Justin McKelvey
Fractional CTO · 15 years, 50+ products shipped
The One-Page AI Acceptable Use Policy I Give Clients (2026): Approved Tools, Three Data Classes, One Sign-Off Rule
TL;DR: Your team is already using AI at work. The question is whether it's on accounts you control. A one-page AI acceptable use policy fixes that with three parts: the approved tool, named in the first line (the business-tier plan you actually pay for, like ChatGPT Business, Claude Team, Microsoft 365 Copilot, or Gemini in Google Workspace); three data classes, green, yellow, and red; and one sign-off rule, where a person approves anything AI-written before it reaches a customer. The full template is below. Copy it, fill in the blanks, and get it signed this week. Prices and vendor terms are as of September 2026.
Why enterprise AI policy templates don't fit a small business
Search for an AI acceptable use policy template and you'll find good documents written for a different company. The pages that rank come from security vendors, a state IT department, a university consultancy, and a legal publisher. They cover risk committees, procurement reviews, and model audits. They're built for an organization with a security team and a legal department.
A 12-person company has neither. What it has is an office manager pasting a customer's paperwork into a free chatbot because it's faster, and an owner who finds out six months later. If a policy takes longer than two minutes to read, nobody follows it. A policy nobody follows is decoration.
So the version I give clients fits on one page and does three jobs. It names the tool, sorts the data, and puts a person in front of anything that leaves the building.
Shadow AI: your team is already using it
Shadow AI is employees using AI tools for work without the company knowing or approving them. Personal ChatGPT accounts. Free browser extensions that read your inbox. AI note-takers someone added to client calls. AI features switched on inside apps you already pay for.
The pages that rank for "shadow AI" are mostly security vendors, and their answer is detection software. For a company of 5 to 50 people, the cheaper fix is boring: pay for the tool. People use personal accounts because the company never gave them a good one. Ban AI without an alternative and the pasting moves to their phones, where you'll never see it.
Here's what the approved alternative costs as of September 2026:
- ChatGPT Business: $20 per user per month billed annually, $25 monthly, 2-user minimum, and no training on your business data by default, per OpenAI. The seat math is on ChatGPT Business pricing.
- Claude Team: $20 per seat per month billed annually, $25 monthly, for teams of 2 to 150.
- Microsoft 365 Copilot Business: $21 per user per month on an annual subscription ($18 for annual subscriptions bought July 1 to December 31, 2026), added to a Microsoft 365 business plan.
- Gemini in Google Workspace: included in the business plans, which run $7, $14, or $22 per user per month with a one-year commitment.
For a 10-person team that's about $200 a month, or nothing extra if the Gemini in your Workspace plan does the job. Compare that to a customer's information sitting in an account that walks out the door with the employee.
The one-page AI acceptable use policy template
Copy everything between the two lines. The blanks are in brackets.
[Company name] AI Acceptable Use Policy
Effective: [date]. Owner: [name]. Next review: [date six months out].
1. Approved tools. Company work goes into [ChatGPT Business / Claude Team / Microsoft 365 Copilot / Gemini in Google Workspace], signed in with the company account we give you. That is the only approved AI tool for company work. Personal AI accounts, free or paid, are for personal use. Want to use a different AI tool, browser extension, or meeting note-taker for work? Ask [owner] first. You'll get an answer within five business days.
2. Three data classes.
- Green: public. Anything already on our website, in our marketing, or that you'd be fine posting publicly. OK in any approved tool.
- Yellow: internal. Drafts, internal documents, meeting notes, our pricing and processes, and customer names and conversations. Approved tools only, signed in to the company account. Never in a personal account.
- Red: restricted. Social Security numbers, bank and card numbers, health information, passwords and API keys, employee HR and payroll records, and anything a contract or NDA says we can't share. Not in any AI tool unless [owner] has approved that specific use in writing.
3. One sign-off rule. AI drafts, a person approves. Nothing AI-written goes to a customer, gets published, gets signed, or moves money until the person sending it has read all of it and would stand behind it as if they wrote it. The only exception is an automated workflow [owner] has approved in writing after it ran cleanly under review. "The AI wrote it" is never the explanation.
4. If something goes wrong. If Red data went into an AI tool, or an AI tool did something it shouldn't have, tell [owner] the same day. Reporting a mistake never gets you in trouble. Hiding one does.
5. When you leave. Your company AI account closes with the rest of your company accounts. Company work stays with the company.
I've read this policy and I'll follow it. Name: ____________ Date: ____________
How to set your three data classes
The template's examples cover most service businesses, but spend ten minutes making them yours. There's one test for every item: if this showed up somewhere it shouldn't, would I have to call a customer, a lawyer, or a regulator? If yes, it's Red. If it would just be embarrassing, it's Yellow. If nobody would care, it's Green.
Two edge cases trip people up. Customer names and email threads are Yellow, not Red, because putting them into an approved business-tier tool is exactly how AI helps with customer email. And health, legal, and financial records stay Red until you've checked your vendor's terms for your industry. For health information that usually means a business associate agreement, which is its own conversation. I covered what that looks like on one platform in is Claude HIPAA compliant.
Why the first line names the tool you pay for
Most templates say "use only company-approved AI tools" and stop there. That sentence does nothing. Nobody knows which tools are approved, so "approved" becomes whatever the employee already has open.
Naming the plan changes behavior. "Company work goes into ChatGPT Business, signed in with your company account" is a sentence someone can follow at 4:45 on a Friday. It also forces the owner to actually buy the plan, which is the real point, because the business tiers are where the data terms live. OpenAI says ChatGPT Business has no training on your business data by default. Google's Workspace privacy hub says your content isn't "used for Generative AI model training outside your domain without permission." A personal account gives you neither promise, and no admin who can shut it off. If you haven't picked the tool yet, best AI for small business picks by what you already run.
The sign-off rule, and why there's only one
Enterprise policies list a dozen review requirements. A small business needs one, and it's the same default I build into AI installs: AI drafts, a person approves, and nothing reaches a customer without a human yes until that workflow has proven itself.
The rule works because it doesn't create a new job. The person who sends the email already owns the email. The rule just makes it clear that AI doesn't change that. It also catches the failure that hurts small businesses most, a confident wrong answer in front of a customer, which is one of the patterns in why AI implementations fail.
Rolling it out in one week
- Monday: buy the business-tier plan, or confirm your Workspace or Microsoft 365 plan includes the AI you're approving, and set up company accounts.
- Tuesday: fill in the blanks and adjust the data class examples for your business.
- Wednesday: 20 minutes with the team. Read it together, answer questions, collect signatures.
- Thursday: ask everyone to stop using personal AI accounts for work and move anything they need onto the company account.
- Friday: put the six-month review on the calendar. Vendors change plans and terms often enough that the tool line will need updating.
A policy tells people what not to do. It doesn't show them what to do instead, and a team that only hears "don't" goes back to doing everything by hand. Pair the policy with one real workflow and a 60-minute working session, the way I lay it out in how to train your team on AI.
What this one page doesn't cover
One page is a floor, not a compliance program. If you're in a regulated industry, handle health or financial records at scale, or have customers who send you security questionnaires, you'll need more, and your lawyer should read the final version. What the one page does is close the gap most small businesses actually have right now: people using AI for work with no approved tool and no rules.
If you want to know where your business stands before you write anything, the free AI Readiness Checklist is 30 yes-or-no questions, and you don't need to give an email to answer them. If you want the whole picture, meaning which tool to standardize on, which workflows to start with, and what the rules should be for your team, that's the AI Readiness Assessment: $2,500 flat, a written roadmap in two weeks, and the fee is credited in full against an install within 90 days. It isn't a governance program. If that's what you need, I'm the wrong person, and I'll tell you so.
Get the Free AI Content Toolkit
The exact system I use to turn one idea into a month of content — atomization framework, voice template, prompt library, weekly system.
Frequently Asked Questions
- What is an AI acceptable use policy?
- An AI acceptable use policy is a short set of rules for how people at your company use AI tools for work, including generative AI chatbots like ChatGPT, Claude, Copilot, and Gemini. It says which tools are approved, what information can and can't go into them, and who reviews AI-generated work before it's used. Enterprise versions run many pages. For a business under about 50 people, one page covering approved tools, data classes, and a sign-off rule does the job, because it's short enough that people read it and follow it.
- What should an AI acceptable use policy include?
- Five things, in this order: the approved tools, named specifically (for example ChatGPT Business, Claude Team, Microsoft 365 Copilot, or Gemini in Google Workspace, on company accounts); data classes that say what can go into those tools, with examples for public, internal, and restricted information; a sign-off rule that a person reviews anything AI-written before it reaches a customer, gets published, or moves money; how to ask for a new tool; and what to do if restricted data was pasted by mistake. Add an owner, an effective date, a review date, and a signature line.
- Does a small business need an AI policy?
- Yes, if anyone on the team uses AI for work, which in 2026 is almost every team. The risk isn't exotic: an employee pastes a customer list or a contract into a personal AI account the company doesn't control. A one-page policy plus a paid business-tier tool fixes most of it. As of September 2026, ChatGPT Business and Claude Team are both $20 per user per month billed annually, and Gemini is already included in Google Workspace business plans from $7 per user per month.
- What is shadow AI?
- Shadow AI is employees using AI tools for work without the company knowing or approving them: a personal ChatGPT account, a free browser extension that reads email, an AI note-taker someone added to client calls. It's the AI version of shadow IT. In small businesses it's rarely malicious; people are trying to get work done faster. The fix that works is giving them an approved tool on a company account plus a short policy, because a ban with no paid alternative just moves the pasting to personal phones.
- Can employees use their personal ChatGPT account for work?
- Only for public information, under the policy on this page. OpenAI's business pricing FAQ says its Go, Free, and Plus plans are designed for individuals, while ChatGPT Business ($20 per user per month billed annually as of September 2026) has no training on your business data by default and gives the company admin control. When an employee leaves, a personal account leaves with them, chat history included. Company work belongs on the company account.
- Who should approve AI-generated work?
- The person who sends it. The sign-off rule in this policy says nothing AI-written reaches a customer, gets published, gets signed, or moves money until the person responsible has read all of it and would stand behind it as if they wrote it. That keeps accountability where it already is instead of creating an AI review committee a small business doesn't have time for. The one exception is an automated workflow the policy owner has approved in writing after it ran cleanly under review.
More on AI for Business
ChatGPT for Nonprofits (2026): $8 Business Seats, Up to 75% Off Enterprise, and How to Get Approved
ChatGPT for nonprofits as of September 2026: eligible nonprofits get ChatGPT Business Standard seats for $8 a user a month billed annually or $10 monthly, Premium seats aren't discounted, and larger organizations can get up to 75% off Enterprise through sales. Why you'll see 20%, 60%, and 75% quoted, how verification works, what 10 seats cost, and the first workflows worth setting up.
ChatGPT Work for Business (2026): What It Does, What a $20 Seat Gets, and the First Jobs I'd Hand It
ChatGPT Work is OpenAI's agent for multi-step jobs: decks, spreadsheets, briefs, and scheduled reports built from your apps and files. As of September 2026 it's included in every ChatGPT Business seat, metered on the same 5-hour allowance as Codex. What it does, which plans get it, what it burns, the admin settings to flip on day one, and the first five jobs I'd give it.
ChatGPT Usage Limits (2026): What Plus, Pro, and Business Actually Get, and the 5-Hour Window
ChatGPT usage limits as of September 2026: everyday text chat is unlimited on every plan, and the limits that actually run out are reasoning models, GPT-6 Pro messages, and the shared ChatGPT Work and Codex allowance on 5-hour windows. Plan by plan for Free, Go, Plus, Pro, and Business Standard and Premium seats, from OpenAI's own help center.
Copilot vs ChatGPT (2026): Which One Your Business Should Actually Pay For
Copilot vs ChatGPT for a business, as of September 2026: Microsoft 365 Copilot is $21 a user a month on top of a Microsoft 365 Business plan ($18 first-year promo), and ChatGPT Business is $20 a seat billed annually on its own. Where each one wins, what 10 people really pay, the data-boundary difference, and how I'd pick.
Written by
Justin McKelvey
Fractional CTO & AI consultant in Austin, TX. 15 years building software, 50+ products shipped, $53M+ in client revenue generated. I help $1M–$50M founders ship production software and automate operations with AI — without hiring a full-time executive team.
Work with meIf this was useful, here are two ways I can help:
Before you go
Score your AI readiness in 3 minutes.
Free, no call. 30 yes/no questions show where AI actually pays off in your business — and where it doesn't yet.
Get my readiness score →