AI Acceptable Use Policy for Small Business (2026 Template)
Every small business is now an AI-using business, whether the owner realizes it or not. Employees paste customer emails into ChatGPT to draft responses. Sales teams run prospect lists through Claude for research. Engineers use GitHub Copilot on production code. Marketing runs images through Midjourney. Without a written AI acceptable use policy (AI AUP), these tools go from productivity boosters to data-leak vectors, IP-attribution disputes, and compliance headaches.
This guide walks through what belongs in an AI AUP for a small business, which decisions the policy needs to make, common template language, and how to actually get employees to follow it.
Why a general AUP isn’t enough for AI
Most small businesses have a general acceptable use policy that covers email, web browsing, and software installation. AI tools break the assumptions in those policies. A general AUP that says “don’t upload company data to unauthorized services” leaves employees guessing whether ChatGPT is authorized, whether a company invoice pasted into Claude counts as “upload,” and whether summarizing a client contract in Perplexity is a data-handling incident.
AI-specific policy language settles those questions in advance so employees have a clear rule to follow and management has an enforceable standard when something goes wrong.
Data classification: what can go into which AI tool
The first decision every AI AUP must make: which data types are approved for which AI tools. A workable three-tier structure:
- Public data (marketing copy, published prices, publicly available research): can go into any AI tool including free public tiers of ChatGPT, Claude, Gemini.
- Internal data (internal memos, unpublished plans, employee names, non-sensitive internal docs): only in AI tools with an enterprise agreement and data-training opt-out (ChatGPT Enterprise/Team, Claude for Work, Gemini for Google Workspace with the appropriate controls).
- Confidential or regulated data (customer PII, PHI, payment info, trade secrets, source code, financial records, HR files): only in AI tools where a Business Associate Agreement (BAA) or equivalent contract explicitly covers the data type; often means self-hosted or specifically-certified enterprise instances.
The tier system is what makes the policy operational — employees don’t have to interpret abstract rules, they just check which tier their data falls into.
Approved and prohibited AI tools list
Every AI AUP should maintain a maintained (not one-time) list of specifically approved tools with their approved data tier. Example:
- ChatGPT Enterprise (Team subscription): Approved for Internal.
- ChatGPT Free/Plus: Approved for Public only.
- Claude for Work: Approved for Internal.
- GitHub Copilot Enterprise: Approved for source code (Internal tier).
- Any generative AI browser extension or plugin not on this list: NOT approved.
The list gets updated by whoever owns IT/security policy at the company — quarterly review minimum, plus ad-hoc updates whenever a new tool comes into use.
Prohibited uses of AI
Beyond data restrictions, spell out use cases that are prohibited regardless of tool:
- Generating content that will be published or sent to customers without human review and explicit approval.
- Impersonating a real person, especially a coworker or customer.
- Using AI to write or execute code that will run in production without a code review.
- Bypassing security controls (using AI to generate exploits, extract passwords, defeat filters).
- Making hiring, firing, or promotion decisions based on AI analysis.
- Providing legal, medical, or financial advice generated by AI without licensed-professional review.
Human review and disclosure requirements
Two related policy elements that catch most small businesses off guard:
Human review: AI output going to a customer, regulator, or public channel must be reviewed by a human before it goes out. This protects against hallucinations, factual errors, and inappropriate tone.
Disclosure: Depending on jurisdiction and industry, use of AI in customer-facing communication may require disclosure. Some states (California under SB 942, several EU jurisdictions) require AI-generated media to be labeled. The policy should default to “when in doubt, disclose.”
Confidentiality and IP
Two problems generative AI creates for IP:
Input becoming training data: Free tiers of public AI tools often use user prompts to train future models. Company confidential information pasted into a prompt can effectively become part of the vendor’s dataset. Enterprise tiers with training opt-out (or explicit no-training terms in a BAA) are the mitigation.
Output IP ambiguity: AI-generated content has unresolved copyright status. The U.S. Copyright Office has held that purely AI-generated work is not copyrightable; human-authored work with AI assistance may be. The AUP should require that AI-assisted work destined for copyright protection include meaningful human authorship.
Training, education, and onboarding
A policy nobody has read is a policy nobody follows. The AUP should be:
- Covered in onboarding for every new hire.
- Re-acknowledged annually (signed acknowledgment form).
- Referenced in security training that covers AI-specific scenarios (prompt injection, model-generated phishing, deepfake voice calls).
- Owned by a named person (typically the IT/security lead) who can answer employee questions and update the tool list.
Incident response for AI misuse
The AUP should describe what happens when a violation occurs:
- Employee reports (or IT detects) that customer data was pasted into an unauthorized AI tool.
- Immediate response: change credentials for any exposed system, revoke session tokens, document what was disclosed.
- Escalation to the incident response team (or per your incident response plan).
- If regulated data was involved (PII, PHI, PCI): notification obligations under state breach laws and applicable regulations.
- Disciplinary action: consistent with the general employee handbook — first-offense typically training/warning, repeat or willful violations to termination.
Vendor management for AI tools
Every AI tool the business uses is a third-party vendor. Standard vendor risk practices apply:
- Review the tool’s terms of service and data processing addendum before approval.
- Confirm the tool’s SOC 2 report, ISO 27001 certification, or equivalent security attestation.
- Confirm data residency and training opt-out settings.
- Sign a BAA if any PHI could be involved.
- Include the tool in the annual vendor review cycle.
Board-level oversight and metrics
For businesses large enough to have a board or advisory committee, AI use should be a standing agenda item:
- Approved tool inventory.
- Number of policy violations year-to-date.
- Any material AI-related incidents (data leak, embarrassing output, regulatory inquiry).
- Emerging tools requiring policy update.
Getting a policy in place fast
Small businesses that don’t have an AI AUP today should not spend six weeks drafting one from scratch. Use a template as the starting point and customize the approved-tools list and tier definitions to your business. Our editable AI Acceptable Use Policy template is a 12-section Word document — purpose, definitions, approved tools, acceptable use, prohibited use, data classification, human-oversight, IP, disclosure, security, compliance, enforcement — that most small businesses can customize in under an hour and have signed by every employee the same week.
How this fits with the rest of the security policy stack
An AI AUP is one document in a broader security policy set that includes a general AUP, a data classification policy, an incident response plan, a WISP (Written Information Security Program), and vendor management procedures. See our overview of how to build a small-business cybersecurity policy for how these pieces fit together, and our policy-building walkthrough for the ownership and review-cycle structure.
Key takeaways
- Every small business needs an AI-specific acceptable use policy — a general AUP doesn’t answer the AI-tool and data-tier questions employees actually face.
- Data classification (public/internal/confidential) plus an approved-tools list is the operational core of a workable AI AUP.
- Prohibit AI-generated customer content without human review, and disclose AI use where jurisdiction or industry requires.
- Free public AI tools often use prompts as training data — enterprise tiers with training opt-out are required for anything sensitive.
- Cover the policy in onboarding, re-acknowledge annually, and update the approved-tools list quarterly.
FAQ
Does my small business really need an AI policy if we only have 5 employees? Yes. The data-leak risk of a single employee pasting a client contract into a free AI tool is the same at 5 employees as at 500. A one-page policy that classifies data and lists approved tools protects the business at any size.
Can I copy someone else’s AI AUP verbatim? You can copy the structure, but the approved-tools list and data classifications must match YOUR business. What is approved at a marketing agency is not approved at a healthcare practice. Use a template as a starting point, then customize.
What if an employee already leaked data through ChatGPT before we had a policy? Address it as an incident under your existing incident response plan — change any exposed credentials, document the disclosure, notify affected parties if regulated data was involved. Then use it as the case study to accelerate getting the AI AUP in place.