What AI uses should be banned completely in a small business policy?
13 September 2026
What AI uses should be banned completely in a small business policy?
A small business AI policy should completely ban staff from using AI for passwords, client confidential data, personal data, final legal or HR decisions, financial approvals, regulated advice, impersonation, covert monitoring and any automation that can act inside business systems without approval. Everything else should sit in approved, controlled use cases with human review.
What should be banned outright?
The clearest ban is this: staff must not put passwords, API keys, recovery codes, client files, personal data, financial records, HR records, contracts under negotiation, trade secrets or confidential business plans into unapproved AI tools. That includes free consumer accounts, browser extensions, unknown AI note takers, image tools, transcription apps and personal automation tools. If the business has not approved the tool, checked its data handling and set the right account controls, the tool should not receive sensitive company information.
A good small business policy should also ban AI from making final decisions about people, money or legal responsibility. That means no AI-only hiring shortlist, no AI-only disciplinary recommendation, no AI-only customer credit decision, no AI-only supplier payment approval, no AI-only legal answer to a client, and no AI-only response to a formal complaint. AI can help prepare information for a qualified person. It should not become the decision maker where someone could be harmed, treated unfairly or exposed to legal risk.
The practical test is simple. If the input is sensitive, the output changes someone's rights or money, or the business would be embarrassed explaining the process to a customer, ban casual AI use and require approval first.
Why blanket bans usually fail
Blanket bans feel simple, but they rarely survive contact with a busy team. Staff use AI because it helps them write, summarise, compare, translate, analyse and move faster. If the official policy says no to everything while workloads keep rising, people find workarounds. The NCSC describes this as shadow AI: AI technology used outside approved systems and processes. It points to research where 71% of employees reported using AI tools their employer had not approved.
That does not mean leaders should shrug and allow anything. It means the policy needs three categories: banned, approved with review, and freely allowed. Banned uses should be narrow and serious. Approved uses should cover the normal work people actually want to do, such as summarising a non-confidential meeting note, rewriting a public-facing email draft, preparing a checklist, or exploring ideas. Freely allowed uses should be low-risk tasks using public or non-sensitive information.
The ICO's AI and data protection guidance is written for businesses in the public, private and third sectors, and it points organisations back to UK GDPR principles when AI uses personal data. That matters for SMEs because size is not a defence. A 12-person firm still has data protection duties if staff paste customer or employee information into a tool.
The banned list I would put in a small business policy
Here is the plain-English banned list I would start with for a UK SME. Staff must not enter passwords, API keys, one-time codes, private keys, recovery phrases or security answers into any AI tool. They must not upload client files, customer records, employee records, payroll information, medical data, safeguarding information, financial records, bank statements, legal papers, NDA material, board papers or unpublished commercial plans into an unapproved AI tool. They must not ask AI to impersonate a real customer, supplier, colleague or director without clear disclosure and authorisation.
Staff should also be banned from using AI to make final decisions in HR, recruitment, disciplinary action, finance approvals, credit, insurance, legal advice, regulated advice, complaints handling or any customer-impacting decision where the person affected cannot challenge the result. AI can support a manager by summarising evidence or drafting questions, but the accountable person must review the source material and make the decision.
Finally, ban unsupervised AI agents that can send emails, move money, change CRM records, delete files, update accounts software or contact customers unless that automation has been approved, tested, logged and assigned to an owner. An AI assistant that drafts a supplier follow-up is one thing. An AI agent that sends it automatically from a shared inbox is a different risk category.
What can be allowed with controls?
Most useful AI work does not need to be banned. It needs boundaries. For example, staff can use approved AI tools to rewrite internal notes, summarise public information, draft non-sensitive emails, create first-pass checklists, prepare meeting agendas, brainstorm customer education topics or explain a technical concept in plain English. If personal or client information is involved, the policy should require redaction, approved accounts and human review.
For automations, the first approved use cases should be narrow and auditable. A weekly management report that pulls figures from approved systems and creates a draft commentary can be useful, provided someone checks the figures before circulation. A customer service assistant that suggests replies can be useful, provided a person sends the final answer. A document extraction workflow can save hours, provided exceptions are flagged and bad data does not flow straight into core systems.
Budget also matters. A lightweight policy, approved tool list and staff training session may cost £750 to £2,500 if done externally. A proper AI governance setup with registers, supplier checks, data mapping and workflow review can cost £3,000 to £10,000 for a small business, rising if regulated data, multiple systems or customer-facing automation are involved. That is still cheaper than cleaning up a preventable data breach or customer complaint.
When this is NOT right for you
A detailed banned-use policy is not the first priority if your business has no approved AI tools, no data classification and no manager willing to own the process. In that case, start smaller. Write a one-page rule that says what must never be pasted into AI, name one or two approved tools, and require manager approval for anything involving customer data, staff data or automation.
This approach is also not enough for regulated, safety-critical or legally complex work. If you operate in financial services, healthcare, legal services, recruitment, education, care, insurance or another sensitive sector, you may need professional advice before approving AI use. The policy should not pretend a generic chatbot can provide regulated judgement. It should say exactly where AI can assist and where qualified human review is mandatory.
It is also not right if leadership wants to use the policy as a way to blame staff while avoiding proper tooling. If the business gives people impossible workloads, refuses to provide approved AI access, and then punishes staff for finding shortcuts, the policy will fail. The best version protects the company and gives people a realistic way to work well.
The practical rule for UK SMEs
Use a traffic-light policy. Red means banned: secrets, confidential data, personal data, final decisions, impersonation and unsupervised actions inside business systems. Amber means allowed only with approval: client-related drafting, customer service support, finance reporting, HR preparation, CRM automation, data extraction and anything touching operational systems. Green means allowed: public information, non-sensitive drafting, learning, brainstorming and admin support using approved tools.
Then make it visible. Put the banned list in the staff handbook, onboarding pack and AI register. Add examples from your own work, not generic policy language. A letting agency should mention tenancy documents. An accountancy firm should mention tax records. A marketing agency should mention client campaign data and unpublished strategy. A trades business should mention customer addresses, job notes and payment records.
Review it every quarter. AI tools change settings, staff discover new use cases, and the business learns where the real risks sit. The aim is not to freeze the policy forever. The aim is to make the first line clear enough that a normal employee can make the right call on a busy Tuesday afternoon.
Is This Right For You?
This applies if your staff are already using ChatGPT, Copilot, Gemini or similar tools and you need a clear line between acceptable use and unacceptable risk. It is especially relevant if your business handles client files, financial records, employee information, customer enquiries or confidential commercial data.
It is not right for you if you want a blanket ban on all AI use and no approved alternative. The NCSC warns that shadow AI grows when policies fail to meet business needs. A useful policy bans the genuinely dangerous uses, then gives staff a safe way to use AI for lower-risk work.
Frequently Asked Questions
Should staff be banned from using free ChatGPT at work?
Not for every task, but free consumer AI tools should be banned for client data, personal data, confidential files, passwords, financial records and anything business-critical. If staff need AI for work, provide an approved tool and clear rules.
Can AI write customer emails?
Yes, if the content is reviewed by a person and the tool is approved for the data used. Ban AI from sending customer messages automatically unless the workflow has been tested, approved and assigned to a named owner.
Can managers use AI for HR decisions?
AI can help organise notes or draft interview questions, but it should not make final HR, recruitment, disciplinary or redundancy decisions. A qualified person must review the evidence and remain accountable.
What data should never go into an unapproved AI tool?
Never enter passwords, API keys, client files, personal data, payroll data, HR records, financial records, bank details, contracts, legal documents, NDA material, trade secrets or unpublished business plans into an unapproved AI tool.
Do small businesses need an AI register?
Yes. Keep it simple. List the AI tool, owner, purpose, data used, approval status, cost, risk level and review date. A spreadsheet is enough for most SMEs.
How often should the banned-use list be reviewed?
Review it quarterly, and immediately after any incident, new AI tool purchase, new automation, major supplier change or change in the type of data the business handles.
Who should own the AI policy in a small business?
The owner or operations lead should own it, with input from whoever handles data protection, finance, HR and systems. Do not leave it to the most enthusiastic AI user by default.