SMBs: the AI usage policy to write before your team uses these tools
Your team already uses artificial intelligence tools, often with customer data, and nobody authorized it. The policy that frames this use fits on one page, costs half a day to write, and prevents communications of personal information outside Quebec that the law requires you to assess beforehand.
- The use is already there. The question is not whether to allow or ban, it is how to frame what happens anyway.
- The Commission d’accès à l’information, Quebec’s privacy regulator, indicates that since September 2023, a privacy impact assessment (PIA), a written analysis of the risks a project poses to personal information, is required before communicating personal information outside Quebec.
- The policy fits in five sections: banned data, approved tools, human review, accountability, and an exception procedure.
- The most useful rule is the simplest: no data that can identify a person goes into a tool without written authorization.
- A policy without an exception procedure gets bypassed within three weeks. Plan how permission is obtained, or nobody will ask for it.
On this page
What is an AI usage policy
An artificial intelligence usage policy is the internal document that defines which data may go into an AI tool, which tools are approved, who reviews the output before it is used, and who answers for an error. It is not about the technology but about how information circulates. Its primary function is to prevent a well-meaning employee from transmitting personal information to a third party without the business having assessed it.
The use is already there
This piece is written for SMB owners whose teams use artificial intelligence tools, which is nearly all of them. It describes an internal document and doesn’t replace legal advice.
The starting point is not deciding whether you allow AI. The decision has already been made by your employees, individually, without the question ever being put to them.
An assistant pastes a customer email to have it rewritten. A sales rep has a recorded call summarized. Someone in sales has a spreadsheet of accounts analyzed for trends. None of these actions is malicious, and all of them transmit information to a third party.
The policy is therefore not there to open a door: it puts a frame around what already happens. That is why a blanket ban never works: it turns visible use into hidden use.
A tool hosted outside Quebec that receives personal information constitutes a communication outside Quebec, subject to a prior assessment. An employee who pastes a customer list into a consumer tool therefore triggers an obligation nobody in the business knows about.
The five sections of the policy
| Section | What it establishes | Useful length |
|---|---|---|
| Banned data | What never goes into a tool, without exception | A list of five to eight lines |
| Approved tools | Which ones, and who approves an addition | A table and a name |
| Human review | What must be checked before external use | Three lines |
| Accountability | Who answers for the output produced | One sentence |
| Exception | How to obtain one-time permission | Two lines and a name |
One page is enough. Beyond that, the policy becomes a compliance document nobody consults at the precise moment the decision is made, that is, at the screen with a file to process.
The rule that settles half the cases
A single sentence settles most situations: no data that can identify a person goes into an artificial intelligence tool without written authorization.
It is easy to remember, it requires no technical skill, and it covers the three most frequent cases: the customer list, the service email, the call recording.
Complete it with a short list of what never leaves, whatever the tool. Health information, customers’ financial information, employee data, documents under a confidentiality agreement, and anything that belongs to a client rather than to you.
Finally, add the reflex that makes use possible: strip identifiers before submitting a text. Names, contact details, account numbers. The habit takes a few seconds once installed and unlocks most everyday marketing uses. Specify, however, that stripping identifiers is not anonymization within the meaning of the law, that is, making the identification of a person irreversibly impossible, a notion governed by strict conditions.
Human review and accountability
Two short sections, and they prevent the two most visible mistakes.
Review. Everything that leaves the business is reread by a person who answers for it: proposal, email to a client, publication, site content, response to a call for tenders. What stays internal can be reviewed more lightly. The rule is not distrust of the tool; it is that nobody signs a document they haven’t read.
Accountability. One sentence is enough: the person who uses the tool answers for the output, as they would answer for a text they had written. That sentence closes the door on the most dangerous excuse a business can let take hold: the error attributed to the tool.
These two sections carry particular weight for professionals governed by a professional order, where ethical responsibility belongs to the professional and cannot be delegated to any vendor or tool.
The exception procedure
It is the section policies forget, and it decides whether the document will be respected.
A policy with no way out gets bypassed within three weeks. An employee facing a real need and a rule that forbids it will choose the need, and will do it without saying so.
So plan how permission is requested: from whom, through what channel, and how quickly an answer comes. Two lines are enough, provided the turnaround is short. An exception that takes two weeks to obtain is the same as a ban.
Document the exceptions granted. They reveal your organization’s real uses and show which ones deserve to be approved outright at the next revision.
What it costs and what it prevents
The math is favourable, and it fits in three lines in front of a board.
Writing the policy, getting it validated and training the team represents about forty hours in total, or roughly $3,900 at the internal rate. It is a one-time expense, partially repeated once a year.
That amount compares with three avoided costs. A missing assessment before a communication outside Quebec, which exposes the business. A confidentiality incident, that is, unauthorized access, use or communication of personal information, which imposes reporting obligations and ties up management for weeks. And an empty answer in a call for tenders that asks about your AI governance, a question institutional clients ask more and more often.
That last point is often what wins the decision with owners: the policy stops being a constraint and becomes a commercial document your competitors don’t have.
What to settle before writing the policy
These five questions get settled in one meeting and determine whether the document will be applied or filed away.
- Which tools do your teams use today, including the ones nobody approved?
- Which data must never leave, whatever the tool or the justification?
- Who approves adding a new tool, and how quickly do they answer?
- Who answers for output produced with the help of a tool, and is it written down?
- If an employee breaks the policy out of ignorance, what happens, and who decides?
The answer that holds up names a list of real tools and one person who approves. A vague answer says the business doesn’t use AI. A vendor who proposes plugging a tool into your customer data without asking whether you have a policy and an assessment exposes you, and you are the one who will answer for it.
Taking the real inventory of your tools and drafting this policy is part of what we deliver in a paid audit.
What you keep in house: the list of banned data, the designation of the person who approves, and the legal validation of your situation. What can be delegated: the inventory of the tools in use, the drafting of the policy, the team training, the tracking of exceptions and the annual revision. A business that writes one page and trains its people in an hour settles nearly all of the everyday risk. A business that bans AI without an exception procedure turns visible use into hidden use, and loses the only thing it had left: knowing what is going on.
The overall view of the marketing plan is in splitting the budget across channels.
Integrating artificial intelligence into execution without exposing the business is at the heart of the Strengthen your visibility in AI answers goal.
Frequently asked questions about the AI usage policy
Should you simply ban AI?
A blanket ban doesn’t work: it turns visible use into hidden use, and you lose the only thing you had left, knowing what is going on. The policy frames a use that is already present rather than opening a door. Above all, it must plan how permission is obtained, otherwise it will be bypassed within a few weeks.
What is the most important rule?
No data that can identify a person goes into a tool without written authorization. That single sentence covers the three most frequent cases: the customer list, the customer service email and the call recording. It is easy to remember and requires no technical skill.
Is removing names enough?
It is an excellent practice that unlocks most everyday marketing uses, but it does not amount to anonymization within the meaning of the law, a notion governed by strict conditions. Write the reflex into the policy, and have your practice qualified rather than assuming it takes you out of the regulatory frame.
Who answers for an error produced with a tool?
The person who used it, as they would answer for a text they had written. Write it in one sentence. Letting the idea take hold that an error can be attributed to the tool is the most dangerous wording for an organization, particularly among professionals governed by a professional order.
How long does drafting take?
Half a day to write the page, an hour to train the team, and an annual revision. What takes time is not the drafting but the prior inventory of the tools actually in use, which almost always reveals twice as many tools as management knew about.
Do you need a policy with five employees?
Yes, and it is even shorter. The risk doesn’t depend on the size of the business but on the type of data handled. A five-person firm that processes client files has the same regulatory trigger as a hundred-person company, with fewer resources to absorb an incident.
- Commission d’accès à l’information du Québec, Principaux changements apportés par la Loi 25 (in French), accessed July 2026. Source for the assessment obligation before a communication of personal information outside Quebec.
- Falia framework, five-section policy structure and arithmetic of the drafting and training cost. Amounts are explicit worked examples, to be redone with your internal rate.

Gabriel almost always takes your first call and carries out your audit. He builds the strategy starting from your growth goal: where to put your budget, which market to test and how to connect each lead to a real sale in your CRM. He mainly leads engagements for three goals: Optimize the profitability of your digital campaigns, Develop a new market, and Generate demand and growth. With Geneviève, he also works on organic search (SEO), AI visibility (GEO) and conversion rate optimization (CRO). The sales a Google Ads or Meta Ads campaign brings in depend on the page that receives the click. He writes mainly about marketing strategy, paid advertising and measurement.
About Falia →