An AI policy your team will follow.

If anyone on your team uses AI, you already have a policy. It is just unwritten. Here is a one-page version you can copy today.

The pages of a ring binder fanned open
Photo by Pontus Wellgraf on Unsplashdithered by Cyborb

An AI use policy tells your team which AI tools they may use, what information may go into them, and who checks the results before they reach a customer. For a small team, one page is enough. This guide gives you an AI use policy template you can copy, explains each rule in plain words, and shows how to roll it out in a week.

You may feel too small to need one. But if anyone on your team uses AI for work, you already have a policy. It is just unwritten, and each person has made up their own version.

The short version
  • A one-page policy beats none. It turns private habits into shared rules that people can remember.
  • Cover six things: approved tools, data rules, human review, disclosure, ownership and security.
  • Sort information into green, amber and red, so nobody has to guess what may go into an AI tool.
  • Give the policy one owner and a review date, because tools and their settings keep changing.
  • Roll it out with a 30-minute walkthrough built on real examples, not a signature form.

Why a one-page policy beats none

Most AI mistakes at work are not exotic. Someone pastes the wrong thing, trusts an answer without checking it, or assumes the tool is responsible for what it said. Three well-documented cases show the pattern.

What happenedWhat went wrongThe rule that prevents it
Samsung, 2023: staff shared sensitive internal data with ChatGPT, and the company temporarily restricted generative AI tools on its devicesConfidential data left the companyData rules and approved accounts
Air Canada, 2024: its website chatbot gave a customer wrong information about bereavement refunds, and a tribunal ordered the airline to payThe airline argued the chatbot was responsible for its own actionsYou own what your AI tells customers
Deloitte Australia, 2025: a government report worth A$440,000 contained nonexistent references. Deloitte disclosed its AI use in a corrected version and agreed to repay the final instalmentErrors reached the clientHuman review and disclosure

The Air Canada tribunal rejected that defense in plain terms: a chatbot is part of the company’s website, and the company is responsible for all of it. Your customers will see it the same way.

What an AI use policy should cover

Six topics cover almost everything. Keep each one to a few lines.

  • Approved tools. Name the tools and, just as important, the accounts. A company business plan and a personal free account can treat your data very differently. Our guide to AI privacy compares the settings.

  • Data rules. What may go into which tool. The traffic-light system below does most of the work.

  • Human review. Who checks what before it is sent, published or merged. Scale the check to the risk.

  • Disclosure. When you tell customers and clients that AI was involved.

  • Ownership. Who owns work made with AI, and when to be careful about copyright.

  • Security. Accounts, sign-in, keys, agents, and a firm rule about money.

Add an owner, a review date and a way to report mistakes, and you are done.

Sort your information into three colors

The data rule is the one people break by accident, so make it visual. Everyone can remember three colors.

GreenAmberRed
What it isPublic or already publishedInternal, but not personal or secretPersonal, secret or under contract
ExamplesWebsite copy, published docs, public dataDraft plans, internal notes, code without secretsPasswords, API keys, customer records, health or financial data, anything under NDA
Where it may goAny approved toolApproved company accounts onlyNowhere, unless the owner approves one tool for that data in writing

Tailor the red list to your business. A clinic will name patient details. An agency will name client briefs under NDA. A software team will name production credentials, which our guide to keeping API keys safe covers in depth.

The AI use policy template

Copy this, replace the brackets, and delete anything that does not apply. It is written to fit on one printed page.

ai-use-policy.md
# How we use AI at [Company]

Owner: [name]. Last reviewed: [date]. Next review: [date + 6 months].

## 1. Approved tools
- [Chat assistant] on our company [business or team] plan: writing,
  research and analysis.
- [Coding assistant or agent] in company repositories: code.
- [Meeting notes tool]: internal meetings, with everyone told it is on.
- Anything else, including browser extensions and plugins: ask [owner].
- Personal AI accounts: green information only, with training turned off.

## 2. Information rules
- Green (public or published): any approved tool.
- Amber (internal, not personal, not secret): company accounts only.
- Red (passwords, keys, customer personal data, health or financial
  records, anything under NDA): never, unless [owner] approves a
  specific tool for it in writing.

## 3. Check before it ships
- You are responsible for anything you send, publish or merge,
  whoever or whatever wrote the first draft.
- Check every fact, number, quote and reference against its source.
- AI-written code passes the same tests and review as any other code.
- Anything legal, medical, financial or about a real person gets a
  second reviewer.

## 4. Tell people when it matters
- Customers are told when they are talking to an AI, not a person.
- We follow each client's contract terms on AI use. If a contract
  is silent and the AI contribution is substantial, we ask.
- We label realistic AI images, audio and video, and never create
  them of a real person without consent.

## 5. Ownership
- Work made with AI for [Company] belongs to [Company], like any
  other work.
- Purely AI-generated material may not be protected by copyright.
  For logos, brand assets and anything we must own outright, talk
  to [owner] first.

## 6. Security
- Company accounts only, with passkeys or an authenticator app.
- Never paste passwords or keys into a prompt. AI agents get test
  keys and a project folder, never production credentials.
- New connectors that can read email, files or calendars need
  [owner]'s approval.
- Money rule: never pay, change bank details or share a code
  because of a call, voice note, video or message alone. Confirm
  on a number we already know.

## 7. When something goes wrong
Pasted something red? AI output caused a problem? Tell [owner]
the same day. We fix first and we do not blame.

## 8. Learning
New starters read this page in their first week. Share useful
prompts and near misses in [channel].

The money rule is there because cloned voices and deepfake video calls now target staff who can move money. Calling back on a known number is the defense the FBI recommends.

How to fill in the blanks

A few choices make the difference between a policy people follow and one they ignore.

  • Name one owner. Not a committee. One person who answers questions within a day.

  • Name real tools and accounts. “Approved AI tools” means nothing. “[Assistant] on the company workspace, signed in with your work email” is a rule.

  • Write rules as actions. “Never paste API keys into a prompt” works. “Ensure appropriate handling of credentials” does not.

  • Use your own examples. Replace the red list with the five things your team is most likely to paste by mistake.

  • Treat agents separately. An agent that can run commands, read files or send email can do more damage than a chat window. Many agent tools, including our own Cyborb, let you choose how much the agent may do without asking. Your policy should name the default.

How to roll it out in one week

  1. Monday: draft it

    The owner fills in the template in under an hour. Use the tools and accounts you have today, not the ones you plan to buy.

  2. Tuesday: ask two people to break it

    Give the draft to two colleagues and ask for real edge cases. “Can I paste this client email?” and “Can I use my own account on my phone?” are the questions that fix a policy.

  3. Wednesday: walk the team through it

    Spend 30 minutes on real examples from your own work: one green, one amber and one red. Answer every question, then fold the answers into the page.

  4. Thursday: put it where work happens

    Pin it in your team chat, link it from onboarding, and set up the approved business accounts. The right choice should also be the easy one.

  5. Friday: set the review date

    Put a reminder in the calendar for six months from now. Review sooner if you add a tool, a client asks, or a law changes.

Keep your AI policy current

Review it every six months, because providers change defaults, add features and rename plans. Ask the team what they actually use. The gap between that and the approved list is the most useful thing you will learn.

Laws can add duties too. The EU AI Act can apply if your team is in the EU or your AI output is used there. Its transparency rules, such as labeling deepfakes, apply from August 2, 2026.

The Act also requires companies that use AI at work to take measures for their staff’s AI literacy. That duty has applied since February 2025. A July 2026 amendment softened it: you must support AI literacy, not guarantee a set level. Our guide to the EU AI Act for small builders explains what applies to you.

Your policy is ready when0 of 8

FAQ

Do small teams really need an AI use policy?

Yes, if anyone uses AI for work. Without one, each person sets their own rules, and you only find out what they were after something goes wrong. A one-page policy takes about an hour to write.

Should we just ban AI tools?

Usually not. Samsung restricted them for a while in 2023, but bans are hard to enforce on personal phones and accounts, so AI use moves out of sight. Approving a few tools on company accounts, with clear data rules, gives you more control.

Do we have to tell clients we use AI?

Check your contracts first, because some clients set rules. Beyond that, tell customers when they are talking to an AI, label realistic AI media, and be open about substantial AI use in work you deliver. Clients forgive tools more easily than surprises.

Who owns work made with AI tools?

Your policy should say the company owns work staff make for it, with or without AI. Copyright is a separate question: purely AI-generated material may not be protected, so be careful with logos and anything you need to own outright.

How often should we update the policy?

Every six months, and whenever you add a tool, change plans or take on a client with AI rules. AI products change their settings often, so a policy that is a year old is probably wrong somewhere.

Next, see how AI scams target the people who can move money, or read who owns what AI makes.

Sources
  1. Samsung bans use of generative AI tools like ChatGPT after April internal data leak, TechCrunch, May 2023
  2. Air Canada ordered to pay customer who was misled by airline’s chatbot, The Guardian, February 2024
  3. Deloitte to pay money back to Albanese government after using AI in $440,000 report, The Guardian, October 2025
  4. Criminals use generative artificial intelligence to facilitate financial fraud, FBI Internet Crime Complaint Center, December 2024
  5. AI Act: regulatory framework for AI, European Commission
  6. Regulation (EU) 2026/1744 (Digital Omnibus on AI), EUR-Lex, July 2026
  7. Copyright Office releases Part 2 of Artificial Intelligence report, U.S. Copyright Office, January 2025
cyborb.ai

Stop reading about it. Build it.

Describe what you want in plain words. Cyborb plans the work, writes and runs the code, makes the assets, and puts the result online.

Download Cyborb

Free to start. No card required.