Your team is already using AI. The rules are the part that's missing.
Banning it doesn't work — people just stop telling you. What works is a short set of rules covering which tools are approved, what can go into them, and what has to stay out, plus enough training that staff remember it.
You're probably here because of one of these.
Client data is going into chatbots
Somebody pasted a contract into a free AI tool to summarize it. You found out by accident.
A customer asked about your AI use
It showed up in a contract or a questionnaire, and you didn't have an answer.
Staff are asking what's allowed
People want to use these tools properly and nobody has told them where the line is.
Everything included.
- A written AI use policy in plain language — short enough that people read the whole thing
- An approved tools list, with the reasoning for each approval so you can decide on new ones yourself
- Clear rules on what data must never go into a public AI tool, written for your business specifically
- Disclosure guidance — when AI use has to be told to clients, and how to word it
- Review steps for AI output that affects a customer, a hiring decision, or anything with legal weight
- A quick inventory of the AI tools already in use, including the ones you didn't know about
- A 45-minute training session for your team, with a one-page summary they keep
- Contract language for vendors who are quietly adding AI features to products you already buy
Start to finish.
What's in use
A short survey and a look at your tool spend. There is always at least one nobody mentioned.
Where the lines go
We agree what's approved, what's restricted, and what's off limits. Your call, my recommendation.
The policy
Drafted, reviewed with you, revised. Short. If it takes more than ten minutes to read, it fails.
Train the team
One session, real examples, and a one-pager. Policies nobody was taught are decoration.
Flat for most small businesses. It goes up if you're in a regulated field, if AI is inside your own product, or if you have staff in the EU and the AI Act is genuinely in scope.
Start hereAsked often enough to write down.
Isn't this just a ChatGPT ban?
No, and bans are why this keeps failing. A ban pushes usage onto personal accounts where you have no visibility at all. The policy defines approved tools and safe use so people stay in the open.
Does the EU AI Act apply to us?
Usually not, for a small US business with no EU customers. If you do sell into the EU, the transparency rules and the high-risk rules have different timelines and I'll walk you through which touches you. I'd rather tell you it doesn't apply than sell you compliance you don't need.
Our vendors are adding AI features. Does that count?
Yes, and it's the part most policies miss. Your CRM or helpdesk quietly turning on an AI feature means your data may be going somewhere new. The policy covers how to handle that, and you get contract language for it.
Do you build the AI tools too?
Yes, separately — see AI agents & tools. They're deliberately different engagements. Policy first is usually the right order.
How is this different from a free template?
A template doesn't know which tools your staff are actually using, what your client contracts say about confidentiality, or which of your workflows would break under a strict rule. Those three things are the whole job.
Find out what's already in use.
Most businesses are surprised by the inventory alone. Start with the form and we'll go from there.
Get in touch