If your staff use ChatGPT or a similar tool, you already have an AI policy. It is just unwritten, and every employee is writing their own version. A Nationwide survey of small and mid-market business owners found that six in 10 say employees use public AI chatbots or writing tools for work, while only 36% have written policies governing that use. This post gives you a one-page outline to close the gap. If you are still deciding where AI belongs in your business at all, AI strategy consulting starts with an audit of your operations; the rules below work for whatever you decide.
Businesses use AI faster than they write rules for it
Most small and mid-market businesses already have staff using AI at work, but only about a third have written rules for it. Nationwide commissioned Edelman Intelligence to run a 20-minute online survey of small and mid-market business owners in July 2026, and published the findings on September 15, 2026. Small and mid-market business owners reported:
- Six in 10 say employees use public AI chatbots or writing tools for work-related tasks.
- 36% have written policies governing employee AI use, and 37% provide training on responsible use.
- 35% believe employees are using unauthorized AI tools for work.
- 27% have rules governing what company or customer information can be entered into AI tools.
- 25% have procedures for verifying AI-generated information before it is used for business decisions.
- 31% say their company was targeted by a scam or fraud attempt using generative AI within the past 12 months.
These are owner-reported figures from a survey commissioned by an insurer. Nationwide's full survey report shows they combine 300 small business owners (1 to 50 employees and under $10 million in annual revenue) and 300 mid-market owners. Among the small businesses alone, 35% have a written policy or guidelines for employee AI use and 39% believe employees use unauthorized AI tools, so the gap looks the same at your size. Read the numbers as a direction, not as a measurement of your industry.
The one-page policy: five headings
A workable AI policy fits on one page and answers five questions. Copy the headings below into a shared document and fill in your own answers, because a policy nobody reads protects nothing.
1. Which tools are approved
List the specific tools staff may use for work, by name and by account type, and say that anything not on the list needs the owner's yes first. Write "the company's paid account of tool X" rather than "AI tools", so nobody has to guess. Before you approve a tool, read the vendor's data and privacy terms for the exact plan you will use, and write down what you found and the date. Review the list every quarter.
2. What data never goes into a public chatbot
Write a short never list, because a rule people can remember beats a rule people have to interpret. Only 27% of the small and mid-market owners in the Nationwide survey say they have rules like this. A starting list to adapt:
- Passwords, logins, access codes and API keys.
- Customer personal information, including contact details, account details, health information and payment details.
- Employee records and HR matters.
- Bank, tax and other financial records.
- Contracts, legal matters, unreleased pricing and anything you promised a customer to keep confidential.
Add a fallback line: when in doubt, ask the owner before pasting. If staff regularly need AI answers drawn from your own documents, a system built on those documents that shows its sources is a different thing from a public chatbot, and knowledge and data systems are built for that case. Ask whoever builds it, in writing, where your data is stored.
3. Who reviews AI output before it reaches a customer
A named person reads everything AI drafts before a customer sees it, and that person is accountable for what goes out. Nationwide found that only 25% of the small and mid-market owners surveyed have procedures for verifying AI-generated information. Your procedure can be three lines: the reviewer checks every name, number, date, price and claim against a real source; the reviewer cuts anything that sounds sure of itself but cannot be checked; and nothing is published as your expertise unless it came from your actual work. AI can draft, but it cannot create business experience, so your people supply that part.
Add one line for decisions about people, such as hiring, discipline and firing: AI output never makes that decision on its own. For discipline and firing in California, this becomes law: SB 947 (Chapter 859, approved September 30, 2026) adds a part to the state Labor Code, operative July 1, 2027, saying an employer "shall not rely solely on an ADS when making a disciplinary or termination decision" (ADS meaning automated decision system), and its bill text sets no headcount threshold in the definition of employer. This is not legal advice, so if you have employees in California, ask your own counsel whether it applies to you.
4. How to handle AI scam attempts
Treat any unexpected request for money, credentials or changed payment details as suspect, however convincing the voice, email or video looks. Nationwide reports that 31% of the small and mid-market owners surveyed say their company was targeted by a generative AI scam or fraud attempt in the past 12 months, and that only 35% have an up-to-date incident response plan for a cyberattack or data breach. Write the response down in plain steps:
- Verify any payment or credential request by calling back on a number you already had, never one supplied in the message.
- Never change vendor bank details or approve a payment on a message alone.
- Require a second person to approve payments above an amount you set.
- Report anything suspicious to the owner the same day, and keep the original message.
5. Who owns the policy
One named person owns the policy, and in a small business that is usually the owner or the operations lead. Put their name on the page with the date of the last review and the date of the next one. Give staff a way to report an AI mistake or a near miss without blame, because you want to hear about it early. Nationwide found that 37% of the small and mid-market owners surveyed provide training on responsible use, and a 20-minute walkthrough of this page is a fair start.
What to do this week
You do not need a perfect policy this week. You need a written one. Five steps get you there:
- Ask your team, without blame, which AI tools they use and for what. You cannot approve a list you have not seen.
- Copy the five headings into one shared page and fill in your answers.
- Write the never list and the callback rule for payments, and put the callback rule into your payment process today.
- Name the owner of the policy and set a review date three months out.
- Walk the team through the page and have each person confirm they have read it.
If the real question is where AI belongs in your business in the first place, work out where AI fits first, then write the rules around what you choose. The policy is the cheap part, and it applies to every tool you add later.