Reasoning Frameworks

Home / Insights / Policy

Policy

A Free AI Policy Starter for Small Teams

Your team is already using AI. The only question is whether they’re doing it with a shared understanding of what’s okay — or quietly guessing, one prompt at a time. A short, plain-English policy fixes that, and you don’t need a legal department to write one.

I hear the same worry from clinic managers, dental office leads, nonprofit directors, and family-business owners: “I don’t want to ban this stuff, but I also don’t want someone pasting a patient’s chart into a chatbot.” That instinct is exactly right. The goal of an AI use policy isn’t to lock people down — it’s to give good people clear guardrails so they can use these tools confidently, without lying awake wondering if they crossed a line.

A policy also protects the people you serve. A physiotherapy patient, a family in your donor database, a client whose contract you’re drafting — none of them agreed to have their information handed to a tool nobody vetted. A one-page policy is how you keep that promise on purpose instead of by luck.

Why a small team needs one — even a team of five

Big companies write AI policies because their legal teams make them. Small teams often skip it because it feels like overkill. But small teams are precisely where an unwritten rule falls apart: everyone assumes everyone else knows the boundaries, and no one actually does. The front-desk coordinator, the part-time bookkeeper, the volunteer running your newsletter — each brings their own idea of “safe.” A policy replaces six private guesses with one shared answer.

It doesn’t have to be long. One page that people actually read beats twelve pages that live in a shared drive nobody opens.

What to include

A useful policy answers five plain questions. Keep the language human — this is a working agreement, not a contract.

  • Approved tools. Name the specific tools your team may use, and say that anything not on the list needs a quick okay first. A short, current list beats a vague “use good judgment.”
  • What data may — and may not — go in. Be concrete. No patient records, no donor financials, no client contracts, no passwords, no anything that identifies a real person, into any tool unless it’s an approved, protected one. General questions and de-identified drafts are fine.
  • Human review. Nothing AI produces goes out the door — to a patient, a client, a donor, or a regulator — without a person reading it first and owning it. AI drafts; a human decides.
  • Client and patient disclosure. Decide when you’ll tell the people you serve that AI helped, and be honest about it. A dental practice using AI to draft appointment reminders may not need to announce it; a counselor summarizing a session should think harder.
  • Who owns it. Name one person responsible for keeping the policy current and answering questions. Tools change monthly; the policy needs a steward.

A copy-paste starter policy

Take the lines below, swap in your details, and you have a real first draft. Say it in your own voice — it should sound like your team, not a template.

  • We use AI to help us serve people better and to give our team time back — never to replace human judgment or care.
  • Approved tools are: [list your tools here]. To use anything else for work, ask [owner’s name] first.
  • We never put personal, confidential, or identifying information — patient records, client details, donor data, financials, passwords — into a tool that hasn’t been approved and protected for that purpose.
  • A person always reviews and approves anything AI helps produce before it reaches a patient, client, donor, or the public. The person who sends it owns it.
  • We are honest about our use of AI. When it materially shapes advice or communication with someone we serve, we’re prepared to say so.
  • [Owner’s name] keeps this policy current and is the person to ask when something isn’t clear. When in doubt, ask before you paste.

How to roll it out in a week

You don’t need a committee. You need five short steps.

  • Day 1 — Draft. Paste the starter above into a doc and fill in your tools, your owner, your specifics. Fifteen minutes.
  • Day 2 — Sanity-check. Read it against your real workflows. A retail shop, a law office, and a nonprofit will each tweak the data rules differently. Cut anything that doesn’t fit.
  • Day 3 — Talk it through. Spend ten minutes at a team huddle explaining the why, not just the what. People follow rules they understand.
  • Day 4 — Post it. Put it where work happens — pinned in your team chat, taped by the front desk, linked in onboarding. If it’s buried, it’s gone.
  • Day 5 — Set a review date. Add a calendar note for 90 days out. Tools shift fast; a policy that never gets revisited slowly stops being true.

That’s it. A page, a conversation, and a place to keep it. You’ve now given your team permission to use AI well and a clear line they won’t cross by accident — which is the whole point. People before tools means protecting your people from the awkward gray zone, not just protecting the organization from risk.

If you’d like a second set of eyes on your draft, or help tailoring it to your sector — health and wellness, medical and dental, nonprofit, family business, retail, or professional services — that’s exactly the kind of thing a short discovery call is for. No hard sell, just a clear look at what fits your team.

Let's talk

Ready to bring AI into your organization — without losing the people?

Book a free 30-minute discovery call. No jargon, no hard sell — just a clear look at where AI could help, and where it shouldn't.