A one page AI policy you can adopt this week.

This AI policy template gives a small business one page that says which tools are approved, what data never goes into a public AI tool, when a person has to check the output, and who signs off. Fill in the blanks and use it as it is.

What is in the policy.

Purpose, approved tools, what stays out of AI, who checks it, training, incidents and sign-off.

AI Use PolicyOne page, fill in the blanks

1. Purpose

This policy sets out how our business uses artificial intelligence tools at work: which tools are approved, what information never goes into them, and who checks the output before it reaches a customer or a decision gets made on it.

2. Approved tools

Only the tools listed below are approved for company work, including free trials and browser extensions. Ask the approver in section 3 before adding a new one.

  • Tool: Approved for:
  • Tool: Approved for:
  • Tool: Approved for:
  • Tool: Approved for:

3. Who approves new tools

(name or role) approves every new AI tool before anyone uses it for company work.

4. What never goes into a public AI tool

  • Customer names paired with financial, health or account information
  • Passwords, API keys or other access credentials
  • Anything covered by a signed non-disclosure or confidentiality agreement
  • Employee records: pay, performance reviews, disciplinary notes
  • Unreleased pricing, financials or legal documents

5. When a person must review the output

  • Anything that goes to a customer or the public, before it sends
  • Any number used in a quote, invoice or financial report
  • Any decision about hiring, pay or discipline
  • Anything AI wrote that states a fact about the business, a person or the law

6. Training

Everyone who uses an approved AI tool reads this policy and completes a short walkthrough with before the end of their first week. Training happens again whenever the tool list changes.

7. Incidents

If sensitive information goes into a tool that is not approved, or an AI tool produces something wrong that already went out, tell the same day. Fixing it quickly matters more than who made the mistake.

8. Sign-off

Name: Date: Signature:

Questions about the policy.

What should an AI policy include?

Which tools are approved, what data never goes into a public AI tool, when a person has to review the output before it goes out, who approves new tools, and what happens if something goes wrong. This template covers all five.

Do small businesses need one?

If anyone on the team uses ChatGPT, Copilot or a similar tool for work, yes. “63% of breached organizations had no AI governance policy.” IBM Cost of a Data Breach 2025. A written page is enough to close that gap.

What is the difference between an AI policy and an acceptable use policy?

An AI policy covers artificial intelligence tools specifically: what they can be used for and what stays out of them. An acceptable use policy is broader, covering company devices, internet and software in general. Most businesses need both, and this template can sit alongside an existing acceptable use policy or start one.

Start with a two-week review.

Fixed fee. You finish with a ranked plan of what to fix first, what it saves and what it protects.

Prefer email? Write to hello@satsumahq.com

One line is plenty. We will ask the rest on the call.