A lot of small businesses do not think they are “using AI” yet.
Then you ask a few questions.
Has anyone used ChatGPT to tidy up an email? Has someone pasted meeting notes into an AI tool and asked for a summary? Has a manager used it to draft a difficult client reply? Has a junior member of staff asked it to explain a contract clause, turn a proposal into bullet points, or rewrite a job advert?
Very often, the answer is yes.
That does not mean the business has done anything wrong. It does mean the business may already need a basic AI policy.
Not a 40-page legal document. Not a committee. Not a ban on useful tools. Just some simple rules that help people use AI sensibly without accidentally sharing client data, confidential information or commercially sensitive material.
The risk is not usually “AI taking over”
For most Cheltenham and Gloucestershire professional businesses, the immediate AI risk is much more ordinary.
Someone copies information into a public AI tool without thinking about where that information goes.
That could include:
- a client email
- a contract or proposal
- an HR issue
- a spreadsheet of customer information
- internal pricing
- board notes
- financial information
- a login, API key or private link
- a complaint or legal matter
The person doing it is usually trying to be helpful. They want a faster summary, a clearer email or a second opinion. The problem is that public AI tools are not the same as an internal colleague. Depending on the tool, settings, account type and data controls, pasted information may be stored, reviewed, used for product improvement, or simply handled in a way that is not appropriate for your business.
Even where a tool has stronger privacy controls, your staff still need to know when it is acceptable to use it and what must stay out.
A policy gives people permission as well as limits
Some business owners hear “AI policy” and assume it means saying no.
It does not have to.
A good starter policy should make useful AI safer and easier. It should tell people what they can do, not just what they must avoid.
For example, you might allow staff to use approved AI tools for:
- improving the wording of non-confidential emails
- creating first drafts from non-sensitive notes
- summarising public information
- brainstorming blog ideas or FAQs
- turning internal how-to notes into clearer instructions
- checking grammar and tone
- creating meeting agendas
But you might restrict or require approval for:
- client-identifiable information
- legal, HR or medical matters
- financial data
- contracts and commercially sensitive proposals
- passwords, credentials or system access details
- anything regulated by a client agreement or professional duty
That balance matters. If the rule is simply “do not use AI”, people will either miss useful opportunities or use it quietly anyway. If the rule is “use whatever you like”, the business takes unnecessary risk.
Start with five simple rules
If your team is already using ChatGPT or similar tools, start with something practical. These five rules are a good first version.
1. Do not paste personal, client or confidential data into unapproved AI tools
This is the big one.
Staff should assume that client names, personal data, private emails, contracts, HR matters, pricing, financial information and internal strategy do not belong in a public AI chat unless the business has specifically approved the tool and settings for that use.
If they need AI help, teach them to remove identifying details first. “A client” is often enough. “A Gloucestershire manufacturing business with this named director, contract value and complaint history” is not.
2. Use approved tools and accounts where possible
One staff member using a free personal account is very different from a business choosing a tool, checking its data settings and deciding what it is for.
You do not need a huge software review for every low-risk use, but you should know which tools are acceptable, who can use them, and whether chat history or model training settings need to be changed.
3. Keep a human responsible for the output
AI can sound confident when it is wrong.
That means someone in the business remains responsible for checking the answer before it goes to a client, customer or supplier. This is especially important for advice, facts, figures, policy, legal wording and anything that affects a decision.
In my Cheltenham Times AI agent experiment, one of the clearest lessons was that speed still needs judgement. The agents could research, draft and organise useful local content, but mistakes led to tighter rules, review queues and better checks. The same principle applies inside a professional business.
4. Do not let AI become a hidden decision-maker
Using AI to help draft, summarise or organise is one thing. Using it to make decisions about people, clients, pricing, recruitment, credit, complaints or risk is another.
If AI influences an important decision, be clear about how. In many small businesses, the right starter rule is simple: AI may assist; a person decides.
5. Ask before using AI on anything sensitive
Your policy does not need to cover every possible situation. It should create a clear default.
If a member of staff is unsure, they should ask before pasting. That alone will prevent many problems.
Make the policy usable, not perfect
The worst AI policy is the one nobody reads.
A useful first version might fit on one page. It could include:
- which AI tools are approved
- what staff may use them for
- what must never be pasted
- when to anonymise information
- when to ask for approval
- who is responsible for checking outputs
- where to report concerns or mistakes
You can improve it later as your AI use becomes more serious. The important thing is to stop pretending the business has no AI use just because you have not formally rolled out an AI system.
The next step
If your team is already experimenting with ChatGPT, Copilot, Claude, Gemini or Perplexity, do a quick audit this week.
Ask three questions:
- Which AI tools are people using?
- What are they putting into them?
- Which uses are helpful enough to support properly?
That conversation will tell you whether you need a simple policy, better tool settings, staff training, or a more private workflow for sensitive work.
If you would like help creating a practical AI policy and identifying safe, useful AI opportunities in your business, book a short consultancy call. The aim is not to slow your team down. It is to help them use AI with clear rules, sensible guardrails and less risk.