Build a Team AI Policy
A simple, one-page AI usage policy template for your team or small business — what's allowed, what's not, and how to keep data safe.
Why you need this
Teams using AI need clear guidelines. Without a policy, people either avoid AI entirely (missing the benefits) or use it recklessly (pasting confidential data into public tools). A simple one-page document prevents both problems.
Step 1. Define scope
- •List which AI tools are approved (e.g., ChatGPT, Claude, Copilot).
- •List which tasks can use AI (drafting, research, coding) and which cannot (legal advice, medical advice, anything requiring professional judgement).
- •Keep it short — one page max.
Step 2. Set data handling rules
- •No customer PII in public AI tools (don't paste names, emails, addresses, or financial data into ChatGPT, Claude, or Gemini).
- •No confidential company data (financials, strategy, client lists).
- •For sensitive work, use approved tools only or local AI (like Ollama).
Step 3. Set disclosure requirements
When must employees disclose AI use?
- •Client-facing work: always disclose.
- •Internal documents: not required but recommended.
- •Code: add a comment noting AI assistance.
- •Be clear about when AI output is presented as human work vs. AI-assisted.
Step 4. Set quality standards
- •AI output must be reviewed by a human before use.
- •Fact-check all claims and statistics.
- •Verify code runs correctly before deploying.
- •Spell-check and tone-check written content.
- •The employee is responsible for the final output, not the AI.
Step 5. Template policy
Provide a copy-paste template for your team to adapt.
Policy Template
AI Usage Policy — [Company Name]. Approved tools: [list]. Permitted tasks: [list]. No customer or confidential data in public AI tools. All AI output must be reviewed by a human before use. Client-facing AI content must be disclosed. Questions: contact [manager]. Review date: [quarterly].
Step 6. Implementation
- 1.Review the policy with your team in a short meeting.
- 2.Get sign-off from key people.
- 3.Train staff on approved tools and prompt patterns.
- 4.Review quarterly and update as tools evolve.
- 5.A policy that isn't communicated doesn't exist.
Quick Tips
- •Keep it simple — one to two pages maximum.
- •Don't ban AI but guide it.
- •Align with existing data protection policies.
- •Update the policy as tools change.
- •Keep the approved tools list current.
- •Consider a simple approval process for new tools.
Need More Help?
StarCaller Academy offers 1-to-1 sessions to help you with any of these topics and more.