Cloud Peach AI

AI Policy for Business: What to Put in Yours (and What to Leave Out)

AI Policy for Business: What to Put in Yours (and What to Leave Out)

Your staff are already using AI. Someone on the sales team is pasting prospect emails into ChatGPT to draft replies. Someone in finance is asking a chatbot to tidy up a spreadsheet of customer invoices. Nobody asked permission, because nobody was told they needed to. An AI policy is how you close that gap: a short, plain-language document that tells people which tools they can use, what information must never go into them, and who to ask when they are unsure.

This guide is for owners and operations leads at small and mid-sized Canadian businesses who know they need one but do not want a 40-page legal document nobody reads. We will cover what belongs in a workable AI policy, what to leave out, how to roll it out so people actually follow it, and when writing one is not the best use of your time yet.

What an AI policy is (and what it is not)

An AI policy is a set of rules for how people in your organization use AI tools at work. At a small company it usually runs two to four pages. It answers practical questions: Can I use ChatGPT for this? Can I upload a client file to it? Do I need to tell the customer that a draft was AI-assisted? Who approves a new AI tool?

It is worth separating an AI policy from two things it often gets confused with:

  • An AI governance framework. Governance is the broader system: who owns AI decisions, how risk is assessed, how systems are monitored over time. The policy is the staff-facing piece of that system. If you want the bigger picture, our guide to building a practical AI governance framework covers it.
  • An AI strategy. Strategy is about where AI should create value for the business. A policy is about using it safely. You can, and often should, have a policy before you have a strategy, because the usage is already happening.

A policy is also not a technical control. Writing “do not paste customer data into public chatbots” does not stop anyone from doing it. It sets the expectation, gives you something to train against, and gives you a clear position if something goes wrong. Pair it with sensible technical settings where you can, but do not expect the document to do the work of a firewall.

Why a small business needs one now

The honest reason is not regulation. It is that the risk already exists and is invisible to you. The main exposures are:

  • Confidential and personal information leaving your control. When an employee pastes a customer’s details into a consumer AI tool, that information may be stored, reviewed, or used by the provider depending on the product and its settings. Under PIPEDA, your organization remains accountable for personal information it has collected, including when it is handed to a third party for processing. Quebec’s Law 25 adds its own obligations for businesses handling Quebec residents’ information.
  • Wrong answers presented as facts. Generative AI produces fluent, confident text that is sometimes simply wrong. If that text reaches a client unchecked (a quote, a policy explanation, a technical recommendation), the error is yours, not the tool’s.
  • Inconsistency. Without guidance, one person refuses to touch AI and another uses it for everything. Neither is a decision the business made.

The Office of the Privacy Commissioner of Canada has published principles for responsible, trustworthy and privacy-protective generative AI technologies. It is written for both developers and organizations using these tools, and it is a sensible reference when you draft the data-handling section of your policy.

What to put in your AI policy

A policy that works covers seven things. Keep each section short. If a section needs more than a few paragraphs, the rule is probably too complicated for people to remember.

1. Purpose and scope

One paragraph. Say why the policy exists (to let people use AI productively without putting clients, colleagues or the business at risk) and who it applies to: employees, contractors, and anyone else working with your data. Say that it covers AI features built into tools you already use, such as email, document editors and CRMs, not just standalone chatbots. That last point is the one people miss.

2. Approved tools

List the specific AI tools that are approved, and under which account type. “ChatGPT” is not specific enough. A business or enterprise plan with data-use controls configured is a very different thing from an employee’s personal free account. Name the tool, the plan, and whether it is approved for general use or only for particular tasks.

Also state the default for anything not on the list. For most small businesses, “not approved until reviewed” is the right default. It is simple and it forces the conversation.

3. Data rules: what can and cannot go in

This is the most important section and the one staff will actually refer back to. A three-tier approach is easy to remember:

  • Fine to use: public information, your own general writing, generic questions, content that is already on your website.
  • Approved tools only: internal documents, non-sensitive business information, anonymized data.
  • Never: personal information about clients or employees, health or financial details, passwords and credentials, anything covered by a confidentiality agreement, and client material you do not have permission to process this way.

Give two or three examples of each drawn from your own business. “Do not paste client intake forms into any AI tool” lands far better than “do not input personal information”.

If data residency matters to your clients (common in health, legal, financial services and public-sector supply chains), note which approved tools process data in Canada and which do not. Do not guess at this. Check each vendor’s documentation or ask them directly, and record the answer.

4. Human review and accountability

State plainly that the person using the tool is responsible for the output. Anything AI-assisted that goes to a client, gets published, or informs a decision must be reviewed by a person who understands the subject. That means checking facts, figures, names and anything that sounds authoritative.

If you use AI in any process that makes or supports decisions about people, such as screening job applicants, approving customers or setting prices, flag it here and require a named owner and a human in the loop. These are the uses where errors and bias do real harm, and where privacy law is most likely to apply. Quebec, for example, requires organizations to tell people when a decision about them is made exclusively by automated processing.

5. Disclosure

Decide when you tell clients or the public that AI was involved. Reasonable positions range from “we disclose when AI generated a substantial part of a deliverable” to “we disclose any customer-facing chatbot or automated response”. There is no single right answer. The point is that the business decides, rather than each employee deciding differently.

6. Approving new tools and uses

Describe a lightweight process: who to ask, what they will check (data handling terms, where data is stored, whether it trains on your inputs, cost, admin controls), and roughly how long it takes. If the process is slow or opaque, people will skip it and use the tool anyway. A one-page request form and a named person who replies within a week is enough for most small businesses.

7. Incidents and questions

Tell people what to do if they think they have put something into an AI tool that they should not have. The answer should be “tell this person straight away”, with a clear message that reporting quickly is expected and will not be punished. Early reporting is what lets you assess whether there is a privacy breach you need to act on. A policy that makes people afraid to admit mistakes guarantees you find out late.

What to leave out

Most AI policy templates online are too long. Common things to cut:

  • Blanket bans you will not enforce. “Employees may not use generative AI” pushes usage onto personal phones, where you have zero visibility. If you genuinely need a ban for a particular kind of work, make it narrow and explain why.
  • Lists of every AI risk ever discussed. Staff do not need a paragraph on existential risk. They need to know whether they can summarize a meeting transcript.
  • Legal language copied from a large-enterprise template. If a clause needs a lawyer to interpret it, your team will not follow it. Have a lawyer review the final policy if your risk warrants it, but write the first draft in plain English.
  • Tool-specific instructions that go out of date. Keep “how to use Tool X” guidance in a separate, easily updated document. The policy should hold the rules; the how-to guides can change monthly.

How to roll it out so people actually follow it

The document is the easy part. Adoption is where most policies fail.

Start by finding out what people already use

Before you write anything, ask your team, anonymously if that helps, which AI tools they use and for what. You will almost certainly find tools you did not know about. Writing the policy around real usage makes it credible. Writing it around imagined usage makes it irrelevant.

Give people a good approved option

A policy that only says no loses to convenience every time. If people are using a personal chatbot account to draft emails, the fix is usually to provide a properly configured business account for that tool and tell them to use that instead. Cost is real, but so is the cost of client data sitting in dozens of personal accounts.

Walk through it in person

A 30-minute team session with real examples from your business beats an email with a PDF attached. Show the three data tiers. Take questions. The questions will tell you which parts of the policy are unclear.

Review it on a schedule

AI tools change quickly, and so do their data terms. Put a review date in the policy itself, every six months is reasonable, and assign someone to own it. Also review it whenever you approve a significant new tool or start using AI in a customer-facing process.

If you want a structured reference for the wider risk side, the NIST AI Risk Management Framework is freely available and widely used. It is more than a small business needs day to day, but it is useful for checking you have not missed a category of risk.

When this is NOT worth doing (yet)

We would rather you spend your time well than write a document for its own sake. An AI policy is not the priority if:

  • You are a team of two or three who talk every day. A shared understanding and a short written note on what data never goes into AI tools is enough. Write the formal policy when you hire people you do not work beside daily.
  • You have no written privacy practices at all. If you do not yet know what personal information you hold, where it lives and who can access it, fix that first. An AI policy sits on top of basic privacy hygiene; it cannot replace it.
  • You are hoping the policy will fix a tool problem. If the real issue is that staff are using an unsuitable tool because there is no better option, buying and configuring a proper business tool will do more than any document.
  • You want a policy mainly to look compliant. A policy nobody reads can be worse than none, because it creates a false sense of control. If you are not going to explain it, enforce it and review it, spend the effort elsewhere.

For everyone else, especially businesses that handle client personal information and have more than a handful of staff, a short, practical policy is one of the cheapest risk reductions available. It is also usually the first step before any serious AI consulting or automation work, because it settles the ground rules before new tools arrive.

A simple starting outline

If you want to draft your own this week, use these headings and aim for one page per heading at most:

  1. Purpose and who this applies to
  2. Approved AI tools (name, plan, approved uses)
  3. What information can and cannot be used, with examples from our business
  4. Checking AI output and who is responsible
  5. When we tell clients AI was used
  6. How to request a new tool
  7. What to do if something goes wrong
  8. Policy owner and next review date

That outline, filled in honestly, will serve a 10- to 100-person business better than most templates. If you would like a second pair of eyes on it, or help connecting it to a wider AI governance approach, that is exactly the kind of practical governance work we help with.

Frequently Asked Questions

Does Canada have an AI law that applies to my business?+

Not an AI-specific one for private businesses at the time of writing. The proposed federal Artificial Intelligence and Data Act (part of Bill C-27) did not become law. What does apply is existing privacy law: PIPEDA federally, plus provincial laws such as Quebec’s Law 25. These cover how you collect and use personal information, including through AI tools. Check the current status before relying on this, as the rules are moving.

What should be included in an AI policy?+

At minimum: which AI tools are approved and under which accounts, what information can and cannot be entered into them, who is responsible for checking AI output, when you disclose AI use to clients, how to request a new tool, and what to do if something goes wrong. Add a named owner and a review date.

Do small businesses really need an AI policy?+

If you have more than a handful of staff and handle client personal information, yes. It is usually two to four pages and a short team session. For a two- or three-person team that works closely together, a brief written note on what data never goes into AI tools is often enough for now.

Can staff use a free personal ChatGPT account for work?+

Treat personal and free consumer accounts with caution. Their data-use settings are controlled by the individual, not the business, and you have no visibility into what has been entered. Most businesses are better off providing a business plan with data controls configured, and limiting personal accounts to public, non-sensitive information only.

Ready to Put AI to Work?

Book a free, no-pressure consultation. We’ll tell you where AI actually pays off – and when it doesn’t.

Book a Free Consultation ->

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top