Somebody has asked whether your business has an AI policy. A client, an insurer, a board member who read something. And you may have said yes, because there’s a document somewhere. Or you said not yet, and you’ve been meaning to.
An AI policy for small business is a short governing document that says which tools your team can use, what information stays out of them, and who decides when that changes. That’s the standard definition, and every template online will get you there in an afternoon.
Misty Phillip thinks the templates skip the first step. Misty is COO of Trilogy Works, a cybersecurity and AI firm that has guided more than 200 clients in finance, healthcare, and energy. She writes governance for banks that have entire compliance departments. And she got there after two decades homeschooling three sons and building Spark Media, a platform for Christian podcasters, before her husband asked her to lay that company down and join his. She made herself a dictionary of the acronyms and started over.
What she sees inside those big institutions is the same thing Kathryn sees in rooms full of small business owners. A policy exists. Nobody knows what it says. This episode is about why that happens, and what to decide before you write a single rule.
Why do AI policies for small business get ignored?
Because the people following them don’t know what the business believes about AI, and most of the time neither does the person who wrote it.
Misty’s line for this came to her in the shower, which is where she says her best ideas show up. How can people write an AI policy if they don’t even know what AI is or what they think about it? Her word for the missing piece is an apologetic. In her faith tradition, an apologetic is a defense of what you believe and why. Applied to AI, it means a plain statement of what you think this technology is, what it’s for in your work, and where it stops.
That’s the principle. The policy is the tactic. When you skip the principle, the tactic turns into a list of rules that nobody can explain, so nobody follows them. Misty’s husband has a saying she repeats: just because you use a toilet every day doesn’t mean you’re a plumber. Using AI isn’t the same as understanding it, and you can’t write rules for a thing you don’t understand.
Is AI neutral?
No. A model is trained on what people wrote, and the people who built it made choices about which writing to use and how the model should respond. Both of those carry a worldview.
Misty puts it bluntly. The training data includes great works of humanity and trash from the same internet, in the same pile. The companies behind each model have their own ideology and their own policy about what the model will and won’t say. Ask the same question in two different models and you’ll see the difference in the answers.
Kathryn teaches this to high school and college students as the E in CREATE, her six-principle framework for ethical AI use (Credit, Responsibility, Equity, Authenticity, Trust, Ethics). Equity asks who created the tool, where the data came from, and who isn’t in the picture. It sounds academic until you say it Misty’s way. The machine has a point of view. Read its answers the way you’d read a person’s.
This matters for your policy because a policy that treats AI as a neutral calculator will never tell your team to check the output. One that treats it as a fast, confident stranger will.
How do you write an AI policy for a small business?
Misty’s answer, in order: learn what AI is, decide what you believe about it, write the policy, then plan to rewrite it.
The learning step is not about tools. It’s about knowing enough to explain, in your own words, what a model does and doesn’t do. That’s the dictionary Misty made for herself when she joined Trilogy Works.
The belief step splits in two. What you’ll allow at home is not what you’ll allow at work, and a church or ministry has a third answer. Misty says both out loud, as a parent and as a COO, because the rules for her kids and the rules for her clients come from the same belief and land in different places.
Then the policy. A governing document, so it stays short. The Good AI Way, Kathryn’s four-part framework for adopting AI responsibly (Standards, Skills, Systems, Support), puts this under Standards: the rules that govern how your team uses AI. The rules only hold when the belief underneath them is clear.
And then the date. Misty doesn’t soften this one. It’s not like you create this policy, you put it on a shelf, and it’s done. Models change every few months. She tells clients to review quarterly and at minimum once a year.
What should never go into an AI tool?
Anything you wouldn’t say on a stage in front of millions of people.
That’s what Misty told a friend who had pasted all her doctor’s reports into a chatbot. It applies to your customer list, your financials, and anything covered by a confidentiality agreement. The chatbot sounds like a friend. It isn’t one. It doesn’t have a soul, and it’s storing what you typed in a data center somewhere.
Kathryn added the small-business version of the same problem: people doing company work in personal accounts, and teams that got Copilot turned on with no training and no idea what boxes they were supposed to check. Your policy is where you name the boxes.
Use This Today
Before you open a template, write three sentences. Ten minutes, no tools.
- What I believe AI is: (one sentence, in your own words, no jargon)
- What it’s for in my business: (one sentence naming the two or three jobs you’d hand it)
- Where it stops: (one sentence naming the one thing you won’t let it touch)
That’s your apologetic. Every rule in the policy should be traceable back to one of those three lines. If a rule isn’t, cut it.
A human pause
Nobody had a policy for this two years ago. The people who look like they have it figured out wrote something down and then changed it. You’re allowed to do the same.
Where to go next
If you want the one-page starting point, the fill-in-the-blank AI Policy document is free at go.goodcirclemarketing.com/summer-of-good-ai. Fill in the three sentences above first and the rest goes faster.
Frequently asked questions
Does a small business need an AI policy?
If anyone on your team uses an AI tool for work, yes. A one-page policy is enough to start. It names approved tools, what information stays out of them, and who decides when the list changes.
What should an AI policy for a small business include?
Approved tools, prohibited data, when a human reviews the output before it goes out, and who owns the policy. Misty Phillip adds a step before all of that: a plain statement of what the business believes about AI and what it’s for.
How often should an AI policy be updated?
Quarterly if you can manage it, and at least once a year. Models and tools change faster than most policies do, so put a review date on the document when you write it.
Is AI neutral?
No. A model reflects the data it was trained on and the choices of the people who built it. Read its output as a point of view and check it the way you’d check a person’s.
Resources
Misty Phillip: mistyphillip.com
Trilogy Works: trilogyworks.com
Misty’s books, Upskill or Die and The Trojan Horse of the Digital Age, are on Amazon.
A Good Pour: Summer of Good AI is a limited series helping small business owners and nonprofit leaders use AI with confidence and integrity. New episodes drop weekly through September 2026.