Almost every small and mid-sized business now has staff using AI tools daily. Almost none of them have a written policy about it. The gap is closing — not through elaborate governance frameworks, but through a two-page document that fits on a whiteboard.
Here is the state of things at most SMBs right now. Staff are using ChatGPT, Claude, Copilot, and vertical-specific tools for daily tasks — drafting emails, summarizing meetings, coding, analyzing documents, preparing presentations. Leadership is aware in the abstract but does not have visibility into specifics. There is no policy. There is no inventory. There is often no vendor review. And in most cases there is a growing exposure that will surface as either a data leak, a compliance question, or an embarrassing content incident.
The solution is not an elaborate governance framework. It is a two-page written policy that defines what is permitted, what is not, and how the firm decides. Every SMB should have one. Almost none do. This is what a working version looks like and how to actually produce one.
Why every SMB needs a written AI use policy — even a short one
The counterargument runs like this: we are a small firm. We do not need bureaucracy. Everyone has common sense. Adding policy for the sake of policy slows us down. This reasoning is wrong for four specific reasons.
First, a written policy protects the firm when a staff member does something inadvisable. In the absence of policy, the firm is on the hook for whatever staff did with AI tools. With a policy, the firm has established a standard of expected behavior — which becomes a defense.
Second, a written policy protects staff. Right now, most staff at SMBs are guessing about what is acceptable AI use. They are asking themselves questions like: can I paste this client email into ChatGPT to help draft a response? Can I use AI to analyze this financial document? Should I disclose that I used AI to draft this proposal? Without a policy, they answer inconsistently, and the inconsistency is the risk. With a policy, they have clarity.
Third, a written policy is often the first thing a client, a partner, or a regulator asks about when AI comes up. The presence of a policy signals seriousness. The absence signals unawareness — which can be disqualifying in certain business relationships.
Fourth, writing the policy itself forces a conversation the firm needs to have anyway. What tools are we using? Who authorized them? What information is going into them? What are our disclosure obligations? The writing exercise surfaces answers that would otherwise remain undiscovered until they became problems.
The eight elements of an effective SMB AI use policy
A working two-page policy covers eight elements. Each in about a paragraph. The point is not comprehensiveness — the point is coverage of the decisions staff actually face, in language they can actually use.
Element 1 — Purpose and scope
A brief opening statement explaining why the policy exists and what it applies to. Who is covered (all staff, contractors, vendors), what AI tools are covered (essentially anything commonly recognized as AI), and what activities are covered (work-related use).
Element 2 — Approved AI tools
A list of AI tools that are explicitly approved for use by staff. This can be as simple as one or two tools that have been vetted, or a longer list if the firm has done broader review. The key is that the list is explicit and current.
Element 3 — Information handling
What information may or may not be shared with AI tools. Typical structure: general information (fine), non-sensitive business information (fine with approved tools), client information (only with tools that have appropriate contractual protections), sensitive personal or financial information (never with consumer AI tools). This element is the most important — it prevents the most common category of AI-related mistakes.
Element 4 — Review requirements
What AI-generated content requires review before it leaves the firm. Typical structure: client communications require review, external content (proposals, marketing, published pieces) requires review, internal drafts do not require review. The point is establishing where human judgment is non-negotiable.
Element 5 — Disclosure obligations
When AI involvement must be disclosed to clients, partners, or third parties. Most firms find that the appropriate baseline is disclosure when AI has materially shaped a deliverable, and no disclosure required for routine internal use. Industry-specific requirements may go beyond this baseline.
Element 6 — Approval of new AI tools
How new AI tools get added to the approved list. Typically: a designated owner (usually a partner or senior manager) reviews requests and approves or declines based on a short checklist. This prevents the accumulation of unreviewed tools while allowing the firm to adopt useful new capabilities as they emerge.
Element 7 — Reporting concerns
How staff report AI-related concerns — a suspected data exposure, a misuse pattern, a client question they don't know how to answer. Named person to contact, expectation of no retaliation for reports made in good faith.
Element 8 — Review and update cadence
A commitment to review the policy quarterly and update as the AI landscape evolves. The AI tool ecosystem moves faster than most policy documents can keep up with. Building in a review cadence prevents the policy from calcifying into irrelevance.
What the policy does not need to cover
Equally important is what the policy should not try to cover. A two-page policy that tries to be comprehensive stops being two pages and stops being useful.
The policy does not need to explain what AI is or how it works. Staff know. The policy does not need to speculate about future AI capabilities. That belongs in strategy documents, not policy. The policy does not need to prohibit uses that are already illegal — the firm's existing legal obligations already cover those. The policy does not need to describe technical implementation details of AI tools. That belongs in vendor documentation or internal knowledge bases. The policy does not need to substitute for common sense in individual situations — it is a framework, not a decision tree for every edge case.
The mental test for whether something belongs in the policy: does a staff member facing this situation tomorrow morning need this information to make a good decision? If yes, include it. If no, leave it out.
Common mistakes to avoid
Firms that get this wrong tend to make the same mistakes. Being aware of them makes them easier to avoid.
Over-restriction. The policy that says "no AI use without written approval" creates shadow use, because staff who need AI to do their work will use it and simply not tell leadership. Better to permit approved tools broadly and restrict data flow tightly.
Under-specification. The policy that says "use AI responsibly" without defining what responsible means leaves the decisions to individual staff — which is the state before the policy existed. Vagueness is not neutrality.
Copy-paste generic templates. Some firms adopt AI policies they found online without adapting them to the firm's actual situation. The policy that references your industry's language and your firm's actual tools is the one staff will follow.
Announce-and-forget. Publishing the policy and never referring to it again is nearly as bad as not having one. The policy needs to be referenced during onboarding, during quarterly reviews, and when tools are added or removed.
How to actually produce the policy
Getting from no policy to a working two-page policy is a two-week exercise, not a two-quarter project:
- Week 1, Days 1-2: Inventory current AI use across the firm. Ask staff, honestly, what they are using and for what.
- Week 1, Days 3-5: Draft the eight elements based on the inventory and the firm's specific situation.
- Week 2, Days 1-2: Review with leadership. Adjust based on their input and any legal counsel review.
- Week 2, Days 3-4: Finalize, format, and prepare for distribution.
- Week 2, Day 5: Distribute firm-wide. Include in onboarding for new hires going forward.
At the end of two weeks, the firm has a written AI use policy, a current inventory of AI tools in use, and a documented process for reviewing new tools. Not sophisticated governance — but real governance. And the gap between real governance and no governance is what matters most.