An AI policy template for small teams (that people will actually follow)
You do not need a twelve-page AI policy written by lawyers. You need a short, plain set of rules your team will actually follow: what is fine to do with AI, what is never fine, and how to handle client and attendee data. Here is a template you can adapt in an afternoon, written for small teams rather than enterprises.

Why a short policy beats a long one
A long policy sits in a folder nobody opens. A one-page policy gets read, remembered, and followed. The goal is not to cover every edge case; it is to give your team a clear line they can apply without asking. Two good rules that people follow beat twenty that they ignore.
The template
Copy this, change the specifics to fit your team, and share it. Five sections is enough.
What AI is for
Name the approved uses: drafting, summarizing, brainstorming, formatting, analyzing survey data, first-pass copy. Make it clear AI is a normal part of the work, not a gray area.
What always needs a human review
Anything attendee-facing or client-facing gets read by a person before it ships. AI drafts; a human approves. Same standard you would apply to a new hire's work.
What never goes into an AI tool
No attendee personal data, no signed contracts or confidential terms, no payment details, no anything covered by a client NDA, unless you are using an approved tool with the right data agreement. When in doubt, leave it out.
Which tools are approved
List the specific tools the team may use for work, and who to ask before adding a new one. This keeps a pile of random subscriptions from becoming a data problem.
Who owns it
Name the person who answers questions and updates the policy. A policy with no owner goes stale the first time a new tool appears.
The data rule, in plain language
The one rule that matters most: do not paste anything into a public AI tool that you would not paste into a public document. Attendee lists, contract terms, and anything under an NDA stay out unless you are on an approved tool with a data-processing agreement. This single line prevents the incident that turns leadership against AI overnight.
Roll it out with training, not email
A policy sent as an email attachment gets skimmed once. Walk the team through it in five minutes during a regular meeting, tie it to the workflows they are already using, and it sticks. It fits naturally into an AI training rollout.
Frequently asked questions
- What should a small team's AI policy include?
- Five things: the approved uses of AI, what always needs human review before it ships, what data must never go into an AI tool, which tools are approved, and who owns the policy. One page is enough for most small teams.
- What data should never be put into AI tools?
- Attendee or client personal data, signed contracts and confidential terms, payment details, and anything under an NDA, unless you are using an approved tool with a data-processing agreement. The simple rule: do not paste anything you would not put in a public document.
- Do small teams really need an AI policy?
- Yes, but a short one. Two or three clear rules that people follow prevent the single data incident that can end AI use on a team. It does not need to be a legal document; a one-page plain-language version is enough.
Set the guardrails, then move fast
A short policy is step one. The AI Readiness Sprint helps a team put the guardrails and the workflows in place together.
See the AI Readiness Sprint