If someone in your company is already using ChatGPT, Claude or Copilot without shared rules, you already have a policy. It’s just implicit, inconsistent and invisible.
This is the point most businesses underestimate. The problem doesn’t begin when you choose a tool. It begins when the team starts using it in different ways, with different data and different standards.
A useful AI policy isn’t about slowing the team down. It stops AI from entering your processes as an ungoverned shortcut.
An operational AI policy means this: a minimum set of rules that defines where AI can enter, who validates outputs, and how the company measures value and risk.
What’s more, AI literacy is not an optional topic. The official EUR-Lex summary on EU rules for trustworthy AI makes clear that obligations such as AI literacy and basic prohibitions have applied since 2 February 2025.
Why an SME needs an AI policy before it even chooses the tool
In our work, we always see the same pattern: the company tries AI on quick tasks, gets some interesting results, then expands its use without having defined boundaries, roles and validation criteria.
The result isn’t innovation. It’s variability.
[ORIGINAL DATA] In the AIEH Pain Taxonomy, built on 311 real leads, recurring signals emerge:
- the team uses different tools for the same problem
- no one knows which outputs can be reused
- data is copied and pasted without governance
- the General Manager senses the chaos but has no metric to measure it
For this reason, before you debate which tool to adopt, you have to decide how your business system will manage inputs, outputs, supervision and accountability.
In one sentence
Before using the tool you must decide:
- what can enter
- who validates
- what remains tracked
- where AI must not enter
If you want the complete framework, start from How to govern AI in an SMB: system, not tool.
The 7 controls that an operational AI policy must contain
An AI policy for a smaller business doesn’t have to read like a legal manual. It has to work as an operational governance checklist.
1. What data can go into AI tools
The first check is the most basic — and the one most often ignored.
You have to define:
- what data can be loaded
- which data should be anonymised
- which data must never leave internal systems
If this distinction doesn’t exist, the risk isn’t theoretical. It’s operational. It’s also almost impossible to defend a decision when data was uploaded without clear criteria.
Minimum checklist
- public or neutral data
- anonymised internal data
- sensitive data excluded or handled in a controlled environment
2. Which outputs require mandatory human review
Not everything that comes out of an AI system can be used in the same way.
You need a simple rule:
- internal draft outputs: freer use
- outputs for clients, boards or partners: mandatory review
- outputs that influence financial or process decisions: double validation
This point is also consistent with the principle of human supervision discussed in the AIEH article on the EU AI Act for SMBs.
Rule of thumb
If the output:
- leaves the company
- affects money
- affects people
- changes a critical process
then it needs a clear human review.
3. Who is responsible for what
If everyone can use AI but no one owns the process, you don’t have adoption. You have dispersion. In practice, the company comes to depend on individual initiative rather than shared standards.
A minimum policy has to clarify:
- who can experiment
- who approves the standards
- who validates the critical outputs
- who monitors the impact on time, errors and ROI
The typical mistake
Many companies say: “anyone can give it a try.” It feels like openness. In reality it often means:
- no owner
- no standards
- no accountability
4. How you track AI use
You don’t need a huge system.
At a minimum, you need to trace:
- where AI is used
- for which tasks
- with what validation criteria
- what improvements or errors it produced
If you can’t explain where AI helps you and where it exposes you, you’re not governing. You’re hoping. So the policy has to leave a simple trace — not a perfect one.
The good news
You don’t need a bureaucratic machine. A minimal trace can be enough:
- process
- owner
- type of output
- level of validation
- impact observed
5. In which cases AI should not be used
This is one of the strongest signs of maturity.
A clear-headed business doesn’t just say “we use AI here.” It also says “we don’t use it here” or “we only use it here as support”.
Typical examples:
- sensitive communications with clients or colleagues
- financial assessments without numerical verification
- HR or organisational decisions taken out of context
- documents that require full confidentiality
This point makes the difference
A mature company doesn’t just say, “We use AI here.” It also says:
- not here
- here only as support
- here never without human control
6. How you measure adoption and ROI
The policy shouldn’t be a forgotten PDF. The way you work has to change.
That’s why it must be tied to three minimum metrics:
- hours saved on repetitive tasks
- number of standardised processes
- reduction of errors or rework in outputs
This is the step that turns governance into a revenue path, not a theory. Without metrics, every discussion about AI slides back into opinion.
The 3 most useful metrics when starting out
If you want to start light, measure:
- time recovered
- quality of outputs
- reduction of rework
7. How you connect the policy to real processes
The policy only works if it lands in the processes.
That means connecting it to:
- reporting
- commercial preparation
- data analysis
- document production
- approval flows
Fabio Armellini is a useful case to keep in mind: the leap in value doesn’t come from the “AI tool” but from the system that cuts days of consolidation and hands back control. In our experience, this is the difference between initial enthusiasm and real adoption.
Recommended sequence
The policy works best if you apply it first to:
- a reporting process
- a commercial process
- a document-production process
Where the EU AI Act comes in — and where you don’t need to complicate your life
For an SME operating in the European market, the EU AI Act isn’t an excuse to bureaucratise everything. It’s a lens for checking whether you’re using AI responsibly.
In practice, for anyone using AI in day-to-day processes, the most useful points are:
- transparency
- human supervision
- minimal documentation
- adequate in-house skills
What you shouldn’t do is turn the policy into a legal document that no one reads.
What you should do is build the governance principle into the way the team works. To explore the regulatory and operational framework further, use EU AI Act and SMEs: what General Managers and Fractional Managers need to know as a reference.
How to transform policy into real team adoption
Policy fails when it remains abstract.
To avoid this, it is best to start from a small perimeter:
- choose one or two high-friction processes
- define minimum rules for AI use
- assign an owner
- measure impact and risk over 30 days
- extend only once you see concrete signs
If you want to know where to start, the For Companies page explains clearly how AIEH sets up adoption for smaller businesses.
In summary
The right policy doesn’t slow the team down. It reduces:
- ambiguity
- variability
- rework
- reputational risk
The signal that tells you if you’re still in chaos
The right question isn’t “does the team use AI?”.
The right question is this:
if tomorrow someone asked you where AI is used, under what rules and with what impact, could you answer in 10 minutes?
If the answer is no, you don’t have a system yet. You only have scattered initiatives.
How to get started without building unnecessary bureaucracy
The smartest way to get started isn’t to write a 12-page policy yourself.
Start with an operational diagnostic:
- where the team already uses AI
- where the team loses time
- where standards are lacking
- where the risk is higher than the value generated
From here you can build a useful, short and above all adoptable policy.
If you want a clear picture of your starting point, the quickest step is the AI Governance Diagnostic Assessment. Within minutes, you can see whether you are governing AI or simply introducing more variability into the system.