AI Governance
A Practical AI Policy for a 20-Person Company
By Shenard Byrd, FounderPublished 7 min read
Why does a small company need an AI policy at all?
Because your team is probably already using AI, whether or not anyone decided they should. In many small businesses, AI arrived through personal accounts, free tools, and browser extensions long before it arrived through a leadership decision. People use it to write emails, summarize documents, and answer questions, sometimes with client information pasted in.
That is not a reason to panic, and it is not a reason to ban AI. Bans in a small company tend to push use out of sight rather than stop it. The better response is a short, clear policy that tells people what is allowed, what is not, and who to ask. A good policy makes safe use the easy path.
A 20-person company does not need the policy a bank needs. It needs something the team will actually read, remember, and follow.
What should a small company AI policy cover?
Keep it to six parts. Each one answers a question your team is already asking, or should be.
1. Approved tools and accounts
List the AI tools the company approves and the accounts people should use. Business accounts matter because the data terms for business plans often differ from consumer plans, including whether what you enter can be used to train the provider's models. Check the terms and settings for each tool you approve. If a tool is not on the list, the answer is to ask, not to experiment with client information.
2. Information that never goes into AI
Be specific. General warnings about sensitive data do not change behavior. Name the categories people must never enter into an AI tool, even an approved one, unless leadership has approved that specific use with the right protections. For most small businesses that list includes:
- Client financial account numbers and payment details.
- Social Security numbers and other government identifiers.
- Health information about clients or employees.
- Passwords, access codes, and system credentials.
- Personnel matters such as performance issues, compensation, and discipline.
- Anything a client contract or confidentiality agreement says you must protect.
3. Work that requires human review
State plainly that a person is responsible for anything AI helps produce. Then name the work that always needs review before it leaves the company: client deliverables, anything with a number the client will rely on, anything that commits the company to a price, date, or position, and anything published under the company name. The rule I recommend is simple: if it goes outside the building, a person read it first.
4. An owner for each approved use
Every approved use of AI, such as drafting proposals or summarizing meeting notes, should have a named owner. The owner decides how the tool is used for that work, answers questions, and notices when something goes wrong. In a 20-person company this is usually the person who leads the function, not an IT specialist.
5. What clients are told
Decide when and how you will tell clients that AI supports your work. Some clients will ask, and some contracts may already address it. Your policy should give staff a consistent answer so nobody improvises one on a client call. In my experience, a clear answer builds trust, especially when it explains how a person reviews the work.
6. Reporting problems and updating the policy
Tell people what to do when something goes wrong: a wrong answer sent to a client, sensitive information entered by mistake, or a tool behaving strangely. Name who they tell, and make it safe to report. Then set a date to review the policy, at least every six months, because the tools and your use of them will change.
What does a one-page AI policy look like?
Here is an outline you can adapt. Each line becomes a short paragraph or a short list. If a section runs longer than a few sentences, it is probably trying to do too much.
- Purpose: one or two sentences on why the company uses AI and what it expects from staff.
- Approved tools: the tools, the account type, and who to ask about anything not listed.
- Never enter: the specific categories of information that never go into AI tools.
- Human review: the work that always needs a person to review it, and who that person is.
- Approved uses and owners: a short table of each approved use and the person who owns it.
- Client disclosure: the standard answer when a client asks how AI is used in their work.
- Problems and questions: who to tell, how quickly, and a commitment that honest reports will not be punished.
- Review date: when the policy will be revisited and who is responsible for updating it.
- Acknowledgment: a line each employee signs or confirms after reading it.
The approved uses in item five come from classifying your work. The Four A's, Automate, Augment, Advise, or Avoid, give you a quick way to decide which uses to approve and which to rule out. I explain them in Automate, Augment, Advise, or Avoid.
How do you roll it out without slowing the team down?
Start by finding out what people already do. Ask each team member, without judgment, which AI tools they use and for what. You will learn where the real risks are and where the useful habits are. Some of those habits belong in the policy as approved uses.
Then walk the team through the policy in a short meeting rather than an email. Explain the reasons behind each part, especially the never-enter list. People follow rules they understand far more reliably than rules they were simply handed.
Finally, make the approved path easier than the unapproved one. If the company pays for a business account with sound data terms, people will use it. If the only option is a personal free account, they will use that instead, and your policy will exist only on paper.
If you want a clear picture of current use before you write anything, an AI audit catalogs the tools already in staff hands, the information they touch, and the decisions they affect.
What is an AI policy not?
An AI policy is operating guidance. It is not legal advice, a security certification, or proof of regulatory compliance. If your business handles health information, financial accounts, or other regulated data, or if your client contracts include confidentiality terms, have counsel review how AI fits those obligations. Total Control Consulting provides operating governance, and when a question needs an attorney or a security specialist, we say so and refer it.
A policy is also not a substitute for judgment. No document anticipates every situation. The goal is a team that understands the reasons well enough to make good calls in the gaps.
Where should you start this week?
- Ask your team which AI tools they use and what they use them for.
- Write your never-enter list and share it before anything else.
- Choose one or two approved tools and set up business accounts.
- Name an owner for each use you approve.
- Put a policy review date on the calendar.
If you want help turning that into a written policy, a register of approved uses, and review steps the team will follow, that is the work of AI governance consulting. It is designed for owner-led businesses that want AI used well, not used less. If you are still deciding whether the business is ready at all, start with the AI Verdict.
Questions owners ask
Does a small business need an AI policy?
Yes, if anyone on the team uses AI tools, and in most businesses someone already does. A one or two page policy that names approved tools, off-limits information, required human review, and owners protects clients and staff without slowing the work.
What should be in a small business AI policy?
At minimum: approved tools and accounts, information that must never be entered into AI, work that requires human review, a named owner for each approved use, a standard answer for clients, and a process for reporting problems and updating the policy.
Should a small business ban AI tools?
Usually not. Bans in small companies tend to push AI use out of sight rather than stop it. A clear policy with approved business accounts gives leadership more control than a ban does.
Is an AI policy the same as legal compliance?
No. An AI policy is operating guidance. If your business handles regulated data or has confidentiality obligations in client contracts, have counsel review how your AI use fits those obligations.
