Back to Resources

Running a team

6 min read · July 31, 2026

Last verified: August 1, 2026

The One-Page AI Policy

A ready-to-adapt policy for a team of 5 to 50. Ten minutes to customize, one meeting to roll out.

What this is for

You need something in writing before someone on your team pastes a client contract into a free AI tool. This is that document: a real one-page policy you can hand out this week, plus a prompt that adapts it to your specific industry and headcount, and a plan for rolling it out without a two-hour training nobody wanted.

Before you start

  • Know your approved tool list, even a short one. One tier distinction matters more than any other line in this policy: consumer plans (ChatGPT Plus, Claude Pro) are personal products. The business tiers (ChatGPT Business/Enterprise, Claude for Work) are the ones that exclude your data from training by default and come with admin controls and a data processing agreement. If the policy says "never paste into a tool that trains on our data," the approved list has to be tools where that's contractually true, and for the big providers that means the business tier, not a Plus account with the company card.
  • Know who the actual point of contact is for AI questions. A name, not a department.

The policy: copy this as-is, then customize

COMPANY AI USE POLICY

Purpose: This describes how we use AI tools at [COMPANY NAME], so
everyone works from the same rules instead of guessing.

Approved tools: [LIST YOUR TOOLS, e.g. ChatGPT Business (company
workspace), Claude for Work (company workspace), Perplexity
Enterprise]. These are the tiers with a no-training commitment and
admin controls. Personal or free accounts may be used for general
research only, never for anything in the "never paste" list below.
New tools need sign-off from [NAME/ROLE] before use on company work.

Never paste into any AI tool, including approved ones, unless that
tool is contractually confirmed not to train on our data:
- Client names paired with financial, health, or legal details
- Unreleased pricing, financials, or strategy documents
- Employee personal information (SSNs, salaries, home addresses,
  medical information)
- Source code containing API keys, credentials, or secrets
- Anything under an NDA that restricts third-party disclosure

The same rules apply to AI features inside other software:
- AI meeting recorders and note-takers may not join client calls
  without the client's consent, and internal calls follow the same
  "never paste" categories.
- Browser extensions or AI agents with access to email, files, or
  our systems count as tools and need the same sign-off before use.

Disclosure: If AI materially shaped a client-facing deliverable
(more than light editing), say so internally when you hand it off,
and use judgment on whether the client needs to know. When in
doubt, disclose. It costs less than being caught not disclosing.

Review requirement: Anything client-facing that touched AI at any
stage (drafting, editing, research, images) gets a human
read-through before it goes out. No AI output ships unreviewed. The
reviewer is the same person who'd be accountable if it were wrong.

If you already pasted something you shouldn't have: tell
[NAME/ROLE] the same day. Don't delete the chat; we may need it to
assess exposure. Nobody gets punished for reporting same-day. The
policy exists to catch mistakes early, not to catch people.

Who to ask: Questions about tools, data, or "can I use AI for this"
go to [NAME/ROLE], not to guessing or asking around.

Last updated: [DATE]. This is a living document; see the review
note below.

Customize it with this prompt

Use ChatGPT or Claude, either one. This is a drafting task, not one requiring live sourcing.

ROLE: You are a plain-spoken policy editor helping a small business
adapt a generic AI use policy to their specific situation.

CONTEXT: I run a [INDUSTRY, e.g. 10-person accounting firm] with
[HEADCOUNT] employees. We handle [TYPE OF SENSITIVE DATA, e.g.
client tax and financial records]. Our approved AI tools are
[LIST]. Our point of contact for AI questions is [NAME/ROLE].

Here is our base policy:
[PASTE THE POLICY ABOVE]

CONSTRAINTS: Keep it to one page. Keep the plain, direct tone. No
legal jargon, no hedging language. Add one industry-specific item
to the "never paste" list if our industry has an obvious one I
haven't listed (e.g. health data, financial account numbers,
attorney-client material). Do not add sections beyond what's here.

OUTPUT FORMAT: Return the complete, customized one-page policy,
ready to send to my team as-is.

Where this goes wrong

  • The policy gets emailed once and assumed read. Nobody reads a policy email. Walk through it live, even for ten minutes, or it doesn't exist in practice.
  • The "never paste" list is written too generically to be useful, so people can't tell if their specific situation counts. Add one real example from your own work, not just categories.
  • The approved list quietly means consumer accounts. A policy that promises "our tools don't train on our data" while the team is on personal Plus accounts is worse than no policy; it documents a confidence you don't have. Check the tier, not just the brand.
  • The policy gets written and never revisited. Tools and risks change every few months; a policy from a year ago is a policy nobody trusts.

Rollout plan

Announce (week 1): Send the policy with one paragraph of context. Why now: not because anything went wrong, but so everyone starts from the same rules. Name the point of contact clearly.

Train once (week 1 or 2): One 15-minute meeting or recorded walkthrough. Cover the "never paste" list with one real example, the incident clause (report same-day, no blame), and the review requirement. Take questions live; this is where people surface the edge cases the policy didn't anticipate.

Review at 90 days: Revisit the tool list, the "never paste" list, and whether the review requirement is actually happening. Update the "last updated" date and note it in your next team meeting. This isn't a compliance formality. It's how the policy stays believed.

One scope note: if you have employees or clients in the EU, the EU AI Act adds transparency duties this template doesn't cover, and if you use AI in hiring or employment decisions, several US states now regulate that specifically (see the caveat in the Performance Review Pack). Both are "get real legal review" territory, not template territory.

Deciding what work is appropriate to hand to AI in the first place is its own judgment call; the delegation matrix is the companion to this policy. For evaluating the tools themselves before they reach the approved list, use the Vendor BS Detector.

The 2-minute version

Copy the policy above, fill in the brackets (business tiers on the approved list, a named contact, the incident clause intact), run the customization prompt if your industry needs specifics, send it with a short note, walk through it once live, revisit in 90 days.

This is a starting template, not legal review. Have someone who actually knows your regulatory environment check it before you treat it as your final policy.


Want to know where you actually stand with AI? The free AI Readiness Assessment takes 10 minutes and gives you a personalized roadmap.

Weekly, on Tuesdays. The Gen Xcelerator: practical AI intelligence for people who already know how to do the job. Subscribe free.

Experience Is the API. GenXcelerate

Related resources

The Gen Xcelerator

A new one every Tuesday. Short, useful, and written for people who already know how to run things.

Get the newsletter