Automation
AI Acceptable Use Policy: A Free Template Small Businesses Can Actually Use
A ready-to-use AI acceptable use policy template for small businesses, plus what belongs in it, the data-leakage risks that make one necessary, and how it lines up with the NIST AI Risk Management Framework.
Somebody on your team pasted a client contract into ChatGPT last week to get a faster summary. Somebody else uploaded a spreadsheet of employee salaries to ask an AI tool to build a chart. Neither one thought twice about it, because nobody ever told them not to.
That is not a hypothetical. It is the default state of most small businesses right now. Employees have AI tools on their work laptops, in their browsers, in Microsoft 365, in their phones, and no one has drawn a line around what is safe to type into them. An AI acceptable use policy is that line. It is a short document that tells your team which tools are approved, what data can and cannot go into them, and what happens if the rule gets broken.
This article covers what belongs in that policy, the real risk it is protecting against, how it connects to the NIST AI Risk Management Framework, and a full template below that you can copy into a document today.
Why your business needs an AI acceptable use policy
The risk is not “AI.” The risk is what happens to whatever a person types into an AI tool once they hit enter.
Public AI tools process input on servers you do not control, under terms of service most employees have never read. Depending on the plan and the settings, that input can be stored, reviewed by the vendor, or in some cases used to train future versions of the model. Once client data, employee records, financial figures, or proprietary business information gets pasted into a prompt, you have lost the ability to control where that information goes. There is no way to pull it back.
This is not a reason to ban AI tools. Banning them does not work, and it does not match how people actually get their jobs done faster now. A person who cannot use an approved AI tool at work will often use an unapproved one on their personal phone instead, which is a worse outcome, not a safer one. The realistic goal is narrower: make sure the tools people already use are the right ones, and make sure everyone knows what data is off-limits before it becomes a problem instead of after.
A few specific risks a written policy addresses directly:
- Confidentiality and client data exposure. Contract terms, pricing, health information, financial records, anything under an NDA, any of it typed into a consumer AI tool can leave your control permanently.
- Intellectual property and ownership questions. Who owns AI-generated work product, and does using a public tool to draft it create a licensing or ownership issue with a client or partner? Most contracts were written before this question existed, which means most businesses have not checked.
- Accuracy and over-reliance. AI tools generate confident, fluent, sometimes wrong answers. A policy that requires human review before AI output reaches a client or a decision keeps a wrong answer from becoming a wrong decision.
- Regulatory and compliance exposure. Businesses handling CUI, HIPAA-covered data, or financial records under an audit requirement have specific rules about where that data can live. A public AI tool almost never meets those rules by default.
None of this requires a large IT department to fix. It requires a page that says, in plain language, what is approved and what is not, and a process for asking when something falls outside the list.
What belongs in an AI acceptable use policy
A usable policy covers six things. Skip any of them and you end up with a document that sounds thorough but does not actually change behavior.
Scope. Who does this apply to, and which tools does it cover? Say explicitly whether it includes AI features built into existing software (Copilot in Microsoft 365, Gemini in Google Workspace) as well as standalone tools like ChatGPT or Claude, because employees often do not think of the built-in ones as “AI tools” at all.
Approved and unapproved tools. A short, specific list. Free consumer accounts and business-tier accounts are not the same product and should not be treated the same in the policy.
Data classification rules. What can go into an approved AI tool, and what can never go into any AI tool regardless of tier. This is the section that actually prevents a leak, so it needs real examples, not just categories.
Human review requirements. Where AI-generated output needs a person to check it before it goes anywhere external: client communications, contracts, financial reports, anything published publicly.
Ownership and attribution. Who owns AI-assisted work product, and whether AI use needs to be disclosed to clients on specific types of deliverables.
Enforcement and reporting. What happens if the policy is violated, and more importantly, an easy way for someone to report “I think I pasted something I shouldn’t have” without fear of getting in trouble for asking. A policy people are afraid to admit breaking is a policy that does not catch problems until they are bigger.
The template
Copy this into a document, fill in the bracketed sections, and have your leadership team read it before it goes out. This is a starting template, not a finished legal document, and a licensed attorney should review the final version before you publish it company-wide, especially if you handle regulated data like CUI, PHI, or financial records under audit.
[Company Name] Artificial Intelligence Acceptable Use Policy
Effective date: [date] Applies to: All employees, contractors, and temporary staff with access to company systems or data
1. Purpose This policy governs the use of artificial intelligence (AI) tools, including generative AI chatbots, AI writing assistants, and AI features built into existing software, in connection with company business. It exists to protect client and company data, maintain accuracy in AI-assisted work, and set clear expectations for every employee.
2. Scope This policy applies to all AI tools used for company business, whether accessed through a standalone application (ChatGPT, Claude, Gemini, Copilot), a browser extension, or an AI feature built into approved software (Microsoft 365 Copilot, Google Workspace Gemini, CRM or helpdesk AI features). It applies on company devices and personal devices used for company work.
3. Approved tools
- [Tool name, tier/plan, and what it is approved for. Example: “Microsoft 365 Copilot (business tier), approved for internal drafting, summarization, and meeting notes”]
- [Tool name, tier/plan, approved use]
- [Tool name, tier/plan, approved use]
Free or consumer-tier accounts of any AI tool are not approved for company business unless specifically listed above with documented settings (chat history and training disabled). Employees may not use personal AI accounts for company work.
4. Data classification: what can and cannot go into an AI tool
Never enter into any AI tool, approved or not:
- Client names paired with contract terms, pricing, or confidential deal information
- Employee personal information: SSNs, salaries, health information, performance reviews
- Passwords, API keys, or any system credentials
- Any data covered by an NDA, a signed confidentiality agreement, or a compliance requirement (CUI, HIPAA-covered data, PCI data)
- Unreleased financial information or anything covered by insider-trading restrictions
- Source code or proprietary technical documentation, unless the specific tool has been approved for that use
Permitted in approved tools, with judgment:
- General drafting: emails, internal memos, marketing copy, job descriptions
- Summarizing publicly available or already-published information
- Brainstorming, outlining, and first-draft work with no client or employee identifying data
- Code assistance on non-proprietary, non-sensitive work, where covered by the tool’s approved use above
When in doubt, don’t paste it in. Ask [designated contact / role] first.
5. Human review requirement Any AI-generated content going to a client, published publicly, or used in a financial, legal, or compliance context must be reviewed and approved by a human before it goes out. AI output is a draft, not a finished deliverable, until a person has checked it for accuracy.
6. Ownership and disclosure Work product created with the help of an approved AI tool remains company property under the same terms as any other work product created by an employee. [Add specific language here if any client contracts require disclosure of AI use in deliverables. Check existing client agreements before finalizing this section.]
7. Reporting and enforcement If you are unsure whether something is safe to enter into an AI tool, ask [designated contact / role] before proceeding. If you believe you may have entered confidential or sensitive data into an AI tool, report it to [designated contact / role] immediately. Reporting a mistake quickly is not a violation of this policy; failing to report a known mistake is. Violations of this policy, including entering prohibited data into an unapproved tool, may result in [disciplinary process consistent with existing company policy].
8. Policy review This policy will be reviewed at least annually, and any time a new AI tool is adopted company-wide. Last reviewed: [date].
That template is intentionally short. A policy nobody reads protects nobody. If your business has more specific needs, government contract requirements, healthcare data, financial services compliance, build those requirements into section 4 with your compliance advisor rather than adding pages of general language nobody will get through.
How this maps to the NIST AI Risk Management Framework
If your business works with government contracts, larger enterprise clients, or an industry that expects a documented risk framework, it helps to know how a policy like this connects to NIST AI 100-1, the AI Risk Management Framework (AI RMF 1.0), published by the National Institute of Standards and Technology in January 2023. It is voluntary, not a law, but it is becoming a common reference point in vendor questionnaires and client due-diligence requests, and being able to point to it saves time in those reviews.
The framework is organized around four core functions:
- Govern. Establish the policies, roles, and accountability structure around AI use. Your acceptable use policy is a direct, tangible piece of the Govern function; it is the documented policy an assessor or client would expect to see.
- Map. Understand the context: what AI is actually used for in your business, by whom, and what could go wrong. Section 2 (scope) and section 4 (data classification) of the template above are your Map work, in plain language.
- Measure. Assess and track AI-related risks over time, rather than assuming a one-time policy covers a moving target. The annual review in section 8 and the incident reporting in section 7 give you a basic version of this.
- Manage. Respond to identified risks and make decisions about where AI use continues, changes, or stops. The enforcement section and the process for approving new tools cover this.
You do not need to run a formal NIST assessment to get value from the framework. Most small businesses get 80% of the benefit by building a policy that maps loosely to these four functions, the way the template above does, and revisiting it as new tools get added. If a client or an insurer specifically asks whether you follow the NIST AI RMF, having a policy that maps to Govern, Map, Measure, and Manage, even informally, is a real answer, not a scramble.
For the technology side of this, where AI tools actually get hosted and what data leaves your network versus stays on infrastructure you control, our Private AI Hosting page covers the option of running AI tools on infrastructure that never sends prompts to a third-party vendor at all. That is the higher-control answer for businesses handling CUI or other regulated data where a public AI tool is not an option regardless of the policy in place.
Rolling the policy out without it becoming shelfware
A written policy that sits in a shared drive and gets referenced once, at onboarding, does not change behavior. A few things make it stick:
Walk through it in a team meeting, not just an email. Five minutes of “here’s what changed and why” gets more retention than a document link nobody opens.
Give people real examples from your own business, not generic ones. “Don’t paste a client contract into ChatGPT” lands harder than “protect confidential information” as an abstract phrase.
Pair the policy with an approved-tool list people can actually find later. If the only place the tool list lives is inside a PDF from onboarding, nobody will go looking for it six months later when they’re deciding whether a new tool is okay to try.
Revisit it when you add a new tool, not just on the annual schedule. AI tools change fast, and a policy that only gets touched once a year will fall behind the tools your team is actually using.
If your team is looking for a starting point on which AI tools to actually use once the policy is in place, our AI Prompt Pack has ready-to-use prompts built around the kind of narrow, repeatable tasks this policy is meant to make safe, and our guide on where to actually start with AI automation covers the tasks worth automating first. If you’re comparing tools before deciding what belongs on your approved list, ChatGPT vs Claude vs Gemini for Business breaks down the practical differences.
An AI acceptable use policy is one piece of a bigger picture: whether your business has the controls, technology, and adoption practices in place to use AI safely at all. That is what our CTGA Framework measures directly, particularly the Controls and Adoption pillars this policy sits inside. If you want to see where your business actually stands before you write a single page, start with the Free IT Assessment.
Read more

Automation
AI Automation for Small Business in Hampton Roads: Where to Actually Start
AI automation for small business works best on narrow, repeatable tasks. See where business process automation pays off for Hampton Roads companies, where it does not, and how to start without a developer.
Cybersecurity
NIST 800-171 Checklist: The 14 Control Families and How Scoring Works
A working NIST 800-171 checklist covering all 14 control families, the SPRS scoring formula, Rev 2 vs Rev 3 changes, and where NIST SP 800-172 fits. Built for Hampton Roads defense subcontractors.
Cybersecurity
IT Disaster Recovery Plan Template (With RTO/RPO and Site Comparison)
A free IT disaster recovery plan template covering RTO, RPO, hot vs. warm vs. cold site recovery, testing cadence, and how it maps to NIST SP 800-34. Copy it and fill in your own numbers.
Frequently asked questions about Helix Stax managed IT services
If any employee has access to ChatGPT, Copilot, Gemini, or a similar tool, and most do by default on a work laptop, you already have AI use happening whether or not it is written down. A short written policy does not stop that use. It tells people what is safe to paste into these tools and what is not, which is the part that actually prevents a data leak.
It depends entirely on the settings and what gets typed into it. Consumer ChatGPT accounts can train on conversation content unless chat history is turned off, and free-tier terms give the vendor broader rights over your input than a business or enterprise plan does. The policy template below treats consumer-tier accounts as unapproved for anything beyond public, non-sensitive drafting.
NIST AI 100-1, the AI Risk Management Framework (AI RMF 1.0), is a voluntary framework published by the National Institute of Standards and Technology in January 2023. It is not a law and carries no penalty for non-adoption on its own, but it is increasingly referenced in vendor security questionnaires, cyber insurance applications, and client due-diligence requests, so businesses that can point to it tend to move faster through those reviews.
Usually yes, with a human reviewing the output before it goes out. The bigger risk with client-facing drafts is rarely the AI tool itself. It is what got pasted into the prompt to generate the draft, client names, contract terms, financial figures, that shouldn't have left your systems in the first place.