Why Your Team Needs an AI Policy Before It Becomes a Crisis
- Jeremy Ross
- 1 day ago
- 5 min read
Somewhere in your business right now, someone is pasting a client contract into ChatGPT to "tidy up the wording." Someone else is feeding your quarterly numbers into an AI tool to build a nicer chart. Nobody asked them to stop. Nobody told them to start either. They just did, because the tool was free, it was fast, and nobody in the building had said otherwise.
That's not a hypothetical. That's what most businesses are doing at the moment. And that's the problem.
The quick version: if you haven't written an AI policy, your team has already written one for you, and it's called "whatever seems fine at the time." That's not a policy, it's a gamble, and gambles involving client data have a habit of losing.
The Problem: Nobody's Driving
Most business owners think they don't have an AI problem because they haven't "rolled out AI" as a company. Meanwhile half the staff are already using it on personal devices, personal logins, with zero guardrails, because the tools showed up faster than the conversation about them did.
Here's the part that should actually worry you. Typing client details, financials, or internal documents into a free public AI tool is the digital equivalent of leaving your home address, a bank statement, and your credit card on a café table and popping to the loo. Nobody's necessarily going to take it. But you've handed a stranger everything they'd need to, and you won't know if they did until it's too late to do anything about it. Most public AI tools can store, log, or use what you type in ways that are somewhere between "unclear" and "you really should have read the terms." Your staff aren't being careless. They just don't know they're leaving the table unattended.
Without a policy, you get a business running three separate, invisible AI programmes:
The efficient one, where someone's genuinely saving hours a week and nobody else knows it's possible
The risky one, where confidential client data, financials, or HR records get typed into a public AI tool with terms and conditions nobody read
The inconsistent one, where quality, tone, and accuracy vary wildly depending on who's prompting and how well
None of these are the AI's fault. All of them are what happens when a powerful tool meets zero direction.
What We Did: Turned "Winging It" Into a Framework
We don't do this by handing clients a twelve-page legal document nobody will read past paragraph two. We build AI policy the way we build everything else: practical first, jargon last.
That means sitting down with the business, mapping out where AI is already being used (usually more places than the owner expects), and then setting clear, sane boundaries. What tools are approved. What data can never go near a public AI model. Who's accountable when something goes wrong. How new tools get vetted before they're allowed near client work.
Not every use of AI deserves the same level of scrutiny, so we grade it:
Risk level | Example | Rule |
Low | Tidying up an internal note | Fine, review before it goes anywhere external |
Medium | Drafting customer-facing content | Allowed, human check required |
High | Shortlisting job applicants | Needs sign-off, usually not worth the exposure |
Not allowed | Client data pasted into a public AI tool | No |
The difference between fine and not fine is usually smaller than people think. "Tidy up this product description" is a different animal to "summarise this complaint from a named client, including their account number." One's a Tuesday. The other's a breach report with your name on it.
For businesses handling anything genuinely sensitive on a regular basis, we'll also talk through self-hosted AI. Instead of sending data out to someone else's servers, the model runs on infrastructure you control, so nothing leaves the building. It's a stronger data security position, full stop. The trade-off is cost: self-hosting means paying for the hardware and setup upfront rather than a monthly subscription, so it's not the right call for every business, but for anyone handling client data at volume, it's worth the conversation.
We pair all of this with the technical side, because a policy without enforcement is just a nicely worded suggestion. That's device management, access controls, and monitoring that actually flags risky behaviour instead of just producing a report nobody opens.
What Changed
Clients who've gone through this go from "we think some people use AI sometimes" to knowing exactly what's approved, what's not, and why. Staff get clarity instead of guesswork, which, unsurprisingly, they tend to prefer. Leadership gets a defensible position if a client or regulator ever asks "how do you manage this?" And the business stops relying on luck as its main data protection strategy.
New tooling and monitoring stays in place after the policy's written, not just during the initial flurry of enthusiasm. That's the difference between a document and an actual system.
Key Takeaway
You don't need to ban AI, and you almost certainly shouldn't try, your team will just use it quietly instead of openly. What you need is a policy that says what's allowed, what's off-limits, and who's responsible, written down before an incident forces you to write it in a hurry. The businesses that get ahead of this aren't the ones with the strictest rules. They're the ones who decided on purpose, instead of finding out by accident.
The quick version, again: your team is already using AI, with or without permission. Without a policy, that's the same as leaving sensitive data unattended on a café table and hoping for the best. Set clear rules on what can and can't be typed into these tools, grade the risk by use case, and consider self-hosting if data security is non-negotiable and the budget allows for it. Do it before something forces the conversation, not after.
FAQs
Do small businesses actually need a formal AI policy? Yes, even a one-page policy beats no policy. If staff have access to AI tools and no guidance, the business has already inherited the risk, whether or not it's been written down.
What should an AI policy actually cover? At minimum: which tools are approved, what data can never be entered into public AI tools, who approves new tools, and what happens if the policy is breached.
Can employees use ChatGPT for work if there's no policy yet? Technically yes, which is exactly the problem. Without guidance, employees make that call individually, often without realising the data protection implications.
Is self-hosted AI worth it for a small business? It depends on how much sensitive data you're handling and how often. Self-hosting keeps data entirely within your own infrastructure, which is the strongest option for data security, but it costs more upfront than a subscription to a public tool. But it might be worth it if you're regularly handling client, financial, or health data. Overkill if you're mostly drafting internal memos.
Is an AI policy a legal requirement in the UK? Not as a standalone law, but it feeds directly into existing obligations under UK GDPR and data protection law, particularly around what happens to client or personal data once it leaves your systems.
How long does it take to put an AI policy in place? For most SMEs, a working policy can be drafted and rolled out within a couple of weeks, the ongoing part is enforcement and keeping it updated as new tools appear.