All answers

Does my business need an AI policy?

If anyone in your business already uses AI at work — and in most businesses they do, whether or not it was approved — you need something written down. One page covering approved tools, prohibited data, work accounts and who to tell when something goes wrong is enough for most SMEs and far better than a long document nobody reads.

Andy CareyPrincipal Consultant, NT Development GroupLast updated 7 October 2026

The question is already answered for you

By the time a business asks whether it needs an AI policy, staff are generally already using AI — on personal accounts, for real work, without anyone having decided what is acceptable. The choice is not between having AI in the business and not having it. It is between knowing where it is and not knowing.

That reframing matters because it changes the policy from a restriction into a permission. A document that only prohibits drives usage further out of sight. A document that says clearly what people may do is the one that gets followed.

What the one page has to contain

  • Approved tools, by name. Not "reputable AI services" — the actual products, on the actual accounts. Ambiguity here is what produces personal-account usage.
  • Data that must never go in, by category and with examples. "Confidential information" means nothing in practice. "Client financial statements, anything with a TFN, employee records, unreleased pricing" is a rule somebody can follow at 4pm on a Friday.
  • Who checks output before it leaves the business. Named role, and the specific contexts requiring review — anything sent to a client, anything that moves money, anything published.
  • What to do when something goes wrong. One name and one sentence. Most harm from an accidental disclosure comes from the hours spent deciding whether to mention it.
  • Disclosure expectations. Whether AI-assisted work needs flagging to clients, and in what circumstances. Some professional and government contracts now require this.

Why the long version usually backfires

Comprehensive AI policies are typically adapted from frameworks written for organisations with risk committees. In a thirty-person business the result is a twenty-page document that is circulated once, acknowledged by everyone, read by nobody, and cited only after an incident to establish that someone was in breach.

It also ages badly. A policy that names specific model versions, specific capabilities and specific restrictions is wrong within a quarter, and a visibly out-of-date policy teaches staff that the rules are decorative. Write the version short enough that revising it is a ten-minute job.

When you do need more than a page

Three situations justify something heavier. If you hold other people’s sensitive information at scale, your obligations are specific enough to need specific controls. If you are in a regulated sector or tendering for government work, the requirement may be contractual and the format may be dictated to you. And if AI output reaches a customer without a human in between, you need a documented position on accuracy, recourse and who is accountable for a wrong answer.

Short of those, a page is proportionate. The purpose of the document is to let a sensible person make a correct decision without asking — not to demonstrate that governance occurred.

This question comes up most often in our Business Advisory engagements.

GovernancePolicyAI for business

Have a question about your own operations?

Send us an outline and we will come back with a fixed-price proposal within three business days.

Talk to our team