Valgard Strategies Group
All posts
July 8, 2026·11 min readReader requestAIPolicyBusiness

How to write an AI (and technology) acceptable-use policy for your business

This one came in as a reader request from an owner who runs a fence company, and it's a genuinely important question: he wants to write an AI acceptable-use policy for his team — one he might also share with the other fence companies and customers he works with — and he made a sharp observation along the way. Most small shops don't even have a basic policy for computers, phones, tablets, internet, and social media, let alone AI. He's right, and you can't really bolt an AI policy onto nothing. So let's cover both: the foundation first, then the AI layer that sits on top of it.

Important caveat up front: this is a practical starting framework, not legal advice. Employment, privacy, and workplace-monitoring laws vary by state, so have an employment attorney review your final policy before you roll it out — especially anything touching discipline, monitoring, or personal devices. Everything below is meant to get you 80% of the way there so the lawyer review is fast and cheap.

Why bother writing this down at all?

Most small trade businesses run on trust and a handshake, and that works right up until it doesn't. It's the leaked customer list, the confidently-wrong AI-written bid that goes out to a GC, the off-color social post that's tagged to your company, the sketchy software someone installs, or the lost phone full of customer info. A written, signed policy does three things at once: it sets clear expectations so nobody has to guess, it protects the company legally when something goes sideways, and it gives you fair, consistent grounds to act when someone crosses a line. It isn't about distrusting your people — it's about everyone knowing the rules of the road.

Part 1: The foundation — a basic technology / acceptable-use policy

Before an AI policy, you need the layer under it: the rules for company computers, phones, tablets, email, internet, and social media. If you don't have this yet, start here — it's the piece almost every shop is missing. Here's what these policies typically cover:

  • Scope and ownership — who it applies to (employees, temps, and subs who touch your systems) and what it covers (company devices, email, accounts, networks, and data). State plainly that the company owns its systems and the data on them.
  • Acceptable use — company devices and accounts are primarily for business; decide and write down whether limited, reasonable personal use is allowed.
  • Prohibited use — no illegal activity, no harassing or discriminatory or offensive content, no adult content, no pirated or unlicensed software, no installing unapproved programs, no sharing passwords, no trying to get around security controls.
  • Email and internet — be alert to phishing and scam links, don't auto-forward company email to personal accounts, and be careful with attachments and downloads.
  • Passwords and security — unique strong passwords, multi-factor authentication turned on, screens locked when you step away, and any lost or stolen device or suspected breach reported immediately.
  • Company data and confidentiality — customer lists, pricing, bids, drawings, and employee info stay inside the company. Don't email them to personal accounts or hand them to outsiders.
  • Personal devices (BYOD) — if the crew uses personal phones for work texts, job-site photos, or customer details, spell out what's allowed and make clear that company data on a personal phone is still company data.
  • Monitoring and privacy — if you monitor company systems, say so in writing, and note there's no expectation of privacy on company equipment. This is exactly the section where state law varies most, so get it reviewed.
  • Social media — separate 'official' (only authorized people speak for the company) from 'personal.' Don't post job-site photos that reveal a customer's security layout or private information, keep it respectful, and add a simple 'views are my own' line for personal accounts.
  • Consequences and acknowledgment — state that violations can lead to discipline, and have every person sign that they read and understood the policy.

Part 2: The AI acceptable-use policy (the new layer)

Here's the urgent part: your people are almost certainly already using AI — pasting a customer's email into ChatGPT to write a reply, asking it to draft a proposal, using it to help price something. That's not a bad thing. Unmanaged, though, it's risky. An AI policy isn't there to ban AI — you want your team using it — it's there to keep them from leaking data, sending customers confidently-wrong information, or creating liability. It sits directly on top of the basic policy above.

What a solid small-business AI policy covers:

  • Approved tools — a short list of AI tools the company has vetted and allows; anything not on the list needs a yes before it's used for work. Account type matters: free/consumer versions may train on whatever you type, while business or enterprise versions usually don't. For anything work-related, use accounts that don't train on your data.
  • The #1 rule — what NEVER goes into a public AI tool: customer personal information, pricing and bid numbers, contracts, plans and drawings, employee records, or anything confidential you wouldn't post in public. This single rule prevents the large majority of AI mishaps.
  • Human review (you own the output) — AI is sometimes confidently wrong. A person checks anything before it goes to a customer, into a bid, into a contract, or drives a real decision. The company — not 'the AI' — is responsible for what leaves the building.
  • Prohibited uses — no AI-generated deepfakes or impersonation, nothing misleading or that you couldn't stand behind, no leaning on AI for final hiring or firing or other high-stakes calls without a human owning the decision, and never using it to cut safety or quality corners.
  • Disclosure and honesty — decide when you'll tell customers or partners that AI was involved (say, an AI-assisted phone line or chat), and never pass off unverified AI output as expert fact.
  • Intellectual property — AI output isn't automatically yours or copyright-protected, and you shouldn't feed in other people's copyrighted work or a competitor's confidential material. Know the terms of the tool you're using.
  • Security — AI accounts follow the same password and MFA rules as everything else, and nobody connects random AI plugins or 'agents' to your real email, files, or customer data without approval.
  • Fairness and bias — anything that touches hiring, reviews, or customers gets checked for bias, and a human makes the final call.
  • Ownership and updates — name a person who owns the policy and review it on a schedule (quarterly is reasonable; AI moves fast). Train the team with real examples of what to do and what never to do.
  • Acknowledgment — same as the foundation policy: everyone signs.

How to actually roll it out (so it works)

  1. Keep it short and in plain English. A two-page policy people actually read beats a twenty-page one they ignore.
  2. Have an employment attorney review it before it's final — especially the monitoring, discipline, and personal-device sections.
  3. Get a signed acknowledgment from every employee, and build it into onboarding for new hires.
  4. Train, don't just distribute. Walk the crew through real 'do this / never do that' examples — 'never paste a customer's info into ChatGPT' lands far better as a quick story than as a bullet point.
  5. Name an owner and a review date. Put AI on a quarterly check, because the tools and the risks keep moving.

Credible places to start — free templates and frameworks

You don't have to write any of this from a blank page. Start from a reputable template, cut it down to your size, and have your attorney review it. The sources worth pulling from:

  • SANS Institute — free, fully customizable information-security policy templates, including a strong Acceptable Use Policy plus email, password, and remote-access policies. This is the gold-standard free foundation. (sans.org/information-security-policy)
  • SHRM (Society for Human Resource Management) — sample HR policies including a Computer, Email, and Internet Usage Policy, a Social Media Policy, and a Generative AI Usage Policy template. (shrm.org — search 'policy templates')
  • NIST AI Risk Management Framework — the U.S. government's reference framework for managing AI risk; a good backbone for the reasoning behind your AI rules. (nist.gov — search 'AI Risk Management Framework')
  • Fisher Phillips — an employment-law firm's free, attorney-drafted sample 'Acceptable Use of Generative AI Tools' policy. (fisherphillips.com — search 'generative AI policy')
  • Workable — free, practical internet-usage and social-media policy templates aimed at small teams. (resources.workable.com)

One honest note on all of them: a template is a starting point, not a finished policy. Every one of these sources tells you the same thing — modify it to fit your actual business — and none of them replaces a quick legal review. Pull the language that fits, delete the enterprise bloat you don't need, and make it sound like your company.

The minimum viable version — if you do nothing else

If a full handbook feels like too much to tackle right now, here's the short list that covers most of the risk for a small shop today:

  • One page — 'How we use company devices, internet, and social media': business use, no illegal or offensive content, protect passwords, report lost devices, don't leak customer or pricing info, and who is allowed to post on behalf of the company.
  • One page — 'How we use AI': approved tools only, never paste customer, pricing, or confidential info into public AI, a human checks anything before it reaches a customer or a bid, and you own the output.
  • One signature page everyone signs, kept in their file.

Start there, get it reviewed, and expand as you grow. Two pages signed today beats a perfect handbook that never gets written.

A quick word on why this matters to us: at Valgard we help trade and field-service businesses actually put AI to work — and doing it right means doing it safely. The systems we build have this baked in from the start: approved tools, clear rules about what data can and can't touch an AI, and a human in the loop by default, so you get the speed without the exposure. If you'd like help writing your policy or standing up AI the safe way, that's squarely the kind of thing we do.

And to the reader who asked — good instinct. The shops that write these rules down now, before something goes wrong, are the ones that get to use AI aggressively and still sleep at night. Grab one of the templates above, trim it to your team, run it past a lawyer, and get everyone to sign. That's a great afternoon's work that saves you a genuinely bad day later. Hope this helps.

Comments

No comments yet — be the first.

Leave a comment

Comments are reviewed before they're posted, and we reply to the good ones.

Want this built into your business?

We design and build the AI and software that runs trade and field-service operations.

Book a Strategy Call