Quick answer
An AI usage policy is a short document that answers three questions: which tools your team may use, what may go into them, and who approves an exception. It does not need to be comprehensive to be effective — a two-page policy people actually read beats a thirty-page one nobody opens. The job it does is removing guesswork before someone pastes a client contract into a chatbot at 11pm.
The seven sections every policy needs
- Scope. Who it covers (employees, contractors, interns), and whether it applies on personal devices.
- Approved tools list. Named tools with the plan tier you have approved — not "AI tools" generically. A list that says "ChatGPT, Claude, and Microsoft Copilot on work accounts" is actionable; "approved AI tools" is not.
- Data rules. What may never be entered: credentials and API keys, client personal data, unpublished contracts, source code under NDA, and anything in a regulated category (health, financial, legal).
- Account rules. Work data goes in work accounts. Personal subscriptions used for work are the most common quiet violation — and the hardest to audit.
- Output rules. A human reviews anything client-facing before it leaves the building. Facts, names, numbers, and citations get verified against a primary source.
- Approval path. One named person or role who decides on new tools, and a simple way to request one. Without this, people don't ask — they just sign up.
- Owner and review date. A policy with no review date is already stale. Put a calendar entry for a quarterly 15-minute look.
A three-tier allow list
The most useful structure for a small team is three tiers, not a banned/allowed binary:
- Tier 1 — allowed: general assistants on public or non-sensitive material: drafting, summarizing a public article, brainstorming, rewriting your own writing.
- Tier 2 — allowed with review: client-facing drafts, analysis of internal (non-regulated) documents, and anything that will be published. Requires a named human reviewer before it goes out.
- Tier 3 — not allowed without written approval: regulated data, identifiable customer records, contract language, credentials, and anything covered by a confidentiality clause — unless the tool has a business agreement with data controls your team has actually confirmed.
The tiers matter because a flat ban produces the worst outcome: people use the tools anyway and stop telling you. A graduated list keeps the conversation inside the policy instead of outside it.
The data question, in practice
Most policies live or die on this paragraph. Three things are worth writing down explicitly:
- Consumer tiers are not business tiers. Data-use and training defaults often differ between the free/individual plan and the business plan. Check the current terms for the exact tier you are paying for.
- Many vendors offer training opt-outs and admin controls — but defaults vary by product and change over time. Verify on the vendor's official page for your tier rather than trusting an old article.
- A vendor's security or compliance page is not your compliance review. It describes their controls, not your obligations. Deployments in regulated industries still need your own legal, privacy, and IT sign-off.
Our guide to whether AI tools are safe for business data walks through training policies, retention, and the questions worth asking vendors.
Where the tools fit into the policy
The policy should name tools your team plausibly already wants, so the answer is documented rather than improvised. Four common patterns:
- Microsoft Copilot — drafts inside Word, Excel, and Outlook, and Microsoft states tenant data is not used to train models under its enterprise data protection. Confirm that applies to the licence you actually buy, and whether your tenant is configured to use it.
- ChatGPT and Claude — strong general assistants. Data-use defaults and admin controls differ by plan; the business tiers exist precisely for this reason.
- Notion AI — answers questions across your own workspace, which also means anything sloppily stored in your wiki becomes answerable.
- Slack AI — channel and thread summaries that respect existing channel permissions. A reminder that permissions hygiene is now an AI control.
Each of our tool reviews links the vendor's official pricing and policy pages, so the people writing your policy can check current terms rather than rely on a summary.
Rolling it out
- Draft the two pages, then have one manager and one practitioner read it for realism.
- Put the approved tool list somewhere findable — a pinned doc, not an attachment in a thread from six months ago.
- Run a 20-minute walkthrough with one worked example: a real "should I paste this?" decision, resolved out loud.
Common mistakes
- Copying a large-enterprise template. A 40-page framework built for a bank's legal team will be ignored by a nine-person agency.
- Banning instead of tiering. Bans push usage out of sight, where it is unmanaged and unrecorded.
- Naming vendors but not tiers. "Approved: ChatGPT" means nothing when free, Plus, Team, and Enterprise have different data controls.
- No reviewer named. "Human review required" without a person attached becomes nobody's job.
- Treating it as finished. Vendor terms, model defaults, and your own workflows all move. A review date fixes that cheaply.
Frequently asked questions
Do we need a policy if we're only five people?
Yes, and it can be a single page. At five people you still have client confidentiality obligations and at least one person inclined to paste a contract into a chatbot. The policy's value is the shared default, not the formality.
Is this legal advice?
No. This is an operational checklist for writing a policy. If you handle health, financial, legal, or children's data, or you work under contracts with confidentiality clauses, have qualified counsel review the result before publishing it internally.
What do we do about people using personal accounts for work?
Make the work-account path the easy one: buy the seats, then say plainly that work material belongs in work accounts. Reimbursing a personal subscription is not the same thing as controlling where client data ends up.