Most small businesses using AI have no written rule about it at all — someone started using ChatGPT for emails, someone else started using it for social posts, and nobody ever decided what's actually okay to paste into it. That gap is where mistakes happen: a staff member pastes a customer's phone number and order history into a chatbot to "summarize it," not realizing that data just left the building. You don't need a lawyer or a 20-page policy to close that gap. You need four decisions and a page to write them on. Thirty minutes, start to finish.
1. Decide what data is off-limits
This is the most important decision on the page. Be specific and err on the side of caution. At minimum, this should include: customer names paired with contact details, financial information, health information, employee personal records, and anything a customer shared with you in confidence. Under Canada's private-sector privacy law (PIPEDA), businesses are expected to protect personal information and only use it for the purpose it was collected for — pasting a customer's details into a public AI tool to "help write an email" is not a use they agreed to, and most AI tools' terms allow that pasted data to be stored or used to improve the model. When in doubt, strip out names and identifying details before you paste anything in.
2. Decide who can use AI for what
Not every tool needs to be locked down to one person, but write down, plainly, who's allowed to use AI and for which tasks — e.g., "front desk staff can use AI to draft email replies to general questions; nobody uses AI to draft anything involving a specific customer's personal or financial details." This avoids both extremes: total free-for-all, or nobody using a genuinely useful tool out of vague nervousness.
3. Set a human-review rule
Every single thing an AI tool produces that a customer, client, or the public will see should be read by a person first. Not skimmed — read. AI tools confidently state things that are wrong, out of date, or off-brand, and a customer won't know or care that "the AI wrote it." The rule is simple: no AI output goes out the door unreviewed.
4. Decide when to disclose AI use
You don't need to caption every social post "written by AI," but decide now, calmly, rather than in the middle of a complaint later. A reasonable default: disclose when AI played a substantial role in something customers might reasonably assume was fully human — a detailed personalized recommendation, for instance — and don't bother disclosing routine use like drafting a generic social caption. Write your own line for this; there's no universal right answer, but there needs to be a answer.
Copy this template
Fill in the blanks and you have a working one-pager:
You can also ask an AI tool to help you tailor it:
Local example: a Yorkton accounting office
Say you run a small bookkeeping office in Yorkton. One staffer had started using a free AI chatbot to draft client emails, occasionally pasting in real account numbers to "make the email specific." Nobody had told her not to — it just hadn't come up. After a 30-minute team meeting using this template, the office landed on: no client financial identifiers ever get pasted into any AI tool, general correspondence drafting is fine for any staff member, and the office manager reads anything AI-drafted before it's sent to a client. Nothing dramatic changed day to day — but the gap that could have caused a real problem was closed in half an hour.
Watch out for
A policy nobody's read isn't a policy. Walk your team through it out loud, post it somewhere visible, and revisit it every few months as you adopt new tools — this is guidance to get you organized quickly, not a substitute for professional legal advice on privacy obligations specific to your industry.
Do this now
Book 30 minutes with anyone on your team who touches AI tools, fill in the template together, and print one copy for the wall.
Want us to map this out for your business? Tell us your goal →