# AI guidelines for [Company name]

A one-page policy for how we use AI. Fill in the blanks in [square brackets], delete anything that
does not apply, and share it with everyone.

- **Version:** [1.0]
- **Adopted on:** [date]
- **Policy owner:** [name, role]
- **Next review:** [date, no more than three months from adoption]

Template published by ExponenLabs: https://www.exponenlabs.tech/pulse/ai-guidelines-for-smes
This is a starting point, not legal guidance. If you work in a regulated sector, have a lawyer read
it before you adopt it.

---

## 1. Why we have this

We want everyone to use AI where it helps, without guessing what is allowed. These guidelines say
which tools we use, what data can go into them, what a person must still check, and who is
responsible when something goes wrong.

They apply to everyone who works for or with [Company name], including contractors, and to every
AI tool, model, agent or automation we use.

## 2. Approved tools

Use only the tools on this list for work. If you want to use something new, ask [policy owner]
first. We would rather add a good tool than have people use it quietly.

| Tool | Approved for | Data allowed (see section 3) | Account type | Owner |
| --- | --- | --- | --- | --- |
| [Tool name] | [e.g. drafting, research, coding] | [Green / Amber] | [Company business account] | [Name] |
| [Tool name] | [ ] | [ ] | [ ] | [ ] |
| [Tool name] | [ ] | [ ] | [ ] | [ ] |

- Use company accounts, never personal ones, for work.
- Check that each tool's business terms say our data is not used to train its models, or record
  here that we have accepted that it is: [notes].

## 3. Data boundaries

| Class | Examples | Rule |
| --- | --- | --- |
| **Green** (public or low risk) | Published marketing copy, public docs, general questions | Any approved tool. |
| **Amber** (internal) | Internal documents, code, non-personal business data, [add] | Approved tools marked Amber only, on company accounts. |
| **Red** (restricted) | Customer personal data, health or financial records, passwords and keys, anything under NDA, [add] | Not in any AI tool unless [policy owner] has approved that specific use in writing. |

If you are not sure which class something is, treat it as Red and ask.

Never paste passwords, API keys or access tokens into any AI tool.

## 4. Human review

AI can draft. A named person decides.

- A person must read and approve AI output before it goes to a customer, a supplier, the public or
  a regulator.
- A person must approve any AI action that spends money, changes a price, changes a contract, or
  deletes or changes customer data.
- Code written by AI is reviewed like any other code. Someone on the team must be able to explain
  what every merged change does.
- Things AI may do without review: [e.g. internal summaries, first drafts, tagging tickets].
- The person who approves AI output is responsible for it, exactly as if they had written it.

## 5. Agent register

Every AI agent or automation that runs by itself goes in this register before it goes live. If it is
not in the register, it does not run.

| Agent / automation | What it does | Systems and data it can access | Spend cap (per run / per day / per month) | Step or call limit | Owner | How to stop it | Last reviewed |
| --- | --- | --- | --- | --- | --- | --- | --- |
| [Name] | [ ] | [ ] | [ ] / [ ] / [ ] | [ ] | [Name] | [ ] | [date] |
| [Name] | [ ] | [ ] | [ ] / [ ] / [ ] | [ ] | [Name] | [ ] | [date] |

The owner is one person, not a team. If the owner leaves, the agent is paused until a new owner is
named.

## 6. Spend caps and kill switch

- Every agent has a per-run cap and a per-day cap, not only a monthly budget.
- Anything that loops has a limit on steps or tool calls per run.
- Alerts go to the agent's owner by name, on a device they will see: [how].
- Anyone on this list can stop any agent at any time, without asking first: [names].
- The way to stop an agent is written in the register and takes under a minute: [e.g. revoke its key
  in the gateway, switch off the scheduled job].
- Company-wide monthly AI budget: [amount]. Owner: [name].

## 7. Telling customers

- We tell people when they are talking to an AI rather than a person.
- We tell customers when AI plays a meaningful part in a decision about them, and how to reach a
  person instead: [how].
- We do not present AI-generated content as a person's own words or experience.
- Our privacy notice says which AI providers process customer data: [link].
- Some laws, including the EU AI Act, require some of these disclosures. Check which apply to us:
  [notes].

## 8. Incident reporting

An AI incident is anything where AI caused, or nearly caused, harm: wrong information sent to a
customer, data put into the wrong tool, an agent that spent or did more than it should, a biased or
offensive output.

- Report it to [name / channel] as soon as you notice, even if you are not sure it counts.
- If it is still happening, stop the agent first (section 6), then report.
- Nobody is blamed for reporting. We want to hear about near misses too.
- [Policy owner] records each incident, what caused it and what changed: [where the log lives].
- If personal data is involved, [name] decides within [24 hours] whether we must notify anyone.

## 9. Review cadence

- [Policy owner] reviews these guidelines and the agent register every [three months], and after
  any serious incident.
- Each agent owner confirms their entries in the register are still true at every review.
- Changes are shared with everyone, with a short note on what changed and why.

---

- **Agreed by:** [name, role]
- **Date:** [date]
