How to Write an AI Use Policy for Your Omaha Small Business (With a Free Outline)

Last reviewed: September 26, 2026

Your staff are probably already using AI. Someone pastes emails into ChatGPT to clean them up. Someone uses Copilot to summarize a meeting. Someone found a free tool that writes job posts. None of that is bad on its own. The trouble starts when nobody has written down what is okay.

A written AI use policy fixes that. It does not need to be long. It needs to be clear, and your team needs to actually read it.

Why a small business needs a written AI use policy

Without a policy, every employee makes up their own rules. Here is where that goes wrong.

Company and client data ends up in the wrong place

A free, personal AI account is controlled by the employee, not by you, and its terms are written for consumers, not for your business. Once a client file is pasted into it, the file is out of your hands.

AI gets things wrong, and sounds sure of itself

Even Microsoft says that answers from generative AI “aren’t guaranteed to be 100% factual” and that people should use their judgment before sending them on. A policy turns checking the work into a rule instead of a habit only some people have.

Clients, partners and insurers may ask

“We have a written policy, and here it is” is a much better answer than “we are still figuring it out.”

Some professions already have rules

Lawyers, for example, have ABA Formal Opinion 512, which says lawyers using generative AI must consider duties that include competence, protecting client information, and supervising their staff. Patient information needs extra care. For medical and dental offices, we help put the technical safeguards HIPAA calls for in place and keep them maintained, alongside your compliance advisor.

What goes in an AI use policy

A good small-business AI policy answers six questions:

  • Which AI tools are approved, and under which accounts?
  • What information can never go into an AI tool?
  • What can AI be used for, and what is off the table?
  • Who checks AI work before it goes out?
  • Who can connect AI to company systems, like email, files or accounting?
  • What do you do when something goes wrong?

If you want a framework behind those questions, NIST’s AI Risk Management Framework is free and voluntary, and its Generative AI Profile (NIST AI 600-1) covers risks specific to tools like ChatGPT and Copilot. You do not need to read all of it. Your policy just needs to cover the basics in plain words.

AI use policy outline template

Copy this outline into a Word document, fill in the brackets, and have the owner sign it. Aim for two or three pages.

1. Purpose and scope

  • Why this policy exists: to protect client and company information and keep our work accurate.
  • Who it covers: employees, contractors and interns.
  • What counts as an AI tool: chat tools, writing assistants, Microsoft Copilot, meeting note-takers, and AI features inside other software.

2. Approved tools and accounts

  • Approved tools: [tool name], [account type], [who may use it].
  • Use company business accounts only. No personal logins for company work.
  • Ask [name] before trying a new AI tool, app or browser extension.

3. Information that never goes into AI

  • Client, patient or student records.
  • Passwords, bank or card numbers, and Social Security numbers.
  • Employee HR, pay or medical information.
  • Anything covered by a confidentiality agreement.
  • [Add your own, such as bids, pricing or legal matters.]

4. Allowed uses

  • Drafting emails, letters and posts for a person to review.
  • Summarizing documents you are already allowed to see.
  • Brainstorming, outlines and first drafts.
  • [Add examples from your office.]

5. Not allowed

  • Letting AI make final decisions about hiring, firing, pay or credit.
  • Sending anything to a client that a person has not read first.
  • Using AI to pretend to be a real person.

6. Human review

  • The person who sends it owns it.
  • Check facts, names, numbers and quotes before anything leaves the building.
  • [State whether and when clients are told that AI helped.]

7. AI connected to company systems

  • Only [name or role] may connect AI tools to email, calendars, files or accounting.
  • AI agents follow approve-on-send: nothing is sent, paid or deleted without approval from a named person.
  • Give each AI tool only the access it needs.

8. Security

  • MFA (a second sign-in step, like a phone prompt) on every AI account.
  • Review who can open which files before turning on Microsoft Copilot.

9. Reporting problems

  • If you pasted something you should not have, or an AI tool produced or sent something wrong, tell [name] right away. Reporting is never punished.

10. Training, owner and review

  • Everyone reads this policy and completes short training when they start.
  • Policy owner: [name]. Reviewed every [6 or 12] months, and whenever we add a new AI tool.
  • Employee signature and date.

Tips for making the policy stick

  • Keep it short. A policy nobody reads protects nobody.
  • Give people a good option. An approved business tool works better than a flat “no.”
  • Train with real examples from your own office.
  • Revisit it when you add a tool, like Microsoft Copilot or an AI agent. Our Copilot readiness checklist covers what to check first.

Frequently asked questions

Do we need a policy if we are only five people?

Yes. A one-page policy is fine for a small team. What matters is that the data rules and the approved tools are written down.

Can we just ban AI?

You can, but a ban is hard to enforce and tends to push use onto personal accounts you cannot see. An approved tool with clear rules is usually the safer choice.

Is Microsoft Copilot safer than a free chat tool?

With a work account, Microsoft says prompts, responses and company data accessed through Copilot are not used to train its foundation AI models. Copilot also only shows people what they already have permission to see, which is why cleaning up file access comes first. Whatever tool you pick, use a business account and read its data terms.

Can Cambium help us write one?

Want help writing yours? Cambium Data builds AI use policies for Omaha-area offices. We start from our own template, talk with you for an hour about your tools and your data, and hand back a plain-English policy, a one-page staff summary and an acknowledgment form, usually in about two weeks. It’s a fixed price, quoted after a short call. A policy is not legal advice, so have your attorney review it, and if you handle patient records we work alongside your compliance advisor.

Policy writing is part of our AI consulting in Omaha, along with Microsoft Copilot readiness. If we also run your IT, see our managed IT services.

Not sure where to start? Talk to us at (402) 514-3200 or through our contact page, and we’ll tell you honestly whether you need either one.

See AI at work before you write the rules

The best way to decide what belongs in your policy is to see what AI can safely do in a real office. We will show you our own AI employees at work, with private details hidden, and talk through the rules that fit your team.

or call (402) 514-3200.

Cambium Data is a Navy veteran-owned managed IT company at 6542 S 118th St, Omaha, NE 68137, serving the Omaha metro since 2009. Owner Tony Underwood has over three decades of experience in IT.

Similar Posts