Articles·Strategy and support

“When unsure, don’t act.” A starter AI acceptable use policy for small agencies.

A robot reads a thick rulebook while a woman taps one line, under a framed sign that reads A person sends.

An AI acceptable use policy is a short set of written rules for how your team uses AI: what it can touch, what it can send, and what a person has to check. The fix is a one page policy built from rules that already work, reviewed by your attorney, and repeated in training. I haven’t written an AI policy for a client yet, so this template comes from the rules I run on my own AI agents every day.

Why does a small agency need an AI policy?

A small agency needs an AI policy because the team is already using AI, with or without one. Somebody pastes a client email into a free chatbot. Somebody connects an AI tool to the shared inbox. Nobody decided whether either was OK.

Most agencies haven’t written the rules down. 55% of independent agencies have no written AI policy, according to the February 2026 Big “I” Agents Council for Technology Tech Trends Report. The same survey found the top worries were data privacy or compliance (24%), inaccurate outputs (22%), and losing the human touch (17%). A good policy answers all three.

What do most agencies try first?

Some agencies ban AI outright, and the curious people on the team keep using it on personal accounts where nobody can see it. Others download a long AI policy template written for a large company, file it, and never read it again.

Both leave the team guessing. A ban hides the use. A long template buries the three or four rules that matter under pages nobody finishes.

Wanna fix it?

An agency with no AI rules gets fixed with a one page AI acceptable use policy that covers who approves what AI writes, what information stays out of AI tools, which tools are approved, and who to ask. Here’s a starter template built from the rules I run on myself.

  1. **Agents draft. A person sends.** No AI tool sends an email, text, or document to a client on its own. My reply agents can read and write drafts, and only my click sends.
  2. Approve before anything is saved to shared memory. If an AI tool remembers facts across the team, a person approves each one first. Mine proposes new facts to a queue and waits for me.
  3. Write voice rules. Keep a list of what AI writing can never contain: invented prices, invented dates, client names, results nobody measured, and phrases your agency would never say.
  4. Keep extremely sensitive health information out of AI tools. If a task needs it, the task stays in the system built for it.
  5. Check client contracts before connecting a tool. Some client agreements list the only tools allowed to touch their information. I keep one client’s details out of my own shared memory for exactly that reason.
  6. Name the approved tools and the person to ask. List which AI tools the team can use and on which accounts. When unsure, don’t act. Ask.

This template isn’t legal advice. Have your attorney review it before your team signs it.

What does it look like once the policy is in place?

Once the policy is in place, people stop guessing. A new hire reads one page and knows the rules. The Staying safe chapter of my AI Basics library covers the same ground in four short lessons: What Not to Paste In, Who Can See the Chat, The AI Is Not the Internet, and When to Stop and Ask a Human.

The settings should back the policy up. On company PCs, IT can limit which folders Claude is allowed to open. Update the policy every time you add a tool.

Can you write an AI policy yourself?

Yes, you can write an AI policy yourself. Start with the six rules above, change the wording to fit your agency, name your tools, and have your attorney review it. One page is enough.

A homemade policy stops working when the rules say one thing and the tools allow another. If an AI tool is able to send on its own, somebody will eventually let it. The permissions have to match the paper. One page of rules, write it yourself. AI tools wired into your inbox and client files, set the permissions to match the policy.

Quick answers

What is an AI acceptable use policy?
A short set of written rules for how a team uses AI tools: what they can touch, what they can send, and what a person checks.
What should an AI use policy include?
Human approval before anything goes to a client, what stays out of AI tools, voice rules, approved tools, and who to ask.
Is there an AI policy template for small agencies?
The six rules in this article work as a starting template. Have your attorney review it before rollout.
How many agencies have an AI policy?
55% of independent agencies have no written AI policy, per a February 2026 Big “I” ACT survey.
Should AI send client emails on its own?
No. Agents draft, and a person sends.
Has DoBetter written AI policies for clients?
Not yet. Chris Cordon’s template comes from the rules he runs on his own AI agents.