Why it matters
Your team is probably already using AI on their phones. Without a few written rules, customer details end up pasted into personal accounts and AI-written messages go out unchecked. The FBI has also warned that criminals use AI to fake voices and messages in payment scams, so the same page should cover both.
Get the rest of this guide free
Enter your email once and every guide and setup on the site opens, this one included. You'll also get AI This Week by Southbeam: the week's AI news for business owners, every Friday.
Steps
- List the tools you'll allow. Keep it short, for example "ChatGPT and Claude, business accounts only" or "any, with the rules below."
- Decide the never-paste list. Start with: card and bank numbers, Social Security numbers, passwords and door or gate codes, health information, and full customer records. The FTC's data security guide for businesses suggests knowing what personal data you hold and keeping only what you need, which is a good lens here.
- Decide what needs a human check before it goes out: anything sent to a customer, anything with a price, anything legal or medical.
- Settle the training question. On personal ChatGPT accounts, anyone can turn off "Improve the model for everyone" under Settings, then Data controls. On personal Claude accounts it's Settings, then Privacy. OpenAI says it doesn't train on ChatGPT Business, Enterprise or Edu workspace content by default. Decide whether staff use personal accounts with training off, or a business plan.
- Add a payment-verification rule. The FBI's IC3 warns that criminals use AI-generated voice and video to impersonate people. A simple rule: no payment, gift card or bank change is approved from a call, text, email or video alone; call back on a number you already have.
- Paste your answers into the prompt below and let ChatGPT or Claude format them into one page.
- Read it out loud at a team meeting. Print it or pin it in your shared drive. Review it every six months.
Copy-paste prompt
Turn my notes into a one-page AI use policy for [BUSINESS NAME], a [TYPE OF BUSINESS] with [NUMBER] employees. Plain language, 8th-grade reading level, fits on one printed page. Sections: 1. Tools you can use 2. Never paste these into any AI tool 3. Always have a person check before sending 4. Account settings (training on/off, which accounts) 5. Money and identity: the callback rule 6. Who to ask if you're not sure: [NAME] Use only my notes below. Don't add legal claims or rules I didn't give you. Write each rule as a short "Do" or "Don't" sentence. MY NOTES: [paste]
Common mistakes
- Writing a ten-page policy nobody reads. One page, short rules.
- Banning AI without discussing it. If people use it anyway, they'll do it with no rules at all.
- Forgetting new hires. Add the page to onboarding.
- Assuming "delete the chat" means the data is gone right away. Check each tool's data controls and retention pages.
- Treating this as legal advice. If you handle health or financial data under specific regulations, have an advisor review it.
Sources
- Protecting Personal Information: A Guide for Business | Federal Trade Commission
- OpenAI Help: Data controls FAQ
- How do I change my model improvement privacy settings? | Anthropic Privacy Center
- Internet Crime Complaint Center (IC3) | Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud