All of Pulse

AI guidelines for SMEs: a one-page policy you can adopt today

ExponenLabs7 min read

Most small companies have no written AI rules. That is understandable. The tools arrived faster than anyone could write a policy, and long policy documents are written for companies with legal teams.

But no rules has a cost. Some people avoid AI because they are not sure it is allowed. Others paste customer data into a personal chat account because nobody said not to. And somewhere an automation someone set up last spring is still running, spending money, with nobody watching it.

This is a policy that fits on one page. It covers the eight things we think every company of 5 to 200 people should decide. It is written to be adopted as it is, then adjusted. You can download the fill-in-the-blanks version and edit it in any text editor.

It is a starting point, not legal guidance. If you work in a regulated sector, have a lawyer read it.

The one-page policy

Below is the policy itself, followed by why each section is there.

1. Approved tools

We use only the AI tools on the approved list for work, on company accounts. Anyone can ask to add a tool. [Policy owner] decides, usually within a week.

The list records, for each tool: what it is approved for, which class of data may go into it, and who owns the account.

2. Data boundaries

All data is Green, Amber or Red.

  • Green — public or low-risk. Any approved tool.
  • Amber — internal documents, code, non-personal business data. Approved tools marked for Amber, on company accounts.
  • Red — customer personal data, health or financial records, passwords and keys, anything under NDA. Not in any AI tool unless [policy owner] has approved that specific use in writing.

If unsure, treat it as Red. Never put passwords, keys or tokens into an AI tool.

3. Human review

AI can draft. A named person decides. A person reads and approves AI output before it reaches a customer, a supplier or the public, and before any AI action that spends money, changes a price or a contract, or changes customer data. Code written by AI is reviewed like any other code. The person who approves AI output is responsible for it.

4. Agent register

Every AI agent or automation that runs by itself is in the register before it goes live. For each: what it does, what it can access, its spend and step limits, its one named owner, how to stop it, and when it was last reviewed. If it is not in the register, it does not run. If its owner leaves, it is paused until a new owner is named.

5. Spend caps and kill switch

Every agent has a per-run and per-day spend cap, not only a monthly budget. Anything that loops has a limit on steps. Alerts go to the owner by name. Named people can stop any agent, at any time, without asking, in under a minute.

6. Telling customers

We tell people when they are talking to an AI. We tell customers when AI plays a meaningful part in a decision about them, and how to reach a person. We do not present AI-generated content as a person's own words or experience.

7. Incident reporting

Anything where AI caused or nearly caused harm is reported to [name or channel] straight away. If it is still happening, stop the agent first. Nobody is blamed for reporting, and near misses count.

8. Review cadence

[Policy owner] reviews this policy and the agent register every three months, and after any serious incident. Changes are shared with everyone.

Why each section is there

Approved tools is first because it is the easiest win. Most of the risk in small companies comes from personal accounts and unknown tools, not from the approved ones. A short list, with a fast way to add to it, keeps people on the tools you have checked without pushing anyone underground. Check each tool's business terms for whether your data is used to train its models. Business plans often differ from consumer ones, and the difference matters.

Data boundaries use three colours because people will remember three. The detail lives in the downloadable version. The rule that matters most is the default: if unsure, it is Red.

Human review is where accountability lives. The sentence doing the work is the last one: whoever approves AI output owns it, as if they had written it. That stops "the AI said so" from ever being an answer. For software teams, we go further in our AI-native SDLC playbook: nothing merges unless a person on the team can explain it.

The agent register is the section we would keep if we could only keep one. An agent that runs by itself — a scheduled job, a support bot, a workflow that updates your CRM — can fail quietly and expensively. The register makes sure every one of them has a person attached. The "paused if the owner leaves" rule sounds harsh. It is the rule that catches the automation everyone forgot about.

Spend caps and a kill switch belong in policy, not just in engineering, because a monthly budget only trips after the money is gone. Per-run and per-day caps, and step limits on anything that loops, are what actually stop a runaway. We explained how to pick the numbers in What a sane agent spend cap looks like.

Telling customers is about trust first and law second. Finding out afterwards that you were dealing with an AI feels like being misled, even when the answer was right. Some laws, including the EU AI Act, also require you to tell people when they are dealing with an AI system, so check which apply to you.

Incident reporting only works if people are not punished for using it. The no-blame line is there on purpose. You want to hear about the near miss while it is still small.

Review cadence is short because AI changes quickly. A policy written today will be partly wrong in six months — a new tool, a new model, a new use. Three months is frequent enough to keep up and rare enough that it actually happens.

How to adopt it this week

  1. Name the policy owner. One person, with the authority to approve tools and stop agents.
  2. Fill in the approved tools list with what people already use. You will learn something.
  3. Fill in the agent register. Ask every team what runs by itself. Put a cap and an owner on each, or switch it off.
  4. Agree the Red list for your business. Add anything specific to your customers or contracts.
  5. Share it with everyone, with a short note: this is what is allowed, and here is who to ask.
  6. Put the first review in the calendar, three months from today.

In a small company, most of this fits in an afternoon. The agent register is the step that usually takes longest, and the one most worth doing.

What a policy does not do

A policy says what is allowed. It does not decide where AI should be used in your business, which tools are right for which job, or how to build the workflows that make it worth it. Those are the decisions an AI leader makes.

In a company without that person, the policy tends to be written once and then drift. That is part of what a Fractional CAIO owns: the policy, the agent register and the decisions that sit around them, kept current as the business and the tools change.

Frequently asked questions

Does a small business need an AI policy? Yes, and a short one. Without it, people either avoid AI or use it with the wrong data on the wrong accounts.

What should it include? Approved tools, data boundaries, human review, an agent register with owners, spend caps and a kill switch, customer disclosure, incident reporting and a review cadence.

What is an agent register? A single list of every agent or automation that runs by itself, with what it does, what it can access, its limits, its owner, how to stop it and when it was last reviewed.

Who should own the policy? One named senior person who can approve tools and stop an automation. Often the founder or head of operations, or a Chief AI Officer where AI is being adopted business-wide.

Working with us

The template is free to copy, change and use, with or without us: download the AI guidelines template. If you want someone senior to own the policy and the decisions around it, the Fractional CAIO page explains how that seat works.

Ready to find out what AI can actually do for your business?

Book a free 30-minute call. If we are not the right fit, we will tell you that too.

Book a Free CTO Call