Writing an AI policy for your SME: what goes in it?
Updated on 29 June 2026
An AI policy is one short agreement that sets out which AI tools your team may use, which data may go into them and who stays responsible for the result. Your SME needs that agreement now, because your people are already using AI anyway, with or without your permission. One page is enough, and below is what belongs in it, plus an example you can lift straight away.
Why does your SME need an AI policy?
Because the alternative is quietly looking away, and that puts customer data into free chatbots without anyone noticing. A short agreement pulls that use out of the shadows and gives your team clarity instead of a ban that gets worked around anyway.
The much-discussed (and methodologically criticised) MIT report on AI in companies found that in over 90% of the companies studied, employees use personal AI tools for work, including where nothing is officially arranged. Anyone who asks around on the shop floor recognises the pattern: customer data in free chatbots, without a data processing agreement, out of anyone's sight. One clear page solves more than a ban does, because a ban only moves the use to the private phone.
There is a legal reason too. The duty to give your staff a basic grounding in AI has applied since February 2025, as we explained in our article on the AI Act. A policy is the natural starting point for that.
What has to be in an AI policy as a minimum?
Six agreements cover it for most SMEs: which tools are allowed, which data may go in, that a human checks every output, who carries final responsibility, when you disclose AI use, and how a new tool gets onto the list. Together they fit on one page.
- Which tools are allowed, by name. A short list you keep adding to, instead of a vague category.
- Which data may go in and which never does: personal data of customers and staff, price agreements and confidential documents stay out, unless the tool is covered by a data processing agreement.
- That a human checks every output that leaves the company: quotes, emails, reports, code.
- Who carries final responsibility: the person who sends or uses the result, never "the AI".
- When you disclose AI use to customers, candidates or colleagues.
- How a new program gets onto the list: one point of contact, a short check, a decision within the week.
Which tools do you allow and which data may go in?
The dividing line is the data processing agreement. Free tools are for public or anonymised information only. Customer and staff data belong exclusively in tools covered by a data processing agreement. Anyone unsure about a specific program asks instead of guessing.
Business subscriptions such as ChatGPT Business or Copilot with a company licence give you contractual guarantees that your data is not used as training data. Free consumer versions usually give you none. Which tools you make centrally available and how you connect them safely is exactly what we mean by AI orchestration.
Who is responsible when AI makes a mistake?
The person who used the output, never the system. That principle deserves its own line in your policy, because someone who knows they are signing off on the quote themselves will read it over.
It fits how the AI Act looks at employers: as a company you stay accountable for what your systems do, so you organise the checks on your side. That is why the human final check belongs literally in the text, so it does not depend on who happens to be paying attention that day.
How do you keep the policy alive?
By reviewing the tool list every quarter and making it easy to flag things. An AI policy ages faster than any other company document, because the offering shifts every quarter. So put a fixed moment in the calendar and tie some training to it.
- Review the tool list every quarter. Drop what nobody uses, assess what the team asks for.
- Make flagging easy. One message to whoever manages the list is enough to get something new assessed. The lower that threshold, the less happens out of sight.
- Tie training to it. Half a day a year keeps the basics up to standard and qualifies for the kmo-portefeuille, the Flemish SME subsidy scheme. If you want to go further than individual tools, read how to implement AI structurally in your business.
What does an AI policy look like in seven sentences?
Like this, short enough to fit on one screen. Copy the sentences below, change the names and the location and you are away.
- We use AI as a tool; final responsibility always lies with the colleague who uses the result.
- Approved tools are on the list at [location]; anything not on it, you do not use for work.
- Personal data, price agreements and confidential documents go only into tools on the list marked "data processing agreement".
- Everything that leaves the company is read over by a human.
- Where AI communicates directly with customers or candidates, we say so.
- New tools you report to [name]; you get an answer within the week.
- Every quarter we run through the list and the agreements in the team meeting.
Want the technical side sorted alongside the agreements, from safe AI tools to your own solution where your data stays in-house? We are happy to think it through with you in a no-obligation conversation.
Frequently asked questions
- What is an AI policy for an SME?
- It is a short agreement, often one page, that sets out which AI tools your team may use, which data may go into them and who stays responsible for the result. It is meant to pull existing use out of the shadows and give your people clarity. A thick document is not needed for that.
- Which data may you put into a free AI tool?
- Only public or anonymised information. Personal data of customers and staff, price agreements and confidential documents belong exclusively in tools covered by a data processing agreement, such as a business subscription. If you are unsure about a specific tool, ask instead of guessing.
- Who is responsible when AI makes a mistake?
- The employee who used or sent the output, never the system itself. That principle keeps the checks healthy, because someone who signs off on a quote themselves will read it over. It also fits the AI Act: your company stays accountable for what your systems do.
- Is an AI policy a legal requirement?
- A policy document as such is not written into the law. Since February 2025 the AI Act does require you to give your staff a basic grounding in AI, and a short policy is the natural starting point for that. It settles your accountability and data protection along the way.