Skip to content
CyberTECTDigital operations control
All resources

AI Acceptable Use Policy for Small Businesses

A useful AI acceptable use policy names the approved tools and accounts, defines permitted and prohibited uses, controls information, assigns human review, manages vendors and records, and tells staff how to report mistakes.

The short answer

An AI acceptable use policy should define its purpose and scope; roles and accountability; approved tools, plans, accounts, and sign-in; permitted, restricted, and prohibited uses; information-handling rules; human review; professional and client obligations; intellectual-property and output requirements; recordkeeping and retention; vendors, apps, agents, and connectors; incident reporting; training; exceptions; enforcement; and a scheduled review process.

Key takeaways

  • Write the policy around daily decisions: tool, account, task, information, reviewer, record, and escalation path.
  • Keep stable principles in the policy and frequently changing tool, use-case, vendor, and exception details in controlled registers.
  • Human review must be tied to consequence and performed by someone competent to detect a plausible but wrong output.
  • The policy must cover AI features inside existing software, agents, connectors, transcription, browser extensions, and personal accounts—not only chatbots.
  • Test the policy against actual office workflows before approval; if staff cannot apply it, the policy is not complete.

An AI policy fails when it says little more than ‘do not enter confidential information’ and ‘verify the output.’ Staff still need to decide what confidential means, which tool is approved, whether a client email can be rewritten, who reviews a calculation, where the final work is saved, and what to do after a mistake.

The Law Society of Ontario provides a generative-AI policy checklist and professional-obligation resources for licensees. The Office of the Privacy Commissioner of Canada and ISED’s SME toolkit also emphasize accountability, privacy, security, transparency, human oversight, and risk-based governance.

The policy should be tailored to the office’s real systems and workflows. A law firm using Microsoft 365, practice-management software, conveyancing tools, identity verification, e-signature, banking, and occasional ChatGPT use needs different examples and approval thresholds than a marketing agency generating public copy from non-client information.

The 13 components of a practical AI acceptable use policy

01 Purpose, objectives, and policy scope

State why the policy exists: to enable approved AI use while protecting clients, employees, information, professional duties, records, security, and the organization’s ability to supervise work.

Define who and what are covered, including employees, contractors, owners, temporary staff, interns, personal devices, remote work, AI features inside existing software, browser extensions, transcription, meeting assistants, agents, and connected applications.

  • Example wording: ‘This policy applies to any system or feature that generates, summarizes, analyzes, transforms, recommends, or acts on information using artificial intelligence for organizational work.’

02 Roles, decision rights, and accountability

Name the policy owner and identify who can approve tools, use cases, information categories, integrations, and exceptions. Clarify manager, user, IT or vendor, privacy, HR, records, and professional-responsibility roles.

Technical administration does not equal business approval. A tool being available in the tenant or software menu does not mean it has been approved for every use.

03 Approved tools, plans, accounts, and sign-in

List approved services or point to a controlled register. Identify the exact plan, company-controlled account, authorized users, multi-factor authentication, administrator, billing owner, settings, and approved integrations.

Prohibit business use through personal accounts unless an explicit exception exists. Require review before enabling new plug-ins, GPTs, agents, browser extensions, connectors, or AI features inside another application.

04 Permitted uses and approved use cases

Give examples of acceptable tasks, such as brainstorming generic marketing ideas, improving non-confidential internal wording, creating a blank checklist, or summarizing public material—subject to approval and review.

Record higher-value use cases separately with the purpose, owner, users, input data, output, consequence, vendor, controls, and review date. Do not make the policy itself carry every changing workflow detail.

05 Restricted and prohibited uses

Define tasks that are prohibited or require elevated approval: final professional advice, unsupervised client communications, employment or credit decisions, identity verification, payment instructions, legal citations without verification, covert monitoring, impersonation, discriminatory profiling, or autonomous actions with material consequence.

The list should reflect the office’s sector, professional rules, contracts, risk appetite, and current capabilities. Include a process for asking about a use that is not listed.

06 Information classification and prompt rules

Identify information allowed in approved low-risk use, information requiring approval, information restricted to specific controlled systems, and information prohibited by default. Use real examples from client, employee, financial, transaction, security, and management work.

Require minimum necessary information, synthetic or generic examples where possible, and caution that removing a name may not prevent re-identification. Address prompts, uploaded files, images, audio, transcripts, feedback, memory, and connected sources.

07 Human review, verification, and final responsibility

Specify who must review outputs and what they must verify: facts, calculations, names, dates, citations, sources, professional analysis, bias, instructions, tone, confidentiality, intellectual property, and suitability for the intended recipient.

Require a reviewer competent in the subject and make clear that AI output is not an authority. Define when two-person review, manager approval, or independent verification is required because money, rights, filings, professional advice, or public claims are involved.

08 Professional duties, client communication, and disclosure

For regulated practices, connect AI use to current professional obligations, supervision, competence, confidentiality, candour, fees, and duties to clients or tribunals. Define when client consent or disclosure may be required and who decides.

Avoid a universal disclosure statement that ignores context. The office should obtain professional advice for its services and record the applicable decision in the approved use case.

09 Copyright, intellectual property, and acceptable output use

Require users to assess whether prompts or outputs contain third-party confidential material, copyrighted content, trademarks, proprietary information, or unsuitable source material. AI-generated content should not be assumed original, accurate, or free of restrictions.

Define rules for public publication, client deliverables, code, images, marketing claims, attribution, source checking, and use of the organization’s proprietary material.

10 Records, retention, and the official file

State when prompts, outputs, approvals, sources, or review notes must become part of the official business or client record. Define where final work is saved and discourage dependence on chat history as the only record.

Align retention and deletion with legal, professional, contractual, privacy, and records requirements. Account deletion, staff departure, or vendor change should not destroy the evidence needed to understand material work.

11 Vendors, apps, agents, connectors, and changes

Require review of the exact vendor, plan, contract, data use, retention, administration, security, sub-processors, location, deletion, incident terms, and exit arrangements. Record which connected systems and data sources the tool can access.

Trigger reassessment when the vendor changes terms, the model or feature changes materially, an agent gains actions, a connector adds a source, or the office changes the information or business use.

12 Incident, error, and concern reporting

Tell staff exactly how and how quickly to report restricted information entered into a tool, incorrect output sent externally, suspected account compromise, inappropriate content, bias, unsafe automation, unexpected access, or vendor incidents.

Prohibit concealment and retaliation for good-faith reporting. The response process should preserve necessary evidence, control access, assess notification or professional obligations, correct affected work, contact vendors where appropriate, and improve the control.

13 Training, exceptions, enforcement, and review

Require onboarding and recurring training using examples from the office’s work. Define how exceptions are requested, approved, time-limited, documented, monitored, and withdrawn.

State the consequences of deliberate or repeated violations in alignment with HR and professional processes. Set an owner and review schedule, with earlier review after incidents, significant new tools, integrations, legal or professional guidance, or material workflow changes.

The supporting records behind the policy

Keep frequently changing operational detail outside the main policy in controlled supporting records. This allows the office to update an approved-tool entry or use-case decision without rewriting the entire policy each time.

  • AI tool and AI-enabled feature inventory.
  • Approved-tool register with plan, owner, users, settings, integrations, and review date.
  • Use-case risk and approval records.
  • Vendor review and contract notes.
  • Information-classification examples and prompt rules.
  • Human-review and quality-control requirements by workflow.
  • Training attendance and awareness material.
  • Exceptions, incidents, corrective actions, and risk register.
Supporting record Accountable owner Review trigger
Approved-tool register AI policy owner with technical administrator New plan, feature, integration, vendor term, or user group
Use-case approval Business owner and competent reviewer Change in task, information, output, consequence, or automation
Vendor review Procurement, privacy, security, or designated owner Contract renewal, incident, sub-processor, location, or retention change
Training and incidents Manager, HR, privacy, or professional-responsibility owner New staff, policy update, mistake, complaint, or unexpected access

A minimum policy statement for immediate use

While a tailored policy is being developed, an office can issue a short interim direction. It should be approved by leadership, communicated to all users, supported by a question path, and replaced or reviewed on a defined date.

Example interim direction

Use only organization-approved AI tools and company-controlled accounts for approved tasks. Do not enter client-identifying, privileged, financial, identity, security, employee, health, or other restricted information unless the specific workflow has been authorized. Verify all output before use, save final work in the official system, and report mistakes or unexpected access immediately to the designated owner.

Test the policy against actual work

A policy should be tested with real scenarios before approval: improving a client email, summarizing a meeting, drafting a closing report, comparing two agreements, producing a marketing post, checking a spreadsheet formula, creating a job description, or using an agent connected to SharePoint.

If staff cannot determine the approved tool, information category, review requirement, record location, and escalation path for those scenarios, the policy is not finished.

Frequently asked questions

Can we use an online AI policy template?

A template can provide structure, but it must be adapted to the office’s tools, accounts, information, workflows, professional obligations, vendors, records, and incident process. Generic language should not claim controls the organization has not implemented.

Should approved AI tools be named inside the policy?

Stable principles can remain in the policy while the exact approved tools, plans, owners, users, settings, and review dates sit in a controlled register referenced by the policy. This makes updates easier and preserves accountability.

Should the policy prohibit all client information?

A prohibition-by-default is sensible until a specific controlled workflow has been assessed and approved. Any exception should address necessity, professional duties, privacy, vendor terms, account controls, retention, access, human review, records, and incident response.

Do employees need to disclose every use of AI?

The office should define disclosure and recordkeeping based on the use and consequence. Low-risk internal assistance may not require the same record as AI used in client work, professional analysis, a filing, an employment decision, or an automated action.

How often should an AI acceptable use policy be updated?

Set a scheduled review and trigger earlier review after incidents, new tools or agents, material integrations, vendor-term changes, new professional or regulatory guidance, data migrations, or a significant change in use.

Write the policy around decisions, not slogans

A useful AI policy makes the next action obvious. Staff can identify the approved tool, account, task, information category, reviewer, record location, and person to contact before the work becomes a problem.

CyberTECT helps professional offices build the operating materials behind the policy: inventory, acceptable-use rules, use-case assessment, vendor review, data classification, human-review requirements, incident procedures, staff awareness, risk register, and approval workflow connected to Microsoft 365, backups, vendors, and continuity.

Start with the level of review you need

Take the 90-second Digital Operations Control Check for an immediate directional result. For an evidence-based review of accounts, files, Microsoft 365 backups, vendors, AI use, and continuity, discuss the Digital Operations Checkup or the complete AI & Digital Operations Review. Scope and fees are confirmed before work begins.

General information only. This article does not provide legal, privacy, professional-conduct, or regulatory advice. Organizations should obtain appropriate advice for their sector, jurisdiction, information, and intended AI use.

Related CyberTECT services and checks

Authoritative sources and further guidance

Using this guidance

CyberTECT resources provide general operational guidance. They do not replace advice specific to your legal, regulatory, contractual or technical circumstances.

Discover more from Cybertect

Subscribe now to keep reading and get access to the full archive.

Continue reading