lyuata.
Field notes · AI adoption · 30 August 2026

The One-Page AI Usage Policy Your Company Actually Needs

An AI usage policy for a small business needs exactly five things, and they fit on one page: a short list of approved tools, a hard list of data that must never be pasted into any AI tool, a rule that work happens on company accounts rather than personal ones, a named owner who approves new tools, and a review date so the document stays alive. That is the whole policy. Everything longer is usually a legal document nobody reads, and everything shorter is usually a vague statement of values that nobody can act on. The point of the one-pager is that a new hire can read it in three minutes and know, for any tool and any piece of data, whether they are allowed to do the thing they are about to do.

Why does the policy need to exist at all?

Because your team is already using AI, with or without you. The pattern I call shadow ChatGPT looks the same everywhere: someone pastes a customer email into a free chatbot to draft a reply, someone else summarizes a contract, a third person uploads a spreadsheet of leads. None of them are acting in bad faith. They are being resourceful with the tools they know, on personal accounts you cannot see, with company data you cannot get back.

Business plans of AI tools carry contractual data protections that free personal accounts do not, and good policy templates make that the deciding condition: Lattice's AI usage policy template, for instance, only permits confidential data in tools whose license guarantees the model cannot learn from it. Your policy's job is not to stop AI use. It is to move the use you already have onto tools and accounts you chose deliberately.

What goes on the page?

1. Approved tools. Name them. Three to five is plenty for most 10-100 person companies: usually one general assistant on a business plan, plus whatever is already embedded in your existing software. An approved list beats a banned list because the banned list is infinite.

2. Data that never goes in. This is the most important block on the page. At minimum: customer names combined with financial or personal details, employee records, credentials and passwords, anything under NDA, and your own pricing or trade secrets. The Lattice template above carries a full prohibited-data list you can adapt rather than write from scratch.

3. Company accounts only. Work happens on accounts created with company email, on the company's plan, with the company's data settings. Personal accounts are for personal life. This one rule quietly fixes most of the shadow problem, because it moves usage somewhere you can see and configure.

4. A named owner. One person approves new tool requests and re-checks the approved list when vendors change their terms. Without an owner, the policy freezes on the day it is written and the shadow tools return within a quarter.

5. A review date. Every six months is enough. AI vendor terms change fast; the policy should say out loud when it will be re-read.

What should stay off the page?

Anything that tries to police how well people use AI. Quality guidance ("always verify AI output before sending it to a customer") belongs in training, not policy, because a policy line you cannot enforce teaches people the whole document is optional. The verification habit matters, and it is the same discipline I write about on the agent side in How to Tell If Your AI Agent Is Actually Working: trust comes from checking outputs against evidence, not from a sentence in a document.

Also leave out tool tutorials, legal boilerplate that repeats your existing confidentiality agreements, and speculative rules for tools you have not approved. The page has one job: clear, enforceable boundaries.

How do I roll it out without it becoming shelf-ware?

Three moves. First, pair the page with a one-hour training session where people bring the actual tasks they already use AI for; you will discover your real shadow usage in that hour, and the tone stays "here is how to do this safely" instead of "stop doing things". The training is also where verification habits live: proofing, editing, and fact-checking AI output before it ships, the same human-oversight basics even minimal AI policy templates emphasize. Second, have the owner actually process the first few tool requests fast, because a slow approval path recreates the shadow problem you were fixing. Third, put the policy where work happens, in the onboarding pack and the team wiki, not in a drawer.

If you want the full picture of why silently wrong AI output is the risk underneath all of this, my essay Your AI Agent Has the Same Red Flags as Your Ex walks through the failure modes on the production side.

Writing this policy, picking the compliant tools, and running that training hour is also exactly the shape of my AI Adoption Sprint: 2 days plus a follow-up, EUR 1,800 fixed, for companies of 10-100 people.

FAQ

Do we need a lawyer to write it? For a one-page internal policy, usually not. You need legal review the moment the policy intersects regulated data, health, finance, or minors, or when you operate under GDPR and process personal data through AI tools. The one-pager is an operating rule, not a contract.

What if employees ignore it? Treat the first violations as training gaps, not discipline cases. Most shadow AI use comes from people who were never given an approved alternative. If violations persist after a real alternative exists, handle it like any other data-handling breach.

Should we just ban AI tools instead? Bans mostly convert visible use into hidden use. The people who found AI useful will keep using it on personal devices, and you lose both the visibility and the productivity. An approved-tools policy keeps the upside and contains the risk.

How is this different from an AI strategy? The policy says what is allowed today. A strategy says what you will automate next quarter and why. Write the policy first, in a week, then take your time with the strategy.

who wrote this

I'm Lyubomir Atanasov, product lead of an AI agent observability platform at Progress and previously PM for ML in high-risk credit decisioning at Experian. I run a fixed-price advisory practice on exactly the problems these notes cover.

Field notes

Agent trust, in your inbox

Occasional field notes on making AI agents provably work in production. No pitch, unsubscribe anytime.

Double opt-in via Buttondown.