An AI use policy should help an employee answer three questions before starting: which tool can I use, what information can I provide and who needs to review the result? For a small business or nonprofit, start with rules people can apply to everyday work, then add guidance for more sensitive uses.
This is an internal operating policy, not a universal legal template. Adapt it to your contracts, confidentiality obligations, activities and the people affected. Obtain legal or professional advice where the situation calls for it.
Start with the uses already happening
Ask where staff use AI today: writing, research, summaries, meetings, coding or document analysis. AI may also appear inside existing software without a separate purchase. Record those features, the accounts being used and the information involved.
Assign a policy owner and someone who can answer questions. Managers need a reasonable way to request approval for a new use case. A short register can capture the need, exact product, plan, owner, permitted information and approval decision.
Classify information before approving tools
Use examples from your organization. A published announcement may be suitable, while a client file, donor list or employee review needs additional controls. The guide to confidential information in AI tools explains these distinctions.
Cover at least:
- public information and fictional examples permitted for trials;
- internal information restricted to approved environments;
- personal and confidential information requiring specific authorization;
- trade secrets, passwords and access keys excluded from routine use;
- documents that contain more than one category of information.
Provide a way to ask before uploading something uncertain. Removing a name does not necessarily make a document anonymous.
Approve an environment, not just a brand
“ChatGPT is allowed” leaves too much open. Identify the product, account type, plan, required settings and permitted features. Distinguish personal accounts from business accounts managed by the organization. An employee’s paid subscription does not, on its own, establish the controls you need.
Check connectors, extensions, sharing links and meeting transcription features too. Permission to draft public content does not automatically authorize access to an entire file repository.
Specify human review and accountability
People remain responsible for checking work within their role. Explain when a normal review is enough and when additional approval is required. A sales proposal, professional opinion and decision affecting an employee have different consequences.
For meeting notes, AI might prepare a draft, but a person must confirm decisions, names, deadlines and commitments before distribution. Include source checking, permitted use and possible reproduction of protected material. Contractual ownership of an output does not guarantee that it is free of third-party rights.
Describe what to do after an error or inappropriate disclosure: who to notify, what evidence to preserve and how to request containment. A policy that makes employees afraid to report a mistake can delay the response you need.
Train people and keep the policy current
Test the rules against realistic situations: uploading a client proposal, preparing a public announcement or recording a meeting. Where the answer is unclear, add an example. Practical team training helps you check whether staff understand the rules.
Give the policy a version date, an owner and a review schedule. Revisit it when a product, contract, connector or use case changes. These common AI implementation mistakes explain why governance should support experimentation rather than arrive after deployment.
Can we start with a short policy?
Yes, provided it covers permitted uses, information handling, review, responsibilities and incident reporting. Add short use-case guides as needed instead of expanding a document nobody reads. NetBLB’s AI integration support can help connect the rules to the workflows your team actually uses.