SHAHEER.
Guides

How to write an AI policy for a small company

One page, four decisions, and the text to copy.

Book a 20-minute call How we work

Check it in ten seconds

What answering the same question costs

A policy people read is one page and answers four questions: what may go into a model, what never may, who approves a new tool, and what happens when output is wrong. The text is here, ready to copy.

Is it a fit?

A never list

The things that may not go into a model, written as a list.

One approver

A named person, and a free trial counts as a new tool.

A review date

A date with a name against it, not a cadence.

Start here. The full policy is further down this page, ready to copy, with no form.

Check the fit first

The plan

Do these six, in order

A time against each one and a way to tell it is finished.

  1. Copy the policy from this page

    Change the names in square brackets and leave the rest alone for now.

    10 minutes · Done when the document carries your company name and one owner

  2. Write your own never list

    Add what is specific to you: a client list, a regulated record, a repository.

    20 minutes · Done when somebody outside the team could follow it without asking

  3. Name the approver

    One person, and say plainly that a free trial counts as a new tool.

    5 minutes · Done when that person knows and has agreed to it

  4. List what is already in use

    Ask the team what they use, with no consequence for answering.

    30 minutes · Done when the list is longer than you expected and it is written down

  5. Say what checking means

    Facts, figures, names and quotes against a source, before anything leaves.

    15 minutes · Done when the check is a specific action rather than read it over

  6. Share it and set the review date

    One page, shared once, and a date in the calendar with a name against it.

    15 minutes · Done when the review date exists in a calendar somebody owns

The policy, ready to copy

Square brackets are the only parts you have to fill in. Nothing here is sent anywhere.

AI USE POLICY
[Company name]. Effective [date]. Owner: [name, role]. Review by: [date].

1. WHAT YOU MAY PUT INTO AN AI TOOL
Material we have already published. Your own drafts and notes. Public
information. Anything you would be comfortable reading aloud in a room
that included a competitor.

2. WHAT YOU MAY NEVER PUT INTO AN AI TOOL
Customer or patient records, including names alongside anything else.
Anything covered by a contract, an NDA or a confidentiality clause.
Passwords, API keys, tokens or access credentials.
Payment details, bank details, and government identifiers.
Health information about any identifiable person.
Source code we do not own, and source code we do own where the tool
retains inputs for training.
Employee records, salaries, performance notes and anything from a
disciplinary process.
If you are unsure, it belongs in this list until [name] says otherwise.

3. APPROVING A NEW TOOL
[Name] approves any AI tool before it is used for work. A free trial, a
personal account used for work, and a feature switched on inside a tool we
already pay for all count as a new tool. Approved tools today: [list].

4. WHEN THE OUTPUT IS WRONG
A named person checks anything that leaves this company or affects a
customer, before it goes. Checking means confirming facts, figures, names
and quotes against a source, not reading it for tone. The person who sends
it owns it. An AI tool is never the author of record.

5. WHEN SOMETHING GOES INTO THE WRONG PLACE
Tell [name] the same day. There is no penalty for reporting it quickly.
The only thing that makes it worse is time.

6. REVIEW
[Name] reviews this policy by [date] and updates the approved tool list.

What you get

What may go in

Public material, your own drafts, anything already published. The list is short, and it is the half most companies get right without being told.

What may never go in

Customer records, anything under an agreement, credentials, health or payment details, and code you do not own. This is the half that carries the risk.

Who approves a new tool

One named person, and a rule that a free trial still counts. Without it the policy governs a couple of them while the company is running nine.

What happens when it is wrong

A person checks anything that leaves the company. Name who, and name what they are checking for, because "review the output" is not a check.

Say it once, on one page

A policy that runs to twelve pages gets read once, at induction, by somebody who is not listening. One page gets read again later.

Review on a date, not a feeling

Put a date on it with a name against it. Tools change quarterly, and a policy nobody has revisited reads as a policy nobody means.

The four decisions

Most AI policies fail the same way. They are written to be defensible rather than followed, they run to a dozen pages, and the people who need them read the first paragraph and go back to work.

The approval question is the one companies skip, and it is why the policy governs a couple of them while nine are in use. Name one person, and say plainly that a free trial counts as a new tool.

Questions we get

Do we need one if we are ten people?

Yes, and at ten people it is easier. Without a policy people use whatever is on their phone, and none of that is visible to you.

Writing it costs an hour.

What if we want to ban AI entirely?

You can write that, and it will be used anyway on personal devices. A narrow permission with a clear never list gets followed. A ban gets worked around quietly.

Either way, say what happens when somebody does it.

Does this cover customer data inside a vendor tool?

Partly. The policy tells your people not to paste it. Whether your vendor may process it at all sits in your contract with that vendor.

Both need to be true, and only one of them is in your control.

Who should own the policy?

Whoever owns operations rather than whoever owns technology, because it is a question about how work gets done.

One name, on the document.

The policy changes shape depending on which you buy. ChatGPT Enterprise or custom AI.

More in the guides and every answer in one place.

Other engagements
AI strategy and rollout AI agent development AI chatbot development Process automation AI benchmarking Business systems integration Technology consulting
Where people hand this over

Most of this is doable in house.

AI strategy and rollout Internal audit Legal operations AI benchmarking Business documents Technology consulting

Read next

What to check before the policy matters, how to tell the tools apart, and who ends up owning the rollout.

Who does the work

Shaheer leads the work, with engineers, writers, filers and analysts behind him. C-suite operations for a San Francisco AI company, Six Sigma on the process side, Anthropic certified on the Model Context Protocol, ten years across eight industries. See what we have built

What is getting in your way?

We reply within one business day.