Ask most small and mid-sized firms whether they have an AI policy and you'll get one of two answers. The first is "no, not yet" — staff are already pasting things into ChatGPT, but nobody has written down what's allowed. The second is "yes, somewhere" — a long document drafted in a hurry, sitting in a shared drive, that nobody has read past the first page.
Neither protects you. The goal isn't the most thorough policy you can write; it's the shortest one that actually prevents the real risks — and that your team will remember on a busy Tuesday. For most SMEs that's a single page.
Why one page beats forty
A forty-page policy feels safe. It looks like you've taken the issue seriously. But a rule that isn't read isn't a rule — it's a document. The risks AI creates in an SME are concentrated and practical: confidential information walking out of the door, a customer receiving something nobody checked, no record of what tools are even in use. You can cover all of those in a page.
The point is to govern from day one without slowing the business down. A short policy that everyone follows beats a comprehensive one that everyone ignores. Completeness is the enemy of adoption here — and adoption is the whole game.
What to put in it
Five things do most of the work. Keep each to a sentence or two.
1. What's allowed and what isn't
Name the tools people may use and the tasks they're suited to — drafting, summarising, first-pass research. Then name what's off-limits: anything where a confident-sounding wrong answer would do real harm, and any use that hasn't been approved. Clear permission removes the grey area that leads to risky workarounds.
2. What must never go into public AI tools
This is the single most important line. Client information, personal data, anything covered by confidentiality or an NDA, commercially sensitive material — none of it should be pasted into a public, consumer AI tool, because you lose control of where it goes. If a task genuinely needs that data, it needs an approved, enterprise-grade tool with the right contractual terms — not the free web version.
3. A human owns every output that reaches a customer or carries risk
AI drafts; a person decides. Anything that goes to a client, gets published, or feeds a decision with real consequences must be reviewed and signed off by a named human. The AI is an assistant, never the final author.
4. Keep a simple register of tools in use
You can't govern what you can't see. A short list — tool, owner, what it's used for, whether it touches sensitive data — turns invisible "shadow" usage into something you can manage. A spreadsheet is plenty.
5. Who to ask when unsure
Name one person. When someone hits a case the policy doesn't obviously cover, they should know exactly who to ask rather than guessing. That single line prevents most of the quiet mistakes.
Keep client and personal data out of public tools
Have a person check anything customer-facing
Log which tools you're using
Ask the named owner when unsure
Send AI output to a client unchecked
Adopt new tools with no one knowing
Treat AI as the final decision-maker
Assume "the model said so" is a defence
Where it connects to the law
The UK has not passed a single "AI Act". Instead it has taken a principles-based, pro-innovation approach: rather than one central regulator, existing bodies apply a common set of principles — safety, transparency, fairness, accountability — within their own sectors (DSIT, 2023–2024). For most SMEs the practical obligations already exist in the law you're subject to anyway.
The big one is data protection. Using AI doesn't suspend UK GDPR: if you process personal data through a tool, the Information Commissioner's Office (ICO) expects the same lawfulness, transparency and fairness you'd apply anywhere else, and the ICO has set out specific guidance on AI and data protection (ICO, 2025). That's exactly why rule two — keep personal data out of public tools — matters.
If you serve EU customers, the EU AI Act can apply to you too, despite Brexit. Its scope reaches providers and deployers outside the EU where an AI system is placed on the EU market or its outputs are used within the EU (European Commission). Some provisions, including prohibited practices and AI-literacy duties, have applied since February 2025, with further high-risk obligations phasing in over the following years.
This article is general information, not legal or compliance advice. Where AI touches regulated activity, personal data at scale, or EU customers, take advice specific to your situation.
Keep it alive
A policy written once and forgotten ages badly, because the tools change every few months. Put a date on it and review it on a sensible cadence — quarterly is fine for most SMEs — and whenever you adopt a new tool. Then make it part of how people join: a new starter should meet the AI policy in their first week, alongside the rest of onboarding. That's how a one-pager stays a living rule rather than a forgotten file.
If you want somewhere to start, this is the outline of a workable one-page policy:
- Approved tools, and the tasks they're allowed for
- What must never go into a public AI tool — client, personal and confidential data
- A named human signs off anything customer-facing or risky
- A short register of the tools in use and who owns each
- One named person to ask when the policy doesn't obviously cover it
- A review date, and a line making it part of onboarding
Lift that, fit it to your business, keep it to a page. Govern from day one — without getting in your own way.
Need a policy your team will actually follow?
We help SMEs stand up a sensible, one-page AI policy — clear enough to use, careful enough to keep you safe — and govern AI from day one without slowing the business down.
Book a call Start a conversationSources: ICO, Guidance on AI and data protection (Information Commissioner's Office, 2025); DSIT, A pro-innovation approach to AI regulation — government response to consultation (Department for Science, Innovation and Technology, 2023–2024); European Commission, EU Artificial Intelligence Act (Regulation (EU) 2024/1689). This article is general information, not legal or compliance advice.