Can your employees use ChatGPT? What an AI policy actually needs to say
Staff are already pasting things into ChatGPT and Copilot whether or not there’s a policy about it. A ban doesn’t work and a one-line “be careful” doesn’t either — what a working AI acceptable use policy actually has to cover.
Somewhere on your team, someone pasted a client email into ChatGPT last week to help draft a reply. Possibly a spreadsheet. Possibly a contract. Not maliciously — it was faster, it worked, and there was no policy telling them not to. That’s the actual starting position for almost every small business right now: real usage, no written rule, and an assumption that “we haven’t had a problem” means there isn’t one to have.
The instinct to write a policy usually shows up only after a scare — a client asks what your AI policy says, an insurer’s questionnaire adds a line about it, or someone realizes what actually got pasted into a tool nobody vetted. Writing it now, before that moment, is cheaper and calmer.
Banning it doesn’t survive contact with how people actually work
The first draft of most AI policies is a ban, and the first thing that happens to a ban is that people quietly ignore it, because the tool is faster than the alternative and nobody’s watching closely enough to catch it. A policy that assumes it will be followed to the letter, by everyone, indefinitely, is a policy that fails exactly where it matters — not because staff are careless, but because the rule was never realistic to begin with. The working version isn’t “don’t use AI”; it’s “here’s exactly what can and can’t go into it, and why.”
What actually has to be in it
A policy that survives contact with a real workday answers three questions, in this order:
- What can’t go in, regardless of the tool. Customer or client information, staff personal information, financial records, passwords, and anything covered by a confidentiality agreement — the moment it’s pasted into a tool the business doesn’t control, the business no longer controls where it sits or who can see it.
- Which tools are actually approved for anything involving real client material — not “AI in general,” a specific list, because a vendor’s own data-handling terms differ tool to tool and someone has to have actually read them before real work goes near one.
- Who owns the output. Whatever an AI tool produces is the employee’s work the moment they send it — checked for accuracy, and never the thing making a decision about a payment, a person, or a client’s affairs that nobody could explain afterward.
Notice what’s absent from that list: nothing there requires knowing which specific AI regulation might someday apply to a five-person firm. The policy works by controlling what goes into the tool, not by trying to classify the tool itself — which is also the part most template AI policies get backwards, spending a page on AI taxonomy and a sentence on the actual data rule that protects the business.
The federal wrinkle that’s easy to miss if you prepare tax returns
There’s one place this stops being general good practice and becomes a specific, real federal exposure: a paid tax return preparer disclosing or using a client’s tax return information without the client’s prior written consent, in the form Treasury’s regulations prescribe, carries its own exposure under 26 U.S.C. § 7216 — criminal penalties where the disclosure is knowing or reckless, civil penalties under § 6713 even where it isn’t. Pasting return information into an AI tool that hasn’t been checked and approved can be exactly this kind of disclosure. If that’s your business, treat tax return information as something that never goes into an AI tool outside a process you’ve actually confirmed with counsel — not a rule to infer from the general policy above.
What it doesn’t do
An AI policy is one page of a bigger document, not a security program on its own — it doesn’t replace MFA, backups, or an incident response plan, and it isn’t a compliance certificate for any regulation that might reach your business. What it does is close the single most common way sensitive information leaves a small business by accident right now: someone trying to be helpful, with a tool that was never told where the line was.
Coverwright’s Complete document set includes this as one section of the Acceptable Use Policy, generated from the same answers as everything else — written at your staff rather than about them, with the tax-preparer clause included automatically where it applies rather than left for someone to remember.