Governance & Trust

A lightweight AI policy for SMEs

Not a 40-page document nobody reads — a one-page set of rules your team will actually follow. Here's what goes in it.

FidwenJune 20265 min read

Ask most small and mid-sized firms whether they have an AI policy and you'll get one of two answers. The first is "no, not yet" — staff are already pasting things into ChatGPT, but nobody has written down what's allowed. The second is "yes, somewhere" — a long document drafted in a hurry, sitting in a shared drive, that nobody has read past the first page.

Neither protects you. The goal isn't the most thorough policy you can write; it's the shortest one that actually prevents the real risks — and that your team will remember on a busy Tuesday. For most SMEs that's a single page.

Why one page beats forty

A forty-page policy feels safe. It looks like you've taken the issue seriously. But a rule that isn't read isn't a rule — it's a document. The risks AI creates in an SME are concentrated and practical: confidential information walking out of the door, a customer receiving something nobody checked, no record of what tools are even in use. You can cover all of those in a page.

The point is to govern from day one without slowing the business down. A short policy that everyone follows beats a comprehensive one that everyone ignores. Completeness is the enemy of adoption here — and adoption is the whole game.

A rule nobody reads isn't a rule. It's a document. Aim for the shortest thing that prevents the risks that actually matter.

What to put in it

Five things do most of the work. Keep each to a sentence or two.

Five things a one-page AI policy covers
1
Allowed & not allowed
Which tools and tasks are fine, and which are off-limits.
2
What never goes in
No client, personal or confidential data in public AI tools.
3
A human owns it
Someone checks every output that reaches a customer or carries risk.
4
A simple register
A short list of which AI tools are actually in use, and for what.
5
Who to ask
A named person to go to when the answer isn't obvious.
Illustrative — a starter structure, not a legal template. Adapt the wording to your business.

1. What's allowed and what isn't

Name the tools people may use and the tasks they're suited to — drafting, summarising, first-pass research. Then name what's off-limits: anything where a confident-sounding wrong answer would do real harm, and any use that hasn't been approved. Clear permission removes the grey area that leads to risky workarounds.

2. What must never go into public AI tools

This is the single most important line. Client information, personal data, anything covered by confidentiality or an NDA, commercially sensitive material — none of it should be pasted into a public, consumer AI tool, because you lose control of where it goes. If a task genuinely needs that data, it needs an approved, enterprise-grade tool with the right contractual terms — not the free web version.

3. A human owns every output that reaches a customer or carries risk

AI drafts; a person decides. Anything that goes to a client, gets published, or feeds a decision with real consequences must be reviewed and signed off by a named human. The AI is an assistant, never the final author.

4. Keep a simple register of tools in use

You can't govern what you can't see. A short list — tool, owner, what it's used for, whether it touches sensitive data — turns invisible "shadow" usage into something you can manage. A spreadsheet is plenty.

5. Who to ask when unsure

Name one person. When someone hits a case the policy doesn't obviously cover, they should know exactly who to ask rather than guessing. That single line prevents most of the quiet mistakes.

The two rules that matter most
Do
Use approved tools for drafting and research
Keep client and personal data out of public tools
Have a person check anything customer-facing
Log which tools you're using
Ask the named owner when unsure
Don't
Paste confidential or personal data into public AI
Send AI output to a client unchecked
Adopt new tools with no one knowing
Treat AI as the final decision-maker
Assume "the model said so" is a defence
Illustrative — general guidance for SMEs, not a substitute for advice tailored to your sector.

Where it connects to the law

The UK has not passed a single "AI Act". Instead it has taken a principles-based, pro-innovation approach: rather than one central regulator, existing bodies apply a common set of principles — safety, transparency, fairness, accountability — within their own sectors (DSIT, 2023–2024). For most SMEs the practical obligations already exist in the law you're subject to anyway.

The big one is data protection. Using AI doesn't suspend UK GDPR: if you process personal data through a tool, the Information Commissioner's Office (ICO) expects the same lawfulness, transparency and fairness you'd apply anywhere else, and the ICO has set out specific guidance on AI and data protection (ICO, 2025). That's exactly why rule two — keep personal data out of public tools — matters.

If you serve EU customers, the EU AI Act can apply to you too, despite Brexit. Its scope reaches providers and deployers outside the EU where an AI system is placed on the EU market or its outputs are used within the EU (European Commission). Some provisions, including prohibited practices and AI-literacy duties, have applied since February 2025, with further high-risk obligations phasing in over the following years.

This article is general information, not legal or compliance advice. Where AI touches regulated activity, personal data at scale, or EU customers, take advice specific to your situation.

Keep it alive

A policy written once and forgotten ages badly, because the tools change every few months. Put a date on it and review it on a sensible cadence — quarterly is fine for most SMEs — and whenever you adopt a new tool. Then make it part of how people join: a new starter should meet the AI policy in their first week, alongside the rest of onboarding. That's how a one-pager stays a living rule rather than a forgotten file.

If you want somewhere to start, this is the outline of a workable one-page policy:

Lift that, fit it to your business, keep it to a page. Govern from day one — without getting in your own way.

Share

Need a policy your team will actually follow?

We help SMEs stand up a sensible, one-page AI policy — clear enough to use, careful enough to keep you safe — and govern AI from day one without slowing the business down.

Book a call Start a conversation

Sources: ICO, Guidance on AI and data protection (Information Commissioner's Office, 2025); DSIT, A pro-innovation approach to AI regulation — government response to consultation (Department for Science, Innovation and Technology, 2023–2024); European Commission, EU Artificial Intelligence Act (Regulation (EU) 2024/1689). This article is general information, not legal or compliance advice.