An employee wants help drafting a customer reply. Another wants to summarize meeting notes. Someone else has connected an AI tool to a work account. Before those decisions become office habits, the business owner needs a shared set of rules.
A useful AI acceptable-use policy tells people what they may do today and how to ask about something new. For a small office in Polson, a Lake County nonprofit, or a Montana professional firm, start with a short policy people can actually follow.
Use PBM's AI Readiness Checklist to identify the decisions you already have and the questions that still need an owner. It is free to read and print; it does not collect your answers.
1. Name the approved tools and accounts
List the exact product, account type, business owner, and approved purpose. Approval for drafting public announcements should not automatically allow uploading client files or connecting the tool to email.
Require a business-managed account for approved work. Assign responsibility for adding staff, removing access, checking licenses, and reviewing changes. Ask employees to report the tools they already use; do not assume a list proves you have discovered every tool.
2. Make the data rules specific
Begin with public information and invented sample data. Write down which information must stay out of an AI tool until the responsible business and technical reviewers have approved the use.
- Never enter passwords, authentication codes, API keys, or recovery secrets.
- Keep client, patient, tax, payroll, payment, personnel, and confidential business records out of unapproved tools.
- Review the actual account, vendor terms, available settings, retention, and intended data use before approving sensitive information.
- Do not assume removing a name makes a document anonymous. Other details may still identify a person or organization.
Record the decision and its limits. This is operational guidance, not a determination that a particular use meets your legal, contractual, or professional obligations.
3. Review permissions before connecting business files
A business subscription is a starting point, not permission to connect every file. Microsoft explains that Copilot can use organizational content the signed-in user is allowed to access. Review shared-file permissions and external sharing before expanding a pilot into connected business data.
Require approval before installing an AI browser extension, connecting a mailbox, or authorizing an app to access shared storage. Write down who approved the connection, what it may read or change, and how access can be removed.
Source: Microsoft's data, privacy, and security documentation, reviewed September 28, 2026. Controls vary by product, account, and license.
4. Keep a person responsible for the final decision
Require staff to verify names, numbers, dates, citations, and instructions before using generated output. A polished answer may still be wrong. The person sending a message or approving work remains responsible for it.
Set explicit boundaries for payments, account changes, hiring decisions, and legal, financial, or clinical advice. A starter policy should prohibit autonomous actions unless a separately approved process defines controls, oversight, and responsibility.
5. Tell staff how to report a mistake
Name the person and internal channel employees should use immediately if they paste restricted information, approve an unexpected connection, or receive suspicious output. Encourage prompt reporting so the team can respond.
Stop the affected activity and contact your designated IT or security lead. Preserve the relevant time, tool, account, and event details through an approved channel; do not paste the sensitive material into another AI service while asking for help. Your response lead should decide containment, evidence handling, and any further obligations.
6. Train on one useful task, then review it
Choose a repeatable, low-risk task such as drafting a routine reply from sample information. Show staff what is allowed, how to review the output, and when to stop. Record the time spent, including corrections and human review, before deciding whether to expand.
Have employees acknowledge the approved policy. Assign a policy owner and review date. Revisit the rules when a tool, license, connection, or business use changes; review the tool register and open actions every month.
See PBM's sample monthly Managed AI Review for a fictional example of a tool register, evidence gaps, and assigned actions. It demonstrates the format and does not represent a client result.
A starter rule to adapt with your team
Use only approved AI tools and business accounts for the purposes recorded in our tool register. Use public or sample information unless the responsible owner has approved a specific data use. Check every output before relying on it. Get approval before connecting business systems or allowing automated actions. Report mistakes promptly through our designated internal channel.
Before adopting this wording, add your actual approved tools, data categories, approver, reporting contact, employee responsibilities, and review date. Your business and legal or compliance leads should resolve any obligations specific to your work.
Turn the policy into an ongoing practice
NIST's voluntary AI Risk Management Framework treats AI risk as something organizations manage through design, use, and evaluation. A policy is useful when it leads to repeatable decisions, checks, and follow-through; the document alone does not certify security or compliance.
Source: NIST AI Risk Management Framework, reviewed September 28, 2026.
PBM's Managed AI Governance & Enablement service helps small businesses define approved tools, establish practical data rules, train staff, and keep a written review with clear next actions.