What Should an SME AI Policy Include? Seven Questions, One Page
The AI policy that works for a 10–200 person firm is a page long and answers seven questions. Here they are, with the wording that holds up.
Most SME AI policies fail in one of two directions: there isn't one, so every employee improvises their own rules on a free chatbot account — or someone downloads a twenty-page enterprise template that nobody reads, which is the same thing with extra steps. The policy that actually works for a 10–200 person firm is about one page long, and it answers seven questions. Here they are.
1. Which tools are approved?
Name them. "ChatGPT Team and Claude for Work, on company accounts" beats "approved AI tools" — vagueness is where shadow use hides. State the corollary explicitly: no work data in personal AI accounts. If you haven't yet chosen a tool, choose one first; a policy with nothing approved is a ban wearing a policy's clothes, and bans don't survive contact with a useful tool.
2. What must never go in?
A short list people can hold in their heads: credentials and bank details; health and other special category data; anything under a client confidentiality clause; whole customer datasets. Four items covers most SMEs. Add your sector's specifics — case details for a law firm, patient information for a practice — and stop there. A list of forty things is a list of zero things.
3. What needs a human before it leaves the building?
Anything a client, regulator, or court might read: contracts, advice, financial figures, published content. The wording that works: AI drafts, a named human reviews and owns. This one line is also most of your defence if an output is ever wrong — "the model said so" has never satisfied anyone, and under UK GDPR meaningful human review is what separates assistance from automated decision-making about people.
4. Where is AI not allowed to decide?
Decisions about individuals — hiring, firing, lending, pricing for a specific person — carry legal weight. AI can prepare evidence for those decisions; a human makes them, visibly. Recruitment screening deserves its own sentence in your policy: under the EU AI Act it's a high-risk category, and the Act reaches more UK firms than assume it does.
5. Do we tell people?
Decide your disclosure line before someone asks. Common ground: no disclosure needed for internal drafting assistance; disclosure where clients are paying for expert judgement and AI did substantive work; and customer-facing bots always identify as bots (from August 2026 the EU AI Act requires this for firms in its scope — and it was always good manners).
6. What happens when something goes wrong?
A route, not a procedure: who to tell (named person), within what time, no blame for reporting. Pasted the wrong thing? Output turned out to be wrong after it shipped? The firms that find out about incidents early are the ones where reporting one doesn't hurt. Wire this into your existing data breach process rather than inventing a parallel one — the governance guide covers how light this can be while still counting.
7. Who owns this document?
A name, not a committee — and a review date every six months, because the tools change faster than policies do. The owner also keeps the approved-tools list current, which is the part that goes stale first.
What deliberately isn't in it
Tool tutorials (training's job, not policy's — see Education), procurement rules for AI vendors (that's a buying decision, covered in build, buy or partner), and philosophy. One page, seven answers, a name at the bottom.
Write it this week — it's an hour's work with the seven headings above, and it's the single cheapest item in the whole SME AI playbook. If you'd like the groundwork checked first, the readiness assessment scores your governance pillar in two minutes, no email required.
Ready to implement these concepts in your organization? Our team can guide you through the entire MCP integration process.
Schedule a Consultation