AI Policy for Small Business: A Free Template With 10 Rules Staff Will Actually Follow
A free AI policy template for small businesses in the UK: 10 plain rules on one page, what staff must never paste into ChatGPT, which tools to approve and how to set them up, what the ICO expects, and a five-day plan to roll it out.

Your staff are already using AI at work. You may not know which tools, or what they have pasted into them. When Microsoft surveyed 2,003 UK employees in October 2025, 71% said they had used consumer AI tools that their employer had not approved, and 51% were doing it every week. Only 32% were worried about the privacy of company or customer data.
Banning it does not work, and ignoring it is how a customer list ends up in a chatbot. What works is a short AI policy for your small business: one page, ten rules, written so that a busy person will read it. This guide gives you the template to copy, explains what UK data protection law expects, and shows how to roll it out in a week. It is practical guidance, not legal advice.
Want the policy written for your business, with a staff quiz and a list of approved tools? Jobbit drafts all three from a short conversation: 100 free credits a day, no card.
How we checked this guide
- The regulator's own words. Data protection points come from the Information Commissioner's Office (ICO) guidance on AI and data protection and its published position on generative AI.
- Official adoption figures. UK business use of AI comes from the Office for National Statistics survey of June 2026.
- The tool makers' own privacy pages. What happens to the text you paste was read on the providers' pages, not assumed.
- Kept to one page. A policy nobody reads protects nobody, so every rule had to earn its line.
Why a small business needs one now
AI use at work has spread faster than the rules for it. The ONS found that 29% of UK businesses used at least one AI technology in June 2026, up from about 12% in late 2023. Among the smallest firms, with fewer than ten people, the figure was 28%. Those are the businesses that say they use AI. The Microsoft survey suggests staff are well ahead of their employers: 28% of the people using unapproved tools said their company gave them no approved option.
The risk is ordinary, not dramatic. Someone pastes a spreadsheet of customers into a free chatbot to tidy it up. Someone asks an assistant to rewrite a complaint and includes the customer's medical details. In 2023 Samsung restricted staff use of generative AI after engineers pasted internal source code into ChatGPT, according to a memo reported by Bloomberg. If it can happen at Samsung, it can happen at a firm of six.
The law has not been suspended for AI either. The ICO's position is that there is no AI exemption to data protection law: if personal data goes into a tool, the rules apply, even if that was not the point of the task.
The 10 rules, on one page
| Rule | The wording to copy | Why it is there |
|---|---|---|
| 1. Approved tools only | "Use only the AI tools on our approved list for work. Ask before adding one." | You cannot protect data in tools you do not know about |
| 2. Nothing personal goes in | "Never paste names with contact details, health, financial or HR information into an AI tool unless the tool is approved for it." | Personal data is still covered by data protection law |
| 3. Nothing secret goes in | "Never paste passwords, bank details, contracts, pricing models or anything marked confidential." | Text you paste may be stored and read |
| 4. Check before you send | "You are responsible for anything AI helps you write. Check every fact, figure and name." | AI states wrong things confidently |
| 5. No decisions about people | "Do not use AI on its own to hire, discipline, price or refuse a customer. A person decides." | Automated decisions about people carry extra legal duties |
| 6. Say so when it matters | "Tell a customer if they are talking to an AI, and never post AI-written reviews." | Fake reviews have been banned in the UK since 6 April 2025 |
| 7. Respect other people's work | "Do not ask AI to copy a competitor's text, logo or photos." | Copying is still copying |
| 8. Use work accounts | "Sign in with your work email, with training on our data switched off where the tool allows it." | Settings on a personal account are outside your control |
| 9. Report mistakes fast | "If you paste something you should not have, tell the owner the same day. No blame for speaking up." | A breach reported early is far easier to deal with |
| 10. Review every six months | "We review this policy and the approved list twice a year." | The tools change every few months |
What staff can and cannot paste
A traffic-light list does more than any paragraph of policy. Print it next to the screen.
- Green, paste freely: public information, your own marketing copy, anonymised examples, general questions, anything already on your website.
- Amber, check first: customer emails with names removed, internal documents, supplier quotes, draft contracts with the parties blanked out.
- Red, never: customer lists, anything about a person's health, finances or employment, passwords and bank details, signed contracts, anything a customer gave you in confidence.
The simplest habit to teach is to swap real details for placeholders before pasting: "Customer A", "the Leeds site", "£X". The answer is just as useful, and nothing real has left the building. Our plain-English guide to AI safety lists seven things never to paste, with the reasons.
Which tools to approve, and how to set them up
Approving a tool takes ten minutes if you ask the right four questions:
- Is our data used to train the model? Consumer plans often use chats for training by default, with a switch to turn it off. Business plans usually do not train on your data by default.
- Can people read what we paste? Google's own privacy page for Gemini says a subset of chats is read by human reviewers, and tells users not to enter confidential information. Assume the same of any free consumer plan unless its terms say otherwise.
- How long is it kept? Gemini keeps activity for 18 months by default, and you can shorten that to 3. Look for the equivalent setting in every tool.
- Is there a private mode? Temporary chats, which are not used for training, exist in several assistants. Make them the default for anything amber.
Then write the approved list on the policy itself: the tool, the plan, who may use it and for what. Three tools is plenty for most small firms. If you are choosing between assistants, the difference between a chatbot and an agent is explained in this short guide.
What the ICO expects
You do not need a lawyer to cover the basics. The ICO's guidance comes down to five questions a small business can answer on one sheet:
- Do we need personal data for this task at all? If the job can be done with placeholders, do it that way.
- What is our lawful reason for using it? The same reason you hold the data in the first place, and it must cover this use.
- Have we told people? Your privacy notice should say that you use AI tools to help with correspondence or admin, if you do.
- Is the output accurate? You are responsible for what the tool produces about a person.
- Is it secure? Work accounts, strong passwords and approved tools only.
For anything higher risk, such as using AI to sift job applicants, the ICO expects a data protection impact assessment before you start. The ICO's guidance on AI and data protection is the reference.
The one-page policy to copy
AI AT WORK: OUR RULES We use AI to save time on writing, research and admin. These rules keep our customers' information safe and our work accurate. 1. Use only the tools on our approved list: TOOL ONE, TOOL TWO, TOOL THREE. 2. Never paste personal information about customers, staff or suppliers unless the tool is approved for it. 3. Never paste passwords, bank details, contracts or anything confidential. 4. Check every fact, figure and name before you send or publish anything AI helped with. 5. A person makes every decision about a customer, a supplier or a member of staff. 6. Tell customers when they are talking to an AI. Never post reviews written by AI. 7. Do not use AI to copy someone else's words, logo or pictures. 8. Use your work account, with training on our data switched off. 9. If you paste something you should not have, tell NAME the same day. 10. We review these rules every six months. Next review: DATE. Questions go to NAME. Signed: ___ Date: ___
Roll it out in five days
- Day 1: ask, do not accuse. Ask everyone which AI tools they use and for what. You will learn more from an honest list than from a ban.
- Day 2: choose the approved list. Pick up to three tools and set them up on work accounts with the privacy settings above.
- Day 3: fill in the template. Add the tool names, the person to ask and the review date. Keep it to one page.
- Day 4: train in 20 minutes. Walk through the traffic-light list with three real examples from your own work.
- Day 5: sign and pin. Everyone signs, and the list goes next to the screens. Put the review in the diary.
How an AI agent helps you run it
ChatGPT, Claude, Gemini, Microsoft Copilot, Manus and Meta's Muse can all draft a policy if you ask. Running one is a different job, and an agent is better suited to it.
- Writes the policy around your business. Tell it your trade, your tools and your team size, and it fills in the template and the approved list.
- Builds the training. A ten-question quiz from your own policy, with the answers explained.
- Keeps shared instructions in one place. In Jobbit Projects the team shares files and standing instructions, so "never include customer names" is written once and applies to every chat.
- Does the work inside the rules. The agent researches, writes documents and builds pages from one chat, so staff are not copying data between five free tools.
- Starts free. Jobbit gives 100 credits a day with no card, and paid plans begin with Go at £7 a month.
For where to point the time you save, see the 12 AI use cases that pay off for a small business.
Frequently asked questions
Does a small business need an AI policy?
If anyone on your team uses AI for work, yes. A survey of 2,003 UK employees found 71% had used unapproved AI tools at work. One page of clear rules protects your customers' data and tells staff what is allowed.
Is it legal to put customer data into ChatGPT?
Data protection law applies to any personal data you paste into an AI tool. You need a lawful reason, the tool must keep the data secure, and customers should be told how their data is used. The safe default is to remove names and details first.
Can staff use free AI tools for work?
Only if the tool is on your approved list and set up properly. Free consumer plans may use chats for training and may be read by human reviewers, so they are a poor fit for anything confidential.
Do I have to tell customers I use AI?
There is no general UK rule that every AI-assisted email must be labelled. You should tell people when they are talking to an AI, never post AI-written reviews, and explain in your privacy notice if AI tools process personal data.
What should an AI policy include?
Approved tools, what must never be pasted, a duty to check the output, a rule that people make decisions about people, honesty with customers, respect for others' work, work accounts, how to report a mistake and a review date.
How do I write an AI policy quickly?
Copy the one-page template above and fill in three things: your approved tools, the person to ask and the review date. Or let an agent write it around your business: start free on Jobbit with 100 credits a day.