AIAI for SMB
LearnTemplatesToolsPricingBlog
Back to Lessons
Beginner 25 min

A One-Page Employee ChatGPT / AI Policy You Can Adopt

Cut the twelve-page AI policy into one page a receptionist can recite: traffic lights, approved tools, review rule, and who to ask.

If the policy is longer than the coffee break you used to announce it, you wrote a brochure. Brochures do not stop someone pasting a customer list into a free chatbot.

What you'll learn

ai policysmall businessChatGPT

A twelve-page AI policy is a document people file. A one-page policy is a document people can recite at the counter when a new hire asks, “Can I paste this into ChatGPT?”

This lesson uses the Policy Generator as a draft mill, then cuts the draft until it fits on one page. You will leave with a policy you can send today and a 20-minute adoption script for the next standup.

Tool: Policy Generator Artifact: one-page policy (download employee-ai-policy.md)

Why the long policy fails

Long policies fail in three boring ways.

  1. Nobody can find the rule they need. The question is always the same: “Can this go in?” If the answer is buried under definitions of “artificial intelligence,” they will guess.
  2. The approved-tool list is a wish list. If the tool is not logged in on a company account, the list is fiction.
  3. There is no named human. “Contact management” is how reports die in a shared inbox.

You do not need a lawyer to write a traffic-light list. You need a lawyer before you present the page as legal advice, or if you are in a regulated trade (health, kids, finance, government contracts). The page is still worth writing this afternoon.

Step 1 — Generate the long draft on purpose

Open the Policy Generator. Choose AI Usage Policy. Fill:

  • Business name
  • A real mailbox someone reads (not info@)
  • The tools people already use, not the tools you plan to buy

Generate. Copy the whole thing into a doc. You will delete most of it. That is cheaper than inventing sections from memory.

Do not publish the generator output as-is. It is a first draft with extra ribs. A first draft that mentions “enterprise APIs” will be ignored by the person who has a free ChatGPT tab.

Step 2 — Cut to four blocks

Keep only these. Everything else is appendix, and appendixes do not get read.

  1. Traffic lights — what may be pasted
  2. Approved tools — what is logged in, plus the rule for anything else
  3. Review rule — what a human must check before it leaves the building
  4. Who to ask — one name, one mailbox

If you want a fifth block, you want a handbook. Write the one-pager first.

Step 3 — Write the lights in shop language

Do not write “personally identifiable information.” Write the objects on the desk.

Green — paste freely

  • Public web copy, blog drafts, generic how-tos
  • Your own published price list
  • Grammar and rewrite of text that is already allowed to be public
  • Brainstorm lists that contain no customer names

Yellow — company account only, strip names first

  • Internal process notes that are not a secret recipe
  • Anonymized ticket themes (“three people asked about gate codes”)
  • Drafts of public emails before they are sent

Red — never paste

  • Customer names, phones, emails, addresses, gate codes
  • Invoices, bank exports, payroll, driver’s licenses
  • Passwords, API keys, alarm codes
  • Medical, school, or children’s data
  • Anything a customer would expect to stay in the shop

Add one red line that is specific to you. A plumber adds “camera footage and basement photos with a house number.” A salon adds “client formulas and phone numbers.” If the red list could belong to any company, it will not stop your company.

Step 4 — The approved-tool table (honest names)

As of August 2026, do not list GPT-4o, Claude 3 Opus, or Midjourney V6 as current tools. Those names are leftover. Current consumer names:

If someone saysCurrent name to put on the pageAccount rule
ChatGPTChatGPT (GPT-5.6 — Terra is fine for drafts)Company login. Turn off training if the product offers it. Free personal tabs are not “approved.”
ClaudeClaude (Sonnet 5 or Opus 5)Company login. Same rule.
ImagesMidjourney V7 or the image tool inside your existing suiteNever publish as a photo of real staff or jobs.
CodeGitHub Copilot or the editor you already pay forNo secrets in the prompt.

If you do not have a company login yet, the policy says so: personal free tiers are yellow at most, and red for anything with a name on it. Do not pretend an enterprise plan exists because it sounded responsible in the generator.

A tool that is not on the table requires a yes from the named human before any business text goes in.

Step 5 — The review rule (one sentence)

Steal this sentence:

AI output is a first draft. The person who sends it owns the facts. Numbers, names, prices, hours, legal claims, and anything a customer will act on must be checked against a source we already have — a price list, a calendar, a signed quote — not against the model’s confidence.

Add one example from last month. “The bot said we open at 8. We open at 7:30 on job days. That is why the calendar wins.”

Step 6 — Adoption in one meeting (20 minutes)

Do not email a PDF and call it training.

  1. Print the page. One side. People do not scroll policies.
  2. Read the red list out loud. Ask: “What did I miss that lives in our texts?” Write it on the page. That is the real policy.
  3. Show the company login or say the date it will exist. A rule without a login is a dare.
  4. Name the human. Write their phone, not just their email.
  5. Run one live example. Take a real text from this week. Classify it. If the room disagrees, the lights are still fuzzy — fix the line, do not add a paragraph.

Send the page after the meeting, not before. Before is wallpaper.

Finished artifact — the one-page policy

Copy the download, fill the brackets, and stop. The full text lives in employee-ai-policy.md. The shape you are aiming for:

[BUSINESS] — Employee AI use (one page)
Last updated: [date]    Owner: [name, phone, email]

We use AI as a draft tool. We do not use it as a source of facts.

GREEN: public info, our published prices, grammar on public drafts.
YELLOW: internal process notes, names stripped, company account only.
RED: customer identity, money, keys, health/kids data, job photos with addresses.
Our extra red line: [your line].

Approved tools (company login only): [list with current names].
Anything else: ask [name] before pasting business text.

Review: the sender owns names, numbers, hours, and promises.
Customer-facing AI (site bot, auto-reply) must say it is not a person
and must hand off when it does not have an approved answer.

Report a paste you regret to [email] the same day. You will not be
punished for a honest report. You will be for hiding it.

This page is an internal rule, not legal advice. Review with counsel
if we take on regulated work. We revisit this page every 90 days.

If it does not fit on one printed page in 11-point type with normal margins, you are not done cutting.

Pair it with the generator without lying

Use the generator when you need a privacy notice or terms skeleton. Keep this page as the thing employees see. Two documents. One of them is short on purpose.

When the generator lists ChatGPT, Claude, and Copilot, replace the labels with the current names in the table above. Do not leave a 2024 model name on a page you dated this month.

When this lesson is done

A new hire can classify a text message in ten seconds without asking you. If they still ask every time, the lights are not written in shop objects yet. Rewrite the red list. Do not add a glossary.