Justin McKelvey

Justin McKelvey

Fractional CTO · 15 years, 50+ products shipped

• AI for Business • 9 min read •

The One-Page AI Acceptable Use Policy I Give Clients (2026): Approved Tools, Three Data Classes, One Sign-Off Rule

TL;DR: Your team is already using AI at work. The question is whether it's on accounts you control. A one-page AI acceptable use policy fixes that with three parts: the approved tool, named in the first line (the business-tier plan you actually pay for, like ChatGPT Business, Claude Team, Microsoft 365 Copilot, or Gemini in Google Workspace); three data classes, green, yellow, and red; and one sign-off rule, where a person approves anything AI-written before it reaches a customer. The full template is below. Copy it, fill in the blanks, and get it signed this week. Prices and vendor terms are as of September 2026.

Why enterprise AI policy templates don't fit a small business

Search for an AI acceptable use policy template and you'll find good documents written for a different company. The pages that rank come from security vendors, a state IT department, a university consultancy, and a legal publisher. They cover risk committees, procurement reviews, and model audits. They're built for an organization with a security team and a legal department.

A 12-person company has neither. What it has is an office manager pasting a customer's paperwork into a free chatbot because it's faster, and an owner who finds out six months later. If a policy takes longer than two minutes to read, nobody follows it. A policy nobody follows is decoration.

So the version I give clients fits on one page and does three jobs. It names the tool, sorts the data, and puts a person in front of anything that leaves the building.

Shadow AI: your team is already using it

Shadow AI is employees using AI tools for work without the company knowing or approving them. Personal ChatGPT accounts. Free browser extensions that read your inbox. AI note-takers someone added to client calls. AI features switched on inside apps you already pay for.

The pages that rank for "shadow AI" are mostly security vendors, and their answer is detection software. For a company of 5 to 50 people, the cheaper fix is boring: pay for the tool. People use personal accounts because the company never gave them a good one. Ban AI without an alternative and the pasting moves to their phones, where you'll never see it.

Here's what the approved alternative costs as of September 2026:

  • ChatGPT Business: $20 per user per month billed annually, $25 monthly, 2-user minimum, and no training on your business data by default, per OpenAI. The seat math is on ChatGPT Business pricing.
  • Claude Team: $20 per seat per month billed annually, $25 monthly, for teams of 2 to 150.
  • Microsoft 365 Copilot Business: $21 per user per month on an annual subscription ($18 for annual subscriptions bought July 1 to December 31, 2026), added to a Microsoft 365 business plan.
  • Gemini in Google Workspace: included in the business plans, which run $7, $14, or $22 per user per month with a one-year commitment.

For a 10-person team that's about $200 a month, or nothing extra if the Gemini in your Workspace plan does the job. Compare that to a customer's information sitting in an account that walks out the door with the employee.

The one-page AI acceptable use policy template

Copy everything between the two lines. The blanks are in brackets.


[Company name] AI Acceptable Use Policy

Effective: [date]. Owner: [name]. Next review: [date six months out].

1. Approved tools. Company work goes into [ChatGPT Business / Claude Team / Microsoft 365 Copilot / Gemini in Google Workspace], signed in with the company account we give you. That is the only approved AI tool for company work. Personal AI accounts, free or paid, are for personal use. Want to use a different AI tool, browser extension, or meeting note-taker for work? Ask [owner] first. You'll get an answer within five business days.

2. Three data classes.

  • Green: public. Anything already on our website, in our marketing, or that you'd be fine posting publicly. OK in any approved tool.
  • Yellow: internal. Drafts, internal documents, meeting notes, our pricing and processes, and customer names and conversations. Approved tools only, signed in to the company account. Never in a personal account.
  • Red: restricted. Social Security numbers, bank and card numbers, health information, passwords and API keys, employee HR and payroll records, and anything a contract or NDA says we can't share. Not in any AI tool unless [owner] has approved that specific use in writing.

3. One sign-off rule. AI drafts, a person approves. Nothing AI-written goes to a customer, gets published, gets signed, or moves money until the person sending it has read all of it and would stand behind it as if they wrote it. The only exception is an automated workflow [owner] has approved in writing after it ran cleanly under review. "The AI wrote it" is never the explanation.

4. If something goes wrong. If Red data went into an AI tool, or an AI tool did something it shouldn't have, tell [owner] the same day. Reporting a mistake never gets you in trouble. Hiding one does.

5. When you leave. Your company AI account closes with the rest of your company accounts. Company work stays with the company.

I've read this policy and I'll follow it. Name: ____________ Date: ____________


How to set your three data classes

The template's examples cover most service businesses, but spend ten minutes making them yours. There's one test for every item: if this showed up somewhere it shouldn't, would I have to call a customer, a lawyer, or a regulator? If yes, it's Red. If it would just be embarrassing, it's Yellow. If nobody would care, it's Green.

Two edge cases trip people up. Customer names and email threads are Yellow, not Red, because putting them into an approved business-tier tool is exactly how AI helps with customer email. And health, legal, and financial records stay Red until you've checked your vendor's terms for your industry. For health information that usually means a business associate agreement, which is its own conversation. I covered what that looks like on one platform in is Claude HIPAA compliant.

Why the first line names the tool you pay for

Most templates say "use only company-approved AI tools" and stop there. That sentence does nothing. Nobody knows which tools are approved, so "approved" becomes whatever the employee already has open.

Naming the plan changes behavior. "Company work goes into ChatGPT Business, signed in with your company account" is a sentence someone can follow at 4:45 on a Friday. It also forces the owner to actually buy the plan, which is the real point, because the business tiers are where the data terms live. OpenAI says ChatGPT Business has no training on your business data by default. Google's Workspace privacy hub says your content isn't "used for Generative AI model training outside your domain without permission." A personal account gives you neither promise, and no admin who can shut it off. If you haven't picked the tool yet, best AI for small business picks by what you already run.

The sign-off rule, and why there's only one

Enterprise policies list a dozen review requirements. A small business needs one, and it's the same default I build into AI installs: AI drafts, a person approves, and nothing reaches a customer without a human yes until that workflow has proven itself.

The rule works because it doesn't create a new job. The person who sends the email already owns the email. The rule just makes it clear that AI doesn't change that. It also catches the failure that hurts small businesses most, a confident wrong answer in front of a customer, which is one of the patterns in why AI implementations fail.

If you write grants, the funder may already have a rule of its own. NIH says it will not treat applications substantially developed by AI as the applicant's original work, and NSF encourages you to disclose how AI was used. What that means for a small nonprofit's workflow is in AI grant writing.

Rolling it out in one week

  1. Monday: buy the business-tier plan, or confirm your Workspace or Microsoft 365 plan includes the AI you're approving, and set up company accounts.
  2. Tuesday: fill in the blanks and adjust the data class examples for your business.
  3. Wednesday: 20 minutes with the team. Read it together, answer questions, collect signatures.
  4. Thursday: ask everyone to stop using personal AI accounts for work and move anything they need onto the company account.
  5. Friday: put the six-month review on the calendar. Vendors change plans and terms often enough that the tool line will need updating.

A policy tells people what not to do. It doesn't show them what to do instead, and a team that only hears "don't" goes back to doing everything by hand. Pair the policy with one real workflow and a 60-minute working session, the way I lay it out in how to train your team on AI.

A customer security questionnaire may ask about AI certifications next. For a company that uses AI tools rather than building them, the honest answer is this policy plus your vendors' own certifications: Anthropic and Microsoft both list ISO/IEC 42001 on their compliance pages. When a certificate is worth paying for is covered in AI governance certification.

What this one page doesn't cover

One page is a floor, not a compliance program. If you're in a regulated industry, handle health or financial records at scale, or have customers who send you security questionnaires, you'll need more, and your lawyer should read the final version. What the one page does is close the gap most small businesses actually have right now: people using AI for work with no approved tool and no rules.

If you operate in Texas, one law already sits under this page. TRAIGA took effect January 1, 2026 with no small-business exemption. For most private companies it is a short list of things you may not build AI to do on purpose, plus a disclosure duty for health care, enforced only by the attorney general after a 60-day chance to fix the problem. The plain-English version is in TRAIGA, the Texas AI law.

If you want to know where your business stands before you write anything, the free AI Readiness Checklist is 30 yes-or-no questions, and you don't need to give an email to answer them. If you want the whole picture, meaning which tool to standardize on, which workflows to start with, and what the rules should be for your team, that's the AI Readiness Assessment: $2,500 flat, a written roadmap in two weeks, and the fee is credited in full against an install within 90 days. It isn't a governance program. If that's what you need, I'm the wrong person, and I'll tell you so.

This policy is one page of a handbook. If nobody in the company owns the handbook, the part-time option and what it costs next to a full-time HR manager (a $149,280 BLS median before benefits) is in fractional HR.

The policy says what's allowed. The Trust Rules say who approves what before it reaches a customer. Free template, plus a 30/60/90 plan. Get the Trust Rules template →

This policy is the part of AI governance your employees read. The rest (who owns AI decisions, the tool inventory, the quarterly check) is the framework around it, and how NIST's four functions and the EU AI Act's dates translate to a company your size is in AI governance framework.

Nonprofits can use this policy as written: swap "customer" for "donor" and "client", and add donor records and case files to the red list. Which AI tools a nonprofit can get free or at $8 a seat, and where they help most, is in AI for nonprofits.

Free Resource Justin McKelvey

Get the Free AI Content Toolkit

The exact system I use to turn one idea into a month of content: atomization framework, voice template, prompt library, weekly system.

Frequently Asked Questions

What is an AI acceptable use policy?
An AI acceptable use policy is a short set of rules for how people at your company use AI tools for work, including generative AI chatbots like ChatGPT, Claude, Copilot, and Gemini. It says which tools are approved, what information can and can't go into them, and who reviews AI-generated work before it's used. Enterprise versions run many pages. For a business under about 50 people, one page covering approved tools, data classes, and a sign-off rule does the job, because it's short enough that people read it and follow it.
What should an AI acceptable use policy include?
Five things, in this order: the approved tools, named specifically (for example ChatGPT Business, Claude Team, Microsoft 365 Copilot, or Gemini in Google Workspace, on company accounts); data classes that say what can go into those tools, with examples for public, internal, and restricted information; a sign-off rule that a person reviews anything AI-written before it reaches a customer, gets published, or moves money; how to ask for a new tool; and what to do if restricted data was pasted by mistake. Add an owner, an effective date, a review date, and a signature line.
Does a small business need an AI policy?
Yes, if anyone on the team uses AI for work, which in 2026 is almost every team. The risk isn't exotic: an employee pastes a customer list or a contract into a personal AI account the company doesn't control. A one-page policy plus a paid business-tier tool fixes most of it. As of September 2026, ChatGPT Business and Claude Team are both $20 per user per month billed annually, and Gemini is already included in Google Workspace business plans from $7 per user per month.
What is shadow AI?
Shadow AI is employees using AI tools for work without the company knowing or approving them: a personal ChatGPT account, a free browser extension that reads email, an AI note-taker someone added to client calls. It's the AI version of shadow IT. In small businesses it's rarely malicious; people are trying to get work done faster. The fix that works is giving them an approved tool on a company account plus a short policy, because a ban with no paid alternative just moves the pasting to personal phones.
Can employees use their personal ChatGPT account for work?
Only for public information, under the policy on this page. OpenAI's business pricing FAQ says its Go, Free, and Plus plans are designed for individuals, while ChatGPT Business ($20 per user per month billed annually as of September 2026) has no training on your business data by default and gives the company admin control. When an employee leaves, a personal account leaves with them, chat history included. Company work belongs on the company account.
Who should approve AI-generated work?
The person who sends it. The sign-off rule in this policy says nothing AI-written reaches a customer, gets published, gets signed, or moves money until the person responsible has read all of it and would stand behind it as if they wrote it. That keeps accountability where it already is instead of creating an AI review committee a small business doesn't have time for. The one exception is an automated workflow the policy owner has approved in writing after it ran cleanly under review.
Is there a free AI acceptable use policy template for a small business?
Yes, the one on this page, free to copy and use as-is. It fits on one page: the business-tier AI tool you pay for named in the first line, three data classes (green, yellow, red) with examples, and one sign-off rule for anything AI-written that reaches a customer. Fill in the blanks, spend ten minutes making the data examples yours, and have everyone sign it. Most free templates that rank are written for enterprises with a security team and a legal department; this one is written for a company of 5 to 50 people.
Is there an AI policy template for nonprofits?
Yes, this one works for a nonprofit with two changes. Swap "customer" for "donor" and "client", and add donor records, client case files and anything health-related to the red list, so they never go into a personal AI account. Keep the approved tool on a business plan your organization controls (as of September 2026, ChatGPT Business and Claude Team are both $8 a user a month for eligible nonprofits), and extend the sign-off rule to funders: a person checks every number in a grant or impact report before it goes out.

More on AI for Business

ChatGPT Business vs Plus (2026): Which One a Small Business Should Actually Pay For

ChatGPT Plus vs Business, as of September 2026: Plus is $20 a month for one person and OpenAI may train on your chats unless you opt out; Business is $20 a seat billed annually or $25 monthly, two seats minimum, with no training by default, admin controls, shared projects for groups, and the Company Knowledge plugin. The side-by-side from OpenAI's pages, and three owner scenarios with a verdict each.

6 min

ChatGPT for Customer Service (2026): What Works, What Breaks, and What It Costs a Small Business

ChatGPT for customer service, as of September 2026: it drafts replies, answers policy questions from your own documents, and triages an inbox for $20 to $25 a seat a month on ChatGPT Business. It can't look up an order, issue a refund, or remember a customer unless you connect the system that holds them. The honest capability line, the plan you need, a setup in six steps, the failure modes, and the point where a real agent takes over.

7 min

ChatGPT Pulse (2026): What It Was, Why OpenAI Retired It, and How to Get the Morning Brief for Your Business

ChatGPT Pulse, the daily research cards OpenAI previewed for Pro users in September 2025, was sunset on June 17, 2026 with a 14-day wind-down. What it did, which plans ever had it, why scheduled tasks replaced it, and how an owner rebuilds the morning brief on a Plus or Business seat without handing ChatGPT the wrong things.

7 min

AI Governance Certification (2026): Which One, What It Costs, and Whether Your Company Needs One

There are two kinds of AI governance certification: one for a person (IAPP's AIGP at $799, ISACA's AAIA and AAIR) and one for a company's management system (ISO/IEC 42001). Here is what each costs, who can sit for it, and why most companies under 200 people need neither yet.

6 min
Justin McKelvey, Fractional CTO and AI consultant in Austin, TX

Written by

Justin McKelvey

Fractional CTO & AI consultant in Austin, TX. 15 years building software, 50+ products shipped, $53M+ in client revenue generated. I help $1M–$50M founders ship production software and automate operations with AI, without hiring a full-time executive team.

Work with me

If this was useful, here are two ways I can help: