An AI policy for small companies: one page is enough

A policy nobody reads changes nothing. One page with six sections that anyone can go through in five minutes changes behaviour — and covers the part that actually matters.

A clear line of light separates glowing shapes on one side from muted ones on the other
Note This piece describes a workable basic structure and is not a substitute for legal advice. Whether further obligations apply to you — from the AI Act, from industry requirements or from customer contracts — has to be assessed case by case.

In short

  • Six sections on one page are enough: accounts, prohibited inputs, the duty to check, accountability, exclusion cases, who to ask.
  • The most important section is the one on exclusion cases — phrased concretely, not as a general warning.
  • A ban with no provided business account leads to personal accounts, not to less use.
  • The policy belongs at the start of the introduction, not at the end.

Why one page

An extensive rulebook gets approved once and is not read afterwards. One page actually gets read — and only what gets read has an effect.

The brevity also forces decisions: anyone wanting to regulate everything regulates nothing bindingly. Six sections cover the cases that actually arise day to day.

The six sections

1. Which accounts

Named business accounts provided by the company. Personal accounts are excluded for work purposes.

The reason, stated in the text: on business plans, use of inputs for training is usually excluded; on personal plans it is not always.

2. What does not get entered

Personal customer data with no settled basis, credentials and keys, unpublished financial figures, documents under a confidentiality agreement.

Concrete rather than general: name examples from your own working day, not categories.

3. What always gets checked

Every verifiable detail before use: figures, studies, legal references, deadlines, prices, quotations, names.

An important addition: the confident tone of an answer says nothing about its accuracy.

4. Who is accountable

Whoever publishes or sends something is accountable for the content — regardless of how it came about. As with any other text.

5. Where it does not get used at all

Five concrete cases from your own field. The most important section — and the only one that cannot be copied.

Examples: legal information to customers with no check by an expert; topics where there is no in-house expertise; anywhere a mistake would go unnoticed.

6. Who to ask

One named person for questions and borderline cases. Without that line, everyone decides alone and differently.

Worth knowing

Section five is the only one that cannot be taken from a template — and precisely for that reason the most valuable. It demands a decision about where in your business a mistake would go unnoticed.

That question is uncomfortable, because it requires naming your own blind spots. But it is the core of any usable policy: nearly all problematic cases arise where nobody has the expertise to recognise a wrong answer as wrong.

What does not belong in it

Not in itWhy
A list of permitted productsout of date within months; better: named accounts
Prompting instructionsbelongs in the training, not in the rule
Technical explanations of how it worksinteresting, changes no behaviour
A blanket ban with no alternativeleads to personal accounts rather than to less use
A labelling duty for every usedoes not get followed; better: name accountability
From practice

The most common faulty construction is the fourth row: a ban with no usable business account in place. The result is never less use — it is use through personal accounts, with no overview and under different terms.

Anyone taking the data situation seriously therefore provides an account first and regulates afterwards. The order is decisive: account, then rule, then training — not the other way round.

How the AI Act relates to this

For most small companies using language models for texts and analysis, the AI Act creates no far-reaching obligations — they are as a rule deployers, not providers of an AI system.

It becomes relevant in three cases: if you offer an AI system yourself or substantially modify one, if you use one in an area classed as high-risk — personnel decisions, for instance — or if you operate systems interacting directly with people. In those cases the assessment belongs with an expert.

Independently of that, the AI Act expects deployers to have a minimum level of competence in handling these systems — which in practice argues for the training that is needed anyway.

Prompt
Help me phrase a one-page AI policy for our company.

Our situation:
- Industry: [details]
- People using AI tools: [number and roles]
- What they should be used for: [tasks]
- Do we work with personal data? [yes / no / partly]
- Do we have customers with confidentiality agreements? [yes/no]
- Which accounts do we provide? [details or "none yet"]
- Fields where we have no expertise ourselves but do get asked
  questions: [list]

Tasks:
1. Phrase the six sections: accounts, prohibited inputs, the duty
   to check, accountability, exclusion cases, who to ask.
   Together at most one page.
2. Phrase section 2 with concrete examples from our industry, not
   with general categories.
3. Phrase section 5 – where it does not get used at all – as five
   concrete cases. Use my list of fields where we have no
   expertise.
4. If we do not provide accounts yet: say clearly why a rule
   without a provided account does not work.
5. Name the points where, given our industry, we should bring in
   an expert.

Do not invent legal articles or deadlines.

In closing

Six sections, one page, readable in five minutes. Five of them can be phrased in half an hour; the sixth — where it does not get used at all — demands an honest look at your own blind spots and is the actual value of the document.

And the order counts: provide a usable account first, then regulate. A ban with no alternative only moves the use to where nobody sees it.

Common questions

What belongs in an AI policy?

Six sections: which accounts get used, what must not be entered, what always has to be checked, who is accountable for published content, in which concrete cases it does not get used at all, and who to ask about borderline cases. Together on one page.

Why is one page enough?

Because only what gets read has an effect. An extensive rulebook gets approved once and is not looked at afterwards. The brevity also forces decisions — anyone wanting to regulate everything regulates nothing bindingly.

Which section matters most?

The one on exclusion cases, because it cannot be taken from a template. It demands the decision about where in your own business a mistake would go unnoticed — and nearly all problematic cases arise exactly where nobody has the expertise to recognise a wrong answer as wrong.

Should you simply ban AI tools?

A ban with no provided business account leads not to less use but to use through personal accounts — with no overview and under different terms, for instance on the use of inputs for training. The sensible order is account, rule, training.

What does the AI Act mean for small companies?

Anyone using language models for texts and analysis is as a rule a deployer and not a provider — far-reaching obligations usually do not follow from that. It becomes relevant when offering or substantially modifying a system yourself, when using one in high-risk areas such as personnel decisions, and with systems that interact directly with people. Those cases belong with an expert.

Marketing that sets itself up

The Studio Engine beta is live. Claim your spot and help shape it from the start.

Join the beta →
← Back to overview