Skip to content
← All articles

A Practical AI Use Policy for a Small Team

6 min read

A good AI policy for a small team fits on a single page and answers four questions everyone can act on: which tools are approved, what data must never go into them, who checks the output before a customer sees it, and when to stop and involve a person. If your policy is longer than that, people will skim it once and forget it. The point is not to sound careful. The point is to let your team use AI confidently without putting customer trust or your reputation at risk.

This guide walks through each part so you can write your own version in an afternoon. It is aimed at growing service businesses with a handful of staff, not a legal department.

Start with what you are actually deciding

An AI policy is a set of small permissions and limits. You are deciding what your team may do, with what tools, using what information, and with how much human checking. Everything else is detail. Keep the language plain enough that a new starter understands it on day one.

Write it as rules people can follow, not principles they have to interpret. “Do not paste customer records into public chatbots” is a rule. “Use AI responsibly” is a wish. The Information Commissioner’s Office is clear that your organisation stays accountable for personal data however it is processed, including through AI tools, so the burden sits with you rather than the software provider. You can read its overview in the ICO guidance on artificial intelligence.

List the tools people are allowed to use

Name the specific tools your team may use for work, and say what each is for. A short approved list beats a vague policy every time, because it removes the guesswork. If a tool is not on the list, the answer is ask first.

  • Approved for general drafting: the specific AI assistants your business pays for or has vetted.
  • Approved for internal notes only: tools you are happy to trial but not yet ready to put near customers.
  • Not approved: anything that has not been checked, and any free consumer tool where you cannot see how data is stored.

Say plainly whether free consumer versions are allowed. Many keep and reuse whatever is typed into them. The National Cyber Security Centre spells out this risk in its explainer on large language models and what the risk is. A paid business tier with clearer data terms is usually the safer default for anything work-related.

Draw a hard line around sensitive and customer data

This is the section that protects you most. Decide what may never be typed, pasted or uploaded into an AI tool, and make it unmissable. For most service businesses the no-go list includes customer names and contact details, health information, payment details, anything covered by a confidentiality agreement, and staff personal data.

Under UK GDPR you remain responsible for personal data even when a third-party tool does the processing, so treating a public chatbot as a safe place to think out loud is a genuine risk. The ICO sets out how data protection law applies to these tools in its guidance on AI and data protection. The NCSC also warns against entering sensitive or confidential information into public models in its note on AI and cyber security.

Give people a workable alternative rather than just a ban. Teach the team to anonymise: strip out the name, the address, the reference number, and ask the question in general terms. “Draft a polite reply to a customer whose delivery is late” needs no personal data at all.

Say who checks the output before it goes out

AI produces confident text that is sometimes wrong. That is not a flaw you can policy away, so your rule has to assume it. The principle is simple: a person is responsible for anything the business sends, publishes or acts on, whether or not AI helped write it.

Spell out the checking standard for different jobs:

  • Customer-facing replies: read every one before sending. Check facts, prices, dates and tone.
  • Public content and quotes: a second person checks anything with numbers, claims or commitments.
  • Anything legal, financial or medical: never send on AI’s word alone. It goes to whoever normally signs it off.

Name the person accountable for each type of output so “someone should have checked” never becomes “nobody did”. If you want a fuller routine for reviewing AI drafts, our piece on writing service content that AI answers can cite covers how to keep published material accurate and trustworthy.

Be clear about when to escalate

The most useful line in any AI policy is when to stop. Give people explicit triggers to hand a task to a human:

  • The tool is being asked for advice with legal, financial or health consequences.
  • A customer is upset, vulnerable, or the situation is sensitive.
  • The AI output contradicts what a colleague knows to be true.
  • Anyone is unsure whether data is safe to use.
  • The request falls outside anything the tool was approved for.

Escalation should feel normal, not like an admission of failure. The same logic applies to any AI answering enquiries for you: it should know its limits and pass the conversation over cleanly. We cover where that line sits in when an AI lead assistant should hand over to a human.

Keep it one page and revisit it

Write the whole thing as a single page a new starter can read in five minutes. Include the approved tools, the data rules, the checking standard, the escalation triggers, and one named owner of the policy. Date it. AI tools change quickly, so put a reminder in the diary to review it every few months and update the approved list as things change.

Then do the part most businesses skip: talk it through with the team. A policy that lives in a shared folder does nothing. A ten-minute conversation where everyone understands why the data rule exists is worth more than any document. Government guidance on AI adoption keeps returning to the same point, that skills and clear ground rules are what turn AI from a risk into a benefit, as set out in the AI Opportunities Action Plan.

Where Kilij fits

Kilij Digital is a UK AI agency that helps service businesses put AI to work with the guardrails built in. Pala, our AI lead-management tool, answers enquiries across WhatsApp, Instagram, email and your website, and hands the conversation to a person when it needs one. That handover rule is the same principle as your staff policy: AI does the fast, repeatable work, and a human stays responsible for the judgement calls. Get the policy right and your team gets the speed of AI on the everyday work while your customers still get careful, accountable answers.

Questions, answered.

What should a small-business AI policy actually contain? +

Four things: a short list of approved tools, a clear rule on what data must never go into them, a checking standard for who reviews AI output before it reaches a customer, and explicit triggers for when to escalate to a person. Keep it to a single page so people actually read and follow it.

Is it safe to put customer information into ChatGPT or similar tools? +

Treat it as unsafe by default. Under UK GDPR you stay responsible for personal data even when a third-party tool processes it, and the NCSC warns against entering sensitive or confidential information into public models. Anonymise your question instead: strip out names, addresses and reference numbers and ask in general terms.

Who is responsible if AI produces something wrong? +

Your business is. AI can draft, but a named person should be accountable for anything you send, publish or act on. Build that into the policy by stating who checks customer-facing replies, public content and anything legal, financial or medical before it goes out.

How often should we update our AI policy? +

Review it every few months. AI tools and their data terms change quickly, so keep the approved-tools list current and re-date the document at each review. Pair the update with a short team conversation so everyone understands any changes.

Do free AI tools count as approved tools? +

Only if you have checked them. Many free consumer versions keep and reuse whatever is typed into them, which makes them risky for work data. A paid business tier with clearer data terms is usually the safer default, and anything not on your approved list should require asking first.

See it on your enquiries.

Book a quick call and we'll show you how this would work for your business.