RESPONSIBLE AI GOVERNANCE
AI Acceptable Use Policy for Small Businesses: What It Should Cover
An AI acceptable-use policy should make safe work easier. It should tell people which tools and tasks are approved, what information must stay out, where human judgment is required, and how to ask for help when the answer is not obvious.
Begin with purpose and scope
State why the organization permits AI and what the policy is meant to protect. Cover employees, contractors, interns, and others who use AI for organizational work. Include stand-alone generative AI tools as well as AI features embedded in office suites, meeting platforms, customer systems, design tools, browsers, and vendor products.
Define AI in plain language and acknowledge that the technology will change. The policy should apply to the use, purchase, connection, and deployment of AI—not only to typing prompts into a chatbot.
Publish an approved-tool process
Maintain a short list of approved tools and the allowed business uses for each. Before approval, review ownership, contract terms, data use, retention, training practices, security controls, access management, export capability, incident notification, and deletion options. Consumer and enterprise versions of the same product may handle organizational data differently.
Give employees a simple path to request a new tool or use case. If approval is too slow or unclear, unreviewed AI use will move into personal accounts and shadow workflows.
Define what information must not be entered
Connect AI rules to the organization’s data categories. Unless a specific tool and use are approved, prohibit the entry of passwords, security secrets, personal identifiers, protected health information, payment data, confidential client material, privileged communications, unreleased financial information, proprietary source material, and information restricted by contract or law.
Remind users that removing a name may not fully anonymize a record. Documents, transcripts, images, spreadsheets, and copied email threads can contain hidden or contextual sensitive information.
Require human review where consequences matter
AI output can be inaccurate, incomplete, biased, insecure, outdated, or falsely confident. Require a qualified person to review factual claims, calculations, citations, code, legal or policy language, customer communications, and decisions affecting people, money, eligibility, safety, rights, or access.
The reviewer should understand the subject and be accountable for the final work. “The AI produced it” is not a transfer of responsibility.
Identify prohibited and high-risk uses
Prohibit impersonation, deceptive media, harassment, discrimination, unauthorized surveillance, malicious code, credential collection, evasion of security controls, and any illegal activity. Require heightened review or explicit approval for employment decisions, profiling, automated recommendations, regulated activity, biometric processing, public-facing agents, and systems that can take actions without a person confirming them.
Protect accounts, connections, and automations
Use organization-controlled accounts, multifactor authentication, least-privilege access, and approved sign-in methods. Review browser extensions, plugins, application connections, and agents that can read email, files, calendars, customer records, or internal systems. An AI feature with broad connected access may create more risk than the prompt itself.
Define who may publish an AI assistant, connect it to business data, or allow it to take actions. Keep test and production environments separate when appropriate and preserve logs needed for oversight and investigation.
Address copyright, ownership, and attribution
Require users to respect intellectual-property, license, contractual, confidentiality, and attribution obligations. Do not assume AI-generated material is original, accurate, or available for unrestricted commercial use. Establish review standards for externally published text, images, audio, video, code, and research.
Organizations should obtain qualified legal guidance for the uses and jurisdictions that apply to them. This article is educational and is not legal advice.
Set rules for records and disclosure
Decide which prompts, outputs, approvals, and review records must be retained based on the use case. Do not keep sensitive prompt history merely because the tool allows it. Define when AI assistance should be disclosed to clients, donors, employees, regulators, or the public, especially when it materially shapes a deliverable or interaction.
Create an AI incident path
Tell users how to report accidental sensitive-data entry, harmful or discriminatory output, unauthorized tool use, account compromise, unexpected data exposure, deceptive content, or an AI system acting beyond its intended scope. The response process should include containment, evidence preservation, access review, legal and privacy escalation, vendor contact, notification analysis, and lessons learned.
Train by role and scenario
A signed policy is not sufficient. Demonstrate approved workflows and practice realistic decisions: summarizing a confidential meeting, drafting a donor message, analyzing employee data, generating code, uploading a contract, or using a meeting assistant. Managers, HR, legal, finance, communications, developers, and frontline workers may need different guidance.
Use a psychologically safe reporting culture. People should be able to ask whether a use is acceptable before taking a risk—and report mistakes quickly if something goes wrong.
Review the policy as the environment changes
Assign an owner and review at least annually, as well as after a significant incident, new regulation, major vendor change, or introduction of a higher-risk use. Maintain an inventory of approved tools and meaningful use cases. Periodically confirm that controls, contracts, integrations, and business purposes still match the approval.
A practical rollout sequence
Inventory current AI use, classify common data, identify an accountable owner, publish an initial approved-tool list, define prohibited information and uses, establish human-review rules, create a request and incident path, train with scenarios, collect acknowledgment, and schedule the first review. Start concise; add detail where real use reveals ambiguity.
Authoritative resources
NIST’s Generative AI Profile specifically recommends defining acceptable-use policies for generative AI interfaces and human-AI configurations. The NIST AI RMF Govern Playbook provides additional guidance on policies, roles, scope, and third-party AI.
RIGHT-SIZED AI GOVERNANCE
Turn AI use into clear, workable policy.
Cyber Valet helps small businesses and nonprofits assess AI use, establish policy, guide teams, and build a practical governance framework—nationwide and remotely.