By this point in the playbook you have probably tried AI for a few things: a draft reply, a summary, maybe a quote template. The next question is not "should we use this more?" It is "what should we never do with it?" That question is worth answering on purpose, in writing, before someone answers it by accident.
Nobody is trying to leak anything
The person who pastes a customer contract into a chatbot to get a quick summary is not being careless. They are trying to finish before they leave for the day. That is exactly why a policy built on warnings does not work: at five in the afternoon, the warning is abstract and the deadline is not. A rule only gets followed if following it is faster than not following it.
What you are actually protecting
Mostly not secrets. Your customers' names and addresses, your prices, anything covered by a signed agreement, and anything about your employees. That is the stuff that turns a shortcut into a phone call you did not want to get.
The four rules
Write these on one page and put it where your team actually looks: the break room, the shared drive, the first page of onboarding. Everything else in this chapter just explains why these four hold up.
Approved tools only
Name two or three tools your team is allowed to use for work. A new one needs a two-minute check with you first, not a guess.
Strip names before you paste
Customer names, addresses, phone numbers, prices from a contract: take them out before anything goes into an AI tool. Replace with "the customer" or a made-up placeholder.
Work accounts, never personal ones
A business account keeps the conversation with the company, not with whoever typed it. A personal login leaves when the person does.
The email test
If it would be a problem in an email sent to the wrong person, it does not go into an AI tool either. Same information, same risk.
Rule four is really the whole policy. The first three just make rule four easy to follow without having to stop and think every time — because a rule that needs judgment at the end of a long day is a rule that gets skipped.
What to strip, and what is fine to leave in
The goal is not to stop your team from using AI for real work. It is to let them describe the shape of a problem without handing over the identity of the people in it. "A customer in the north side wants a quote for a 12x14 deck, similar to the Miller job" works just as well as a version with the real name and address, and it gets you the same answer.
Taking out the details usually adds fifteen seconds. That is the whole cost. Nobody needed the customer's real name to get a useful draft.
Why the account type is worth fixing first
This is the cheapest item on the list and the one most small businesses have never been told about. A free, personal AI account will often use what gets typed into it to improve the underlying model — it says so in the terms, most people never read that far. A paid business account usually does not, and says so in writing.
- A personal account can end up training a model on your customer data without anyone deciding that on purpose
- A business account gives you an actual record of who used it and roughly what for
- When someone leaves the company, a personal account and its history leave with them
- Moving a small team to business accounts is usually a small monthly cost per person, not a project
Compare a few dollars a month per person against one conversation explaining to a client why their contract went through somebody's personal chatbot account. The math is not close.
Check before it goes out, not after
AI drafts sound confident whether they are right or not. That is fine for a first pass and a problem if it becomes the final version. The fix is not "double-check everything forever" — it is knowing which outputs need a human set of eyes before anything leaves the building.
| What AI drafted | Who checks it before it goes out |
|---|---|
| A reply to a routine question | Spot-checked weekly, not line by line every time |
| A quote with numbers in it | Always: the person who would sign it, before it is sent |
| Anything mentioning a price, a policy or a guarantee | Always, against what your business actually offers |
| A social post or a blog draft | Read once for tone and facts before it publishes |
Notice the pattern: the more it can cost you to be wrong, the more a person has to look at it before it ships. That single line does more work than a page of legal language.
What this looks like on an ordinary Tuesday
Picture a small HVAC company. A technician gets back from a job and wants an AI tool to turn her rough notes into a clean service summary for the customer file. Under the four rules, that is easy: she leaves out the homeowner's name and exact address, describes the unit and the repair, and pastes the draft back into the real record herself once it reads well. Nothing about the job stopped moving, and nothing identifying left the building through a tool the company does not control.
Now picture the office manager wanting to use AI to draft a response to an unhappy customer whose complaint mentions a specific invoice and a dollar amount. That one goes through the table above: it touches a price and a guarantee, so a person reads it against the real invoice before it is sent, whether or not AI wrote the first draft. Same tool, two different amounts of caution, because the two situations are not the same risk.
Someone has to own this, by name
A policy with no owner is a document nobody enforces. It does not need to be a manager. It can be whoever already handles the phone system or the shared inbox. Their job is small: keep the one page updated, answer "can I use this tool for that?" in under a day, and notice if a new AI tool shows up on somebody's laptop that nobody approved.
Putting it in place this week
Day 1
Pick your two or three approved tools. Write the four rules on one page.
Day 2
Move everyone who uses AI for work onto a business account. Usually a fifteen-minute setup per person.
Day 3
Ten minutes with the team. Read the four rules out loud, with an example from your own business, not a hypothetical one.
Ongoing
Add the page to onboarding for anyone new. Revisit it when a new AI tool shows up.
Do not skip the ten-minute talk and just send the page by email. A page that gets read out loud, with a real example, gets remembered. A page that gets filed does not.
This is not legal advice
This chapter is a practical starting point for how a small business uses AI day to day, not a substitute for a lawyer. If your business handles health records, financial accounts, legal filings, or anything covered by a specific regulation in your industry, have someone qualified review your policy before you rely on it. What counts as sensitive data, and what you are required to do with it, changes by industry and by state.
The goal is a team that uses AI confidently in the open, not one that uses it quietly because nobody ever said what was off-limits.
Keep going
- AI policy generator
Answer a few questions about your business and get a one-page policy draft you can hand to your team this week.
- How we handle data and security
What we ask about security when we scope a project, in plain language.
- Guide: The One-Page AI Policy
The four-line rule this chapter is built on, with more on what to strip and why the account type matters.
Take this with you
- · Four rules beat a long policy: approved tools, strip the details, work accounts only, the email test.
- · Moving your team to business AI accounts is cheap and removes the biggest silent risk.
- · The more an AI draft can cost you if it is wrong, the more a person needs to check it before it ships.
- · One named person owns the policy: keeps it current and answers questions fast.
- · This is a starting point, not legal advice — check it against your industry's actual rules.