The AI policy for small teams, on a single page
Ten steps to an internal rule for two to ten people that actually gets read and followed. With a template you can copy.
At some point the moment arrives when you are no longer the only one in your team working with AI. The working student writes quotes with it, the freelancer has code explained to them, someone uploads a customer list to get it sorted. Usually you only find out afterwards.
A policy is the cheapest answer to that. Not because a document prevents anything, but because without a shared basis everybody invents their own. And the version somebody quietly puts together for themselves is, if in doubt, the riskiest one.
What follows is a working template, not legal advice. Which duties actually apply to you depends on your industry and your role, and for that DACH legal, EU AI Act and GDPR is the right way in. This is about the operating manual next to it.
1. Limit it to one page
The temptation is to regulate everything. Twelve pages, neatly structured, with definitions up front. A document like that gets skimmed once during onboarding and never opened again.
Set yourself a hard limit: one page. Whatever does not fit is either not important enough or belongs in a document of its own. In a team of three to ten people that easily covers ninety percent of the real cases.
The test is simple. When somebody new starts, they should read the thing in four minutes and know afterwards what they are allowed to do.
2. Three approval levels instead of a list of bans
Lists of bans go stale the moment a new tool appears. Levels last longer.
Green, no need to ask. Everything without personal data and without client references. Drafting texts, collecting ideas, summarising public information, having code explained, smoothing out an email you wrote yourself.
Yellow, checked by a second person. Everything that goes outside or supports a decision. Quotes, client emails, numbers in a presentation, replies to applicants. It may be created with AI, but it does not leave the house before a human has looked at it.
Red, only after talking to you. Everything involving client data, HR data, health data, contracts, credentials. And every new tool nobody in the team has used before.
Three levels are something anyone can remember. Five already are not.
3. Make the data list concrete
"No sensitive data" is not a rule, it is a feeling. Everybody draws the line somewhere else.
Write the list out concretely, with examples from your own business. For a small agency it looks roughly like this: no client names in combination with revenue, no job applications, no invoices with full addresses, no credentials or keys, no contracts in their original form.
And then the more important part, namely the way out. Anonymising is almost always possible. "Client A, annual revenue in the mid five figures" gives you answers just as good as the real name for most questions. If your policy only forbids and never shows a path, it will be worked around. Data protection with AI tools goes into this more deeply.
4. Keep a positive list of tools
Not which tools are banned, but which ones are approved. Three to five names, a small team does not need more.
Plus one line per tool with what matters: which contract sits behind it, whether it is a business account or a private one, and whether content entered there is used for training. These points differ considerably between private and business plans of the same provider, and that is exactly where the most common silent mistake sits.
Add one sentence on how a tool gets onto the list. In a team your size this is enough: a new tool means a short conversation with you, and then it is on the list or it is not.
5. Settle the liability question in one sentence
The most important sentence in the whole policy, and it is short: whoever sends it, owns it.
Not the tool, not the provider, not the colleague who wrote the prompt. The person who hits send.
That sounds harsh, but it is the only version that works. It ends the "but the AI said so" discussion before it starts, and as a side effect it makes people actually read their results instead of passing them along. How to systematically check claims from an AI answer is in Fact-checking an AI answer.
6. Settle how you label things externally
This is where opinions in the team differ most, which is exactly why it needs a rule. Otherwise one person labels every email and another never labels anything.
A workable baseline: where a human is responsible for the content and the AI only helped with the wording, you need no notice. Where the content was essentially produced by a machine, it should be marked as such. And where clients explicitly want to talk to a human, you say honestly who or what is answering.
The details and the boundary cases are in Spotting and correctly labelling AI content.
7. Treat client data separately
The moment your clients' data goes into a tool, it stops being an internal matter. There are promises attached to it that you made to your clients, often in contracts older than the tools.
Two lines in the policy are enough for everyday life. First: client data only goes into tools where the contractual basis has been clarified. Second: when in doubt, anonymise or ask, never quietly assume it is fine.
The clarification itself is your job as the owner, not your people's. What that takes belongs in the legal playbook, not on this one page.
8. Write down a fear-free way to report problems
Sooner or later somebody accidentally uploads something that should never have been uploaded. That is not a question of whether.
What happens next decides the damage. If the person says so immediately, you can react. If they are afraid of getting into trouble, you hear about it three months later from somebody else.
So write it down, in this order: report it immediately, look at it together, no consequences for honest mistakes. That last half-sentence is the one that makes the whole path usable in the first place.
9. Test it against three real cases
Before you hand the thing out, take three situations from last week and walk through them. Not made-up ones, real ones.
For instance these three: someone wants a quote for an existing client drafted. Someone wants an Excel sheet with revenue figures analysed. Someone wants to try out a new image generator.
For each case your page has to give a clear answer, in under thirty seconds. If you have to think about it yourself, the rule is too vague. If two people in the team arrive at different results, even more so.
10. Give it a place and a rhythm
A document nobody can find does not exist. It belongs where your team looks anyway, and the link belongs in the onboarding.
Add a fixed review date. Twice a year is enough at this size. Twenty minutes, three questions: which tools are we using by now that are not on the list. Which rule got annoying in practice. What went wrong and is still missing.
Put a date on the page while you write it. A policy without a date cannot be placed a year later, and in this field a year is a long time.
The template
To copy and adapt:
KI-NUTZUNG BEI [FIRMA] Stand: [Datum]
FREIGABE-STUFEN
Grün ohne Rückfrage: keine Personen-, keine Kundendaten
Gelb ein Zweiter schaut drauf: alles was nach aussen geht
Rot vorher mit [Name] sprechen: Kunden-, Personaldaten,
Verträge, Zugangsdaten, neue Tools
NIE EINGEBEN
[eure konkrete Liste, 4 bis 6 Punkte]
Ausweg: anonymisieren ist fast immer möglich.
FREIGEGEBENE TOOLS
[Tool] | [Konto: geschäftlich/privat] | [Training: ja/nein]
VERANTWORTUNG
Wer es abschickt, verantwortet es.
KENNZEICHNUNG
[eure Grundlinie in zwei Sätzen]
WENN ETWAS SCHIEFGEHT
Sofort bei [Name] melden. Keine Konsequenzen für ehrliche Fehler.
ÜBERPRÜFUNG
Nächster Termin: [Datum]
What you have afterwards
One page that costs four minutes of reading and decides the three most common disputes in advance: what may go in, who is liable, what happens when something goes wrong.
What it does not do: it replaces neither a review of your concrete duties nor contractual clarification with your clients. Both remain your job, and both only get easier with a clear internal basis.
The most honest measure comes three months later. If somebody asks you then "is this green or yellow", the page has worked. If nobody remembers it exists, it was too long.