Most small businesses do not need a long AI policy. They need a short one that exists. Below is a complete AI use policy for a UK small business, written to be copied, pasted into a document with your company name at the top, and issued this week. Nine clauses, plain wording, nothing behind an email form. Four of them you must decide for yourself, and those are marked.
Last checked: October 7, 2026.
Why does a small business need the policy written down at all?
Because your staff are already using AI, and the question is only whether they are doing it inside rules you set or outside them. Office for National Statistics figures published on July 20, 2026 show around 35% of UK businesses with 10 or more employees reporting use of at least one AI technology in June 2026, up from around 12% when the series began, with 28% of micro businesses of 0 to 9 employees reporting the same. Large language models were the single most common application, at 18%.
That is adoption without instruction. In the businesses I work with, nobody has banned AI and nobody has explained it, so each person has quietly invented their own rule about what is acceptable to paste into a chat window. A written policy replaces nine private rules with one shared rule, and it takes an afternoon.
The test the policy has to pass is not legal. It is this one:
"The Monday Test is a single question to ask of any AI strategy before it is signed off: could a member of staff read it and know what to do differently on Monday morning?"
A policy that fails the Monday Test is a document that protects nobody. If you want the argument for having one at all, including whether your business is small enough to skip it, I have written separately on whether a small business needs an AI policy. This article is the document itself.
The template: a one-page AI use policy you can copy
Copy everything in the quoted blocks. Replace anything in square brackets. Keep the numbering, because people refer to clause numbers when they ask questions.
1. Scope
"This policy applies to everyone who works for [Company], including employees, directors, contractors, freelancers and temporary staff. It covers any use of an AI tool for [Company] work, whether the tool is one we pay for or a free one you use in your own browser, and whether you are on a company device or your own."
The free-tool-on-a-personal-device sentence is the one that matters. That is where most unapproved use actually happens, and a policy that only covers company accounts is a policy that misses it.
2. Approved tools
"You may use the following AI tools for [Company] work: [list them]. You may not use any other AI tool for work that involves customer information, staff information, supplier contracts, pricing, or anything we would not publish on our website. If you want to use a tool that is not on this list, ask [name] first. The list is reviewed on the first working day of each quarter."
3. What never goes into an AI tool
"Never enter the following into any AI tool, including approved ones, unless [name] has confirmed in writing that the tool is covered by a business agreement that permits it: customer names, contact details or account information; staff personal data, including anything about health, pay or performance; anything marked confidential by a client; login details or passwords; the text of signed contracts; and anything that would identify a named individual."
4. What you are encouraged to use AI for
"You are encouraged to use approved AI tools to draft, summarize, rewrite, translate, plan, brainstorm, explain, check your own writing and prepare for meetings. Using AI for these jobs is not cutting corners, and nobody at [Company] will be judged for using it well."
Most policies stop after the prohibitions. A policy that only says no teaches staff that AI is a risk to be avoided, and the practical result is that the careful people stop and the confident ones carry on. The permission clause is what makes the rest of the policy credible.
5. The human check before anything goes out
"AI output is a draft, never a final answer. Before anything produced with AI leaves [Company], a named person reads it in full and is responsible for it. That person is responsible for the content whether or not AI was used. If you cannot personally confirm that a fact, figure, quotation, legal statement or client detail is correct, remove it or check it at source before it goes out."
Before you accept "a human checks it" as a safeguard, run it through the question I put to leadership teams:
"The Loop Test is three questions I ask before accepting 'a human checks it' as an answer: Would that person notice a wrong result without being told to look for it? Would they notice in time to stop it mattering? And if they missed it, could the work be put back? Oversight that survives all three is a safeguard. Oversight that fails any of them is a signature."
6. Decisions about people
"An AI tool must not decide anything about a person on its own. This includes hiring, rejecting an application, promotion, pay, discipline, dismissal, rostering, and any decision about a customer's account, credit or eligibility. AI may help a person prepare, sort or summarize. The decision is made by a person who can explain it, and who can show what they considered."
This clause is doing legal work as well as ethical work. Section 80 of the Data (Use and Access) Act 2025 replaced Article 22 of the UK GDPR with a new framework for significant decisions taken with "no meaningful human involvement". Where such a decision produces a legal effect or a similarly significant effect for someone, the controller must put safeguards in place: information about the decision, a route to make representations, a route to obtain human intervention, and a route to contest it. The simplest way for a business of 20 people to stay clear of all of that is not to let software decide about people in the first place.
7. Telling customers
"[Choose one, see the decision table below.] We tell customers when AI has been used in work they receive, in the following cases: [list]. Where a client's own contract or policy requires disclosure, that comes first and you must check before the work starts."
8. Mistakes
"If an AI tool gets something wrong and it reaches a customer, or if you put something into a tool that this policy says should not go in, tell [name] the same day. Nobody will be disciplined for reporting an AI mistake promptly and honestly. The purpose of this clause is to let us correct the work and fix the rule, which we cannot do if we do not know."
A policy without an amnesty clause produces silence rather than compliance. If the only thing a member of staff can do after a mistake is conceal it, that is what will happen.
9. Questions, ownership and review
"[Name] owns this policy. Ask them anything, including questions you think are obvious. This policy is reviewed on [date, six months from issue] and whenever we add a tool to the approved list. Version [1.0], issued [date]."
Which four choices can nobody make for you?
These are the clauses where the right answer depends on your business rather than on the law, and where a downloaded template usually goes wrong by answering them for you.
| Choice | Option A | Option B | What decides it |
|---|---|---|---|
| Approved tools (clause 2) | A short named list: one assistant, one meeting tool | Any tool from an approved category, checked with the owner first | A short list is easier to govern and slower to adapt. Choose the short list unless your work genuinely varies by client |
| Client data (clause 3) | Nothing identifiable goes in, ever | Identifiable data permitted only in tools covered by a business agreement, listed by name | Option B needs someone to read the contract terms. If nobody will do that this month, choose A |
| Disclosure (clause 7) | Tell customers whenever AI materially shaped the work | Publish a general statement on your website, and tell customers only when they ask or when the contract requires | Your client contracts and your sector. Professional services firms should look hard at Option A |
| Who owns it (clause 9) | The owner or managing director | A named manager, with the owner signing off changes | Whoever will actually answer the questions on a Wednesday afternoon |
The verdict for most businesses under 50 people: Option A, Option A, Option B, and the owner. That combination is the one a small team can hold to without anybody needing to interpret it, and it can be loosened later once you can see how AI is really being used. The hardest clause to get right is disclosure, and I have set out the full argument on when to tell customers you use AI.
What does the law actually require of a UK small business here?
Less than most owners fear, and in a different place than they expect.
On personal data, the Information Commissioner's Office guidance on AI and data protection applies the ordinary UK GDPR principles to AI systems: a lawful basis, transparency, accuracy, fairness, and a data protection impact assessment where the processing is high risk. The guidance carries a last-updated date of March 15, 2023 and states that it is under review following the Data (Use and Access) Act, so treat the principles as settled and the detail as moving.
On AI literacy, Article 4 of the EU AI Act has applied since February 2, 2025 and reaches providers and deployers of AI systems. The European Commission's AI literacy questions and answers, last updated July 27, 2026, confirms that the duty is to take measures to support staff AI literacy appropriate to their knowledge and context, not to certify anyone or guarantee a level, and that after the Digital Omnibus the emphasis moved toward Commission and member state support rather than a prescriptive standard on organizations. A UK business is caught only where it places an AI system on the EU market or its output is used in the EU, which I have set out in full on what the EU AI Act means for a small business now.
Three practical consequences for the document above. Clause 3 is your data protection clause. Clause 6 is your automated decision-making clause. And the act of issuing the policy, with a named owner and a review date, is a large part of how a small business demonstrates the accountability the ICO expects, because for a business of this size there is rarely anything else written down.
What I Tell Business Owners
The policy is not the hard part. Every owner I work with can produce one in an afternoon, and many already have a draft sitting in a folder. The hard part is that a policy only changes behavior if people can remember it without reading it.
So when a leadership team asks me to review their AI policy, the first thing I do is not read the document. I ask three people who do not sit in that room whether they know what they are allowed to use AI for. If the answers do not match, the document is not a policy yet; it is a file. The fix is almost never more clauses. It is fewer clauses, said out loud in a team meeting, by the person named in clause 9.
The second thing I look for is whether anyone has written down what staff are encouraged to do. A policy made only of prohibitions reads as a warning, and the people most likely to obey a warning are the careful ones you least needed to warn.
What should you do this week?
- Copy the nine clauses into a document, put your company name in, and answer the four bracketed choices using the table above. Forty minutes.
- Name the person in clauses 2, 3, 8 and 9. One name throughout, not a committee.
- Write the approved tool list from what people are actually using, not from what you have paid for. If you do not know, ask, and promise in advance that nobody is in trouble. That conversation is the shadow AI problem solving itself.
- Read it out in your next team meeting, including clause 4. Ten minutes.
- Put the review date in the calendar before you issue it.
Where to go next
A policy tells your team what they may do. It does not tell you whether the rest of your business is ready for them to do it. If you want to see where the gaps are before you spend another quarter experimenting, the free Workplace AI Readiness Check scores seven dimensions in about eight minutes, and the seven dimensions of AI readiness explains what each one means.
If your team now has permission on paper but nobody has shown them how to use AI well on their own work, that gap is exactly what my AI training for business teams is built for. If the harder question is governance rather than skills, that is the AI strategy and governance work.
Sources and further reading
- Artificial intelligence in UK businesses: 2023 to 2026, Office for National Statistics, July 20, 2026 (reference period June 15 to 28, 2026)
- Data (Use and Access) Act 2025, section 80, UK Parliament, 2025
- Guidance on AI and data protection, Information Commissioner's Office, last updated March 15, 2023 (under review)
- AI literacy: questions and answers, European Commission, last updated July 27, 2026
Dan Fitzpatrick is The AI Educator: a Forbes contributor, international keynote speaker and bestselling author who helps businesses use AI well, safely and every day.



