Do I need different AI rules for managers, admin staff and customer-facing teams?

8 September 2026

Do I need different AI rules for managers, admin staff and customer-facing teams?

Yes. A small business should set one company-wide AI policy, then add role-based rules for managers, admin staff and customer-facing teams. The difference should be based on data access, customer impact, decision authority, risk level and training, not job title politics.

Why one AI policy is not enough

One AI policy is useful, but it should not pretend every person in the business creates the same risk. A manager using AI to summarise performance concerns, an admin assistant using AI to tidy a supplier email and a customer service adviser using AI to draft a reply to a complaint are not doing the same thing. The tool might be the same, but the data, consequences and review duties are different.

The Office for National Statistics reported in July 2026 that AI use among UK businesses with 10 or more employees rose from around 12% in late 2023 to around 35% in 2026. It also found that adoption is still relatively shallow, with the average adopter using about 1.6 AI technologies. That matters because many SMEs are not running mature AI programmes. They are adding AI features into ordinary work tools and hoping common sense will fill the gaps.

The better answer is a simple role-based framework. Everyone gets the same baseline rules: do not paste passwords, do not upload confidential client files to unapproved tools, do not use AI as the final decision-maker, and check outputs before sharing them. Then each role gets extra rules based on what they can access and what damage a mistake could cause.

For a typical SME, the split is straightforward. Managers need rules about decisions, staff data, approvals and accountability. Admin staff need rules about client records, invoices, emails, suppliers and system updates. Customer-facing teams need rules about customer disclosure, tone, complaints, vulnerable customers and escalation. That is more practical than asking everyone to read the same generic policy and guess what it means for their job.

Useful source: ONS, Artificial intelligence in UK businesses: 2023 to 2026.

What rules should apply to everyone?

Before you split rules by role, write the non-negotiables that apply to everyone. These should be short enough for a busy employee to remember. If the rules need a training session just to understand them, they are probably too complicated for day-to-day use.

The first rule is data control. Staff should know which AI tools are approved, which are banned for business use and what information cannot be pasted into any public or personal AI account. For most SMEs, banned inputs should include passwords, payment details, payroll information, medical information, HR records, confidential client documents, legal letters, commercially sensitive pricing and anything covered by a client confidentiality agreement.

The second rule is human responsibility. AI can draft, summarise, compare and suggest. It should not approve refunds, reject job applicants, change payment details, diagnose legal risk, make disciplinary recommendations or send sensitive customer messages without a named person checking the output. The ICO's AI and data protection guidance is clear that accountability, fairness, transparency and accuracy still matter when AI is involved. Using an AI tool does not move responsibility away from the organisation.

The third rule is traceability. If AI is used for anything important, the team should record the tool, the purpose, the data used and who checked the result. This does not need to be heavy. A spreadsheet AI register is enough for many small businesses. The value is that managers can later answer a basic question: where are we using AI, and what risk have we accepted?

The fourth rule is source checking. AI output that affects customers, finance, legal wording, technical advice or regulated work must be checked against a reliable source before it is used. The NCSC warns that generative AI can produce incorrect statements as facts and can be vulnerable to prompt injection. That means staff need permission to challenge the tool, not pressure to trust it because it sounds confident.

Useful sources: ICO guidance on AI and data protection and NCSC guidance on AI and cyber security.

What extra rules do managers need?

Managers need tighter AI rules because their work often affects people's jobs, pay, workload, performance, customer promises and commercial priorities. A manager using AI is not just saving time. They may be shaping decisions that carry employment, financial or reputational risk.

The first manager rule should be no final people decisions by AI. A manager can use AI to prepare interview questions, summarise anonymised feedback, draft a training plan or structure a performance conversation. They should not use AI to rank candidates, decide who is underperforming, select people for redundancy, score grievances or make disciplinary recommendations unless the business has taken proper legal, HR and data protection advice. Even then, a human decision-maker must stay responsible.

The second rule is extra care with staff data. Managers can see information that admin or customer-facing staff should not process in AI tools: absence records, salary details, disciplinary notes, mental health references, complaints about colleagues and performance history. If AI is used at all, the safest default is to anonymise, minimise and use approved business accounts only. Personal AI accounts should be off limits for staff records.

The third rule is approval authority. Managers should be allowed to approve low-risk AI workflows only after checking purpose, data, permissions, testing, error handling, ownership and rollback. A useful internal threshold is this: if the automation can change a customer record, send a message, update finance data or influence a staff decision, it needs manager approval and an entry in the AI register.

The fourth rule is transparency with the team. Managers should tell staff where AI is being introduced and what it will change. The worst pattern is hidden monitoring or quiet productivity scoring. It damages trust and can create legal and cultural problems. If AI is being used to review calls, tickets or written work, staff should know what is being assessed, who sees the output and how it will be used.

What extra rules do admin staff need?

Admin teams often touch the most useful and sensitive operational data in the business. They handle inboxes, invoices, spreadsheets, supplier details, CRM records, meeting notes, contracts, forms and customer documents. That makes AI useful, but it also makes casual use risky.

The first admin rule should be approved tools only for business records. If an admin assistant is using AI to summarise emails, extract information from forms or prepare CRM updates, the business needs to know where that data goes. Public consumer accounts are usually the wrong place for client records, invoices, order details or internal commercial information. Use approved workspaces with business ownership, sensible retention settings and access controls.

The second rule is review before system updates. AI can help turn messy notes into structured records, but it should not update a CRM, accounts system or project management board without a review step unless the workflow is very low risk and well tested. A wrong phone number is annoying. A wrong bank detail, VAT number, delivery date, contractual note or customer status can be expensive.

The third rule is data minimisation. Admin staff should be trained to give AI only the information needed for the task. If the job is to draft a polite supplier follow-up, the AI does not need the full contract, all historic emails and a customer complaint thread. It may only need the order number, promised date, current status and the desired tone.

The fourth rule is exception handling. Admin staff should know when to stop using AI and ask a person. Examples include disputed invoices, legal letters, complaints, safeguarding concerns, payment changes, HR documents, suspicious supplier requests and anything involving a vulnerable customer. This is where a simple traffic-light model helps: green tasks can use AI freely, amber tasks need review and red tasks should not be put into AI without approval.

What extra rules do customer-facing teams need?

Customer-facing teams need AI rules built around trust. They can use AI to speed up replies, summarise previous conversations, find knowledge-base answers and prepare handover notes. But they are also the people most likely to put an AI-generated answer directly in front of a customer.

The first rule is no unchecked AI replies for sensitive situations. AI can draft a response to a routine delivery update or appointment change. It should not handle complaints, refunds, legal threats, vulnerable customers, safety issues, medical or financial hardship, high-value commitments or anything where the customer is already upset without a human checking it.

The second rule is approved language. Customer-facing teams should not let AI invent policies, pricing, guarantees, discounts or technical commitments. If the answer is based on a company policy, the policy should be in an approved knowledge source. If the AI cannot show where the answer came from, the adviser should treat it as a draft, not a fact.

The third rule is disclosure where it matters. A business does not need to tell every customer that AI helped tidy grammar in an internal note. But disclosure becomes sensible, and sometimes necessary, when AI is involved in customer service decisions, automated responses, professional advice, eligibility checks or complaint handling. The ICO expects organisations to think about transparency and explainability when AI affects people. Customer-facing teams need plain wording they can use when asked.

The fourth rule is escalation. AI should make escalation easier, not harder. If a customer says the answer is wrong, if the situation is unusual, if the adviser feels unsure or if the AI output conflicts with policy, the team should have permission to stop and escalate. A rigid chatbot or overconfident suggested reply can turn a simple service issue into a public complaint.

A simple role-based rules matrix

You do not need a complex governance platform to start. A simple matrix is enough for most SMEs. List the roles down the left, then define approved tools, allowed data, banned data, allowed uses, review requirements and escalation points across the top.

RoleAllowed usesExtra controls
ManagersPlanning, meeting summaries, anonymised analysis, policy drafts, workflow reviewNo final HR, finance or customer-impact decisions without human approval
Admin staffEmail drafts, document summaries, data extraction, CRM preparation, supplier chasingApproved tools only, review before system updates, no sensitive records in public tools
Customer-facing teamsSuggested replies, knowledge lookup, handover notes, call summariesHuman check for complaints, vulnerable customers, refunds, guarantees and policy-sensitive answers

Then add cost and ownership. A practical first policy review often costs nothing more than internal time if the business is small and the use cases are low risk. If client data, finance systems, HR decisions or regulated work are involved, budget roughly £1,500 to £5,000 for a focused external review and staff guidance. If you want approved AI workspaces, automation design and manager training, a sensible pilot budget is often £3,000 to £12,000 depending on how many systems and teams are involved.

Do not overcomplicate the first version. The aim is not to produce a perfect policy. The aim is to stop unmanaged AI use while giving staff a safe way to use the tools they are already reaching for. Review the rules every quarter at first, because tools, settings and staff habits change quickly.

When this does NOT apply

Role-based AI rules may be unnecessary if your business has not approved any AI use and staff genuinely are not using these tools. That is rare now, but it can happen in very small or highly controlled environments. Even then, it is worth writing one short rule that says staff must ask before using AI with business information.

This also does not apply if you operate in a highly regulated setting where AI use is already governed by a stricter framework, legal advice or sector-specific compliance requirements. In that case, the role matrix should sit underneath the formal controls, not replace them.

Finally, do not use role-based rules as a way to create unfair surveillance or hidden productivity scoring. If managers are using AI to monitor staff, assess performance or compare individuals, that needs a separate risk assessment, clear communication and proper HR advice. A simple SME AI policy is for safe everyday use. It is not a shortcut around employment law, data protection or common decency.

The practical answer is this: start with one company policy, then add different rules for managers, admin staff and customer-facing teams where their data, decisions and customer impact are different. That gives people freedom to use AI where it helps, while keeping the business in control where mistakes matter.

Is This Right For You?

This approach is right for you if your team is already using ChatGPT, Microsoft Copilot, Gemini or built-in AI features in tools like your CRM, accounts package, helpdesk or document system. It is especially relevant if different staff can see different levels of client data, financial information, staff records or customer conversations.

It is not right if you are trying to write a 40-page AI policy before anyone has used AI in a real workflow. Start with a short company rule set, then add role-specific controls for the places where misuse could cause harm. For many UK SMEs, the useful first version is a two-page policy, a one-page role matrix and a simple AI register.

Frequently Asked Questions

Should every employee have access to the same AI tools?

No. Basic drafting and research tools may be suitable for most staff, but access should depend on data sensitivity, role risk and training. Staff who handle HR, finance, client files or customer complaints usually need tighter controls.

Can managers use AI for performance reviews?

They can use AI to structure notes or draft neutral wording, but they should not let AI make performance judgements, rank staff or decide outcomes. A manager must check accuracy, context and fairness.

Can admin staff paste customer emails into ChatGPT?

Only if the business has approved that tool for customer data and the email does not include sensitive or confidential information beyond the approved use. In many SMEs, the safer rule is to use an approved business workspace or anonymise the content first.

Do customer service teams need to tell customers they used AI?

Not for every grammar edit or internal summary. Disclosure becomes more important when AI is involved in automated replies, complaint handling, advice, eligibility decisions or anything that materially affects the customer.

How often should role-based AI rules be reviewed?

Review them quarterly while adoption is new, then at least every six months once usage is stable. Also review them whenever a new AI tool is approved, a workflow is automated or an incident occurs.

What is the easiest way to start?

Write a one-page baseline policy, create a simple role matrix for managers, admin and customer-facing staff, and start an AI register listing tool, owner, purpose, data used, review requirement and renewal date.

Who should own the AI rules in a small business?

The business owner or operations lead should own the rules, with input from managers, data protection support, finance and whoever understands the systems involved. Do not leave ownership with the keenest AI user by default.