Governance for AI: the minimum viable policy

You don't need a 40-page framework to start safely. The essentials that keep adoption responsible.

Most businesses get AI governance wrong in one of two directions. Either there’s no policy at all and staff are pasting client data into whatever chatbot tab is open, or someone has produced a 40-page framework that nobody has read past the cover page and adoption quietly dies. Neither helps you. The useful version sits in the middle, and it fits on a page.

It’s worth being clear about what’s actually at stake, because “governance” sounds like a big-company word and most small businesses tune out the moment they hear it. Here’s the small-business version. Your bookkeeper pastes a client’s payroll summary into a free chatbot to draft an email, and that data is now sitting on a server you’ve never heard of, under terms nobody read. Your estimator uses AI to draft a quote, gets a figure that’s confidently wrong, and sends it before anyone checks. A staff member signs up for a tool with their work email, connects it to the company Google Drive, and leaves the business six months later with the connection still live. None of these need a framework to prevent. They need four sentences someone actually wrote down.

What no policy looks like from the inside

The awkward part is that the no-policy business usually thinks it has no AI. Ask an owner whether their team uses AI and the answer is often “not yet, we’re still looking into it”. Ask the team and it’s a different story: three people have personal ChatGPT accounts open in a browser tab all day, someone in admin found an AI tool that summarises PDFs and has been feeding it supplier contracts, and the new hire uses AI for every email because that’s how they worked at their last job. The adoption already happened. It just happened without you, on personal accounts, with nobody thinking about what went where.

That’s the real case for a policy, and it’s not about slowing anyone down. It’s that the alternative to a written policy isn’t no AI use. It’s unmanaged AI use, which means the business is already carrying the risk and just hasn’t priced it. The choice you actually have isn’t whether AI gets used. It’s whether you find out about a problem from a one-page policy review or from a client asking why their information turned up somewhere it shouldn’t have.

What a minimum viable policy covers

Four things, and you can write them in an afternoon.

First, what can go where. A plain list of which information is allowed in which tools. Customer records in this, public marketing copy in that, nothing sensitive anywhere off the approved list. Get this one rule right and you’ve headed off most of the trouble before it starts. Make the categories concrete rather than legal: “client names and financials”, “staff details”, “anything under NDA”, “stuff already on our website”. A rule like “no client-identifiable information in free-tier tools” is one your team can apply at 4:55pm on a Friday. “Exercise appropriate caution with sensitive data” is not, because nobody knows what it means and everyone decides it means whatever they were already doing.

Second, a name against the decisions. Pick the person who owns AI choices for the business. The point is to turn “someone should probably look at this” into a specific human who actually does. In a ten-person business that’s probably the owner or the operations manager, and the job is small: field the “can I use this tool?” questions, keep the approved list current, and be the person who hears about it first when something goes wrong. What you’re avoiding is the diffuse version, where everyone assumes someone else is across it and the actual answer is that nobody is.

Third, a short list of tools you’ve said yes to. Approve a handful of good options out loud. If you don’t, people will go shopping on their own and you’ll find out which tool they picked the day something leaks. The approved list also does something less obvious: it gives staff permission. Plenty of teams are quietly using AI while half-suspecting they’re not supposed to, which means they’ll never ask the questions that would surface a problem early. A visible yes-list turns the secret usage into open usage, and open usage is the kind you can manage. If the work is sensitive enough that public tools are off the table entirely, that’s the point where private AI enters the conversation, models running where you control the infrastructure and the data never leaves.

Fourth, keep a person in the loop wherever the output drives a decision that matters. A draft quote, a summary that informs a call, a flagged invoice. AI suggests, a human signs off before it lands. The test for “matters” is simple: if the output being wrong would cost money, embarrass you in front of a client, or create a legal problem, a named person checks it before it goes anywhere. Internal brainstorming and first drafts don’t need the gate. The email that commits you to a price does.

The 40-page version fails for a specific reason

It’s tempting to think the long framework is the safe option and the one-pager is the compromise. In practice it’s the reverse, and the reason is boring: policies only work if people can remember them at the moment of decision. A staff member with a client file open and a chatbot in the next tab is not going to consult section 7.3 of a governance document. They’re going to do whatever the ambient culture around them does. A one-page policy has a chance of actually being in their head at that moment. The 40-pager was filed the day it was circulated.

There’s also an incentive problem with the long version. Framework-length governance is usually produced to be shown to someone, a board, an insurer, a client’s procurement team, rather than to change behaviour. That’s not worthless, but don’t confuse the two documents. The one that protects you day to day is the short one your team has actually read. If you need the long one for a contract, write it separately and don’t let it replace the page that does the work.

Writing it: an afternoon, honestly

Here’s what the afternoon looks like. Sit down with whoever runs operations and list the information categories your business handles, five or six lines, no more. Decide which tools you’re comfortable with and at what tier, because the paid business version of a tool often has meaningfully better data terms than the free one, and that difference is exactly the kind of thing nobody checks. Write the four rules in plain sentences. Put a name and a date on it. Send it to the team with a two-line email saying AI use is fine, here’s how we do it here, and ask everyone to reply with any tools they’re already using that aren’t on the list.

That last step matters more than it looks. The replies are your real audit. Most owners who run this exercise find at least one tool in use they’d never heard of, and it’s far better to find it via a friendly email than via an incident. Whatever turns up, resist the urge to punish it. The goal is to move usage into the open, and nothing drives it back underground faster than someone getting in trouble for answering honestly.

Start small, tighten later

A one-page policy people follow beats a thorough one they ignore. Write the four essentials, put a name against them, and tighten as you use AI more and learn where it bites. Revisit it quarterly for the first year, not because governance demands a cadence but because your usage will change fast: the tools your team leans on in month six won’t be the ones from month one, and rules written for a chatbot don’t automatically cover an AI agent that acts on your systems. Each review is twenty minutes: what are we using now, what nearly went wrong, does the page still match reality.

The whole point of governance is to make it safer to adopt AI, not to give everyone a reason to never start. If you’d like a second pair of eyes on where AI fits your business and what the policy should cover for your kind of data, the AI readiness assessment is a practical place to start, and if the answer involves keeping sensitive work off public tools entirely, we can talk about what private AI looks like at your size.

All insights

Turn the thinking into a plan.

Send the process, risk or idea. We will help you work out what is worth doing first.