AI and law. Symbolic of the judicial system and artificial intelligence, this image represents the intersection of jurisprudence and the prohibition or prohibition of AI. abstract 3d digital concept
getty
among them 2026 report on the impact of AIIntuit’s 2026 AI Impact Report used data from more than 34,000 surveys of small and medium-sized businesses in the United States. Of these, 77% reported using AI daily. But if you ask these same business owners about creating AI policies for small businesses, you’ll get a blank stare. This was due to the way small and medium-sized businesses deployed AI one subscription at a time. The rulebook they created didn’t exist.
As long as the AI exists within the browser window, there is no need for such rules to exist. However, the situation has changed with the advent of new external rule sets.
Rules were born before anyone wrote anything down.
On August 2, the E.U. Transparency in AI law The regulations come into effect. Businesses that interact with EU users (both covered and non-covered) must provide notifications when users are interacting with AI systems. Additionally, you may be required to label content generated or modified by AI. In the United States, 47 states have enacted laws that: Media generated by artificial intelligence. However, each state has its own standards for what constitutes “AI-generated” media. As a result of this proliferation of state-specific regulations, the Federal Trade Commission (“FTC”) has opened public comments until July 31 on a proposed policy statement on the “accuracy” of AI systems, but the establishment of these federal standards for small businesses may conflict with a myriad of existing state-based regulatory requirements.
Actual costs not covered by insurance
of Black Fog/Sapio Learning The study involved a sample of 2,000 people from companies with 500 or more employees in both the US and UK. The study reported that 49% of these employees are using unapproved AI tools, and 58% of those employees are using free versions, which may lack strong data controls. I also wrote about What is this “shadow” AI activity in the workplace? The following situations may occur within small and medium-sized enterprises: Individuals are posting customer information to personal accounts Sensitive financial information is not under the owner’s control Three employees use three different AI “voices” for writing purposes, none of which are affiliated with the company.
None of this is malicious. This is what happens when there are gaps in your organization. If employees are not provided with an employee-approved AI solution, or if an AI data privacy policy is established by the owner, all employees will create their own policy. No one shares information with other employees. Damage occurs after the fact. This may include a violation of your client’s privacy or a loss of your brand’s voice. “AI Slop”or an AI feature that has already been created. existing solutions, Use of Customer Data Prior to Approval.
Policies fit on one page
What you need isn’t a one-page, five-short-paragraph “binder” that explains what regulators, customers, and staff are actually asking.
Approved tools. List all approved AI tools available to your company’s employees. Identify which accounts have access and specify who should approve new tools.
data rules. Specify what should never go into an AI tool, such as customer names, account information, financial data, health data, and data with NDAs. This section of the AI Data Privacy Policy is where you can prevent your worst day.
disclosure. Establish a frequency for disclosing to customers whether they are interacting with AI and where to label AI-generated content? Even if your business does not have EU customers, create this section to comply with EU standards. Because EU standards are widespread.
Check the points. Before shipping, we decide which work will be visible to others. This is a core rule for using AI responsibly in business. Covers all customer content, quotes, and anything legal or medical.
Expenditures and Audits. Combine all your AI costs into one capped budget line and compare your monthly expenses to what your tools are producing. Give owners proof of ROI
Where should I start on Monday morning?
Let’s start with amnesty. Find out from your employees what AI tools are being used. Tell them there is no penalty if they are honest. It’s surprising to know who used what (and when), and here’s why. Without this list of employee AI tool usage, you could ban tools that no one uses and miss tools that everyone uses.
Develop the five sections of the policy with your team’s participation. Employees using these tools can see where the real questions lie. Are there recording devices during calls with clients? Are draft proposals considered to be generated by AI? Do free accounts paid for by employees belong to the business? Workplace AI policies developed by the people using the tools will be followed. One-page memo-based AI policies will be avoided. This is how we encountered the shadow AI problem.
Schedule a quarterly review before filing your pages. New tools appear every month and rules change faster. If you review a one-page AI policy four times a year, you’re sticking to it. A 10-page policy that has never been considered is fiction with a header.
One page beats a binder
Small and medium-sized enterprises have an advantage in developing AI governance frameworks because they develop them more rapidly than larger enterprises. Small business owners may be able to develop an AI governance framework in hours or days, while larger companies may need weeks or even months to develop it. So small business owners can write it down on Sunday and start using their new AI governance framework by Monday morning.
Pages are also sales documents
Compliance cases get media coverage, but sales cases can be more important. Large clients are communicating their concerns about AI through their vendor supply chains. Clients are looking for answers regarding what kind of proposals their company will make using AI. Where is the client data? Who reviews the AI output before it is delivered to the client? These types of questions arise regularly during security review processes, master services agreement negotiations, and renewal processes. More importantly, they usually show up with little notice. Business owners who have a one-page document outlining their company’s current business guidelines regarding AI will be able to respond to these inquiries quickly (within minutes) and will appear well-organized compared to competitors who need to develop answers to these inquiries. Conversely, business owners who lack such documentation will either make something up in their response or remain silent. In any case, both look weak when compared to their prepared competitors. Similarly, such documents provide employees with a clear “yes” to which tools will support them, versus the vague fear that they may lose their jobs due to the potential misuse of AI.

