Small businesses are embracing AI tools faster than they can create policies to govern their use, leading to potential risks and challenges

The rapid adoption of artificial intelligence (AI) by small businesses has outpaced the development of policies to govern its use. A 2026 report by Intuit revealed that 77% of small to mid-sized businesses in the United States use AI daily.
However, many of these businesses lack clear guidelines for AI usage, leading to potential risks and challenges.
The lack of AI policies in small businesses is due in part to the incremental adoption of AI tools. As long as AI was confined to browser windows, there was no perceived need for formal rules.
However, the introduction of new external rule sets has changed this landscape. The EU’s AI Act, set to go into force on August 2, 2026, requires businesses interacting with EU users to provide notice of AI interactions and label AI-generated content.
In the United States, 47 states have enacted legislation addressing AI-generated media, creating a patchwork of regulations.
The Cost of Operating Without an AI Policy
A study by Black Fog/Sapio involving 2,000 employees from firms with over 500 employees in the US and UK found that 49% were using unapproved AI tools. Of these, 58% were using free versions of these tools, which may lack strong data controls. This ‘shadow’ AI activity can lead to various issues, including client privacy breaches, loss of brand voice, and unauthorized use of customer data.
The lack of a clear AI policy can result in employees creating their own guidelines, leading to inconsistencies and potential damage. For example, sensitive financial information may leave the owner’s control, or different employees may use separate AI ‘voices’ for writing purposes, none of which are affiliated with the company. These issues are not malicious but rather a result of the void in organizational guidelines.
Creating an Effective AI Policy
An effective AI policy does not need to be complex. A one-page document with five key sections can provide clear guidelines for employees. These sections should include approved tools, data rules, disclosures, review points, and spending and audit procedures.
Approved tools should list all AI tools that employees can use, along with the accounts they have access to and the approval process for new tools. Data rules should specify what information should never be entered into AI tools, such as customer names, account information, financial data, health data, and any NDA’d data. Disclosures should establish how often customers are informed about AI interactions and where labels should be placed on AI-generated content.
Review points should determine what work always gets human eyes before shipping, covering all customer-facing content, quotes, and anything legal or medical. Spending and audit procedures should put all AI costs into one budget line with a cap and check against monthly spend versus what those tools produced.
Implementing and Maintaining the AI Policy
Implementing an AI policy should start with amnesty, allowing employees to disclose the AI tools they are using without penalty. This information can be used to develop the five sections of the policy with the team present. Employees who have been using these tools will know where the real questions are and can provide valuable insights.
The policy should be reviewed quarterly to keep up with new tools and changing rules. A one-page AI policy reviewed four times per year will remain relevant, while a ten-page policy that has never been reviewed is likely to be ignored. Small businesses have an advantage in developing an AI governance framework quickly, allowing them to begin using it soon after creation.
The compliance case for an AI policy receives media coverage, but the sales case may be more important. Larger clients may require proof of AI governance, making a clear policy a selling point. The one-page policy can also serve as a sales document, demonstrating the business’s commitment to responsible AI use.
