UbertAI engineering for SMEsBook an intro call
Solution

AI policy for business: written in a few hours

An AI policy for business sounds like something for large organisations with a legal department. It is not: the moment someone runs a customer email through an AI tool, you need an AI policy — whether you wrote it down or not.

And that is already happening. In almost every small business someone uses ChatGPT, Copilot or a translation tool, usually with good intentions and without asking. As long as nothing is written down, the rule in practice is: everyone decides for themselves what is allowed.

Below is what belongs in such a document, how it differs from a usage agreement and a data processing agreement, how the EU AI Act comes into it, and how to write it in a few hours. This is not legal advice. We are AI engineers, not lawyers — if something real is at stake, have a lawyer look at it.

Book an intro call Take the free AI scan
4 platforms built by us and running€110 / €165 per hour, fixed hoursInsured for professional and public liability

Why you want this on paper the moment people use AI

The trigger is almost never a fine, but an employee who meant well. The back office at an installation company pastes an aged debtor list into a free tool to turn it into a polite reminder. The work planner at a construction firm has a specification summarised. At an accounting firm a draft goes through a chat model to make the notes read better.

Nobody there is being stupid; they are doing their work faster. Only nobody told them where the line is, so there is no line. And it is not only about what goes out, but just as much about what comes back: text that sounds confident, is factually wrong, and reaches a client unchecked.

A policy is therefore mainly there to put people at ease. Someone who knows what is allowed does not have to be secretive or second-guess themselves. Not control, then, but clarity.

What belongs in an AI policy, as a minimum

A usable AI policy for a small business fits on two pages. Longer than that and it does not get read. Six parts belong in it in any case:

  • Which tools are allowed. Name them: these are approved, these are not, this is how you request a new one. A list works better than a principle, because a principle leaves everyone to do their own translation.
  • Which data may and may not go in. Concrete, in your own terms: no personal data of clients or staff, no case contents, no purchase prices or margins, no login details. Say what is allowed too, or it reads as a ban on everything.
  • Who checks the output. Per type of work: an internal email needs no check, a client letter does, a quote or a calculation always goes past someone who knows the trade. Without this the rest is worth little.
  • That a human stays responsible. What the model produces is a draft. Whoever sends it puts their name to it, exactly as with text from an intern. This is the most important sentence in the document.
  • What you do when it goes wrong. Who to tell and what happens next. Reporting must not carry a penalty, or you will hear it from the client instead.
  • Who owns it and when it gets reviewed. One name, one date. Out-of-date policy is worse than none, because people assume it still holds.

Policy, usage agreement and data processing agreement

These three get mixed up constantly, and then a company believes it is covered while there is a gap.

The policy is your internal choice: this is what we consider responsible AI use. The usage agreement is the translation to the shop floor: one page on what an employee does and does not do, often different per role — the back office needs different rules than the field engineers. That is the paper people actually read.

The data processing agreement is something else: a contract between you and a supplier about personal data that supplier processes on your behalf. You sign it with the company behind the tool, not with your own staff. Whether you need one and what has to be in it depends on what you process and with which service; that is a question for a lawyer or privacy adviser.

Short version: the policy says what you want, the usage agreement what you do, the data processing agreement governs your relationship with the supplier. None of them replaces another.

How the EU AI Act comes into it

The EU AI Act is European legislation on AI that takes effect in stages. Most SMEs do not build AI systems but use them, which is a lighter position than that of a provider. There is no need to panic.

One point touches almost every company that uses AI: AI literacy. Organisations are expected to make sure the people working with AI understand enough about what they have in their hands — what it can do, where it goes wrong, and when you should not simply take an answer at face value. That is not a certificate or a three-day course, but an explanation that fits the work someone actually does.

In practice: record who received what explanation and when, and give new joiners the same. What the law asks of your business specifically depends on your sector and your use case. We make no claims about that; it is legal territory.

How to write it in a few hours instead of a few months

Policy takes months when you start back to front: first a working group, then a template off the internet, then a debate about definitions. The other way round works better. Start with what is happening now.

  1. Step 1 — Ask around what is already being used (30 to 60 minutes). Just ask, and make clear there are no consequences. You will almost always hear about more tools than you expected. That list is the basis of your whole policy.
  2. Step 2 — Set your data line (30 minutes). Sort your types of data into three buckets: may go in, must never go in, unsure. The unsure bucket goes to your lawyer or privacy adviser; until then it counts as “not allowed”.
  3. Step 3 — Pick a check level per type of work (30 minutes). Internal text, client communication, and anything involving money or engineering. Agree who looks at it before it leaves the building.
  4. Step 4 — Write it up, on two pages (1 to 2 hours). Plain language, no glossary, no legal articles nobody will look up. Six headings: tools, data, checking, responsibility, reporting, ownership.
  5. Step 5 — Tell people rather than emailing it (30 minutes per team). With examples from their own work. Emailing it round is the same as doing nothing. Note who attended; that is your AI literacy record in one go.
  6. Step 6 — Put a review date in the diary. Revisit in six months: by then there will be different tools, new features in the packages you already run, and different habits.

What it costs

If you do it yourself, it costs a half-day of two people. That is usually the better route as well: the document gets better when it comes out of your own business.

If you do it with us, it hangs off the project you are running anyway. Our core session on your shop floor is a half-day of 4 hours and costs €596 excluding VAT and travel; a full day is €1,192. Our advisory rate is €149 per hour, travel €0.45 per kilometre. In that session we look at your processes, and AI use within them comes along naturally.

Separate policy work and the explanation to your teams come out of the same hours budget as the rest: €110 per hour for straightforward work, €165 for complex development, paid monthly in advance from an AI budget you set.

What comes on top: the legal review. We are not legal advisers, so those hours are not with us. Count on them as soon as you handle personal data or sensitive case files.

What goes wrong — and when policy does not work

Three ways this falls apart, and we see all three more often than we would like.

  • Policy nobody reads. Twelve pages, written by someone who does not do the work, emailed round on a Friday afternoon. Formally handled, in practice nothing changes. Two pages that were discussed beat twelve that were sent.
  • Bans people work around. “AI is not permitted here” rarely reduces use; it moves it to personal phones and personal accounts, out of your sight. Then you carry the risk with no overview. A short list of approved tools is safer.
  • A document that no longer fits a year later. It lists a tool you dropped, and meanwhile your package gained an AI feature nobody assessed. Without an owner and a review date, this happens every time.

Write it yourself, use a template, or call a lawyer

Writing it yourself is the sensible option for most SMEs. You know your own data and your own people, and the steps above get you to two pages in a half-day. We would rather not sell hours for something you can do better yourself.

Downloading a template helps you not to forget anything, but never produces a working document. Templates leave out precisely the things that matter to you: your packages, your data, your exceptions. Use one as a checklist, not as text.

Calling a lawyer is the answer as soon as something real is at stake: special categories of personal data, work for healthcare or government, requirements set by a client in their contract, or doubt about your data processing agreements. Then you want someone trained and insured for it. That is not us.

What we do handle is the practical part: looking at which tools are genuinely embedded in your processes, assessing which integrations send data outside, and explaining to your people what a model can and cannot do. We carry professional indemnity and public liability insurance, and a subsidy partner routinely checks whether a scheme applies. The legal review stays with a lawyer, even if you ask us to just do it anyway.

The first step

Do not start by writing. Start by asking what is already being used, with nothing attached to the answer. That half-hour gets you further than half the document.

If you want to know where AI fits in your processes first, take the free AI scan: five minutes online, a score and a few concrete opportunities. And once more: this page is not legal advice, it is how we approach it in practice.

Frequently asked questions

Does a small company really need an AI policy?

The moment anyone uses AI for work, you effectively have a policy — except right now everyone sets it themselves. Two pages make clear which tools are allowed, which data never goes in and who checks. For a company of ten people that is a half-day of work, not a project.

What is the difference between an AI policy and a data processing agreement?

An AI policy is your internal choice about responsible AI use and applies to your own people. A data processing agreement is a contract with a supplier about personal data that supplier processes for you. They do not replace one another. Whether and which agreement you need is a legal question.

Should we just ban AI outright?

That rarely works. A ban usually does not reduce use; it moves it to personal phones and personal accounts, out of your sight. Then you carry the risk with no overview. A short list of approved tools and a clear data line is safer.

What does the EU AI Act ask of a small business?

Most SMEs do not build AI systems but use them, which is a lighter position than that of a provider. The point that touches nearly everyone is AI literacy: anyone working with AI should understand what the tool can do and where it goes wrong. What the law asks of you specifically is a question for a lawyer.

Can you write our AI policy for us?

We can do the practical part: mapping which tools are genuinely in use, which integrations send data outside, and explaining to your teams what a model can and cannot do. The legal review we leave to a lawyer. We are AI engineers, not legal advisers.

How do you keep the document current?

Put one name and one date in it: who owns it and when it gets reviewed. Six months is a reasonable rhythm, because tools get added and your existing packages gain AI features nobody has assessed. Without an owner and a review date it is guaranteed to be wrong within a year.

Is this legal advice?

No. This page describes how we approach it in practice and what you want written down in any case. We make no claims about what the law requires in your situation. If something real is at stake, have your policy and your agreements reviewed by a lawyer.

What we do for this

AI guidance & training

A system nobody uses delivers nothing. That's why we don't leave your team alone with a tool: we train on the shop floor, with you

AI compliance & grants

We build with confidence because the basics are in place. For each project we record which risk class your AI application falls in

Further reading

6 min read
The EU AI Act for SMEs, without legal jargon

The AI Act hits most SMEs less hard than feared, but two things already apply: prohibited applications and AI literacy f

6 min read
GDPR and AI: what can you do with customer data?

The GDPR does not prohibit AI, but it does set requirements for purpose, legal basis and processors. Most mistakes at SM

8 min read
Is your business ready for AI? How to tell without a consultancy

You do not need a consultancy to work out whether AI is for you. Four things decide the answer, and none of them is abou

Other topics

AI implementation for small business workflow automation for small business AI consultant for small business automating quotes automating invoice processing automating customer contact having an AI agent built rolling out Copilot AI training for employees

First find out where AI sits in your processes

Take the free AI scan: five minutes online, a score and a few concrete opportunities. If you would rather talk through what is already being used, book an intro call.

Book an intro call Take the free AI scan