Your Team Is Already Using AI: Write the Policy Before There’s an Incident

Start from a safe assumption: people at your company are using AI tools for work right now, whether or not anyone approved it. They are drafting emails, summarizing meetings, cleaning up spreadsheets, writing code, and rewriting proposals. Most of them are doing it to be faster at their jobs, which is exactly the behavior you want from good employees. The risk is not the tool. It is what gets pasted into the box.

What can actually go wrong

  • Confidentiality. Client contracts, patient details, employee records, unreleased pricing, and proprietary source code pasted into a personal AI account leave your control. On free and consumer tiers, that content may be retained and used to improve the model, depending on the provider’s terms.
  • Client contracts. Many master service agreements, NDAs, and security addendums restrict sharing client data with third-party services or new subprocessors without notice. A consumer AI account is a third-party service, and nobody signed off on it.
  • Regulatory exposure. HIPAA, GLBA, CJIS, CMMC, and state privacy laws do not carve out an exception for convenience. Putting regulated data into an unvetted tool is the same category of problem as emailing it to a personal address.
  • Confidently wrong output. AI can produce work that reads well and is incorrect — invented citations, subtly broken code, numbers that do not reconcile. Unreviewed output going to a client is a professional liability, not an IT issue.

Consumer accounts versus business accounts

This one distinction does most of the work. Business and enterprise tiers of the major AI platforms generally commit to not training on your content, provide administrative controls and logging, and can sign the agreements your compliance program requires. Personal free accounts usually do none of that. Moving your team onto company-managed AI accounts with single sign-on removes a large share of the risk before you write a single line of policy, and it costs far less than one incident.

What a one-page AI acceptable use policy should cover

Keep it short enough that people actually read it. Five sections is plenty:

  1. Approved tools. Name the specific AI tools employees may use for work and explain how to get an account. When a sanctioned option exists, most people use it.
  2. What never goes in. A plain list: client and patient data, PII, financial account numbers, credentials and API keys, proprietary source code, anything under NDA. Be concrete — the phrase "sensitive information" means nothing to a busy employee on a deadline.
  3. Human review of output. Whoever uses AI output owns it. Anything client-facing, legal, financial, medical, or code that ships gets reviewed by a qualified person before it leaves the building.
  4. Disclosure. State when AI use must be disclosed — to clients, inside deliverables, or in hiring and employment decisions. Some client contracts and some state rules now require it.
  5. Who to ask. One named person or inbox for tool questions, plus a no-blame way to report a mistake. People hide errors when policy is punitive, and hidden errors are the expensive kind.

Train instead of banning

Outright bans do not work. They push usage onto personal phones and personal accounts where you have no visibility at all — the same shadow IT pattern the industry has watched play out with every new tool for twenty years. A better sequence: provide approved tools, publish the one-pager, spend thirty minutes showing people what good and bad use looks like using examples from your own business, and revisit it every six months as the tools change.

Decide who owns this, too. AI governance tends to land nowhere in a small business — not quite IT, not quite legal, not quite HR — so it never gets done. Name an owner, even a part-time one, and give them authority to approve tools.

Equal Tech Solutions helps small and mid-sized businesses set AI policy that fits how their people actually work: approved tooling, a policy short enough to be read, and the technical controls to back it up.

Writing this before an incident is far cheaper than explaining one to a client afterward. Equal Tech Solutions serves Chattanooga, Cleveland, and the Southeast US. Contact Equal Tech Solutions to get a practical AI policy in place.