Skip to main content

What should an AI use policy for a small service business actually say?

AI Security & Governance Published August 7, 2026
Short Answer

Keep it to one page and answer five questions: which tools are approved, what data may go into them, what always needs a human before it reaches a customer, who to ask when unsure, and how employee-facing AI like call evaluation works. Most policies fail by being long and abstract. A short policy people read beats a thorough one nobody opens, and it is far easier to keep current.

The five questions a usable policy answers

  • What is approved. Name the specific tools and accounts. "Use good judgment" is not a control.
  • What data is allowed in. Customer records, transcripts, financials, payroll — say which are fine, which need approval, which are never.
  • What requires a human. Anything that reaches a customer, anything that touches an employment decision, anything that writes to a system of record.
  • Who to ask. One named person. Ambiguity plus no owner equals people quietly doing whatever.
  • What AI is used on employees. Call evaluation, scheduling, forecasting — what it looks at, who sees it, how to dispute it.

Approved tools is the section that decides everything

The failure mode is a ban. If the policy says no AI without approval and approval takes three weeks, people use their personal accounts on their phones, and your customer data ends up in consumer products with consumer terms. That is worse than the thing the ban was meant to prevent.

The better move is to approve something genuinely useful on business terms, make it easy to access, and then enforce the boundary. Governance works when the compliant path is the convenient one.

The employee section is the one that gets read

Staff skim the data-handling rules and go straight to whether AI is watching them. Write that section as if it is the whole document, because to many readers it is.

State plainly that evaluation applies your written standards, that the output supports a manager's coaching decisions rather than replacing them, and that there is a path to dispute a result. Vagueness here costs you more trust than any other paragraph. How coaching actually runs should match what the policy says.

Set a review date on the page

Tools, terms and capabilities change on a quarterly rhythm. A policy with no review date becomes wrong quietly, and then people stop treating it as real.

Put the date on the document, review it, and record what changed. Do the same for the underlying systems — an AI platform that gains new integrations has new data paths, and the policy should catch up before the paths do. For anything with employment or privacy implications, run the wording past your own counsel.

Topics: AI policy · governance · employees · small business

Have a version of this question about your own business?

The useful answer usually depends on which systems you run and how they're connected. That's a conversation, not a blog post.

Related Answers

People who read this also asked

Browse the Answer Hub →

AI is easy to access. Making it useful is hard.

Bluefrog makes AI useful by integrating it with the way your business actually works — your software, your calls, your customers, your marketing and your revenue.

Technology development since 1997 · AI integration platforms since 2001