An AI usage policy is a short written rule set naming which AI tools people can use for work, what data they can’t put into them, and who checks the output before it goes out. Most guides answer this for a company with a legal team and an HR department, prescribing a 10-section governance document. For a business of one to five people, that document will never get written, and if it is, it will never get read twice. The version worth building is the one short enough that it actually survives contact with a Tuesday.

Every existing template answers the wrong scale

Search for an AI policy template and nearly everything that comes back assumes an organization with HR, legal review, and a compliance function checking a “consequence ladder” for violations. That’s the right document for a company large enough to have those functions β€” one detailed SMB-focused guide even recommends keeping it under three pages as its idea of lean. It’s the wrong document for a freelancer or a 3-person team, for the same reason a 10-page NIST-aligned risk framework is the wrong onboarding doc for a new part-time contractor. The gap between those two situations is exactly what our piece on shadow AI for small business covers on the risk side; this one covers the fix.

The headline data point used to justify all of these templates comes from IBM’s 2025 Cost of a Data Breach Report (Ponemon Institute, 600 breached organizations, average breach cost $4.44 million): organizations with high shadow AI use paid $670,000 more per breach than those with low or no shadow AI use, and 63% of the breached organizations had no AI governance policy at all, or one still in draft. That’s real, and it’s the correct evidence that governance gaps cost money. It is also a study of organizations large enough to suffer a multimillion-dollar breach in the first place β€” not evidence that a solo operator needs the same 10-section document those companies were missing. The finding that transfers down is narrower: having something written, reviewed regularly, beats having nothing, at any size.

What the templates agree on (so you don’t have to read ten of them)

Strip the legal boilerplate out of the SMB-focused guides, the enterprise frameworks, and the one publicly funded government template in this space, and the substance converges on five things:

AreaWhat it actually needs to say
Approved toolsName the specific tools and tiers people can use for work β€” not “AI,” specific product names and whether it’s the free, personal-paid, or business tier
Prohibited dataName what never goes into any of them β€” client names, contract terms, financial figures, anything under an NDA, anyone’s personal information
Review requirementState that a human checks AI output for accuracy before it’s sent, published, or acted on β€” this is also where disclosure requirements under things like the EU AI Act’s transparency rules get named if any of your output reaches EU users
Reporting lineSay, in one sentence, who a person tells if they think they made a mistake β€” even if the answer is “you, to yourself, in writing”
Review datePut a date on the policy and a note of what changed last time, so it’s obviously not abandoned the moment it’s written

Australia’s government-run National AI Centre policy guide and template is worth a look specifically because it’s one of the only genuinely free, non-sales-pitch templates in this space β€” most of what ranks for “AI policy template” exists to sell a training platform or a compliance tool underneath it.

The one-screen version β€” for when the 3-page template is still too long

Even the SMB-specific guides that recommend “keep it under three pages” are writing for a business with at least a few employees to coordinate. If it’s genuinely you, or you plus one or two people, three pages is still a document nobody reopens. Here’s a version built to fit on one screen, adapted from the five areas above:

AI Use β€” [Business name], reviewed [date]
Approved: [ChatGPT Business / Claude for Work / etc.] β€” no free personal accounts on client work.
Never goes into any AI tool: client names, contract terms, financial numbers, anyone’s personal data, anything under NDA.
Everything an AI tool produces gets checked by a human before it’s sent or published β€” no exceptions for “it looked fine.”
If something goes wrong: write down what happened the same day, fix what can be fixed, don’t wait to mention it.
Next review: [date, 6 months out].

Five lines. If you use subcontractors, add their names to the “approved tools” line and send it to them directly rather than assuming a verbal mention counts β€” this is the same one-line-in-every-contract move recommended in the shadow AI piece, just written out as its own document instead of buried in a contract clause.

Rolling it out so it actually gets followed

Writing the five lines is the easy part. Getting a subcontractor or a co-founder to actually follow them takes a little more than sending a document once:

  • Send it, don’t just post it. A policy sitting in a shared drive folder gets read once, if that. Send the five lines directly in the message where you’re onboarding someone to a project, every time β€” repetition is what makes it stick, not where it’s filed.
  • Name the tool, not the category. “Use AI responsibly” means nothing to a subcontractor with their own personal ChatGPT habit. “Use the Claude for Work account I’ll send you a login for β€” not your personal account” is a rule someone can actually follow or break, which is the whole point of writing it down.
  • Make the approved option easier than the workaround. If your business-tier account is slower to log into than someone’s personal free account, the policy loses to convenience every time. This is the same lesson Okta’s own security lead drew from enterprise shadow AI data β€” a rule with no easy-to-use alternative just pushes the behavior out of sight rather than stopping it.
  • Revisit it out loud, not just on paper. At the six-month review, actually ask whoever’s using AI tools on your work whether the approved list still matches what they’re reaching for. A policy that’s drifted silently out of date is worse than no policy, because it creates false confidence that something is being managed.

Where this connects to the tools you’re actually choosing

The “approved tools” line only works if you’ve actually decided what counts as approved, which usually comes down to a free-versus-paid-tier decision β€” covered in more depth in our guide to what’s worth paying for β€” and, if any part of the work involves an AI agent acting on your behalf rather than just drafting text, what that agent is and isn’t safe to do unsupervised, which our AI agents guide covers separately. If you’re picking that initial tool list from scratch rather than trimming an existing one, our small business AI toolkit and our AI tools for freelancers guide are both built around the same approved-versus-everything-else split this policy needs. If you’re building this alongside a broader plan for the business itself, it belongs next to the plan covered in our guide to writing a business plan with AI, not as an afterthought once something’s already gone wrong.

Who can skip this entirely

If you’re the only person who will ever touch your business’s AI tools, you never handle another person’s confidential material, and you’re not planning to bring on a subcontractor, a formal written policy is optional β€” the discipline matters more than the document. The moment a second person, even a part-time subcontractor, touches client work with an AI tool, write the five lines down. Verbal agreements about data handling don’t survive being repeated three times.

Do I actually need a written AI policy if it’s just me?

Not urgently. The discipline behind the policy β€” knowing which tool you’re using for what, and keeping confidential material out of free consumer accounts β€” matters more than the document itself when you’re the only person involved. Write it down the moment a second person, even a part-time subcontractor, starts using AI tools on your work.

What’s the actual minimum an AI usage policy needs to cover?

Five things: which tools are approved, what data never goes into them, a human-review requirement before output is used, who gets told if something goes wrong, and a review date. Everything else in the longer enterprise templates is scaffolding for organizations big enough to need it.

Does a one-page policy actually hold up if something goes wrong?

It demonstrates you had a rule and it was known, which is the substance behind IBM’s finding that governance gaps β€” not document length β€” correlate with worse outcomes. A one-page policy that’s actually followed does more than a ten-page one that sits unread in a drive folder.

Should the policy ban free-tier AI tools outright?

Not necessarily β€” free tiers are fine for public-facing brainstorming or drafts that never touch confidential material. The line to draw is by data, not by tool: anything touching client confidentiality or personal information should default to a paid, business-tier account with training turned off; general drafting doesn’t need that overhead.

How often should the policy actually be reviewed?

Every six months is a reasonable default for a small business, or immediately after adding a new tool, taking on a subcontractor, or any near-miss worth learning from. The review date is also what signals to a client or an insurer that the document is a living rule rather than something written once and forgotten.

Where can I find a free AI policy template that isn’t a lead magnet for a compliance tool?

Australia’s National AI Centre publishes a free, government-produced guide and template with no product attached to it, which is unusual in a space where most search results exist to sell training platforms or governance software underneath the template.

Shurah is the founder of AI Tools Daily, tracking pricing, licensing and policy changes across AI tools so readers can make decisions without wading through marketing claims themselves.