Writing an AI Use Policy for Your Business
A written AI use policy does not need to be long or legalistic. A single page covering what staff can put into AI tools, which tools are approved, and who to ask before trying a new one covers most of what a small business needs.
Reading is great. Tracking makes it stick. Sign up for a free Dashboard to tick off tasks and see your Security Score.
Get my free Dashboard →
Cyber Nova AI helps you prepare for Cyber Essentials. It doesn't award or certify it. Follow the steps here to get ready, then apply for certification through an accredited Cyber Essentials body when you're set.
Why a short policy beats no policy
Most small businesses that use AI tools have no written policy at all, staff just use whatever seems helpful. A short, plain-English policy closes the biggest gaps: accidental data leaks, unapproved tools, and inconsistent practice across the team. Business owners often think a policy needs to be a formal legal document before it is worth having. A one-page policy that staff actually read and follow is far more useful than a comprehensive one that sits unread.
What to include
5 steps
How it goes wrong without one
4 steps
How to protect yourself
3 steps
Frequently asked questions
Does an AI use policy need to be legally binding?
It helps to reference it in your existing staff handbook, but the value comes from staff actually reading and following it, not from legal weight alone.
How often should we update the policy?
Every six months is a reasonable starting point, given how quickly AI tools change.
What if we only have one or two employees?
The same principles apply. Even a sole trader benefits from writing down which tools they use and what they will not put into them.
Track your AI safety progress. Free.
Create a free account to tick off tasks, see your Security Score improve, and know exactly what you've done and what's still to do.
Start your free security check