Simple AI Use Policy for Small Businesses: NCSC Data Security Advice and What We Recommend
AI tools are now part of everyday work for many small businesses. A team member might use ChatGPT to draft an email, summarise notes, tidy up a policy, create a job advert, or explain a spreadsheet formula. That can save time, but it also creates a simple risk: people may paste sensitive information into tools without thinking about where that data goes next.
That is why a simple AI-use policy matters. It does not need to be long, technical, or full of legal language. For most small businesses, the goal is clear: help people use AI safely, while protecting customer data, business information, and staff confidentiality.
The UK National Cyber Security Centre, better known as the NCSC, has warned organisations to treat AI tools with care, especially when entering sensitive data. Tools like ChatGPT can feel private because they act like a chat window. They are not the same as a private notebook. Data entered into an AI service may be processed, stored, reviewed, or used depending on the provider’s settings and terms.

Why AI data security matters for small businesses
Small businesses often move quickly. People wear several hats, systems are practical rather than perfect, and new tools are adopted because they solve a problem today.
That makes AI both useful and risky.
A staff member might paste in:
A customer complaint containing names and contact details
A draft contract with commercial terms
Internal financial figures
Employee sickness or performance notes
Login details or technical information
A supplier dispute
Source code or product plans
Most of the time, this is not done carelessly. It happens because the tool is easy, the task is urgent, and the risk is not obvious.
The NCSC’s advice is a useful reminder that data shared with an AI tool should be treated like data shared with an external service. Before entering anything, businesses should ask whether that information is safe to share, whether the tool has been approved, and whether the settings meet the organisation’s needs.
A small business does not need a complex AI governance programme. It does need a few clear rules that everyone understands.
What the NCSC advice means in plain English
The NCSC has highlighted several key points about AI tools and data security. In simple terms, the message is this: do not assume information typed into an AI system stays private.
Different tools work in different ways. Some enterprise versions offer stronger data controls. Free or public tools may have different settings. Some providers allow users to switch off training on submitted data. Others may keep prompts for abuse monitoring, service improvement, or other stated purposes.
For a small business, the safest practical rule is:
If you would not email the information to an unknown third party, do not paste it into a public AI tool.
That does not mean AI tools should be banned. It means staff need boundaries.
AI is low risk when used for general tasks, such as rewording non-sensitive text, creating a blank template, brainstorming blog ideas, or explaining a public concept. The risk rises when the prompt includes personal data, confidential business information, credentials, legal details, or anything covered by client confidentiality.

A simple AI-use policy should answer five questions
A good policy helps people make decisions without slowing down every task. Keep it short enough that people will read it. One or two pages may be enough.
1. Which AI tools are allowed
List the tools the business is happy for staff to use. This might include a paid AI tool, built-in features in approved software, or a specific chatbot.
Also state that staff should not use unapproved tools for work data. This reduces the risk of someone trying a new app that has weak security or unclear terms.
2. What information must never be entered
This is the most important section. Use plain examples.
Do not enter:
Customer names, addresses, phone numbers, email addresses, or account details
Payment information
Passwords, API keys, or login credentials
Employee records or HR matters
Confidential client documents
Contracts, quotes, or pricing that are not public
Sensitive technical information
Anything subject to a non-disclosure agreement
This list should reflect the business. A care provider, accountant, consultancy, trades business, online retailer, and charity will all have different sensitive information.
3. What AI can be used for
Give people safe uses, not only restrictions.
AI can often help with:
Drafting generic emails
Turning rough notes into a clearer structure
Creating checklists
Summarising public information
Generating training quiz questions
Improving grammar in non-sensitive text
Creating first drafts from anonymised information
This approach makes the policy feel useful rather than punitive.
4. How to anonymise information
Anonymising data means removing details that identify a person, client, project, or transaction.
For example, instead of pasting:
“Please summarise this complaint from Sarah Jones at 14 Church Road about invoice 00451.”
Use:
“Please summarise this customer complaint about a delayed invoice. Remove emotional language and produce a polite response.”
Replace real names with roles, such as “customer”, “supplier”, or “employee”. Remove addresses, reference numbers, financial details, and any unusual facts that could identify the person or business.
5. Who to ask when unsure
Every policy needs a simple route for questions. For a small business, this could be the owner, operations manager, data protection lead, or IT support provider.
The rule should be clear: if unsure, do not paste it in until someone checks.

How to create the policy without making it a big project
A useful AI-use policy can be created in an afternoon. Start with what people already do, then write rules around the real risks.
Step 1. Ask how AI is already being used
Have a quick internal check. Ask staff which tools they use, what tasks they use them for, and what information they enter.
The answers may be surprising. This is not about catching people out. It is about understanding current habits before setting rules.
Step 2. Sort data into risk levels
Create three simple categories.
Data type | Example | AI use |
Public | Website copy, public product descriptions | Usually safe |
Internal | Draft process notes, general planning | Use care |
Sensitive | Personal data, contracts, financials, credentials | Do not enter into public tools |
This gives staff a quick way to judge a task.
Step 3. Choose approved tools and settings
Check the privacy and security settings for any AI tools the business uses. Where available, turn off the use of prompts for model training. Review who has access, whether accounts are shared, and whether the tool supports business-level controls.
Avoid shared logins. They make it harder to manage access and review activity.
Step 4. Write the policy in plain language
Use short rules. Avoid technical terms unless needed. Include examples from the business.
A simple structure works well:
What AI may be used for
What must not be entered
Which tools are approved
How to anonymise data
Who to ask for help
What happens if something is entered by mistake
If someone accidentally shares sensitive information, the business should know what to do next. That may include recording the incident, checking the tool provider’s options, changing exposed credentials, and seeking data protection advice if personal data is involved.
Step 5. Share it and revisit it
A policy only works if people see it. Share it during onboarding, keep it in the staff handbook, and remind people when new tools are introduced.
Review it every few months, or whenever the business adopts a new AI service.
Make the policy practical, not scary
The best policies match how people actually work. If the rules are too strict, staff may avoid asking questions. If there are no rules, people will make their own.
A balanced policy says:
Use AI for low-risk work
Remove sensitive details before prompting
Use approved tools
Pause and ask when the data is private, personal, or commercially sensitive
Check AI outputs before relying on them
That last point matters. AI tools can produce confident but wrong answers. Data security is one risk. Accuracy, bias, and copyright concerns are also worth covering briefly, especially if AI output will be sent to customers or used in important decisions.

What we recommend
Create a simple AI-use policy now, even if AI use feels informal. Do not wait for a data scare before setting expectations.
Our recommendation is to take these steps this week:
Find out which AI tools are already being used
Decide what information must never be entered
Approve a small list of suitable tools
Show staff how to anonymise prompts
Write a one-page policy and share it
Review settings and update the policy regularly
AI can be a helpful tool for small businesses, but only when people know where the boundaries are. A clear policy gives staff confidence, protects sensitive information, and turns the NCSC’s advice into everyday practice.



