If someone in your company is already using ChatGPT, Claude or Copilot without shared rules, you already have a policy. It’s just implicit, inconsistent and invisible.

This is the point most businesses underestimate. The problem doesn’t begin when you choose a tool. It begins when the team starts using it in different ways, with different data and different standards.

A useful AI policy isn’t about slowing the team down. It stops AI from entering your processes as an ungoverned shortcut.

An operational AI policy means this: a minimum set of rules that defines where AI can enter, who validates outputs, and how the company measures value and risk.

What’s more, AI literacy is not an optional topic. The official EUR-Lex summary on EU rules for trustworthy AI makes clear that obligations such as AI literacy and basic prohibitions have applied since 2 February 2025.

Why an SME needs an AI policy before it even chooses the tool

In our work, we always see the same pattern: the company tries AI on quick tasks, gets some interesting results, then expands its use without having defined boundaries, roles and validation criteria.

The result isn’t innovation. It’s variability.

[ORIGINAL DATA] In the AIEH Pain Taxonomy, built on 311 real leads, recurring signals emerge:

  • the team uses different tools for the same problem
  • no one knows which outputs can be reused
  • data is copied and pasted without governance
  • the General Manager senses the chaos but has no metric to measure it

For this reason, before you debate which tool to adopt, you have to decide how your business system will manage inputs, outputs, supervision and accountability.

In one sentence

Before using the tool you must decide:

  • what can enter
  • who validates
  • what remains tracked
  • where AI must not enter

If you want the complete framework, start from How to govern AI in an SMB: system, not tool.

The 7 controls that an operational AI policy must contain

An AI policy for a smaller business doesn’t have to read like a legal manual. It has to work as an operational governance checklist.

1. What data can go into AI tools

The first check is the most basic — and the one most often ignored.

You have to define:

  • what data can be loaded
  • which data should be anonymised
  • which data must never leave internal systems

If this distinction doesn’t exist, the risk isn’t theoretical. It’s operational. It’s also almost impossible to defend a decision when data was uploaded without clear criteria.

Minimum checklist

  • public or neutral data
  • anonymised internal data
  • sensitive data excluded or handled in a controlled environment

2. Which outputs require mandatory human review

Not everything that comes out of an AI system can be used in the same way.

You need a simple rule:

  • internal draft outputs: freer use
  • outputs for clients, boards or partners: mandatory review
  • outputs that influence financial or process decisions: double validation

This point is also consistent with the principle of human supervision discussed in the AIEH article on the EU AI Act for SMBs.

Rule of thumb

If the output:

  • leaves the company
  • affects money
  • affects people
  • changes a critical process

then it needs a clear human review.

3. Who is responsible for what

If everyone can use AI but no one owns the process, you don’t have adoption. You have dispersion. In practice, the company comes to depend on individual initiative rather than shared standards.

A minimum policy has to clarify:

  • who can experiment
  • who approves the standards
  • who validates the critical outputs
  • who monitors the impact on time, errors and ROI

The typical mistake

Many companies say: “anyone can give it a try.” It feels like openness. In reality it often means:

  • no owner
  • no standards
  • no accountability

4. How you track AI use

You don’t need a huge system.

At a minimum, you need to trace:

  • where AI is used
  • for which tasks
  • with what validation criteria
  • what improvements or errors it produced

If you can’t explain where AI helps you and where it exposes you, you’re not governing. You’re hoping. So the policy has to leave a simple trace — not a perfect one.

The good news

You don’t need a bureaucratic machine. A minimal trace can be enough:

  1. process
  2. owner
  3. type of output
  4. level of validation
  5. impact observed

5. In which cases AI should not be used

This is one of the strongest signs of maturity.

A clear-headed business doesn’t just say “we use AI here.” It also says “we don’t use it here” or “we only use it here as support”.

Typical examples:

  • sensitive communications with clients or colleagues
  • financial assessments without numerical verification
  • HR or organisational decisions taken out of context
  • documents that require full confidentiality

This point makes the difference

A mature company doesn’t just say, “We use AI here.” It also says:

  • not here
  • here only as support
  • here never without human control

6. How you measure adoption and ROI

The policy shouldn’t be a forgotten PDF. The way you work has to change.

That’s why it must be tied to three minimum metrics:

  • hours saved on repetitive tasks
  • number of standardised processes
  • reduction of errors or rework in outputs

This is the step that turns governance into a revenue path, not a theory. Without metrics, every discussion about AI slides back into opinion.

The 3 most useful metrics when starting out

If you want to start light, measure:

  1. time recovered
  2. quality of outputs
  3. reduction of rework

7. How you connect the policy to real processes

The policy only works if it lands in the processes.

That means connecting it to:

  • reporting
  • commercial preparation
  • data analysis
  • document production
  • approval flows

Fabio Armellini is a useful case to keep in mind: the leap in value doesn’t come from the “AI tool” but from the system that cuts days of consolidation and hands back control. In our experience, this is the difference between initial enthusiasm and real adoption.

The policy works best if you apply it first to:

  • a reporting process
  • a commercial process
  • a document-production process

Where the EU AI Act comes in — and where you don’t need to complicate your life

For an SME operating in the European market, the EU AI Act isn’t an excuse to bureaucratise everything. It’s a lens for checking whether you’re using AI responsibly.

In practice, for anyone using AI in day-to-day processes, the most useful points are:

  • transparency
  • human supervision
  • minimal documentation
  • adequate in-house skills

What you shouldn’t do is turn the policy into a legal document that no one reads.

What you should do is build the governance principle into the way the team works. To explore the regulatory and operational framework further, use EU AI Act and SMEs: what General Managers and Fractional Managers need to know as a reference.

How to transform policy into real team adoption

Policy fails when it remains abstract.

To avoid this, it is best to start from a small perimeter:

  1. choose one or two high-friction processes
  2. define minimum rules for AI use
  3. assign an owner
  4. measure impact and risk over 30 days
  5. extend only once you see concrete signs

If you want to know where to start, the For Companies page explains clearly how AIEH sets up adoption for smaller businesses.

In summary

The right policy doesn’t slow the team down. It reduces:

  • ambiguity
  • variability
  • rework
  • reputational risk

The signal that tells you if you’re still in chaos

The right question isn’t “does the team use AI?”.

The right question is this:

if tomorrow someone asked you where AI is used, under what rules and with what impact, could you answer in 10 minutes?

If the answer is no, you don’t have a system yet. You only have scattered initiatives.

How to get started without building unnecessary bureaucracy

The smartest way to get started isn’t to write a 12-page policy yourself.

Start with an operational diagnostic:

  • where the team already uses AI
  • where the team loses time
  • where standards are lacking
  • where the risk is higher than the value generated

From here you can build a useful, short and above all adoptable policy.

If you want a clear picture of your starting point, the quickest step is the AI Governance Diagnostic Assessment. Within minutes, you can see whether you are governing AI or simply introducing more variability into the system.

Primary sources and references

Next Step

Reading is not enough if the system stays the same.

If this article touches a real source of friction, the useful next step is not consuming more content. It is understanding where you are losing time, control or margin today.

Take the AI Governance Assessment → See the path for companies →