Does a small business need an AI policy?
Yes, if anyone uses AI for work.
What a small firm's policy must cover, with a one-page template.
Yes, if anyone in the firm uses AI for work, and in most small firms someone already does.
You do not need a long document.
One page that says which tools staff may use, what must never go into them, and who checks the output covers most of the risk.
Why a small firm needs one
Without a rule, each person decides alone.
One pastes a client email into a personal account to tidy it up.
Another sends an AI-written letter without reading it.
Neither thinks of it as a risk, because nobody said it was one.
UK GDPR expects you to control how your staff handle personal data.
A written rule is how you show that you do.
It also gives you an answer when a client asks whether you use AI on their work, which more of them now do.
What it has to cover
- —Which tools staff may use, on accounts the firm controls rather than personal logins.
- —What must never go in, starting with passwords, bank details and client records in unapproved tools.
- —Who checks the output, because AI tools make confident mistakes.
- —What to do after a mistake, so people report one the same day instead of hiding it.
- —Who owns the policy, and when it gets reviewed.
A one-page template
This version suits a firm of six to twenty people whose staff use AI for drafting and for client emails.
Adapt it to your tools and your sector.
AI use policy
1. Why we have this policy. We use AI tools to save time on routine work.
This policy sets out which tools we use, what may go into them, and who checks what comes out, so we get the benefit without putting clients or the firm at risk.
2. Approved tools. Use only the AI tools listed by the firm, on accounts the firm controls.
Do not use a personal or free account for firm work.
Ask before trying a new tool, including AI features newly switched on in software we already use.
3. What must never go into an AI tool. Never enter passwords, bank or card details, or client information into a tool that is not on the approved list.
Only enter client personal information into an approved tool, and only what the task needs.
4. A person checks every output. AI tools make confident mistakes.
Check every figure, name, date and reference against the source before relying on it, and never send AI-written work to a client without reading it in full.
5. Writing to clients. You remain responsible for anything sent in your name.
Where AI drafts a message to a client, a person reviews and approves it before it is sent.
6. Telling clients. Our privacy notice explains that we use AI tools to process information.
Answer honestly if a client asks whether AI was used on their work.
7. Mistakes and concerns. If something goes into an AI tool that should not have, tell the owner the same day.
Reporting quickly matters more than the mistake.
8. Who is responsible. The owner is responsible for this policy, the approved tools list and answering questions about it.
9. Review. We review this policy every six months, and whenever we adopt a new AI tool.
If staff record meetings, screen candidates or handle health information, add a clause for each.
A regulated firm should add one stating that its professional rules still apply to AI-assisted work.
Before you adopt it
- —Write the approved tools list, with the account type for each.
- —Check each approved tool against the data protection questions: training, a processing agreement and where the data goes.
- —Update your privacy notice to mention AI tools.
- —Walk the team through it in ten minutes and ask what AI they already use.
Most firms find some.
The second step is where most firms find work to do.
Our guide to putting client information into ChatGPT walks through the checks for each tool.
Keep it alive
A policy written once and filed goes stale within months, because the tools change faster than the document.
Put the review date in the calendar, and revisit the policy whenever someone wants to try a new tool.
Ten minutes at a team meeting does more than a signed copy in a drawer.
This template is a starting point, not legal advice.
Adapt it to how your firm works and to any rules from your regulator or professional body.
Frequently asked questions
Does a small business legally need an AI policy?
No law names one.
But UK GDPR expects you to control how staff handle personal data.
A written rule shows that you do.
How long should an AI policy be?
One page for a small firm.
A longer policy goes unread, and an unread policy protects nobody.
What if staff already use their own ChatGPT accounts?
Most do.
Ask openly what they use, without blame, then move that work onto approved company accounts.
Keep reading
Get started
See it on your own business
Opafex is live in beta.
Tell us your first agent’s job and we’ll set you up.