The AI Policy Every Company Needs (Template Included)
Founder, Automation Squad ·
Your team is already pasting client data into ChatGPT — policy or not. Here's the eight-section policy that actually stops the Samsung-style mistake, plus a starter template you can adapt this week.
By the Automation Squad Research
Somewhere in your company, right now, someone is pasting a client contract into ChatGPT to get a faster summary. Maybe it's fine. Maybe that contract has a confidentiality clause that just got violated the moment it left your systems. You don't have an AI policy, so nobody actually knows — including the person who pasted it, who probably assumed it was no different from using spellcheck.
This isn't hypothetical. In April 2023, engineers at Samsung pasted proprietary source code and internal meeting notes into ChatGPT to help debug and summarize — three separate incidents in under a month, according to reporting at the time. Samsung banned generative AI tools company-wide shortly after. Italy's data protection authority temporarily banned ChatGPT outright that same month over data handling concerns. Neither company set out to make headlines. Both just hadn't written down, in plain language, what was and wasn't OK to type into a chat box. You can close that gap in an afternoon.
Paste that into your AI assistant along with your actual list of tools and a rough sense of what data your team handles, and ask it to expand each line into two or three plain-English sentences your team will actually read. Fifteen minutes, and you've closed a gap that's currently sitting wide open.
Why "we'll get to it" is the expensive option
Employees are already using AI tools, policy or not — free ChatGPT accounts, personal Claude subscriptions, whatever's fastest. That's not a discipline problem; it's what happens when a tool makes someone's Tuesday easier and no one's told them otherwise. A policy doesn't slow that down. It tells people which tools are sanctioned, what data can go into them, and who to ask when a situation isn't covered — which turns "I hope nobody pastes anything sensitive" into an actual, enforceable answer.
The eight sections every AI policy needs
Skip the fifty-page legal document. A policy nobody reads protects nobody. Here's what belongs in a version your team will actually use:
- Purpose and scope. One paragraph. Why this policy exists, and who it covers — every employee, contractor, and anyone using AI tools on company devices or company data, full stop.
- Approved tools list. Name the specific AI tools your company has vetted and paid for — "Claude (business plan), Microsoft Copilot, ChatGPT Team" — and state plainly that free consumer accounts are not approved for anything involving company or client data. Vague statements like "AI tools should be used responsibly" don't stop anyone from doing anything.
- Data classification — what can and can't go in. This is the section that would have stopped the Samsung problem. Three tiers work for most small businesses: public information (fine, anywhere), internal information (approved company tools only, never free/personal accounts), and restricted information — client data, financials, anything under an NDA, health or payment information — which requires a specific carve-out approval before it touches any AI tool at all.
- Human review requirement. State it as a rule, not a suggestion: no AI-generated output goes to a client, gets published, or triggers a financial transaction without a named human reviewing it first. Name which roles sign off on what.
- Accuracy and "hallucination" awareness. AI models generate confident, fluent, sometimes-wrong answers — a known limitation, not an edge case. Require a fact-check step on any AI output involving numbers, dates, legal claims, or anything a client could hold you to.
- Disclosure to clients and customers. Decide, in writing, when you tell a client that AI was involved in producing something they're paying for. The EU AI Act, which entered into force in August 2024, includes transparency obligations for certain AI-generated and AI-interacted content — and several U.S. states have introduced similar disclosure rules. Getting ahead of that with your own honest default avoids having the decision made for you by a regulator later.
- Accountability. Name who owns this policy, who approves new tools, and who employees report a mistake or a near-miss to. "The AI did it" is never the end of the accountability chain — a named human is.
- Review cadence. This space moves fast enough that a policy written in January can be stale by June. Put a specific date on the calendar — every six months is reasonable — to review and update it, not "as needed," which in practice means never.
The one line that actually prevents the Samsung problem
If you only add one sentence to your existing employee handbook today, make it this one: "Do not enter client data, financial information, source code, or anything covered by an NDA into any AI tool that has not been specifically approved for that purpose." That single line, said out loud in a team meeting and put in writing, closes most of the real exposure a small business has right now — long before you get around to the other seven sections.
Rolling it out without a legal budget
You don't need outside counsel to launch version one. You need a document short enough that people actually read it, a list of approved tools your team already has logins for, and one meeting where you walk through the data classification tiers with real examples from your own business — "this spreadsheet, yes; this client's medical intake form, no." Get that far and you've covered the situations that actually happen day to day. Save the formal legal review for the version you circulate company-wide.
Adapt this starter policy this week
Copy this into a document and fill in your specifics:
- "[Company Name] AI Use Policy — v1. Approved tools: [list]. Restricted data (never enter into any AI tool without written approval): client contracts, financial records, health information, anything under NDA, unreleased product or pricing information. All AI-generated content used externally (emails, proposals, marketing copy) must be reviewed by a human before sending. Questions or exceptions go to [name/role]. This policy is reviewed every six months, next review: [date]."
