Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Set up a small-business AI use policy by listing the tools and tasks staff actually use, sorting each use by risk and data sensitivity, then approving specific tools and setting clear rules for data entry, human review, accountability, and exceptions. Keep the policy short enough to use, assign an owner to maintain it, and tailor it to your location, industry, contracts, and actual AI use. NIST frameworks can help organize the work, but they are voluntary guidance—not proof of legal compliance.

Start with the AI your business actually uses

Before writing rules, make a simple inventory of AI products already in use or under consideration. Include browser-based tools and personal accounts employees may use informally, not just software purchased by the business. For each tool and task, record:

  • Who uses it and for what business purpose.
  • What information is entered, including whether it is public, internal, confidential, or personal.
  • Who receives or relies on the output.
  • What decision, communication, or operational action the output could affect.

This inventory is a practical way to apply risk-management thinking; NIST does not prescribe this exact form. It helps expose why a single rule such as “AI is allowed” or “AI is banned” is unlikely to fit every use.

Sort uses into three policy categories

Use categories employees can understand, and give each proposed use one clear status. These examples are policy-design choices, not universal legal classifications.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Category Typical treatment Examples
Allowed Staff may use an approved tool for a named, low-risk purpose, following the data and review rules. Brainstorming or drafting routine text using public information.
Approval required Staff must get permission before using the tool or handling the data. The reviewer assesses the service, configuration, purpose, and safeguards. Work involving customer or employee personal data, confidential company material, financial information, or contract-restricted information.
Prohibited Staff may not use AI for the purpose unless the business changes the policy after an appropriate assessment. Unreviewed uses that make or materially influence consequential decisions about people, safety, finances, legal rights, or regulated work.

Be specific about what “approval” means: name the person or role that decides, and tell employees how to ask. For consequential or regulated uses, the right outcome may be a stronger assessment or a prohibition rather than routine approval.

Approve tools and settings—not just a brand name

Maintain a short list of approved services. For each one, record its permitted business uses, required account or configuration settings, and the person responsible for revisiting the approval. Approval should cover the particular service and use, not merely a vendor’s name or a plan label.

Do not assume that a paid plan, an “enterprise” label, or a vendor assurance automatically makes a service appropriate for sensitive information. Check the service’s current terms, privacy and security information, and available settings against your business needs. Those details can change; this guide does not compare vendors or establish their data-retention practices.

Set a clear rule for information employees enter

Unless the business has explicitly approved the specific service and use, employees should not enter confidential company information, customer or employee personal data, credentials, regulated information, or material restricted by a contract. Make the rule concrete with examples from your own work, such as customer records, payroll details, unpublished financials, access tokens, or contract documents.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Use public or appropriately anonymized information for unapproved tools only when that fits your business rules.
  • Do not paste a sensitive document into a tool just because the task seems routine.
  • If you cannot tell whether information is restricted, stop and ask the policy owner before entering it.

The legal meaning of personal, regulated, or restricted information varies by jurisdiction, industry, and contract. The policy should reflect the obligations that actually apply to your business.

Require a person to verify output before it matters

AI output can be wrong, incomplete, or misleading. Assign a person—not the tool—to be accountable for work that uses it. Before relying on output, that person should verify facts, calculations, citations, code, and claims against appropriate sources or tests.

Scale review to impact. A draft for internal brainstorming may need a quick factual check; material that reaches a customer, affects an employee, changes a financial or operational decision, or bears on legal obligations needs more careful review and a clearly identified decision-maker. NIST identifies validity and reliability, accountability, transparency, explainability, privacy, and safety as trustworthiness considerations. This review procedure is a practical application, not a specific NIST mandate.

Assign ownership, exceptions, and incident reporting

Name a policy owner who maintains the approved-tool list and fields questions. Also name who can approve a new use or exception. Keep the approval record lightweight but useful:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Tool and proposed purpose.
  • Information involved and who may see the output.
  • Expected benefit, risks considered, and safeguards.
  • Decision-maker, decision, and date to review the approval.

Give staff a known channel to report accidental data entry, harmful or misleading output, suspected bias, security concerns, or other AI-related incidents. Make clear that prompt reporting is expected, so the business can contain an exposure or correct an error. NIST supports governance and risk management over an AI system’s lifecycle; it does not prescribe this particular small-business form or reporting channel.

Publish, train, and review the policy

Keep the policy accessible and written in plain language. Train staff on which tools and tasks are allowed, what data they must keep out, how to check output, when disclosure may be relevant, and how to ask for approval or report a problem. A fixed review cycle—such as at least once a year—is a useful business choice, not a cadence set by the sources below.

Review sooner when a new tool or materially different use is proposed, vendor terms or configuration change, an incident occurs, or relevant business obligations change. A policy that does not track the services and work staff actually use can quickly become unreliable.

What to put in the written policy

A concise internal document can use these headings. They are a practical structure, not a universal standard or legal checklist.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Purpose and scope: why the policy exists and which people, tools, and work it covers.
  • Approved tools and uses: named services, permitted tasks, account expectations, and an owner.
  • Restricted and prohibited uses: what needs approval and what is not allowed.
  • Data rules: what must not be entered without explicit approval, with business-specific examples.
  • Human review and responsibility: what must be checked and who is accountable for the result.
  • Security and access: the account, configuration, and access practices staff must follow.
  • Disclosure: when customers or employees must be told AI was used, as required by the business’s applicable obligations or policy.
  • Administration: policy owner, training, reporting route, exception approver, and review triggers.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Use NIST resources for the right purpose

NIST resources can provide structure, but they have different scopes and are voluntary guidance. They do not certify a small-business AI policy, make a policy mandatory, or ensure that the business complies with applicable law or contracts.

Resource Scope and audience How it can help
NIST AI Risk Management Framework (AI RMF) Voluntary AI risk-management framework. Organizes consideration of trustworthiness through AI design, development, use, and evaluation. NIST says it is “intended for voluntary use and to improve the ability to incorporate trustworthiness considerations into the design, development, use, and evaluation of AI products, services, and systems.”
NIST Generative AI Profile (AI 600-1) Companion, cross-sector resource focused on generative AI. Use alongside the AI RMF when considering risks specific to generative AI.
NIST Cybersecurity Framework 2.0 Small Business Quick-Start Guide (SP 1300) Cybersecurity starting point for small and medium-sized businesses with modest or no existing plans. Supplements the Cybersecurity Framework; it is not an AI policy standard.
NIST Small Business Quick-Start Guides Small-business resources, including a voluntary Privacy Framework guide. The privacy guide uses the areas Identify, Govern, Control, Communicate, and Protect.
NIST RMF Small Enterprise Quick Start Guide (SP 1314) Introductory risk-management resource for small, under-resourced entities. Addresses broader risk management, including information-security and privacy risk.

NIST’s April 14, 2026 announcement for an initial public draft focused on U.S. non-employer firms cites 34.8 million U.S. small businesses and says 81.9% of them have no paid employees besides their owner or owners, citing the U.S. Small Business Administration Office of Advocacy. Those figures describe the U.S. small-business population, not AI use or AI-policy adoption; the announcement concerns a draft, not a final AI-policy rule. See NIST’s Small Business Cybersecurity: Non-Employer Firms initial public draft.

Adapt the policy to your obligations

The applicable laws, disclosure duties, retention requirements, employment rules, and sector obligations depend on where your business operates, what it does, what information it handles, and what its contracts require. No general policy template can settle those questions without those details. Businesses handling regulated information or using AI for consequential decisions should get qualified advice for their jurisdiction and sector before approving those uses.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.