How to Write an AI Policy for Your Business
Most businesses already have employees using AI tools. The question is whether those employees are working inside a clear set of rules or figuring it out as they go.
A 2026 survey of more than 2,000 U.S. workers by Founder Reports found that 44 percent of employees say their employer has no clear AI policy. A separate SurveyMonkey study of 8,482 adults that same year found that among workers who use AI at work, 48 percent say no rules exist at all. At companies under 100 people, the gap is even wider.
An AI acceptable use policy is not a lengthy legal document. It's a practical document that tells your team which tools are approved, what data stays out of prompts, when a human needs to review AI output before it goes anywhere external, and what happens when the rules get broken. This is how to build one.
Why the Policy Gap Matters
The Founder Reports survey found that 89 percent of workers have used AI for work. Thirty-eight percent use it daily. Most of that usage is happening regardless of whether a business has addressed it. What varies is whether employees have guardrails.
Seventy-five percent of workers who use AI at work are self-taught, according to SurveyMonkey's Q1 2026 data. That means most employees developed their AI habits on personal accounts with default settings that may not be appropriate for business use. Several popular consumer AI tools train on user inputs by default. An employee who doesn't know that may be feeding client names, financial data, or proprietary processes into a model their employer doesn't control and didn't approve.
The downstream effect shows up in quality, too. The same Founder Reports survey found that 45 percent of workers have had to fix or redo a coworker's work that relied too heavily on AI. Seventy-seven percent say they review a coworker's output more skeptically when they know AI was used. The trust deficit is already there. A policy doesn't eliminate the problem. It creates a shared baseline so people know what "good" looks like.
What an AI Policy Covers
An AI policy is distinct from your general IT acceptable use policy, though they overlap. It addresses AI-specific questions: which tools are approved for work, what categories of data may never go into a prompt, when AI-assisted output requires human review before it goes out the door, and how your business handles AI-generated content in client-facing situations.
Think of it as the document that closes the gap between "we allow ChatGPT" and "here's how we use it responsibly."
Step 1: Inventory What Tools Are Already In Use
Before writing anything, find out what's actually happening. Survey your team, or ask managers to ask their direct reports. You will almost certainly find three to five tools in common use, plus a longer tail of tools individuals discovered on their own. This is sometimes called a shadow AI audit.
Common tools at most businesses in 2026: ChatGPT (personal and business plans), Claude, Gemini, Microsoft Copilot, Perplexity. The list usually surprises business owners.
For each tool, document what it's used for, what data it handles, and whether the business has an enterprise agreement or whether employees are using personal free accounts. That last point matters more than people realize. A personal ChatGPT account does not carry the same data protection terms as a business subscription with data retention turned off.
Step 2: Tier Your Tools by Data Sensitivity
One practical framework is a three-tier system. Assign every tool to a tier based on what data it's allowed to touch.
Tier 1 covers public or non-sensitive data only. Free-tier consumer accounts belong here. Drafting marketing copy, summarizing publicly available articles, and brainstorming are appropriate Tier 1 uses. Anything internal is not.
Tier 2 covers internal business data but excludes customer personally identifiable information and confidential client materials. Business-grade plans with data retention disabled typically live here. Drafting internal documents, summarizing meeting notes, and internal research tasks fit.
Tier 3 covers sensitive data including client records, financial data, healthcare information, or anything under an NDA. Only enterprise-grade deployments with appropriate data processing agreements should reach Tier 3. Azure OpenAI, on-premise language models, or approved enterprise instances with data isolation fall into this category.
Any tool not on an approved list requires explicit sign-off before use. Most businesses never define this, and that's exactly how client data ends up in the wrong place.
Step 3: Define What Data Cannot Go Into a Prompt
This is the most important section of the policy. Write it as a list, not a principle. "Sensitive information" is not a policy. "Client names, email addresses, and account numbers may not be entered into any Tier 1 or Tier 2 tool" is a policy.
Categories most businesses prohibit from Tier 1 and Tier 2 tools:
- Client names, email addresses, phone numbers, or account identifiers
- Proprietary financial data or unpublished internal results
- Contracts, NDAs, or legally privileged correspondence
- HR records, compensation data, or performance reviews
- Source code containing API keys, credentials, or proprietary algorithms
- Any information covered by a client confidentiality agreement
The goal is that an employee reading this list should be able to make a clear yes or no decision before they start typing a prompt.
Step 4: List What AI Cannot Be Used For
Prohibited uses define the hard stops regardless of tool tier. Common prohibitions at most businesses include:
- Generating content intended to deceive customers, partners, or vendors
- Using AI to bypass approval, HR, or security review processes
- Passing off AI-generated output as fully human-reviewed when it has not been
- Making consequential decisions about people (hiring, compensation, client eligibility) without human review
- Using personal consumer AI accounts for any business-classified data
- Feeding AI-generated code directly into production without review
A 60-person professional services firm that skips this section is exposed the moment someone uses a free AI account to draft a client deliverable and it goes out with a hallucinated figure in it.
Step 5: Require Human Review for External Output
Any AI-assisted output going to a client, partner, or the public needs a human review step before it leaves the building. The policy should say this clearly and define what review means. A spell-check pass does not count. The reviewer should verify facts, confirm that any numbers are accurate, check that citations exist and say what the document claims they say, and confirm that the output reflects what your business actually does or advises.
This is not about distrust of AI. It's about where accountability sits. AI tools do not take responsibility when a client report contains a wrong number. Your business does.
Step 6: Establish Governance and a Review Schedule
Name who owns the policy. At a 50-person business, this might be the owner, the IT manager, or a designated operations lead. Define how violations get reported and handled. Set a review cycle.
The AI landscape is moving fast enough that a policy written today may have meaningful gaps in six months. A quarterly review is realistic for businesses adopting new tools regularly. Annual at minimum for everyone else. The review catches new tools employees have started using, changes to vendor terms, and updated regulatory requirements.
BCG's 2026 AI at Work survey, covering nearly 12,000 respondents, found that half of all organizations lack clear governance for managing teams that involve both people and AI. Governance does not need to be complicated. It needs to exist and have someone's name on it.
What Implementation Actually Takes
Writing the policy is the straightforward part. Implementation involves:
- Getting every employee to read and acknowledge the policy
- Blocking unapproved tools at the network level where your IT infrastructure supports it
- Running a short training session so employees understand the rules and why they exist
- Setting up audit logging on any Tier 3 tools the business uses
For most businesses in the 25-to-200-person range, the implementation step is where things stall. Distributing and enforcing a policy requires someone who understands both the governance requirements and the technical controls. That's typically an IT function.
A policy that exists as a document no one has read is only marginally better than no policy at all.
Frequently Asked Questions
Does every business need an AI policy? If your employees use AI tools for work, yes. The question is not whether you need one. It's whether you want the rules to exist on paper or only in employees' heads.
How long does an AI policy need to be? A practical policy for a 50-to-150-person business can be four to six pages. Clarity matters more than length. A short, specific policy beats a comprehensive document no one reads.
What's the most common mistake businesses make with AI policies? Writing something too vague to enforce. "Use AI responsibly" is not a policy. The policy needs to name specific tools, specific data categories, and specific prohibited uses so employees can make clear decisions.
Should the AI policy cover AI tools built into existing software? Yes. Microsoft Copilot inside M365, AI assistants in customer service platforms, and similar embedded tools all need to be addressed. Employees often don't think of these as "using AI" in the same way as ChatGPT, but the data handling implications are the same.
How often should an AI policy be updated? At minimum, once a year. For businesses in regulated industries or those actively adopting new AI tools, a quarterly review is more appropriate. Build it into a standing calendar event so it actually happens.