AI Governance Policy Examples: Real Templates and Sample Clauses for Small Businesses

AN
AI Navigator Collective

Your team is at the moment using AI; some of the employees write their emails in ChatGPT, your designer uses Copilot, and your CRM is automatically summarising the calls in the background. The real problem now is whether or not this is being controlled.

An AI governance policy is a set of rules in written form that outlines how your business is to use AI—specifying which tools are approved, what data those tools can use, who is responsible, and what steps are taken when a problem occurs. It is not a ban on the use of AI; instead, it allows you to use AI with confidence rather than leaving yourself open to unexpected legal and reputational risks.

Most small businesses do not carry out this step. A survey carried out by the U.S. Chamber of Commerce in 2025 found that about 68% now use AI in some manner, but certain estimates suggest that around three-quarters have no written policy. It is within this gap that avoidable incidents take place, as shown by the example of the airline which was held legally responsible by a tribunal for a refund its chatbot had invented.

The thing this guide provides which most articles fail to do is to include real examples that you can copy and modify, sample clauses suitable for various kinds of businesses, a minimum viable policy that you can launch this week, and an explanation in simple English of the 2026 rules.

Key Takeaways

  • A policy concerned with AI governance sets out simple rules about which AI tools can be used, together with the kind of data they can use and the level of supervision they must have.
  • It isn’t limited to enterprises either, since most small teams can manage with a one-page policy and complete it in less than a day.
  • It is possible to enforce the rule “do not place customer data into unapproved tools”, whereas you can’t enforce “use AI responsibly”.
  • Begin by listing the AI tools that are currently in use, and then draw up a policy based on the results of that listing.
  • The NIST AI Risk Management Framework should be used as your starting point because it covers most of the overlapping requirements of the U.S. and EU.
  • Now hide the AI agents since those tools that take actions by themselves represent a different and growing risk.

What is an AI governance policy?

AI governance policy

An AI governance policy is a written document that sets out how an organisation can use, buy, and supervise AI systems, indicating which tools are approved, what data can be used, who is responsible, and how risks and incidents are to be managed; it’s similar to road rules which allow your business to move swiftly without crashing.

To understand it one must take into account the general situation. If you are asking yourself what AI governance really entails, then here is a short explanation: by governance is meant the system, and your policy is the written aspect of that system.

How AI Governance Connects to Related Ideas

Even though these terms are frequently used in the same way, they serve different functions. It is important to understand the relationships between them if you want to draw up a policy that remains coherent.

Concept What it means Its role in your policy
AI governance The overall system of oversight and accountability Your policy is its written foundation
Responsible/ethical AI The values you hold (fairness, transparency, human dignity) The principles your policy commits to
AI risk management Identifying and reducing AI-related harms The process your policy triggers (e.g., NIST AI RMF)
AI compliance Meeting laws and standards What your policy helps you demonstrate (EU AI Act, GDPR)
AI security Protecting data and systems used with AI The technical controls your policy references
AI transparency Disclosing AI use and decisions A specific rule in your policy (label AI content)
AI regulation The external laws that apply What policy maps your business to

A well-defined policy turns the general objectives of responsible AI into rules that people can follow on a Tuesday afternoon.

What Counts as “AI” in Your Policy

It is in this area that most policies fail to deal with the issue, since people’s conception of AI tools is mainly limited to ChatGPT, Claude, Gemini, and Copilot. Nevertheless, AI has already been included in the software that your team uses on a daily basis—for example, in the writing assistant in your documents, in the smart features of your CRM, and in the autocomplete function of your code editor.

Any policy that mentions only standalone chatbots does not consider most of your actual exposure. Your definition should cover three elements: standalone AI tools, AI features that are included in other software, and agentic AI that takes actions on its own.

Actually, do small businesses need one?

In most cases the honest answer is yes, but the quantity of details you should provide will vary according to the kind of work you’re engaged in. Use this simple test.

You need at least a one-page policy if any of these are true:

  • The staff use AI tools that involve customer or company data.
  • You provide your services to larger companies (since the vendor security questionnaires that these companies use now include questions on AI governance).
  • You deal with personal data, health records, or details relating to payments.
  • You use AI in a regulated function like hiring, lending, or healthcare.

So long as the number of people is less than five, neither is any regulated data held nor is any customer information entered into an AI tool, and in that situation you can keep things simple. Yet in that case a single-page acceptable-use statement is still no better than nothing.

There really is a governance gap and this can be measured. A survey carried out by Genesys in 2025 found that 35% of technology leaders said their organisations had ‘little to no formal AI governance’. Research conducted by Economist Impact shows that only about 2% of small organisations have a comprehensive governance framework.

For the majority of small and medium-sized businesses, the first obstacle they face isn’t a regulator but a sales barrier. Increasingly, enterprise customers will not agree to a deal until you can demonstrate a documented approach to AI, and having a policy together with a brief line of evidence is enough to change their “no” into a “yes”.

What to Include: The 10 Building Blocks

What to Include The 10 Building Blocks

All effective AI governance policies include the same basic sections and each should be brief and to the point.

  1. The purpose and scope of the policy—that is, the reasons for its existence and the people it applies to—include embedded AI.
  2. Definitions: what is meant by an AI system, what constitutes an approved tool, what is regarded as a high-risk use, what is considered personal data, and what is agentic AI.
  3. Roles and ownership: one named owner is enough for a small team. (Larger teams may form an AI governance committee.)
  4. Approved tools list what’s allowed, and how to request something new.
  5. Prohibited uses: clear bans, not vague rules.
  6. The rules for handling data are divided into three levels: never share it, use only approved tools, and allow free use.
  7. Human oversight: which decisions need a person before action is taken.
  8. Transparency and disclosure: label AI-generated external content and credit sources.
  9. Incident reporting: what to report, to whom, and how fast.
  10. The training, the enforcement, and the acknowledgement of the consequences along with the review date.

These ten blocks are the skeleton. The examples below show what they look like with flesh on the bones. For a deeper structural blueprint, see our guide to building an AI governance framework.

AI Governance Policy Examples You Can Adapt Today

What competing articles seldom offer are actual, practical examples. Adjust the sections in brackets to suit your business.

Example 1: A Minimum-Viable AI Policy (for any team under ~50)

This fits on a single page and covers the essentials without slowing anyone down.

[Company Name] AI Use Policy

You may use only the AI tools that are on our Approved Tools list. If you would like to request a new one, please message [owner/channel]; we will review your request within five business days.

Rules concerning data: do not input customer personal data, payment details, health records, source code, passwords, or unreleased financial information into any tool which is not approved for that type of data. If you are in any doubt, ask before you paste.

Human review. A person reviews and approves any AI-assisted work before it goes to a customer or gets published.

Disclosure. Label AI-generated content for clients where our contracts or the law require it.

Accounts of incidents. Notify [owner] of any mistake relating to AI or incident of data exposure within two business days.

We carry out a review of this policy annually, and more quickly if a new tool, piece of legislation, or incident arises.

You are in advance of the majority of small businesses simply because of that brief document.

Example 2: Prohibited Uses Weak vs. Strong

The difference between a policy that works and one that gets ignored is specificity.

  • Weak: “Employees must use AI responsibly and ethically.”
  • Strong: “Do not input customer personal data, payment information, health records, source code, or unreleased financials into any AI tool that is not on the Approved Tools list and covered by a signed data processing agreement.”

A few more strong, enforceable clauses to adapt:

  • Avoid using your personal AI accounts when handling company or customer data.
  • Make sure that human review is properly documented before reaching any final decisions regarding hiring, termination, or performance.
  • Do not publish AI-generated content externally without a human review and, where required, disclosure.

Example 3: Sample Clauses by Business Type

Various businesses involve different levels of risk, and the following brief, ready-to-edit examples illustrate how the same policy can be adapted.

Business type Sample clause to adapt
Marketing / creative agency
Label AI-assisted deliverables to clients where contracts require it, run an originality and IP check on generated assets, and never upload a client’s unpublished campaign to a consumer AI tool.
E-commerce / DTC brand
A human must review AI-generated product claims and pricing before publishing. Customer order data and PII may not enter unapproved tools. Disclose to shoppers when they’re chatting with an AI bot.
Medical / wellness clinic
No protected health information may enter any AI tool without a signed business associate agreement. AI may draft, but a clinician approves anything patient-facing. Disclose AI use in care where required.
Professional services (legal, finance, consulting)
Confidential client data may only be used in approved, contracted tools. Fact-check all AI output. A partner or owner signs off on advice materially influenced by AI.

Example 4: Lessons From Real AI Failures (Turned Into Clauses)

The best argument for having a system of governance is to be found in the situation that arises in its absence; against each of the stories listed there is a clause which you can use in your own policy.

  • In the case of Moffatt v. Air Canada from 2024, a tribunal ruled that the airline was responsible because of a refund policy which its chatbot had come up with. The takeaway is that clauses regarding customer-facing AI outputs should be reviewed, approved, and clearly labelled.
  • The leak of Samsung’s source code. In 2023, engineers pasted proprietary source code into ChatGPT, as a result of which the company decided to restrict the use of AI. Lesson → rule: the prohibited-data rule together with an approved-tools list (mentioned above).
  • Zillow’s pricing model. In 2021, an automated home-buying model contributed to a roughly $304 million write-down and the unit’s shutdown. Lesson → clause: keep a human in the loop on any decision that moves money or affects people.

Want the full version? You can build on these examples with our AI governance best practices guide.

The 2026 Rules at a Glance

The 2026 Rules at a Glance

You don’t need to memorize every law. You do need to know which ones might touch your business, and the landscape shifted in 2026.

The Global Benchmark: The EU AI Act

The EU AI Act is based on a risk-oriented method, dividing AI into four categories: unacceptable, high, limited and minimal risk. It applies to your AI if that AI has an effect on people in the EU.

The most demanding requirements concerning high-risk systems under the EU’s 2026 “Digital Omnibus” simplification plan have been postponed until December 2027 in the case of standalone high-risk applications and until August 2028 when AI is incorporated into regulated products. The rules regarding the labeling of AI-generated content are to be introduced in December 2026. Fines for prohibited practices still amount to as much as €35 million or 7% of global turnover, which shows clearly where the policy is heading despite the delay.

The United States: A State-by-State Patchwork

There is still no comprehensive U.S. federal AI law, so states are setting the rules:

  • It will come into effect on January 1, 2026. The regulation focuses on intentional harms and provides a safe harbour if you comply with the NIST AI RMF; the fines for each breach range from $10,000 to $200,000.
  • Colorado repealed its original AI Act and replaced it with a narrower automated-decision law (SB 26-189), effective January 1, 2027.
  • California SB 53 and AB 2013 took effect January 1, 2026, focused on frontier-model and training-data transparency.
  • Illinois (through HB 3773) and New York City (via Local Law 144) have introduced rules concerning the use of AI in hiring, these rules including requirements for bias audits of automated hiring tools.

The Shortcut for Small Businesses

The practical step that is rarely stated clearly is to establish a single AI inventory and a single risk management program using the NIST AI Risk Management Framework. This one program addresses most of the areas of overlap between the requirements of Colorado, California, and the EU AI Act, while at the same time securing Texas’s safe-harbor status.

The steering wheel is the policy while the engine is strong risk management for AI. (This is general information, not legal advice—seek advice from counsel if you are dealing with regulated data.)

How to Write Yours in a Day

A practical policy is better than a flawless plan that never gets launched. Here is a realistic route that can be followed on the same day.

  1. Start with the inventory and then deal with the documentation. Make a list of all the AI tools being used. Check the expense reports, the browser extensions, and the SaaS add-ons. You cannot govern something that you cannot see.
  2. Group them according to their level of risk and identify the ones that involve personal data or have an effect on decisions about people.
  3. Name an owner; if ownership is diffuse, then the policy will become obsolete within a year.
  4. This is a draft based on a template; begin with the example given above and then adjust the sections concerning prohibited uses and oversight.
  5. If you work with regulated data, take a moment to check the legal side.
  6. Before you publish, create the list of approved tools; if you publish with no approved tools, you’re effectively banning all tools, which is why the staff will ignore the policy and continue to use the ones they already had.
  7. Gather the acknowledgements, carry out the training, and fix a date for the review.

Best Practices for Small Teams

A few habits separate policies that work from ones that sit in a folder:

  • Make the prohibited uses specific so that they can be understood without having to interpret them.
  • Separate the policy from the procedure so that the “how-to” may be changed without
  • requiring re-approval.
  • When it comes to getting approval for a tool, it’s faster to ask than to sneak around; shadow AI reduces the size.
  • Link your decisions to the policy, not just your tools, by using a clear AI decision-making framework.

Common Challenges (and How to Solve Them)

Common Challenges

Challenge Practical solution
Staff already use unapproved AI (“shadow AI”) Run an inventory, then approve safe tools fast so people have a sanctioned option
The policy is too vague to enforce Replace principles with specific, testable rules
No one keeps it current Assign one named owner and a fixed annual review
The policy ignores embedded AI Define AI broadly to include features inside everyday software
Agents act before a human can intervene Add an agent appendix with action limits and logging (below)

Where AI Governance Is Heading

The two trends will determine what happens next year, and your policy should be prepared for both.

The latest frontier is agentic AI. In the case of a chatbot, the human has to carry out the final action. But when it comes to an AI agent that sends emails, runs code, or makes purchases, the action is taken first. Research by Deloitte showed that although 74% of organisations plan to adopt agentic AI within two years, only about 21% have a well-developed method for governing it, and 35% admit that they wouldn’t be able to shut down a rogue agent.

If your team is experimenting with agents, bolt a short appendix onto your policy answering five questions:

  1. What actions is an agent allowed to take without having
  2. Going to get approval?
  3. How much data can it access? (No more than the individual who deployed it.)
  4. Then who is the named human owner responsible for it?
  5. Is every one of its external actions logged?
  6. What is the approval threshold for deploying a new agent?

Regulations are constantly changing. You should expect there to be more state laws, greater scrutiny of the vendors involved, and more demanding requirements concerning transparency. Having a policy that is living and has a genuine review date will keep you prepared. The most affordable form of insurance you can purchase is to get started early by aligning with established frameworks for the responsible adoption of AI.

Frequently Asked Questions

So what constitutes an AI governance policy?

It is a written document that sets out the way in which your business uses and monitors AI, specifies which tools are approved, states what data is allowed, identifies who is responsible, and outlines the actions to be taken when something goes wrong. It aims at enabling the safe use of AI rather than prohibit it.

What then should an AI governance policy contain?

The absolute minimum should be purpose and scope, definitions, roles and ownership, a list of approved tools, prohibitions on use, rules regarding data handling, requirements for human oversight, rules on disclosure, procedures for reporting incidents, and a schedule for review.

Is my small business legally obliged to have an AI policy?

It depends on both the place where you operate and the type of data you handle. Even if it is not strictly mandatory, having a written policy helps to reduce liability and is now increasingly expected by enterprise customers and insurers.

How long should an AI governance policy be?

In most cases of small teams, one page is sufficient. You can then add more details when the team grows, when it starts to handle regulated data, or when it decides to obtain certifications such as ISO/IEC 42001.

Data that should never be fed into AI tools includes customer personal data, health records, payment information, source code, passwords, and unreleased financial information unless the tool has been approved for that type of data and is covered by a signed agreement.

What is the way of governing AI agents?

Include an appendix that specifies which actions require human approval, what data the agent is allowed to access, who owns it, how its actions are recorded, and the criteria for deploying a new one.

How frequently should the policy be updated?

It should be reviewed at least once every year, and more often if a new type of tool, a new regulation, or an incident occurs.

Conclusion: Start Small, Start Now

AI governance is not equivalent to bureaucracy; it is what enables you to say “yes” to AI without having to take on risks that are not visible. It is the companies that have no rules at all—which are rarely the ones that end up being harmed—that get burned.

You won’t need an enterprise budget or a legal department if you want to get started. Simply adapt the one-page example given above, carry out a rapid inventory of the tools that your team currently uses, and assign a name to each tool alongside the name of its owner. There’s a genuine policy there, and you can have it completed this week.

If you’d like to access templates and frameworks and join a community of practitioners who are addressing the same questions, then become a member of the AI Navigator Collective.

Stay Connected To The AI Navigator Collective

Sign Up for our newsletter.