Getting your business information ready for AI
What good data means for a small business using AI, and the ordinary housekeeping that gets your files ready and pays off with or without AI.
· 6 min readWhy a short, positive AI use policy helps your team use AI with confidence, what it should cover under UK GDPR, and a one-page outline you can adapt.

Somewhere in your business, someone has probably already used an AI assistant this week. Perhaps they tidied up a tricky email, summarised a long supplier contract, or asked for help with a stubborn Excel formula. Some will have asked first. Most won't have thought there was anything to ask.
That's encouraging. It means people are finding their own ways to save time. It does raise a fair question for the owner, though: are we comfortable with how this is happening, and does everyone know where the sensible lines are?
A short AI use policy answers that question. The aim is one page that tells people what's encouraged, what needs care and who to ask, rather than a ban or a long document nobody opens. This article explains what to include and gives you an outline you can adapt this week.
It's natural to think of a policy as a list of restrictions. For AI, the more useful way to see it is as permission with a few clear guardrails.
Without one, people tend to fall into two camps. Some quietly avoid AI because they aren't sure it's allowed, and miss out on genuine time savings. Others use whatever tool is to hand, including free consumer apps on personal accounts, without thinking about what they're pasting in. Neither is anyone's fault. Both are what happens when nobody has said what good looks like.
The UK's data protection regulator, the ICO, put this well when it published its own internal AI use policy in August 2025. Its foreword names, as one of the risks, "that we don't have the confidence to use the AI capabilities available to us because we aren't clear how to do that responsibly." The policy exists to fix that. Yours can do the same, at a fraction of the length.
Start by naming the tools people can use for work. This is the single most helpful line in the policy, because it turns a vague worry into a clear answer.
For most small businesses, the list is short. It might be the assistant built into the software you already pay for, such as Copilot in Microsoft 365 or Gemini in Google Workspace, and perhaps one standalone assistant on a business plan. If you haven't chosen yet, our article on Microsoft 365 Copilot for a small team covers one option in detail, and a guide to choosing between the main assistants is coming soon.
When you choose, look at the terms for each tool. Two questions matter most: whether the information your team types in can be used to train the provider's models, and what controls you get as the account owner. Free consumer versions and paid business plans often differ on exactly these points, so it's worth a few minutes with the provider's business terms before you add a tool to the list.
Then say it plainly: "Use these tools, signed in with your work account. If you'd like to try something else, ask first, and we'll look at it together."
This is the section people most want clarity on, and the one where UK GDPR comes in. The ICO is clear that there is no "AI exemption" to data protection law: if you put personal data into an AI tool, the usual rules apply. Its guidance on AI and data protection is the reference point (the ICO notes it's being reviewed following the Data (Use and Access) Act, so check it for updates).
For everyday use, a simple traffic-light approach works well:
| What it covers | In approved tools | |
|---|---|---|
| Green | Public information, general questions, your own drafting, non-sensitive internal documents | Fine to use |
| Amber | Client names and details, commercial information, anything covered by a confidentiality agreement | Approved business tools only, and only what the task needs |
| Red | Health information, HR and disciplinary records, bank details, passwords, anything you'd be uncomfortable explaining to the person concerned | Not without asking first |
The amber row reflects a principle called data minimisation, which simply means using only the personal information you actually need. Often you can remove a name or account number before asking for help and lose nothing.
If you've already tidied where sensitive information lives, as we described in getting your business information ready for AI, this part of the policy becomes much easier to follow.
AI assistants are very good at producing fluent, confident text. Occasionally that text is wrong: a figure that's slightly off, a regulation that doesn't quite say what's claimed, a summary that leaves out the one point that mattered.
So the policy should say, simply, that a person checks anything before it's relied on or sent. The ICO's own policy asks for exactly this, with a human reviewing outputs and amending them where necessary. In practice that means:
The person who sends it owns it. That's true of every email and proposal already, and AI doesn't change it.
Clients don't generally need to know that an assistant helped tidy an email. They may well want to know if AI plays a meaningful part in work you deliver to them, or if their information is involved.
A sensible line is: be open where it would matter to the client. If a contract or a client's own policy says something about AI, follow it. And if you use AI in a way that touches people's personal information, check whether your privacy notice needs a sentence to explain it.
Finally, name a person. It might be the owner, an operations manager, or the colleague who looks after IT. The aim is that anyone with a question ("Can I use this for that?") knows exactly where to take it, and feels comfortable doing so.
It's also worth agreeing that the policy will be reviewed, say every six months. The tools change quickly, and so will your team's confidence.
Copy this into a document, replace the bracketed parts, and you have a first version:
How we use AI at [Business name]
Why: AI can save us time on everyday work. We want everyone
to use it well and feel confident doing so.
Approved tools: [e.g. Copilot in Microsoft 365, signed in with
your work account]. Ask [name] before trying anything else.
Information:
- Green: public information, general questions, your own drafts. Fine.
- Amber: client details, commercial information. Approved tools
only, and only what the task needs.
- Red: health, HR, bank details, passwords. Ask first.
Checking: you check everything before it's used or sent.
You own what you send, however it was drafted.
Clients: be open where it would matter to them, and follow
any client contract or policy on AI.
Questions: ask [name]. No question is too small.
Review: we'll update this every six months. Last updated [date].
This week, write your first version using the outline above, and keep it to one page. Then share it at a team meeting and ask two questions: "What are you already using AI for?" and "What's unclear here?" The answers will tell you which lines to adjust, and they often turn up useful ideas worth sharing across the team.
If you'd like help with your policy, choosing tools or getting your team started, our AI Adoption service covers all three, and we're happy to talk it through.

What good data means for a small business using AI, and the ordinary housekeeping that gets your files ready and pays off with or without AI.
· 6 min read
How to write a simple one-page technology plan: where you are, what matters this year, a few priorities, a rough budget and a named owner.
· 5 min read
What Microsoft 365 Copilot does, how it differs from the free Copilot Chat, what it needs to work well, and how to trial it sensibly in a small team.
· 6 min read