BLACKSIG SYSTEMS/Resources/Does a Small Business Need an AI Policy

// Resources

Does a Small Business Need an AI Policy, and What Should It Say?

Your staff are already using AI whether you have decided anything or not. What a usable two page policy decides, which US state rules actually apply in 2026 with their dates, and the three things a policy will not fix.

Last updated · 2026-10-02

The short version

Yes, and the reason is that your staff are already using AI whether you have decided anything or not. Microsoft and LinkedIn's 2024 Work Trend Index found 75% of knowledge workers using AI at work and 78% of those bringing their own tools, rising to 80% at small and medium companies. A usable policy is two pages: which tools are approved, what must never be pasted into them, what a human has to check before anything leaves the building, who to tell when something goes wrong. The laws that bite are mostly about decisions concerning people and about telling customers when they are talking to a machine, and they apply based on where your employees and customers are rather than where you are. A policy will not stop a determined person pasting a client list into a chatbot. Approved tools that are good enough to use will.

Does a small business need an AI policy?

A small business needs an AI policy if anybody at the company uses AI, and they do.

Microsoft and LinkedIn's 2024 Work Trend Index, a survey of 31,000 knowledge workers across 31 countries run by Edelman Data and Intelligence, found 75% using AI at work, 78% of those users bringing their own AI tools, and that figure rising to 80% at small and medium companies. It also found 52% reluctant to admit using AI for their most important tasks. That last number is the one that should decide this for an owner. The usage is happening and it is partly hidden, which means you do not currently know which tools hold your client data.

The governance gap is measurable too. The Global Technology Industry Association's 2026 study of 520 small and mid sized business decision makers, End-User AI Adoption, found 44% with an acceptable use policy for AI tools, 40% with employee training and accountability requirements, and 39% with data security and confidentiality requirements. In the same study 84% reported positive business impacts from AI. Adoption is running well ahead of the rules.

A policy is not a legal shield you buy and file. It is the shortest way to answer four questions that are being answered informally right now at your company: which tools, with what data, checked by whom, and who gets told when something goes wrong. Two pages is enough for most companies under 200 people. A twelve page document assembled from a template nobody reads is worse than two pages that people actually follow.

What happens if you do not have an AI policy?

Without an AI policy, client data ends up in accounts you do not control, and you find out later than you would like.

Cyberhaven's 2025 AI Adoption and Risk Report, built from telemetry across 7 million workers, found that 34.8% of the corporate data employees put into AI tools is sensitive, up from 10.7% two years earlier, and that more than 73% of workplace AI use runs through unsanctioned personal accounts rather than corporate ones. Personal accounts bypass single sign on, central logging and retention controls, which is what makes the first number hard to answer for. That is vendor telemetry rather than a peer reviewed study, and the direction it shows matches what we see when we start work at a company.

The practical consequences are mundane and expensive. A proposal containing a client's pricing sits in somebody's personal chat history. An employee leaves and takes an account you cannot audit with them. A customer asks whether their data has been put into an AI tool and nobody can answer. A new enterprise client sends a security questionnaire with an AI section and you have nothing to attach.

None of that requires a dramatic breach to cost money. It costs deals, because you cannot answer the question, and it costs a weekend when somebody finally asks.

What should an AI use policy actually say?

An AI use policy should say six things, and each one is a decision rather than a paragraph of principles.

Section What it has to decide A sign it is working
Approved toolsWhich AI tools are allowed for work, in named accounts your company controls, and how somebody asks for a new onePeople ask before using something new, because asking is quick
Never paste thisThe specific data classes that must not go into any AI tool: client identifiers with financial or personal detail, personnel records, credentials, anything under an NDA, protected health informationStaff can recite three examples without looking it up
Human checkWhich outputs need a person's review before they leave the building, and whose name is on that reviewNothing client facing ships unreviewed, and the reviewer is named in the record
DisclosureWhen you tell a customer AI was involved, including anything customer facing that answers in your company's voiceYour customer facing automations say what they are, and your staff know the rule
IncidentsWho to tell, within what time, when sensitive data went somewhere it should not haveThe first report arrives within a day rather than during an audit
ReviewWho owns this document and when it gets looked at againIt has been updated at least once since it was written

Two things to leave out. Vague commitments to using AI responsibly, which decide nothing and will be quoted back at you by somebody who did something foolish. And a ban on AI use, which produces exactly the shadow usage the policy exists to prevent, as the 78% bringing their own tools in the Work Trend Index suggests.

Have counsel read the result, especially the disclosure and incident sections, and especially if you are in a regulated industry. An hour of review on two pages is cheap.

Which AI laws actually apply to a small business in 2026?

The AI laws that apply to a small business in 2026 are the ones about decisions concerning people, and they apply where your employees and customers are rather than where your office is.

Illinois amended its Human Rights Act through HB 3773, Public Act 103-0804, with effect from 1 January 2026. Using AI in a way that discriminates on a protected basis in recruitment, hiring, promotion, discipline, discharge or the terms of employment is a civil rights violation, and failing to disclose that AI is being used for those purposes is a separate violation. The amendment also prohibits using zip code as a proxy for a protected class. Ogletree's summary sets out what employers have to do. One wrinkle to know: the Illinois Department of Human Rights proposed the rules defining what a compliant notice looks like on 15 May 2026 and withdrew them on 2 June 2026 with no refiling date, so the duty is live while the detail is unsettled. Give the notice anyway and keep a record of what you sent.

California's Civil Rights Council regulations on automated decision systems under the Fair Employment and Housing Act took effect on 1 October 2025 and reach employers with five or more employees in the state. They confirm that an employer carries responsibility for a discriminatory automated decision even where a third party vendor supplied the tool, require records relating to automated decision systems to be kept for four years, and make anti-bias testing before and after adoption an express defence. Mayer Brown's alert covers the detail.

The California Privacy Protection Agency's automated decisionmaking technology regulations were filed with the Secretary of State on 22 September 2025 and took effect on 1 January 2026. Businesses covered by the CCPA that use such technology for significant decisions about California consumers owe a pre-use notice explaining how it works and what influences its output, at least two ways to opt out, and risk assessments. Businesses already using it have until 1 January 2027 to have notice and opt out in place. Pillsbury's summary of the 2026 California AI laws puts those alongside the rest of the set.

What about Colorado's AI Act and the federal picture?

Colorado's AI Act no longer exists in the form it was written, and the federal position is unsettled enough that nobody should plan around it.

Colorado passed the first comprehensive state AI law in 2024, delayed it twice, and then replaced it. A federal magistrate stayed enforcement of the original act on 27 April 2026, and on 14 May 2026 Governor Polis signed SB 189, which repeals and replaces it with a narrower framework governing automated decision making technology, effective 1 January 2027. The replacement drops the original's duty of care, risk management programme and impact assessments in favour of disclosure: consumer notices, disclosure after an adverse outcome, and rights to ask for correction of inaccurate data and for meaningful human review of certain automated decisions. Wilson Sonsini's analysis of SB 189 sets out what changed. The practical read for a small business: what survived is close to what California and Illinois already require, which is notice and a human in the loop on decisions about people.

Federally, there is pressure on the state patchwork and no law replacing it. President Trump signed an executive order titled Ensuring a National Policy Framework for Artificial Intelligence on 11 December 2025, which created an AI Litigation Task Force inside the Department of Justice from 10 January 2026 to challenge state AI laws in federal court. An executive order cannot preempt a state statute by itself; that needs legislation from Congress, which has not passed. So the state rules that apply to you today still apply today, and the map may be redrawn by litigation rather than by a deadline you can diary.

The voluntary framework worth knowing is the NIST AI Risk Management Framework, published in January 2023, with a generative AI profile added on 26 July 2024. Nobody will fine you for ignoring it. Enterprise customers increasingly ask whether you follow something, and naming it is a cheap, honest answer.

Do you have to tell customers when they are talking to AI?

You have to tell customers they are talking to AI in some states, and the requirement depends on what the AI is doing rather than on your size.

California has required disclosure since SB 1001, the Bolstering Online Transparency Act, took effect on 1 July 2019. It makes it unlawful to use a bot to mislead somebody about its artificial identity in order to incentivise a sale or influence a vote, and requires clear and conspicuous disclosure instead. Maine went further for consumer interactions: its Chatbot Disclosure Act, enacted in June 2025 and effective 24 September 2025, requires businesses using AI chatbots to communicate with consumers to tell them clearly that they are not dealing with a live human, enforceable under the state's Unfair Trade Practices Act.

Utah's AI Policy Act took effect on 1 May 2024 and was narrowed by SB 226, effective 7 May 2025, so disclosure is now required when a person asks whether they are dealing with AI, and in higher risk interactions involving health, financial or biometric information. California's SB 243, signed on 13 October 2025 and effective 1 January 2026, applies to companion chatbots that simulate emotional relationships, expressly excludes customer service bots, and lets a user injured by a violation sue for the greater of actual damages or $1,000 per violation. Cooley's review of the chatbot rules covers these together and is worth reading before you launch anything customer facing.

The simple operating rule, which costs nothing and travels across every state: have anything customer facing say what it is in its first few words, and answer honestly when somebody asks. Every voice and chat system we build does that by default, and no client has ever asked us to remove it. The people who were going to be annoyed are more annoyed by being tricked.

What the laws do not require is a confession in the middle of ordinary work. A system that drafts a reply for a person to check and send is that person's reply. Disclosure attaches to interactions where a customer could reasonably believe they are talking to a human and they are not.

What does an AI policy not fix?

An AI policy does not fix three things, and the first one is the reason most policies fail.

A policy does not give people a usable tool. Staff reach for their own accounts because the approved option is slower, or because there is no approved option. If the policy bans the thing people find useful and offers nothing in its place, you have not changed behaviour, you have moved it out of sight. Approve something that is actually good, in an account your company holds, and the shadow usage mostly evaporates on its own.

A policy does not make your data safe to use. Rules about what staff may paste into a chat window are a different question from whether your records are consistent enough to build on, and both come up in the same month. The second question is in is our data good enough for AI, and what a vendor should be asked about data handling is in is it safe to give an AI system access to my business data.

A policy does not decide where AI is worth using. That is the strategy question, and a company that writes rules without answering it tends to end up with careful governance over a few people using chatbots for email, while the expensive work in the business carries on untouched. The order we would argue for: decide where AI belongs, write the rules that let you do that safely, then build. That sequence is what our transformation work is, and what the plan contains is in what an AI roadmap should include.

Who should own the policy, and how often should it change?

The policy should be owned by one named person and reviewed quarterly for the first year, and that owner should not be whoever is most enthusiastic about AI.

In a company under about 200 people this usually sits with whoever already owns employment matters and vendor contracts, with somebody technical named as the second signature on approving a tool. Two names rather than a committee. The reason to keep it with the employment side is that the rules that carry penalties, from Illinois HB 3773 to the California FEHA regulations, are employment rules.

Quarterly review for the first year sounds excessive until you look at the dates in this article. Colorado's law was delayed twice, stayed by a federal court and then repealed and replaced inside two years. Illinois has a notice duty in force whose implementing rules were proposed and withdrawn within three weeks. The federal position changed by executive order in December 2025 and is now being tested in court rather than in statute. After the first year, review it when a new tool gets approved, when you start using AI in a decision about a person, and when a customer facing system goes live.

One practical thing to do at the same time as writing it: ask every team which AI tools they are using now, with an explicit promise that nobody is in trouble. The list will be longer than you expect, and it is a better starting point than any template.

Frequently asked questions

How much does it cost to put an AI policy in place?

What costs money is the review and the tooling rather than the writing. An hour or two of employment counsel on a two page document, and whatever an approved tool costs in business accounts for the people who need it. A policy that exists only on paper is cheap and worth little; a policy with approved tools behind it costs the licences and stops the shadow usage. If your work touches employment decisions or California consumers, add a legal review of those specific flows, because that is where the obligations with penalties live. BLACKSIG does not sell policy documents and does not publish a rate card for what it does sell; governance work comes up inside a strategy engagement because it changes what is buildable.

How do you actually write one for a 20 person company?

Start with the inventory: ask every team which AI tools they use now, no consequences. Then make four decisions and write them down: which tools are approved and in whose accounts, which data classes never go into any of them, which outputs need a named human check before they leave, and who gets told when something goes wrong. Add disclosure for anything customer facing and a review date. Have counsel read it. Two pages, one owner, done inside a fortnight.

Is an AI policy different from our existing data or acceptable use policy?

It overlaps and it is not the same document, though a small company can bolt it on as a section rather than issuing something new. What is genuinely new is the output side: nothing in an old acceptable use policy tells you who checks a machine written client email before it goes out, or when you have to disclose that a customer is talking to software. If your existing policy is well read and well understood, extend it. If nobody has read it since onboarding, a short standalone document has a better chance.

Can we just ban AI tools instead?

You can, and the usage will continue in personal accounts where you cannot see it. Microsoft and LinkedIn's 2024 Work Trend Index found that 78% of AI users bring their own tools to work, rising to 80% at small and medium companies, and 52% reluctant to admit using AI for their most important tasks. A ban converts a manageable problem into an invisible one. The exception is a specific tool with terms you have read and rejected, which is a decision rather than a posture.

Does any of this apply if we are a 12 person company in a state with no AI law?

Some of it does, because the rules follow your employees and your customers. If you hire in Illinois or California, or sell to consumers in Maine, or run anything that makes decisions about people in a state with rules, those rules apply whatever your head office address. Federal employment discrimination law applies regardless of state AI statutes. Beyond compliance, the commercial argument is simpler: enterprise customers ask about this in security questionnaires now, and having an answer wins work.

Related resources

Find out where AI belongs in your business

We map how your business actually runs, decide where AI is worth using, then our engineering team builds what the plan calls for and we run it from there. We own the outcome, not the deliverable.