Local Business
Shadow AI: your team is already using it, so write the one-page policy this week
Staff are pasting client emails, contracts, and spreadsheets into free AI tools. Banning it rarely works. Here is how to write a one-page AI usage policy, pick approved tools, and sort your data into classes a small team can actually remember.
Somewhere in your business this afternoon, someone is copying a client email into a free AI chatbot and asking it to write a polite reply. Someone else is pasting a spreadsheet of customer names and invoice amounts into a different one to “clean up the formatting.” Nobody asked permission, because nobody thought they needed to. The tool was free, it was in the browser, and it saved them twenty minutes.
This is shadow AI: staff using AI tools the business has not chosen, configured, or even heard about. It is the same pattern as shadow IT a decade ago, when people signed up for personal file-sharing accounts to get around a clunky server. The difference is speed. AI tools spread through a team in weeks, and what people paste into them is often the most sensitive material in the building.
The good news is that this is a policy problem before it is a technology problem, and a small business can get most of the way there with one page and one decision about tools.
Why it matters more than it looks
The risk is not that AI is dangerous in some abstract way. The risk is specific: data leaves your control and goes somewhere you have not vetted.
When someone pastes client information into a consumer AI tool on a free or personal account, a few things can be true at once. The provider’s terms may allow that input to be used to improve their models. The conversation may be stored in the employee’s personal account, which you cannot access, audit, or delete when they leave. And the account itself may be protected by a reused password and no second factor.
For a small business, that can mean client confidentiality commitments quietly broken, personal information handled in ways your privacy obligations did not anticipate, and no record of what went where. Canadian privacy law expects organizations to protect the personal information they hold and to be accountable for it when a third party processes it. “An employee pasted it into a chatbot” is not a position you want to explain to a client.
There is also a quieter risk: people trusting output they have not checked. An AI-drafted contract clause, tax summary, or client email can be confidently wrong. A policy should cover that too.
Why banning it usually fails
The instinct is to send a firm email: no AI tools, full stop. It rarely works. The tools are genuinely useful, the people using them are usually your most motivated staff, and a ban mostly teaches them to stop mentioning it. You end up with the same behaviour and less visibility.
A better approach is to give people a sanctioned way to get the benefit, draw clear lines around the data that must never go into an unapproved tool, and make the rules short enough that people remember them without looking them up.
Sort your data into three classes
Most small businesses do not need a formal data classification scheme. They need three buckets that anyone on the team can apply in two seconds.
Public. Anything already on your website, in a brochure, or that you would happily post online. Marketing copy, published prices, general industry questions. Fine in any tool.
Internal. Business information that is not secret but not public either. Internal process notes, draft job postings, meeting agendas without client names. Fine in approved tools only.
Confidential. Client names and details, personal information about anyone, financial records, contracts, health information, passwords, anything covered by a confidentiality agreement. Approved tools only, and only where the tool and account are set up for it. Never in a free or personal account.
Write those three definitions on the policy page with two or three examples each, drawn from your own business. A law office’s examples will look different from a construction firm’s, and specific examples are what make the rule stick.
Choose approved tools, not just banned ones
The policy works only if there is a yes alongside the no. For most small teams that means picking one general-purpose AI assistant on a business plan, tied to company accounts rather than personal ones.
When you evaluate options, the questions that matter are practical:
- Does the business plan state that your inputs are not used to train the provider’s models?
- Are accounts managed centrally, so you can add people, remove them, and require multi-factor authentication?
- Can you see or export activity if you need to, and does data get deleted when an account is removed?
- Where is data stored and processed, and does that matter for any of your clients?
- Does it fit the platform you already pay for? If you are on Microsoft 365 or Google Workspace, their business AI features may be the simplest place to start.
You do not need to pick the perfect tool. You need to pick a reasonable one, put it on company accounts, and tell people it exists. An approved tool that is slightly worse beats an unapproved tool that is slightly better.
The one-page policy
Here is a structure that fits on a single page. Keep the language plain and the sentences short.
- Purpose. One sentence: we want people to use AI to save time, and we want to protect client and company information while they do.
- Approved tools. List them by name, with how to get access. Anything not on the list needs a quick ask first.
- Data classes. Public, internal, confidential, with your own examples.
- The core rule. Confidential information goes only into approved tools on company accounts. Never into free or personal accounts.
- Check the output. You are responsible for anything you send, file, or publish, whether AI helped write it or not. Verify facts, figures, names, and legal or financial statements before they leave the building.
- Tell clients when it matters. If a client contract or professional standard requires disclosure of AI use, follow it.
- Ask first when unsure. Name the person to ask. Make asking easy and blame-free.
- Review date. This policy gets reviewed every six months, because the tools change that fast.
That is the whole thing. It will not cover every edge case, and it does not need to. It needs to change what people do on an ordinary Tuesday.
What to do this week
You can get from nothing to a working policy in a few days without a consultant or a committee.
- Monday: ask, without judgement. Send a short note asking which AI tools people use and what for. Make it clear nobody is in trouble. You will learn more in one honest reply than in a month of guessing.
- Tuesday: pick the approved tool. Based on what people are actually doing, choose one business-grade assistant. Check the data-use terms on the business plan.
- Wednesday: draft the page. Use the structure above. Fill in your own examples for each data class.
- Thursday: set up accounts. Company accounts, multi-factor authentication on, access limited to the people who need it.
- Friday: walk the team through it. Fifteen minutes in a meeting. Show the approved tool, read the core rule aloud, and answer questions.
Then follow up in a month. Ask what is working, what is awkward, and whether anyone has hit a situation the policy does not cover. Adjust.
Where this fits
An AI usage policy is one page within a broader set of house rules. If you do not yet have the rest, our guide to a security policy for a small team covers the other pages worth writing, and the same principle applies to AI meeting-note tools, which record some of your most sensitive conversations.
If you want help deciding where AI genuinely earns its place in your business before you pick tools, the AI readiness sprint is built for exactly that question.
Write us a short brief about how your team uses AI today, and we will reply in writing within one business day.