts. Here is what a small-business AI policy must answer, what UK GDPR, US guidance and the EU AI Act's AI literacy duty mean for you, and what to do this week.

Orange cut-paper key threaded on a black keyring with a small black padlock outline hanging below, on a cream background

In brief

Yes. If anyone in your business uses AI for work, even on a personal account, you need an AI policy, and for a small business it should fit on one page: which tools are allowed, what must never go in, what a person checks, what clients are told and who to ask. Businesses using AI in the EU have also had to support staff AI literacy since February 2, 2025.

If a member of your team pasted a client email into ChatGPT on their own phone this morning, which rule did they break? In many small businesses the honest answer is none. There was no rule to break.

So yes, a small business needs an AI policy, and the smaller the business, the shorter it should be. If anyone on your team uses AI for work, even on a personal account, you need one page that says which tools are allowed, what must never go in, what a person checks, what clients are told and who owns the answers. And if you use AI in the EU, the AI Act has expected you to support your staff's AI literacy since February 2, 2025.

Why does a small business need an AI policy if it only has a few staff?

Your staff are already using AI, and without a policy each of them is writing the rules alone.

In October 2025, a Censuswide survey of 2,003 UK employees, commissioned by Microsoft, found that "71% of UK employees have used unapproved consumer AI tools at work" and that "51% continue to do so every week" (Microsoft UK, October 13, 2025). Only 32% said they were concerned about data privacy.

Small firms are not the exception. Microsoft's 2024 Work Trend Index, which surveyed 31,000 knowledge workers in 31 markets, found 78% of AI users bringing their own AI tools to work, a habit "even more common at small and medium-sized companies (80%)" (Microsoft and LinkedIn, May 8, 2024).

This is shadow AI: AI tools the business has not approved, usually on personal accounts. Asked why, 41% of the UK employees said "it's what they're used to in their personal life," and 28% said "their company doesn't provide a work-approved option." Neither answer describes a rogue employee. Both describe a gap the owner can close. (Microsoft sells workplace AI, so weigh its framing accordingly.) The pattern matches what I see when I train business teams: the first question after a session is rarely "which tool is best?" It is "am I allowed to put this in?"

Should you ban AI instead of writing a policy?

A ban does not stop AI use; without an approved alternative, it moves AI onto phones where you cannot see it. It also throws away the upside: employees in the same UK research reported "saving 7.75 hours a week on average," a self-reported figure, but a large one. Bans are one quiet reason small businesses are not getting value from AI yet.

Does your business need a full AI policy? A decision guide

Every business whose people use AI needs the one page; some situations need more on top.

If this describes your business What you need
Staff use AI for work, even occasionally or on personal accounts The one-page policy below, plus one approved tool with work accounts
You handle personal data about customers, patients or employees The page, plus a data protection check of each tool before personal data goes in
You hold client information under confidentiality terms The page, plus a read of your client contracts first
You use AI in the EU, or your AI use affects people in the EU The page, plus AI literacy measures for staff and a record of them
AI will help decide things about people: hiring, performance, credit Specialist legal advice before you start; one page is not enough

A plain word: this is practical guidance, not legal advice. Where your obligations turn on specifics, speak to a qualified adviser.

The One-Page Five: what should a small-business AI policy say?

A small-business AI policy should answer five questions on one page, in words a new starter understands on their first day.

I call this the One-Page Five. It is my suggested way of thinking about a first policy for small and medium-sized businesses (SMBs, or SMEs in the UK and Europe), not an established standard:

The One-Page Five is the five questions a small business's AI policy must answer, on a single page, in words a new starter would understand on their first day: Which tools may I use? What must never go in? What must a person check before it goes out? What do we tell clients? Who do I ask when I am not sure? If your policy cannot answer all five on one page, your staff will answer them for you, one at a time.

1. Which tools may I use?

Name the tool and the account. "ChatGPT" is not an answer; "our company workspace, signed in with your work email" is. Consumer and business accounts often carry different terms on storing your data and training on it, so read them. Name no tool and you have chosen shadow AI by default.

2. What must never go in?

List it in plain nouns: customer names and contact details, employee records, anything about health, client documents under confidentiality terms, passwords, unannounced financial results.

In the UK, pasting a named customer's complaint into a chatbot is processing personal data, and UK GDPR follows it there. The Information Commissioner's Office (ICO) puts it bluntly: "there are no carve-outs or sweeping exemptions for generative AI. If an organisation is processing personal data, then data protection law will be applicable" (ICO, September 4, 2025). Its Guidance on AI and data protection (last updated March 15, 2023, now under review) covers data protection impact assessments (DPIAs), the risk check you may need first.

In the US, the Small Business Administration's guide puts the rule in one line: "Try not to feed any sensitive data or proprietary information" (SBA, updated February 14, 2025). Privacy duties in the US vary by state and sector, so ask your adviser which apply to you.

3. What must a person check before it goes out?

Say who checks and what. "A human checks it" is only as strong as the check, which is why I use the Loop Test: "The Loop Test is three questions I ask before accepting 'a human checks it' as an answer: Would that person notice a wrong result without being told to look for it? Would they notice in time to stop it mattering? And if they missed it, could the work be put back? Oversight that survives all three is a safeguard. Oversight that fails any of them is a signature." Aim the check where errors cost you: figures, names, dates, legal claims, and anything with a client's name on it.

4. What do we tell clients?

Decide once and write it down. The SBA suggests you "consider drafting a public statement that discloses how your small business uses AI." Some clients have decided for you in their contracts, so check them. Never overstate what AI does: announcing a crackdown on deceptive AI claims, the Federal Trade Commission's chair said "there is no AI exemption from the laws on the books" (FTC, September 25, 2024). Disclosure you choose reads as honesty. Disclosure a client discovers reads as a secret.

5. Who do I ask when I am not sure?

Name one person, not a committee. That person owns the page, sets a review date and keeps the record of who has been trained, which also covers you in the EU.

Here is the page for a hypothetical 20-person firm:

Section Hypothetical example line
Why we use AI "To draft and research faster, so we spend more time with clients."
Tools "Only our company AI workspace, signed in with your work email."
Never goes in "Client files, personal details, passwords, unannounced numbers."
Checks "Whoever sends it checks every figure, name and claim."
Clients "We tell clients we use AI to help draft, and that a person reviews everything."
Questions and owner "Ask Sam. Sam reviews this page every six months and keeps the training record."

What does the EU AI Act's AI literacy duty mean for a small business?

If your business uses AI in the EU, you must already take measures to support your staff's AI literacy, and an internal record is enough to show it.

From the European Commission's AI Literacy Questions & Answers (last updated July 27, 2026):

  • When: Article 4 of the AI Act "entered into application on 2 February 2025," and "the supervision and enforcement rules apply from 3 August 2026 onwards." National market surveillance authorities could impose penalties.
  • Who: providers and deployers of AI systems. Asked whether a company whose employees use ChatGPT to write advertising text or translate must comply, the Commission answers: "Yes, they should be informed about the specific risks, for example hallucination."
  • Proof: "There is no need for a certificate. Organisations can keep an internal record of trainings and/or other guiding initiatives."
  • Reach: the Act applies "inside and outside the EU as long as the AI system is placed on the Union market, used in the Union or its use has an impact on people located in the EU." UK and US firms with EU customers should read that twice.
  • What changed: the Digital Omnibus amendments to Article 4 entered into force in mid-July 2026. AI literacy remains an obligation for providers and deployers, but no specific or "sufficient" level is mandated.

For a small team, that means a short session on what AI gets wrong, the one page, and a spreadsheet of names and dates. My guide to AI training for small business teams covers what makes it stick.

The Mistake I See Most Often

The most common mistake is a policy that lists everything staff must not do and never says what they may do.

It often starts with a template borrowed from a large company: twelve pages of prohibitions, no named tool, no named person. Staff read it once, decide the safest move is never to ask, and the phones come back out. Lists of don'ts do not stop shadow AI. They hide it.

Write permission first. My Readiness Test puts it this way: "The Readiness Test is three questions an organization must be able to answer consistently, from the top to the front line, before it can call itself AI ready: What is AI for here? What may I do with it? Who decides when it goes wrong?" A policy is the written answer to the second and third. I have advised government bodies on AI, including the UK Department for Education, Dubai's Knowledge and Human Development Authority (KHDA) and the Ministry of Education in Kazakhstan. Whether the guidance is for a national system or a 15-person agency, the question underneath is the same: can the person at the front line tell what they are allowed to do? (Permission is one of the seven dimensions in my guide to how ready your business is for AI.)

What can you do this week?

You can have a working AI policy by Friday without a project team.

  1. Ask before you write. At your next team meeting, ask which AI tools people use for work, on which accounts, and promise nobody is in trouble for the answer.
  2. Pick one approved tool and set up work accounts, so nobody on your team is left in the 28%.
  3. Draft the One-Page Five in an hour. Hand it to two members of staff and ask them to mark every place they would still have to guess.
  4. Run a short session on what AI gets wrong, and record who attended.
  5. Put a review date in the diary six months out.

Not sure yet what AI is for in your business? Start with how a small business should start using AI.

Where to go next

If you want your leadership team agreed on these answers before anyone writes them down, that is what my AI strategy and governance work is built for. If you would rather see where you stand first, take the free Workplace AI Readiness Check: 21 questions, about eight minutes.

Sources and further reading

Dan Fitzpatrick is The AI Educator: a Forbes contributor and international keynote speaker who helps businesses and governments use AI well, safely and every day.

Key takeaways

  • Any small business whose staff use AI for work, including on personal accounts, needs an AI policy, and it should fit on one page.
  • Shadow AI is already normal: in an October 2025 survey commissioned by Microsoft, 71% of UK employees had used unapproved consumer AI tools at work.
  • Banning AI without an approved alternative does not stop use; it moves it onto personal phones where the business cannot see it.
  • Dan Fitzpatrick's One-Page Five says a small-business AI policy must answer five questions: which tools, what never goes in, what a person checks, what clients are told, and who to ask.
  • In the UK, the ICO says there are no carve-outs or sweeping exemptions for generative AI: if personal data goes in, data protection law applies.
  • Under Article 4 of the EU AI Act, applying since February 2, 2025, businesses that use AI in the EU must take measures to support staff AI literacy; no certificate is needed, and an internal record of training is enough.
  • The most common mistake is a policy that lists only prohibitions; write what staff may do first, and name one person who owns the page.

Frequently Asked Questions

Does a small business need an AI policy?

Yes, if anyone in the business uses AI for work, including on a personal account. A small business does not need a long document. One page that names the approved tools, what data must never go in, who checks AI output, what clients are told and who to ask is enough to start.

What should a small business AI policy include?

It should answer five questions: which tools and accounts staff may use, what information must never go into them, what a person must check before AI output goes out, what the business tells clients about AI, and who staff ask when unsure. Add an owner and a review date.

Can employees use their personal ChatGPT accounts for work?

They can, but it is risky, because the business cannot see or control what goes in. Consumer and business accounts often have different terms on storing and training on your data. A better approach is to approve one tool, set up work accounts and say so in writing.

Can staff put customer or client data into AI tools?

Only if the tool has been checked and approved for it. In the UK, the ICO says there is no AI exemption: if personal data goes in, data protection law applies. The US SBA advises small businesses not to feed sensitive or proprietary information into AI tools. Check client contracts too.

Do I have to tell clients that my business uses AI?

There is no single rule for every business, but deciding in advance is wise. The US SBA suggests a public statement disclosing how your business uses AI, and some client contracts set conditions. Tell clients what AI helps with and that a person reviews the work.

Does the EU AI Act's AI literacy rule apply to small businesses?

Yes, if the business uses AI in the EU or its use affects people in the EU. Article 4 has applied since February 2, 2025. The European Commission says companies whose staff use tools like ChatGPT should inform them of risks such as hallucination. No certificate is needed; an internal training record works.

Should a small business ban ChatGPT at work?

Usually not. A ban without an approved alternative tends to push AI use onto personal phones, where the business cannot see it, and throws away time savings. A short policy with one approved tool, clear data rules and a named person to ask gives far more control than a ban.

Dan Fitzpatrick helps businesses use AI well through keynotes, practical AI training for teams, and AI strategy and governance for leadership teams.

D
Dan Fitzpatrick

Delivered training to 150K+ educators | Founder of The AI Educator and AI Educator Tools | Forbes Contributor | International Keynote Speaker | 4 x #1 Bestselling Author