AI Acceptable-Use Policy for SMBs: A One-Page Guide

Before Your Team Pastes Anything Into ChatGPT: Building an AI Acceptable-Use Policy

Your employees are already using AI tools at work, whether or not you’ve approved them. An AI acceptable-use policy — one page, written in plain English — is the fastest way to turn that unmanaged activity into something you can actually govern.

This isn’t a compliance exercise for its own sake. When a paralegal pastes a draft settlement agreement into a free chatbot, or a billing coordinator uploads a spreadsheet with patient names to summarize it, the question isn’t whether they meant well. They did. The question is whether your firm has told them where the line is. Most SMBs haven’t.

Why “we’ll just tell people not to use it” doesn’t work

Blanket bans fail for a predictable reason: the tools are genuinely useful, and they’re free. Someone facing a 40-page vendor contract at 5 p.m. on a Thursday will find a way to summarize it. Industry surveys of knowledge workers consistently find that a meaningful share of employees have used generative AI at work without telling anyone — and that number climbs when the employer has no stated policy at all. A ban you can’t enforce just moves the activity to personal devices and personal accounts, where you have zero visibility.

The better play is what security teams call shadow-AI discovery followed by sanctioned alternatives. Find out what’s actually in use, give people an approved tool that does the same job inside your tenant, and write down the rules for both. For most of our clients that approved tool is Microsoft Copilot, because it operates inside the Microsoft 365 boundary and inherits the permissions you’ve already set — a Copilot query doesn’t surface a document the user couldn’t already open. That’s a meaningfully different data posture than pasting the same content into a consumer chatbot.

What actually happens to data you paste into a public AI tool

This is the part most policies get wrong, because the answer varies by product tier and changes over time.

Consumer-grade free tiers of major AI assistants have historically used conversation content to improve models unless the user opts out in settings. Paid business and enterprise tiers generally commit contractually to not training on customer data. That distinction — free consumer account versus licensed business account — is the single most important thing your policy needs to communicate, and it’s the part employees almost never know.

Beyond training, there’s retention. Even when a vendor doesn’t train on your input, they may retain conversation logs for a period for abuse monitoring and support. Your policy should assume that anything typed into a third-party AI tool has left your control and may sit on someone else’s infrastructure for weeks or months. For a construction firm summarizing a subcontractor bid, that’s probably tolerable. For a law firm pasting client communications, it is not.

We cover the technical side of tenant configuration and data boundaries in our cybersecurity services, but the policy has to come first. Controls without stated rules leave your team guessing.

The privilege and PHI problem

Two verticals need to be more careful than everyone else, and both are heavily represented among Atlanta-area SMBs.

Law firms and attorney-client privilege

Privilege protects confidential communications between attorney and client. Disclosing that communication to a third party can waive it. Whether pasting a privileged document into a public AI tool constitutes disclosure to a third party is an open question that courts and bar associations are still working through — several state bars have issued guidance urging caution and requiring lawyers to understand where the data goes before using these tools on client matters.

For a firm of 25 to 100 attorneys and staff, the practical answer is straightforward: no client-identifying content, no matter facts, and no draft work product into any AI tool that hasn’t been vetted and contractually covered. Redacted hypotheticals and general legal research questions are a different category, and your policy should say so explicitly rather than leaving associates to guess. See our notes for legal practices for more on how this interacts with your existing confidentiality obligations.

Medical and dental practices under HIPAA

Protected health information pasted into a general-purpose AI tool is a disclosure to a business associate — except that a free consumer chatbot is not your business associate, has not signed a BAA, and will not sign one. That makes it an impermissible disclosure under the Privacy Rule, and potentially a reportable breach depending on scope and content.

The scale here is worth being honest about. A single employee summarizing a batch of patient messages could put hundreds of records in front of an unvetted vendor. For a practice in the 25–300 employee range, breach notification, an OCR inquiry, and the associated legal and remediation work is a serious, budget-visible event, and it starts with something that felt like a two-minute productivity shortcut. Our healthcare guidance goes deeper on where AI can and can’t sit in a clinical workflow.

Your one-page policy: a template outline

Keep it to a single page. A 14-page policy nobody reads protects nothing. Here’s the structure we use with clients.

1. Scope. Who this applies to (employees, contractors, temps) and what it covers (any generative AI tool, on any device, used for company work — including personal accounts on personal laptops).

2. Approved tools. Name them. “Microsoft Copilot in our tenant” and “[specific tool] for [specific purpose]” is far more useful than “approved AI tools.” If the list is short, that’s fine — say so.

3. Never paste this. The hard-ban list. Make it concrete and vertical-specific:
– Protected health information or anything that identifies a patient
– Client names, matter details, or privileged communications
– Social Security numbers, financial account numbers, payment card data
– Employee HR records, compensation, or investigation files
– Source code, proprietary designs, or CAD files
– Anything under NDA or covered by a customer contract’s confidentiality clause
– Credentials, API keys, or configuration files

4. Generally fine. People need permission, not just prohibition. Public marketing copy, general research questions, meeting agendas, first drafts of internal documents, formatting and rewriting work you’ve already de-identified.

5. Human review required. Anything client-facing, anything going into a legal filing or medical record, anything with numbers in it. AI output is a draft, never a final answer, and never a substitute for professional judgment. Name the person accountable for review.

6. Disclosure. When AI-assisted work must be flagged — to clients, in filings, in deliverables where a contract requires it.

7. Who to ask. One name or one email address for “can I use it for this?” questions. Ambiguity is what drives people to just try it and find out.

8. Consequences. Brief and proportionate. The goal is compliance, not fear.

Rolling it out without killing adoption

Announce the policy alongside the approved tool, not before it. A policy that only says no reads as a ban; a policy that says “here’s what you can use, and here’s where the line is” reads as enablement.

Pair it with 30 minutes of live training. Show two real examples — one appropriate use and one that crosses the line — using scenarios from your own business. A construction office manager summarizing an RFI thread is a good yes. The same manager uploading a signed subcontract with pricing terms is a no. People remember examples; they don’t remember bullet lists.

Then check your work. Shadow-AI discovery tooling can show which AI services your network is actually reaching, and Microsoft 365 audit logs will show Copilot usage inside your tenant. Review it quarterly. If a tool keeps appearing that isn’t on your approved list, that’s a signal your sanctioned option isn’t meeting a real need — not necessarily that someone is being reckless.

Revisit the policy every six months. AI vendor terms change, new tools appear inside software you already own, and your own comfort level will shift as you get experience. A policy from 18 months ago is probably wrong about at least one product’s data handling.

Where to start

If you don’t have anything written down today, start with the hard-ban list. It’s the highest-value 20 minutes you’ll spend on AI governance, and it’s the part your team can act on immediately.

Century Solutions Group has helped Atlanta-area firms in law, healthcare, construction, and professional services put AI acceptable-use policies in place and pair them with tooling that makes the rules enforceable rather than aspirational. If you want a second set of eyes on a draft, or you’d like to know what AI tools your network is already reaching, reach out for a short discovery call. We’ll walk your current state, flag the gaps that matter for your vertical, and give you a one-page starting draft you can put in front of your team — no obligation to buy anything.

Book a Free IT Consultation

Try Our Free, No Obligation 30-Minute Cyber Security Consultation

Book a Free IT Consultation

Please complete the form and we will be in touch.

Menu