If a member of your team pasted a client email into ChatGPT on their own phone this morning, which rule did they break? In many small businesses the honest answer is none. There was no rule to break.
So yes, a small business needs an AI policy, and the smaller the business, the shorter it should be. If anyone on your team uses AI for work, even on a personal account, you need one page that says which tools are allowed, what must never go in, what a person checks, what clients are told and who owns the answers. And if you use AI in the EU, the AI Act has expected you to support your staff's AI literacy since February 2, 2025.
Why does a small business need an AI policy if it only has a few staff?
Your staff are already using AI, and without a policy each of them is writing the rules alone.
In October 2025, a Censuswide survey of 2,003 UK employees, commissioned by Microsoft, found that "71% of UK employees have used unapproved consumer AI tools at work" and that "51% continue to do so every week" (Microsoft UK, October 13, 2025). Only 32% said they were concerned about data privacy.
Small firms are not the exception. Microsoft's 2024 Work Trend Index, which surveyed 31,000 knowledge workers in 31 markets, found 78% of AI users bringing their own AI tools to work, a habit "even more common at small and medium-sized companies (80%)" (Microsoft and LinkedIn, May 8, 2024).
This is shadow AI: AI tools the business has not approved, usually on personal accounts. Asked why, 41% of the UK employees said "it's what they're used to in their personal life," and 28% said "their company doesn't provide a work-approved option." Neither answer describes a rogue employee. Both describe a gap the owner can close. (Microsoft sells workplace AI, so weigh its framing accordingly.) The pattern matches what I see when I train business teams: the first question after a session is rarely "which tool is best?" It is "am I allowed to put this in?"
Should you ban AI instead of writing a policy?
A ban does not stop AI use; without an approved alternative, it moves AI onto phones where you cannot see it. It also throws away the upside: employees in the same UK research reported "saving 7.75 hours a week on average," a self-reported figure, but a large one. Bans are one quiet reason small businesses are not getting value from AI yet.
Does your business need a full AI policy? A decision guide
Every business whose people use AI needs the one page; some situations need more on top.
| If this describes your business | What you need |
|---|---|
| Staff use AI for work, even occasionally or on personal accounts | The one-page policy below, plus one approved tool with work accounts |
| You handle personal data about customers, patients or employees | The page, plus a data protection check of each tool before personal data goes in |
| You hold client information under confidentiality terms | The page, plus a read of your client contracts first |
| You use AI in the EU, or your AI use affects people in the EU | The page, plus AI literacy measures for staff and a record of them |
| AI will help decide things about people: hiring, performance, credit | Specialist legal advice before you start; one page is not enough |
A plain word: this is practical guidance, not legal advice. Where your obligations turn on specifics, speak to a qualified adviser.
The One-Page Five: what should a small-business AI policy say?
A small-business AI policy should answer five questions on one page, in words a new starter understands on their first day.
I call this the One-Page Five. It is my suggested way of thinking about a first policy for small and medium-sized businesses (SMBs, or SMEs in the UK and Europe), not an established standard:
The One-Page Five is the five questions a small business's AI policy must answer, on a single page, in words a new starter would understand on their first day: Which tools may I use? What must never go in? What must a person check before it goes out? What do we tell clients? Who do I ask when I am not sure? If your policy cannot answer all five on one page, your staff will answer them for you, one at a time.
1. Which tools may I use?
Name the tool and the account. "ChatGPT" is not an answer; "our company workspace, signed in with your work email" is. Consumer and business accounts often carry different terms on storing your data and training on it, so read them. Name no tool and you have chosen shadow AI by default.
2. What must never go in?
List it in plain nouns: customer names and contact details, employee records, anything about health, client documents under confidentiality terms, passwords, unannounced financial results.
In the UK, pasting a named customer's complaint into a chatbot is processing personal data, and UK GDPR follows it there. The Information Commissioner's Office (ICO) puts it bluntly: "there are no carve-outs or sweeping exemptions for generative AI. If an organisation is processing personal data, then data protection law will be applicable" (ICO, September 4, 2025). Its Guidance on AI and data protection (last updated March 15, 2023, now under review) covers data protection impact assessments (DPIAs), the risk check you may need first.
In the US, the Small Business Administration's guide puts the rule in one line: "Try not to feed any sensitive data or proprietary information" (SBA, updated February 14, 2025). Privacy duties in the US vary by state and sector, so ask your adviser which apply to you.
3. What must a person check before it goes out?
Say who checks and what. "A human checks it" is only as strong as the check, which is why I use the Loop Test: "The Loop Test is three questions I ask before accepting 'a human checks it' as an answer: Would that person notice a wrong result without being told to look for it? Would they notice in time to stop it mattering? And if they missed it, could the work be put back? Oversight that survives all three is a safeguard. Oversight that fails any of them is a signature." Aim the check where errors cost you: figures, names, dates, legal claims, and anything with a client's name on it.
4. What do we tell clients?
Decide once and write it down. The SBA suggests you "consider drafting a public statement that discloses how your small business uses AI." Some clients have decided for you in their contracts, so check them. Never overstate what AI does: announcing a crackdown on deceptive AI claims, the Federal Trade Commission's chair said "there is no AI exemption from the laws on the books" (FTC, September 25, 2024). Disclosure you choose reads as honesty. Disclosure a client discovers reads as a secret.
5. Who do I ask when I am not sure?
Name one person, not a committee. That person owns the page, sets a review date and keeps the record of who has been trained, which also covers you in the EU.
Here is the page for a hypothetical 20-person firm:
| Section | Hypothetical example line |
|---|---|
| Why we use AI | "To draft and research faster, so we spend more time with clients." |
| Tools | "Only our company AI workspace, signed in with your work email." |
| Never goes in | "Client files, personal details, passwords, unannounced numbers." |
| Checks | "Whoever sends it checks every figure, name and claim." |
| Clients | "We tell clients we use AI to help draft, and that a person reviews everything." |
| Questions and owner | "Ask Sam. Sam reviews this page every six months and keeps the training record." |
What does the EU AI Act's AI literacy duty mean for a small business?
If your business uses AI in the EU, you must already take measures to support your staff's AI literacy, and an internal record is enough to show it.
From the European Commission's AI Literacy Questions & Answers (last updated July 27, 2026):
- When: Article 4 of the AI Act "entered into application on 2 February 2025," and "the supervision and enforcement rules apply from 3 August 2026 onwards." National market surveillance authorities could impose penalties.
- Who: providers and deployers of AI systems. Asked whether a company whose employees use ChatGPT to write advertising text or translate must comply, the Commission answers: "Yes, they should be informed about the specific risks, for example hallucination."
- Proof: "There is no need for a certificate. Organisations can keep an internal record of trainings and/or other guiding initiatives."
- Reach: the Act applies "inside and outside the EU as long as the AI system is placed on the Union market, used in the Union or its use has an impact on people located in the EU." UK and US firms with EU customers should read that twice.
- What changed: the Digital Omnibus amendments to Article 4 entered into force in mid-July 2026. AI literacy remains an obligation for providers and deployers, but no specific or "sufficient" level is mandated.
For a small team, that means a short session on what AI gets wrong, the one page, and a spreadsheet of names and dates. My guide to AI training for small business teams covers what makes it stick.
The Mistake I See Most Often
The most common mistake is a policy that lists everything staff must not do and never says what they may do.
It often starts with a template borrowed from a large company: twelve pages of prohibitions, no named tool, no named person. Staff read it once, decide the safest move is never to ask, and the phones come back out. Lists of don'ts do not stop shadow AI. They hide it.
Write permission first. My Readiness Test puts it this way: "The Readiness Test is three questions an organization must be able to answer consistently, from the top to the front line, before it can call itself AI ready: What is AI for here? What may I do with it? Who decides when it goes wrong?" A policy is the written answer to the second and third. I have advised government bodies on AI, including the UK Department for Education, Dubai's Knowledge and Human Development Authority (KHDA) and the Ministry of Education in Kazakhstan. Whether the guidance is for a national system or a 15-person agency, the question underneath is the same: can the person at the front line tell what they are allowed to do? (Permission is one of the seven dimensions in my guide to how ready your business is for AI.)
What can you do this week?
You can have a working AI policy by Friday without a project team.
- Ask before you write. At your next team meeting, ask which AI tools people use for work, on which accounts, and promise nobody is in trouble for the answer.
- Pick one approved tool and set up work accounts, so nobody on your team is left in the 28%.
- Draft the One-Page Five in an hour. Hand it to two members of staff and ask them to mark every place they would still have to guess.
- Run a short session on what AI gets wrong, and record who attended.
- Put a review date in the diary six months out.
Not sure yet what AI is for in your business? Start with how a small business should start using AI.
Where to go next
If you want your leadership team agreed on these answers before anyone writes them down, that is what my AI strategy and governance work is built for. If you would rather see where you stand first, take the free Workplace AI Readiness Check: 21 questions, about eight minutes.
Sources and further reading
- Rise in 'Shadow AI' tools raising security concerns for UK organisations, Microsoft UK (research by Censuswide), October 13, 2025
- AI at Work Is Here. Now Comes the Hard Part (2024 Work Trend Index), Microsoft and LinkedIn, May 8, 2024
- AI Literacy - Questions & Answers, European Commission, last updated July 27, 2026
- Tackling misconceptions (response to the consultation series on generative AI), Information Commissioner's Office, September 4, 2025
- Guidance on AI and data protection, Information Commissioner's Office, last updated March 15, 2023 (under review)
- AI for small business, U.S. Small Business Administration, last updated February 14, 2025
- FTC Announces Crackdown on Deceptive AI Claims and Schemes, Federal Trade Commission, September 25, 2024
Dan Fitzpatrick is The AI Educator: a Forbes contributor and international keynote speaker who helps businesses and governments use AI well, safely and every day.


