Knowing how to write an AI usage policy has become as basic a piece of business admin as having a staff handbook or an expenses procedure. If your team is already pasting customer emails into ChatGPT or asking Claude to draft contracts, you have an AI policy in practice whether you have written one down or not. Tools such as conversational AI expense workflows are exactly the kind of new integration a policy should name explicitly. The only question is whether it is one you chose.
A workable AI usage policy for a small business does not need to run to twenty pages or read like a corporate legal document. Before finalising which tools to allow, it is worth reading how Claude now watermarks its output, since that changes what staff should disclose when publishing AI-assisted content. It needs to answer three questions clearly: which tools staff can use, what data they must never put into them, and who checks the output before it goes to a customer or regulator. Get those three right and most of the risk is covered.
Why a small business needs this in writing
Generative AI tools have moved from novelty to daily habit faster than almost any workplace technology before them. Tools such as the ChatGPT small business agent with free in-person training are accelerating that shift. Staff use them to draft emails, summarise meetings, write marketing copy and even do first-pass bookkeeping queries. Most of this happens with no oversight at all, a pattern often called “shadow AI”: tools adopted by individual employees that nobody in the business has approved, reviewed or even knows about.
The risk is not the technology itself. It is what happens when a member of staff pastes a client’s financial details, a job applicant’s CV, or unreleased pricing into a public AI tool to get a quicker answer. Once that information leaves your systems, you have effectively lost control of it, and under UK GDPR and the Data Protection Act 2018, you remain accountable for it regardless of which tool did the leaking, a risk that grows now tools like Claude watermark their AI output. Staff awareness is often the weak point, as research on staff scam recognition shows.
Research on AI adoption among UK small firms, including the Dell study on which SMEs get the most time back from AI, consistently finds that the businesses seeing real productivity gains are the ones with some structure around how AI is used, not just access to the tools. A policy is part of that structure.
What to include in an AI usage policy
A practical policy for a business with fewer than 50 staff typically covers seven areas. It is worth pairing that policy with practical guidance such as what Claude’s output watermarking means for firms publishing AI content and what ChatGPT’s small business agent actually offers. You do not need a lawyer to draft the first version, though it is worth having one check it once it is in use. For a sense of what can go wrong when AI runs unchecked, see how an autonomous AI hacked a small business.
- Approved tools list. Name the specific AI tools staff are allowed to use for work, such as those covered in our look at the ChatGPT small business agent, and note which ones are explicitly banned or require sign-off first.
- Data classification. Set out what can and cannot be entered into an AI tool: customer personal data, financial figures, health information, anything covered by a client NDA, and unpublished commercial plans should generally be off-limits for free or consumer-tier tools.
- Human review requirement. State that AI-generated content, whether it is a customer email, a contract clause or a social media post, must be checked by a person before it goes out. AI tools can produce fluent but factually wrong answers, and the business, not the tool, carries the liability.
- Disclosure rules. Decide whether customers need to be told when AI has been used, for example in customer service replies or marketing content, and be consistent about it.
- Intellectual property and confidentiality. Cover who owns AI-generated output and confirm that company or client confidential information must never be used to train a public model.
- Account and access control. Specify whether staff use personal AI accounts or company-provisioned ones, since business-tier accounts from providers such as OpenAI and Anthropic generally exclude your data from model training, while free consumer tiers often do not.
- Review date. AI tools and their terms change quickly. Set a six-monthly review as a minimum.
A worked example
Take a five-person bookkeeping practice. One team member uses ChatGPT to draft client emails and another has started using Claude for report summaries. Without a policy, there is nothing stopping either of them pasting a client’s bank statement into a free-tier chatbot to get a quick summary.
With a policy in place, the practice instead specifies that the paid business tier of a named tool is the only approved option, that client financial data must be anonymised or redacted before it goes anywhere near an AI tool, and that a partner reviews any AI-drafted client communication before it is sent. That is the whole policy for a business that size: a page, not a manual.
Firms in regulated professions have extra ground to cover. Law practices weighing up tools such as the AI features in Actionstep’s practice management software need to think about client privilege and confidentiality obligations specifically, not just general data protection, because the professional conduct rules go further than UK GDPR alone.
Watermarking, disclosure and AI-generated content
If your business publishes content, whether that is blog posts, product descriptions or social captions, your policy should address AI-generated text specifically. Some providers now embed markers in their output: Anthropic’s Claude, for instance, watermarks text it generates, which matters if you are publishing AI-assisted content and want to understand how detectable that is. Smart SME has covered what Claude’s watermarking means for small businesses publishing AI content in more detail, and it is worth reading before you finalise a disclosure policy.
The safest default for most small businesses is to treat AI as a drafting assistant, not a publisher: content goes through a human edit and fact-check before it appears under the company’s name, and the policy says so explicitly.
Tools that help enforce the policy, not just write it
A written policy is only as good as your ability to check it is being followed. A handful of tools exist specifically to help businesses see which AI tools staff are actually using and stop sensitive data leaving through them, though most are aimed at businesses with an IT function or a managed service provider rather than a five-person shop.
| Provider | What it does | Best suited to | UK pricing |
|---|---|---|---|
| Microsoft Purview | Data governance and labelling that can flag or block sensitive files before they reach tools like Copilot | Businesses already on Microsoft 365 who want built-in controls | Included in higher Microsoft 365 tiers; standalone compliance add-ons quoted per tenant |
| Acronis | Cyber protection and backup with data loss prevention that can flag sensitive files before they are shared externally, including to AI tools | Small firms wanting security and backup from one supplier rather than several | Quoted per workload via partners; no fixed published SME price list |
| Netskope | Cloud security platform that can see which AI apps staff are using and restrict uploads of flagged data | Growing businesses with a dedicated IT or security lead | Enterprise pricing, quote-based |
| Zscaler | Secure internet gateway with controls over which cloud and AI services traffic is allowed to reach | Businesses managing multiple sites or a remote workforce | Enterprise pricing, quote-based |
| MetaCompliance | UK-based policy management and staff awareness training, including sign-off tracking for policies like this one | Small and mid-sized businesses that want staff to formally acknowledge the policy | Quoted per user, typically scaled for SME headcounts |
| CoreView | Microsoft 365 management platform that shows which apps, including AI add-ins, are actually in use across the business | Firms with a larger Microsoft estate wanting visibility over shadow IT and shadow AI | Quote-based, typically priced per licensed user |
For most businesses under 20 staff, none of these will be necessary at first. A clear written policy, an approved tools list and a named person who reviews it twice a year will cover the basics. Tools like these become worth the cost once you have enough staff, or enough sensitive data, that you cannot rely on trust alone.
The security risk a policy does not cover
A usage policy governs how your own staff use AI. It does nothing to stop AI being used against you. Small businesses are increasingly targeted by attacks that use AI to write more convincing phishing emails or to probe systems automatically, a trend covered in Smart SME’s report on how an autonomous AI was used to hack a small business. Your AI usage policy and your cyber security measures need to sit alongside each other, not replace one another.
The UK’s National Cyber Security Centre publishes guidance on using AI tools securely, and the Information Commissioner’s Office has published guidance on AI and data protection that is worth reading before you finalise your policy’s data handling section, particularly if your business processes any special category data such as health or financial records.
Introducing the policy without staff ignoring it
A policy nobody reads is worse than no policy, because it creates a false sense that the risk is covered. The businesses that get this right treat the rollout the same way they would a health and safety change: a short briefing explaining why it exists, a signed acknowledgement from each staff member, and a real example of what could go wrong if the rules are not followed. Tools such as those from ChatGPT’s small business agent and its free training sessions can also be a useful moment to introduce the policy, since staff are already paying attention to how the tool should be used properly.
Do UK small businesses need a written AI policy by law?
There is no specific UK law requiring a standalone AI policy. However, UK GDPR and the Data Protection Act 2018 already require businesses to control how personal data is processed, and a business using AI tools without any policy will struggle to demonstrate that control if the ICO ever asks.
Can staff use ChatGPT or Claude with client data?
Generally, no, unless the business is on a business-tier account with a data processing agreement in place and the client’s contract permits it. Free consumer tiers of most AI tools may use conversations to improve their models, which is not appropriate for confidential client information.
Who owns the copyright in AI-generated content?
UK copyright law here is still developing, and the position depends on how much human creative input went into the final output. The safer commercial approach is to treat AI drafts as a starting point that a person edits and takes ownership of, rather than publishing raw AI output as finished work.
How often should the policy be reviewed?
Every six months as a minimum, or sooner if you adopt a significant new tool. AI providers change their terms of service, pricing and data handling practices more often than most software categories, so a policy written a year ago may already be out of date.
What happens if an employee breaches the policy?
Treat it the same way as any other confidentiality or IT policy breach, with a proportionate response set out in your staff handbook. The important step is having a clear process to follow, rather than deciding case by case, which can create inconsistency and grievances.
What to do next
- Draft a one-page policy covering approved tools, banned data types and the human review rule, using the seven areas above as a checklist.
- Get every member of staff to read and sign it, and keep a record of who has done so.
- Check whether your team’s current AI tool subscriptions are business tier or free consumer tier, and upgrade any that handle client or financial data.
- Set a calendar reminder to review the policy in six months, and sooner if you adopt a new AI tool in the meantime.





