Most small businesses adopt AI tools before deciding what may be put into them. A single page, written once, prevents most of the problems that follow.
Short answer
Decide three things and write them down: which tools are approved, what categories of information may never be uploaded, and who to ask when it is unclear. One page. Everyone reads it. Revisit it twice a year.
What the policy has to answer
- Which tools are approved. A short list beats a ban nobody follows.
- What must never be uploaded. Client data covered by a confidentiality clause, personal data, credentials, unpublished financials.
- What is fine. Public information, your own marketing copy, anonymised examples.
- Who decides the grey cases. One named person.
- The review date. Terms change; so should the policy.
Check your client contracts first
Many service contracts restrict sharing client information with third-party processors. An AI vendor is a third-party processor. This is the clause that turns a productivity decision into a contractual problem, and it is usually easy to check.
Check the vendor terms too
The questions that matter: is input used for training, how long is it retained, and can you turn training use off? The answers differ between the free tier and the business tier of the same product, which is often the real reason to pay.
Keep it one page
A ten-page policy is a policy nobody reads, which is functionally the same as no policy. One page, plain language, on the wall.
Frequently asked questions
Do we need this if we only use free tools?
Especially then. Free consumer tiers are the most likely to use input for training.
Who should write it?
Whoever owns client relationships, with input from whoever understands the tools. It is a commercial document, not a technical one.
