Back to blog
IA para negociospolítica de IAAI policysmall business AIAI implementation

How to Write an AI Use Policy for Your Small Business (With Ours as the Working Example)

Luis D. González8 min readUpdated

TL;DR

An AI use policy for a small business has three sections: what you use AI for (specific tasks and tools), what stays human (judgment, relationships, accountability), and how you stay accountable (review, transparency, a path to a real person). Writing it takes about one page and answers the most important question any customer will ask: "Do you use AI?"

An AI use policy is not a compliance document you write to satisfy a regulator. It is a way of scaling your own judgment — turning the decisions you have already made (which tools, which tasks, how much oversight, what you tell customers) into a record your whole operation can act from consistently. Most small-business owners are already running an informal policy. The question is whether those decisions live in your head alone, or somewhere that actually holds you accountable.

Why bother — the case in one paragraph

Every week you make micro-decisions about AI: do I let it draft this email? Do I review this output before it goes out? Do I tell this client the proposal started as an AI draft? Those decisions add up to a practice whether you document them or not. Documenting them has two benefits: it stops you and your team from spending energy re-deciding the same questions, and it gives you a clear, honest answer when a customer asks. A written policy also sets the cultural norm for what the time AI saves is supposed to go toward — back into the relationship (the follow-up call, the personalized detail), not just into more output volume.

The three sections every good policy has

You do not need a legal team or a template service to write this. Three sections cover everything a small business needs.

1. What we use AI for

This is the specific, approved list: the tasks and the tools. Not "writing assistance" in the abstract — that is vague enough to mean anything and commit to nothing. Be concrete: "First-pass drafts of common customer inquiries (Claude)" or "Social caption variations from an approved brief (ChatGPT)" or "Summarizing meeting transcripts into action items (ChatGPT)." If you would not say the tool name out loud to a customer, include it here precisely — that specificity is what makes the section useful.

This section also tells new collaborators what is already in use — without a conversation. The policy does the onboarding.

2. What stays human

Every business that uses AI thoughtfully has work it does not hand to a tool — judgment calls that require real context, relationships where the human touch is the product, decisions that are hard to reverse, accountability that has to sit with a named person. For most service businesses that means: final decisions on pricing, conversations involving real complaints or conflict, and client-facing communication in emotionally sensitive situations. The point is not to be exhaustive — it is to be honest about where AI is not in the loop, and why.

3. How we stay accountable

This section has three parts: oversight (who reviews AI output before it reaches a customer, and how), transparency (how and when you disclose AI use), and consequence (what you do when something goes wrong).

On oversight: the practical standard for most small businesses is that any AI-generated content that leaves the building gets a human read first. Writing it down means you actually hold it.

On transparency: a simple, honest disclosure is enough. Something like "parts of this were drafted with AI assistance" in a footer, or "our first response is AI-assisted — a team member is available if you need them" in a chat window. Gugubrand publishes its AI policy openly — you can read it as a worked example of what concrete, honest disclosure looks like in practice.

On consequences: what is your process when AI output contains an error, or a customer objects to AI use they did not know about? Having a sentence on this is not pessimism — it is the difference between a policy and a wish list.

How to write yours — the four-step process

Reading about the framework is not the same as having a policy. Here is how to actually get there.

Step 1 — Reflect first. Before opening any AI tool, answer three questions in plain language: Which tasks do I confidently hand to AI — and with which specific tools? Which work will I always keep human, and why? What do my customers and team need to know? These notes are your raw material — more honest than anything a model will draft from a cold prompt.

Step 2 — Draft with AI using your notes. Paste your answers into the AI tool and ask it to organize them into the three sections. This is exactly the scaffolding task AI handles well. You will edit heavily.

Step 3 — Edit for truth and your own voice. Read every line: Is this actually true? Does this sound like how I run my business? Cut the aspirational, add what was missed. If a line says you always review outputs before they go out and that is not always true, change the practice or change the line.

Step 4 — Stress-test with one question. Imagine a customer asks, "Do you use AI?" Does your policy give you a clear, honest answer you could say out loud? If you hesitate, there is a gap. Keep the finished document to about one page.

Being the human in the loop

One thing worth saying plainly: being "the human in the loop" is not just about reviewing outputs before they ship. It is about deciding what problems AI should be solving in the first place.

AI handles the first-pass draft so you have more time to read it carefully and personalize it. AI handles the transcript summary so you can spend more time on what the client actually needs. The time it frees should go back into the human work — the handwritten note, the proactive check-in, the judgment call that requires knowing the customer. If AI is freeing up time that just fills with more AI output, the policy needs a section on that too.

The practical test is whether you can explain, in a sentence, what the AI is doing in any workflow. Not what model it is — but what the task is, and why you reviewed the result before it left your hands. If you can explain it, you are in the loop.

*This approach draws on the AI Fluency Framework developed by professors Rick Dakan (Ringling College of Art and Design) and Joseph Feller (University College Cork).*

For more on the framework behind deciding which tasks belong to AI and which stay human, see our post on the 4D framework for AI in your business.


What you can do today

  1. 1Open a notes app and answer the three reflection questions: which tasks do you confidently hand to AI, which do you always keep human, and what do your customers need to know. Write in plain language, not policy language — that comes later.
  2. 2Take those notes into an AI tool and ask it to draft a one-page policy organized into the three sections: what you use AI for, what stays human, and how you stay accountable. Edit every line for truth and voice before you save it.
  3. 3Read Gugubrand's published AI policy as a concrete example — not to copy it, but to see what honest, specific disclosure looks like from a real service business.

Frequently asked questions

What is an AI use policy for a small business?

An AI use policy is a short document — usually one page — that records three things: which tasks and tools your business uses AI for, which work stays exclusively human, and how your team and your customers can expect you to stay accountable for AI-assisted outputs. It is not a legal contract; it is a decision log that stops you and your team from relitigating the same judgment calls every week.

What should an AI policy include?

Three sections cover the essentials: (1) What you use AI for — specific, approved tasks and the actual tools (not "writing" in the abstract, but "first-pass drafts of common customer inquiries using Claude"). (2) What stays human — the work AI does not touch, and the reason why (judgment, relationships, irreversible decisions). (3) How you stay accountable — who reviews AI output before it reaches a customer, how you disclose AI use, and what happens when something goes wrong.

Do I have to tell my customers that I use AI?

In most contexts, yes — and the argument for doing it is practical, not just ethical. When customers discover AI use after the fact, they feel deceived even if nothing went wrong. When you disclose it upfront and pair it with a clear path to a human, most customers accept it readily. Your policy should define exactly how and when you disclose: a note in a footer, a line in your email signature, a mention in your intake form.

Do I need an AI policy if I am a solo operator?

Yes — arguably more than a team does. Solo operators make AI decisions constantly and informally: they decide what to hand to a tool, what to keep themselves, and what to tell clients, often in real time and under pressure. A one-page policy turns those decisions into a record you can act from consistently. It also prepares you for the day you hire someone or bring in a contractor — they inherit your standards from day one.

How often should I update my AI policy?

Review it when something meaningful changes: you start using a new tool in a significant way, you change what you disclose to customers, or an incident makes you rethink a boundary. For most small businesses, once or twice a year is enough. The goal is not a living document you update constantly — it is a stable record that reflects how you actually operate, which you revisit when your operation changes.

Want every AI tool to sound like your brand?

Find out in 60 seconds. The AI Brand Algorithm makes ChatGPT, Claude, Gemini and more sound exactly like you.

See if you’re a fit — 60 sec