Write this one page before your team opens a chatbot.
AI is already in your business, whether or not anyone approved it. One page decides whether that is an advantage or an exposure.
Most small businesses already have AI in the building. Not because anyone approved it, but because somebody on the team started pasting things into a chatbot to get through the afternoon, and it worked, so they kept doing it.
That is not a crisis. It is usually a good sign. But it means the decision about what is acceptable is currently being made by whoever is at the keyboard, one paste at a time, with no guidance.
The fix is one page. Not a policy document, not a compliance program. One page, written in plain language, that everyone reads once.
What goes on it
- Which tools are approved. Name them. Two or three is plenty. An employee using a random free tool nobody has evaluated is the actual exposure, and it happens because nothing was named.
- What never goes in. The hard line, written so there is nothing to interpret.
- What always gets checked by a person. Anything that goes to a customer, anything with a number in it, anything that becomes a commitment.
- Who to ask. One name. Questions that have nowhere to go get answered by guessing.
- What to do after a mistake. Someone will paste the wrong thing eventually. A page that makes that reportable without humiliation is worth more than a page that makes it forbidden.
The two categories that never go near it
Whatever else you decide, two kinds of information should be out of bounds without exception.
Anything that identifies a customer in a sensitive way. Health information, financial account details, government identifiers. In some industries this is regulated and the penalty is not theoretical. In all industries it is the thing that ends a customer relationship permanently when it goes wrong.
Anything you are contractually obligated to protect. If you have signed an agreement with a client about how their information is handled, a chatbot is a third party, and pasting their material into it may breach that agreement regardless of how the vendor handles data.
A one-page policy is not about restricting the team. It is about making it safe for them to move fast.
Why one page and not twenty
A twenty-page policy does not get read, which means it does not change behavior, which means it exists to protect the business on paper rather than in practice. Everyone involved knows this.
One page gets read. It gets read because it is short enough that reading it is easier than avoiding it. That is the entire design goal.
Write it before the team is deep into habits you then have to unwind. It takes an afternoon, and it is the cheapest risk work a small business will ever do.