AI governance for small businesses.
Clear rules for how your team uses AI tools, written for real businesses and not for enterprises.
Why it matters now
If your team has internet access, someone is probably already using an AI tool for work, often without telling anyone. That is not a problem to punish. It is a gap to manage. The risks are practical:
- Confidential or customer data pasted into tools that may retain it
- Inaccurate output used in client work or decisions without anyone checking it
- Unclear ownership of AI-generated content
- Customers and contracts that increasingly ask how you use AI
- New state and international rules on AI that your business may fall under
Good governance does not mean banning AI. It means your team can use it confidently, because they know the rules.
What an AI use policy should cover
- Which tools are approved, and which accounts to use (business versus personal)
- What data must never be entered, such as customer personal information, health data, credentials, or confidential contracts
- Human review of AI output before it goes to a customer or informs a decision
- When to tell customers or partners that AI was used
- How to handle AI features that vendors add to software you already use
- How to report a mistake or a data exposure
- Training, so the policy is understood and not just filed away
Beyond the policy: a lightweight program
For most small businesses, a workable AI governance program has four parts:
- An inventory of the AI tools in use, including the ones nobody officially approved
- A simple risk rating for each use, so higher-risk uses get more scrutiny
- A review process for new tools, covering data handling, retention, and security
- A named owner and a regular check-in, so the policy keeps up as tools change
When you are ready for more structure, recognized frameworks exist. The NIST AI Risk Management Framework (Govern, Map, Measure, Manage) is voluntary and works at any size. ISO/IEC 42001 is a certifiable standard for an AI management system. The EU AI Act may apply if you have EU customers or operations. Our framework glossary explains each in plain English.
How we help
We help you put the basics in place: an AI use policy written in plain English, an inventory and risk review of the tools your team already uses, vendor and tool reviews, employee guidelines, and, when it fits, alignment with NIST AI RMF or ISO/IEC 42001.
Related guides
AI governance questions, answered.
Do we need an AI policy if we do not build AI?
Yes, if your team uses AI tools at all. A policy is about how AI gets used in your business, not whether you develop it.
Are tools like ChatGPT, Claude, and Copilot safe for business use?
It depends on the plan and settings. Business and enterprise plans generally offer stronger data protections than free consumer versions, but terms differ by vendor and change over time, so each tool's data-handling terms are worth reviewing before your team relies on it.
Do we need ISO 42001 certification?
No, it is voluntary. It can be useful if customers start asking for it or you want a formal structure, but most small businesses start with a policy and a simple review process.
Does the EU AI Act apply to a U.S. business?
It can, if you have EU customers or operations, or if an AI system's outputs are used in the EU. Whether it applies to you depends on your specifics, so it is worth reviewing early.
Can we just ban AI tools?
You can restrict them, but a blanket ban is hard to enforce and often just moves usage out of sight. Approved tools plus clear rules usually give you more visibility and control.
Want clear rules for AI at your business?
Start with a free conversation, or see where you stand first. No pressure, no jargon.