How to Write an AI Policy Your Team Will Actually Follow

Only one in six workers currently uses AI on the job, according to Pew Research Center's October 2024 survey of 5,273 employed adults. That number feels low until you notice the other finding sitting next to it: 70 percent of workers in Microsoft's 2023 Work Trend Index said they would delegate as much work as possible to AI to reduce their workload. Those two numbers describe a specific window. Adoption is still narrow. Appetite is enormous. The informal habits your staff form right now will be the de facto policy you live with for years.
The problem with banning tools you cannot monitor
A blanket ban on ChatGPT or similar tools does not stop a staff member from opening a browser tab on their phone. It stops them from telling you they did. That distinction matters because unmanaged technology use raises incident costs and resolution times, per the research cited in IBM's data breach studies. The ban does not eliminate the risk. It makes the risk invisible.
The alternative most founders land on is the opposite extreme: no rules, full experimentation. That position has its own failure mode. A 25-year-old on your team who is comfortable with AI will paste a customer contract into a public chatbot to get a summary. Not out of malice. Out of efficiency. Without a rule naming that as off-limits, you have no standing to correct it after the fact, and no record showing you tried to prevent it.
What risk tiers actually look like in a five-person firm
The NIST AI Risk Management Framework, the OECD AI principles, and the UK Information Commissioner's Office guidance all converge on the same structural answer: sort tasks by risk level, not by tool name. Permit low-stakes use freely. Require a named human to review any AI output before it reaches a client or affects a hiring or pay decision. Restrict the narrow category of tasks where the cost of an error is severe and the AI failure mode is well-documented.
In practice for a small team, this breaks into three lists you write once and revisit quarterly.
The first list covers what staff are free to use AI for without asking anyone: internal drafts, research summaries, brainstorming, formatting. Low stakes, no customer data involved, no output going anywhere outside the building.
The second list covers outputs requiring sign-off before they leave: client-facing documents, financial projections, anything that quotes a price or makes a commitment. One named person signs off. Not a committee. One person, named by role, so the rule survives staff turnover.
The third list covers data categories staff cannot enter into any external AI tool: customer PII, payment data, employee records, anything under NDA. This list does not require enforcement infrastructure. It gives staff a concrete rule at the moment they are about to paste something into a chatbot. That is a different mechanism than monitoring, and it works at the point of decision rather than after the fact.
When a written policy makes your legal position worse, not better
The strongest objection to this approach is worth stating at full strength. A policy that exists on paper but goes unmonitored does not reduce risk. It documents that you knew what the risks were and chose a response with no teeth. When an incident occurs, the policy is evidence against you, not for you.
This objection is correct about one thing: a policy drafted once and filed in a shared drive folder will decay. It is wrong about the comparison it implies. The alternative to a weak policy is not a strong one. For most small founders right now, the alternative is no policy. And the research is clear that unmanaged use produces measurable costs when incidents occur. A named data-category list does not require a compliance officer to check logs. It changes what staff do at the moment of decision, which is where the risk actually lives.
The Pew data also matters here. With only one in six workers currently using AI on the job, and use concentrated among younger staff, you are setting rules before the majority of your team has formed habits around unmanaged tools. That window closes as adoption rises.
Start with the shortest version
Write one page. Name the three lists. Assign one person per role to sign off on consequential outputs. Review it in 90 days. The SHRM white papers on workplace AI governance position training, not surveillance, as the operative control for small teams. Send the policy in a 20-minute team meeting, explain the reasoning behind each list, and ask for questions. That meeting is the enforcement mechanism.

Read next

AI as Strategy
Your AI Policy Fits on One Page
Most small businesses use AI daily without written rules. Here's a time-bound checklist covering data handling, approved tools, and oversight for lean teams.
3 min read

AI as Strategy
AI Governance Checklist for Small Teams
A lightweight AI governance policy covering acceptable use, data boundaries, output verification, and escalation ownership — built for teams without legal or IT
3 min read

AI as Strategy
Your AI Policy Checklist for Safe Small Business Use
Half of small business founders already paste sensitive data into public AI tools. Here's the one-page policy that stops ungoverned use before it costs you.
3 min read