Playbook6 min read

The one-page AI policy every small team should write (free template)

Someone on your team pastes a client's tax notice into a free chatbot to draft a quick reply. They're not careless: they're saving twenty minutes, and nobody told them where the line is. The risk with AI in a small business isn't the tools. It's the silence. Here is the fix: one page, six rules, readable in two minutes.

The video loads from YouTube (Google) only if you click. Watch on YouTube

Why it can't wait

In June 2026, Statistics Canada reported that 19.2% of Canadian businesses used AI to produce goods or deliver services, three times the 6.1% of two years earlier. Among them, only 32.0% reported AI training for their existing employees. And the barrier businesses named most often was cybersecurity or privacy concerns (13.4%).

So people are learning AI on their own, and what owners worry about most is exactly what nobody has explained to them. A one-page policy answers the six questions your team actually has: which tools can I use, what can I put into them, who checks the result, can AI decide about people, do we tell clients, and who do I call when something goes wrong.

Rule 1: the approved tools

Write them down by name, with the type of account: for example, your team account on one AI assistant and the AI features built into your office software. Then the line that matters: for client work, approved tools only, with a work account, never a personal one.

Before approving a tool, read its business terms and check whether what you type can be used to train its models. When someone wants a new tool, they ask first, and the answer should take a day, not a month.

Rule 2: a traffic light for data

The heart of the page: where each kind of data can go
ColourWhat it coversWhere it can go
GreenAnything already public: your website, published prices, job postsAny approved tool
YellowInternal but not personal: procedures, drafts, numbers without namesApproved tools only
RedPersonal information about anyone (clients, employees, job applicants), health, banking, ID numbers, passwords, anything under a confidentiality agreementNever in an AI tool, unless the owner approved that tool for it in writing

The federal government gives its own employees the same instinct in its guide on generative AI: don't enter sensitive or personal information into tools it doesn't manage.

Rule 3: a person reads every AI output

Every email, quote or summary that leaves the business is read by a person first, who checks four things: facts, numbers, names and promises. AI writes confident sentences, and confident isn't the same as correct.

Rule 4: AI never decides alone about a person

AI can help prepare, sort or summarize. But hiring, discipline, a customer's credit or an individual client's price is a person's call.

In Quebec, this rule has a legal basis. Under section 12.1 of the private sector privacy act, a business that uses personal information to render a decision based exclusively on automated processing must inform the person concerned and give them the opportunity to submit observations to someone who can review the decision. The simplest habit: a real person decides.

Rule 5: clients know when they're talking to an AI

If a chatbot answers on your website, by phone or by email, it says so up front and shows how to reach a person. People forgive a bot that's honest about being a bot. They don't forgive feeling tricked. Here is the opening message an AI wrote when we asked it for one:

Real AI answerWebsite chat opening message
Hi! I'm an AI assistant, not a person, and I can help with general questions about our services, hours and what documents to bring. To talk to someone on our team, call us at [phone number] or email [email address], Monday to Friday, 9 a.m. to 5 p.m.

Rule 6: one owner, and a same-day rule for mistakes

Put a name on the page. In Quebec, the law already names someone: by default, the person exercising the highest authority in the business is in charge of protecting personal information, and can delegate that function in writing (section 3.1). Make it the same person.

Then the rule: if red data ends up where it shouldn't, tell the owner the same day, with no blame. If it becomes a confidentiality incident that presents a risk of serious injury, the law requires prompt notice to the Commission d'accès à l'information and to the people concerned (section 3.5). You can only act on what you know.

Let an AI write the first draft

Give an AI assistant your answers and one key instruction: don't add rules we didn't give you, and if something is missing, ask. We tried it for a fictional 12-person accounting office in Laval. The model filled in only what had actually been decided, wrote “to be decided” everywhere else, and ended with eight questions, like these two:

Real AI answerTwo of the eight questions it asked
2. Red: Is red data never to be entered into any AI tool, even the approved ones?
4. Telling clients: Do we tell clients we use AI? If yes, where: engagement letter, website, or only when asked?

Those questions are your real policy work. The full prompt is in the library: draft your one-page AI policy.

Then stress-test the page

Give the AI your finished policy and five real situations, and ask for allowed, not allowed or unclear, quoting the rule each time. It got the obvious ones right: a client's tax notice pasted into a personal account is not allowed; automatically rejecting 30 job applicants is not allowed, because a person makes the call.

Then it found a gap we had missed. Our red list said “clients or employees”. Job applicants are neither. One word fixed it: anyone. If an AI can't tell from your page, neither can your team. Get the stress-test prompt.

Your next step

  1. Copy the template

    Take the free one-page template and fill in your tools and your owner.

  2. Run the stress test

    Five real situations from your week, through the stress-test prompt.

  3. Read it as a team

    Fifteen minutes at your next meeting: read it together and answer questions.

  4. Set a review date

    Every six months, and whenever you add a tool.

Sources

  1. Statistics Canada, Analysis on artificial intelligence use by businesses in Canada, second quarter of 2026
  2. Government of Canada, Guide on the use of generative artificial intelligence
  3. Act respecting the protection of personal information in the private sector (CQLR, c. P-39.1), ss. 3.1, 3.5 and 12.1
  4. Commission d'accès à l'information du Québec, person in charge of the protection of personal information (in French)

Frequently asked questions

Does a small business need an AI policy?

If anyone on your team uses AI tools for work, yes. It doesn't need to be long: one page that says which tools are approved, what data can go into them, who checks the result and who to call when something goes wrong prevents most problems.

What should an AI policy for employees include?

Six rules cover most situations: approved tools, a data rule (public, internal, personal), human review of every output, no automated decisions about people, telling clients when they talk to an AI, and one owner with a same-day rule for mistakes.

Does Quebec's privacy law apply to AI tools?

The Act respecting the protection of personal information in the private sector applies to the personal information you handle, including what you put into an AI tool. Section 12.1 specifically covers decisions based exclusively on automated processing. This article is general information, not legal advice.

Can employees use their personal AI account for work?

Not for client work. The template's rule is: approved tools only, with a work account, and never red data unless the owner approved that tool for it in writing.

Where should you start with AI?

The free assessment gives you, in 4 minutes, the 3 tasks to automate first in your business.

Take the free assessment

Newsletter

The essentials of AI for small businesses, once a week

The week’s articles in 5 minutes, plus a prompt and a template to use right away. Free, no ads.