AI Use Policy for Small Businesses: What to Include (Plus Template Language)

Your employees are already using AI at work. Here's what an employee AI use policy needs to cover, why bans backfire, and copy-and-paste language to start from.


Right now, someone on your team has a browser tab open to an AI chatbot.

They're not doing anything malicious. They're drafting a client email, cleaning up a proposal, summarizing a long thread they didn't have time to read. It's making them faster, and they're probably not going to mention it to you.

That's the actual situation in most small businesses in 2026. Not "should we allow AI," but "we already do, we just haven't decided anything about it."

An AI use policy isn't about whether to permit the technology. It's about whether you have any visibility into what's happening with your company's information, and whether your team knows where the lines are before someone crosses one.

Why "just don't use it" doesn't work

The instinct for a lot of owners is to ban it outright. It feels like the safe choice. It isn't.

A ban doesn't stop usage. It stops disclosure. People who find a tool genuinely useful don't abandon it because of a memo. They stop mentioning it. So you end up with the same data exposure you had before, plus you've lost the ability to see it, correct it, or train anyone on doing it well.

There's a second cost. A blanket ban tells a capable employee that your company would rather they work slower. That's a strange message to send in a tight labor market, and it's the kind of thing that shows up in exit interviews.

The workable position is narrower and more useful: approved tools, defined limits, human accountability. That's what the rest of this post covers.

The seven things your policy has to answer

1. Which tools are approved

Name them. Not "AI tools generally." The actual products your company has vetted and, ideally, pays for.

This matters more than it sounds like it does. Consumer free tiers and paid business tiers of the same product often handle your data differently. The free version may retain inputs and use them to improve the underlying model. The business version typically doesn't. If your policy says "you may use AI," employees will reasonably assume the free account they already have is fine.

Include a path for requesting a new tool, and name who approves it. Without that, your approved list goes stale in a month and people quietly work around it.

2. What data can never go into a prompt

This is the section that prevents the incident you'd actually lose sleep over.

Be specific and be absolute:

  • Client or customer information of any kind, including names
  • Employee personal information, including Social Security numbers, addresses, dates of birth
  • Compensation and salary data
  • Health information, medical notes, accommodation requests
  • Anything covered by an NDA or confidentiality agreement
  • Login credentials, API keys, financial account details
  • Unreleased business information such as pricing strategy, acquisitions, or layoffs

Then give people the workaround, because a rule with no alternative gets broken by well-meaning people under deadline pressure. Teach anonymization: strip names, replace specifics with placeholders, describe the situation rather than pasting the record. "Draft a response to a client who is 60 days late on an invoice" gets the same output as pasting the actual account, with none of the exposure.

3. Human review is mandatory

Write this as a hard rule: AI output is a draft. A person is responsible for what goes out the door.

Whoever sends it owns it. Not the tool, not the vendor, not "the AI said so." That framing has to be explicit, because the failure mode isn't people intentionally passing off bad work. It's the plausible-sounding paragraph nobody thought to check. AI systems produce confident, fluent, entirely fabricated details: citations that don't exist, figures that were never real, policies your company never had.

For anything client-facing, legal, or financial, require verification of every factual claim before it goes out.

4. When clients get told

Decide your disclosure position before a client asks you about it.

There's no universal rule here, and reasonable businesses land in different places. What's not defensible is having no position and improvising when a client raises it. A workable middle ground for most service businesses: AI used to draft, edit, or research internally doesn't require disclosure; AI used to generate a deliverable the client believes was human-produced does.

Also check your contracts. Some client agreements and government contracts now include AI restrictions or disclosure requirements. Those override whatever your internal policy says.

5. Where AI can and can't touch people decisions

This is where a small business is most likely to create a real legal problem, and where most owners have no idea there's exposure.

The line worth drawing isn't whether AI is involved. It's who authored the work and who owns the outcome.

Prohibit, without exception:

  • Screening, ranking, or scoring job applicants
  • Making or recommending hiring decisions
  • Any final decision produced by a tool without human review
  • Determining discipline, promotion, compensation, or termination
  • Monitoring employees without telling them
  • Generating anything discriminatory, harassing, or retaliatory

Allowed, with human authorship:

  • Drafting a performance review from a manager's own documented observations, where the manager edits it, verifies the specifics, and signs it
  • Turning meeting notes into a written summary
  • Drafting job descriptions, offer letters, and policy language
  • Summarizing your own data so you can see what's happening on your team

The difference is real. A manager who supplies the substance, checks the details, and puts their name on the result has authored that review. A manager who types "write a performance review for someone who's been late a lot" and sends whatever comes back has not, and that gap will be obvious to anyone who reads it later.

The next section explains why the applicant screening items carry weight beyond ordinary caution.

6. Who owns the output

Short section, worth including. State that work product created with AI assistance during employment belongs to the company, same as any other work product.

Flag the wrinkle: purely AI-generated material may not be copyrightable in the U.S. If your business produces content where ownership matters, such as marketing assets, published work, or anything licensed, that's worth a conversation with counsel rather than an assumption.

7. What happens when someone violates it

A policy with no consequence is a suggestion. Tie violations to your existing progressive discipline process, and be clear that entering protected data into an unapproved tool is treated as a data security incident, not a paperwork slip.

Include a reporting path. If someone pastes client data into a chatbot at 11pm and realizes it an hour later, you want them telling you the next morning, not hoping nobody notices. Make self-reporting explicitly safer than concealment.


The legal exposure most small businesses miss

Here's the part that surprises owners: there is no federal law specifically governing AI in employment, but Title VII, the ADA, and the ADEA apply the same whether a decision was made by a person or an algorithm.

The federal posture has actually gotten quieter. The EEOC removed its AI employment guidance from its website in January 2025, and a 2025 executive order directed federal agencies to deprioritize enforcement of disparate impact liability. That is not the same as the underlying discrimination statutes going away. They're unchanged, and private plaintiffs still bring claims under them.

The activity has moved to the states, and it's genuinely messy:

  • Illinois. HB 3773 took effect January 1, 2026, amending the Illinois Human Rights Act to prohibit employers from using AI that has a discriminatory effect based on protected class across the full employment life cycle, from recruitment through termination. It also requires employers to notify applicants and employees when AI is used in hiring and other employment decisions.
  • California. Civil Rights Council regulations covering employers' use of AI took effect October 1, 2025, making bias testing (or its absence) relevant to discrimination claims and imposing extended recordkeeping for automated-decision system data. Records generated or used by automated decision systems must be kept for at least four years, and employers can't shift blame to a vendor whose tool discriminates. Separate rules on automated decision-making technology arrive January 1, 2027.
  • Colorado. Worth flagging because a lot of articles still online are wrong about this. Governor Polis signed SB 189 on May 14, 2026, which revised the state's original AI law, pushed the effective date from June 30, 2026 to January 1, 2027, and significantly scaled back the requirements, dropping the risk management program and impact assessment obligations in favor of a narrower disclosure and transparency approach.
  • New York City. Local Law 144 imposes bias audit, notice, and related obligations on employers using automated employment decision tools.
  • Texas. HB 149, the Responsible Artificial Intelligence Governance Act, took effect January 1, 2026 as a broad technology law covering data protection, transparency, and ethical use across industries.

Why this matters if you're a 30-person company in Florida. You might read that list and conclude none of it touches you. Often that's right. Many of these laws have jurisdictional or size triggers.

The trap is remote hiring. If you post a remote role and an applicant in Illinois applies, you may have pulled yourself into an Illinois requirement. Same with a remote employee you hired in California. Small businesses now recruit across state lines routinely and almost never map their legal exposure to match.

And the vendor question is live. In the closely watched Mobley v. Workday case, a federal court in California authorized notice to potential class members in February 2026 over allegations that AI-driven screening software filtered out applicants based on age, race, and disability. If you use an applicant tracking system, a resume screener, or an interview scoring tool, you are relying on someone else's algorithm, and "the software did it" is not much of a defense.

For most small businesses without dedicated HR, the practical answer is narrow and easy to hold: keep AI out of applicant screening entirely, and never let a tool make the call on a person. Drafting, summarizing, and formatting are fine, because a human is still authoring and signing the result. Don't use it to decide who gets the job. That single rule removes the large majority of your exposure.

This is general guidance, not legal advice. State AI law is moving quickly, and specific obligations depend on where your employees and applicants are located.


Template language to start from

Adapt this to your business. It's a starting point, not a finished policy.

Artificial Intelligence Use Policy

Purpose. This policy governs employee use of artificial intelligence tools in connection with Company business. It applies to all employees, contractors, and interns.

Approved tools. Employees may use only AI tools on the Company's approved list, accessed through Company-provided accounts. Personal AI accounts may not be used for Company work. To request a new tool, submit a request to [ROLE] before using it.

Prohibited data. Employees may never enter the following into any AI tool: client or customer information; employee personal information including Social Security numbers and dates of birth; compensation data; health or medical information; anything subject to a confidentiality agreement; passwords, credentials, or financial account information; or unreleased business information. When in doubt, remove identifying details or ask [ROLE] first.

Human review. AI output is a draft. The employee who submits, sends, or publishes the work is responsible for its accuracy and quality. All factual claims, figures, citations, and legal or financial statements must be independently verified before use.

Employment decisions. AI tools may not be used to screen, rank, or score applicants, to make or recommend hiring decisions, or to determine discipline, promotion, compensation, or termination. AI may be used to draft documents such as performance reviews and job descriptions, provided the responsible manager supplies the substance, verifies the content, edits it, and signs it. Human judgment governs all employment decisions.

Client disclosure. [Insert your position.] Employees must review applicable client agreements for AI-related restrictions before using AI on that client's work.

Ownership. Work product created with AI assistance in the course of employment is the property of the Company.

Reporting. Employees who believe protected information may have been entered into an AI tool must report it to [ROLE] immediately. Prompt self-reporting will be considered favorably.

Violations. Violations may result in disciplinary action up to and including termination.

Changes. This policy will be reviewed periodically as tools and laws evolve.


The part people skip

A policy nobody signed is a document, not a protection.

If a dispute ever arises, whether a client complaint, an agency charge, or a termination someone contests, the question won't be whether you had a policy. It'll be whether you can show the employee received it, read it, and acknowledged it on a specific date.

That means tracked acknowledgements, a record of which version each person signed, and a re-acknowledgement process when you update it. AI tools change fast enough that this policy will need revision more often than your dress code does.

If you're managing that in a folder of signed PDFs, you already know how that ends.


Human Solutions+ gives small businesses the handbook, the policies, and the acknowledgement tracking without the HR department. Join the waitlist →


Related reading

  • The Complete Guide to Employee Handbooks for Small Businesses (pillar)
  • Social Media Policy: What Small Businesses Need to Include
  • Attendance Policy Essentials
  • PTO Policy: Building One That Works
Previous
Previous

How to Write a Social Media Policy for Your Employee Handbook

Next
Next

How to Write a PTO Policy for Your Employee Handbook