PublishedAugust 5, 2026
Last reviewedAugust 5, 2026
Editorial ownerFounder, Fortera Labs
Review status✓ Human-approved
AI assistedYes — disclosed
Sources6 cited
Back to Insights
GenAI GovernanceAI PolicySmall BusinessShadow AI5 min

The Smallest AI Policy That Actually Works

Six in ten workplaces have no rule on generative AI, and employees have quietly filled the vacuum themselves — concealing usage, skipping verification, pasting client data into free tools. The answer is not a forty-page framework; it is one page and five decisions.

Fortera Governance PracticeReviewed by Founder, Fortera Labs · Last reviewed August 5, 2026

The most common AI governance posture in small business is not refusal, and it is not managed adoption. It is unmanaged use: employees quietly working with tools nobody approved, under rules nobody has written.

The policy gap is now the norm, not the exception

The largest study of workplace AI behavior to date — 48,000 people across 47 countries, run by KPMG and the University of Melbourne — found that 58% of employees now use AI at work intentionally, and a third use it weekly or daily. Only 40% say their workplace has any policy or guidance on generative AI at all.

The behavior inside that gap is worse than most owners assume. In the same study, nearly half of employees admitted using AI in ways that contravene company policy, more than 57% said they hide their AI use or present AI-generated work as their own, and 66% said they rely on AI output without checking its accuracy. Employees also reported uploading confidential company information into free public tools. Fewer than half — 47% — had received any AI training.

the employee's improvisation is the company's AI policy — unwritten, unreviewed, and invisible to the people accountable for it.

None of this is malice. It is what happens when the tools arrive years before the rules. A capable employee with a deadline will use what works, and if the company has taken no position, the employee's improvisation is the company's AI policy — unwritten, unreviewed, and invisible to the people accountable for it.

Ungoverned use is already showing up in breach data

This stopped being a theoretical risk in the incident statistics some time ago. IBM's Cost of a Data Breach 2025 research, drawn from 600 breached organizations across 17 industries, found that one in five breaches now involves shadow AI — unsanctioned tools adopted without oversight — and that those incidents added roughly $670,000 to average breach costs. Among the breached organizations studied, 63% had no AI governance policy, and 97% of those reporting AI-related breaches lacked proper AI access controls.

Enterprises absorb a number like that. A thirty-person firm does not: the same exposure lands on a company with no security team, no incident retainer, and customer relationships that do not survive a disclosure letter. The absence of a policy does not keep a small company out of this data. It is what puts it there.

One page, five decisions

The instinct, especially after a scare, is to adopt a framework — a forty-page document adapted from an enterprise template, covering model risk tiers a ten-person company will never have. Nobody reads it, so it governs nothing. What a small company needs is one page that records five decisions people can actually follow.

  • Count what is already in use. Before writing a single rule, ask every person what AI tools they touch in a working week, and promise amnesty for the answers. You cannot govern tool use you have never counted; the inventory is the cheapest control a small company will ever buy.
  • Name the approved tools — and the default for everything else. A short list of sanctioned tools on business accounts, and one sentence: anything not on the list needs a yes before first use.
  • Draw the data lines. Client names and matters, credentials, financials, and personal data never go into unapproved public tools. This single rule addresses the confidential-upload behavior the KPMG study documented.
  • Require verification and disclosure. A named human checks AI output before it reaches a client, and AI-drafted work is not passed off as unassisted where it matters. This is the direct answer to the 66% who never check.
  • Give the policy an owner. One named person approves new tools, hears about incidents, and rereads the page quarterly. Accountability that points nowhere is not accountability.

This is not a rejection of formal frameworks — it is their entry point. NIST's AI Risk Management Framework is voluntary and deliberately scalable, and its four functions — govern, map, measure, manage — compress honestly to exactly these decisions at small-company scale. Start with the page; grow into the framework when the business earns the complexity.

Regulation is already sized to include you

The one-page policy is also, increasingly, a legal artifact. Under Article 4 of the EU AI Act, every provider and deployer of AI systems has been required since February 2, 2025 to ensure its staff have a sufficient level of AI literacy — an obligation with no small-company exemption. National supervision and enforcement of that duty began on August 2, 2026. That deadline has now passed: the duty is live and supervised, and a small deployer with nothing written down is behind it rather than ahead of it.

The proportionality cuts in a small company's favor. The European Commission's guidance, as law firm analyses of it note, prescribes no format and mandates no AI officer: what is expected scales with role, risk, and context, though merely handing staff a tool's instructions is typically not enough, and keeping a record of training delivered is the recommended defense. A one-page policy, an hour of documented training against it, and a dated record of both is a proportionate, defensible response for a small deployer — and it doubles as the answer to the AI questions now arriving on insurance questionnaires and customer due-diligence forms.

The companies that get hurt will not be the ones that chose the wrong framework. They will be the ones that never took a position while their employees took one for them — quietly, tool by tool, in the six in ten workplaces where employees report no rule at all. One page, five decisions, a named owner, and a dated training record: that is the smallest AI policy that actually works, and European regulators are now in a position to ask to see it.

Source basis

  1. 01KPMG / University of MelbourneTrust, attitudes and use of AI: 48,000 people across 47 countries; 58% use AI at work, 40% report any workplace policy
  2. 02University of Melbourne (FBE Newsroom)Media release: ~half of employees use AI contrary to policy; 57% conceal use; 66% do not verify output; 47% trained
  3. 03IBMCost of a Data Breach 2025: 1 in 5 breaches involve shadow AI, ~$670k added cost; 63% of breached orgs lacked an AI governance policy
  4. 04NISTAI Risk Management Framework: voluntary, scalable; govern / map / measure / manage
  5. 05Latham & WatkinsEU AI Act Article 4: AI literacy obligation for providers and deployers effective 2 February 2025, no small-company exemption
  6. 06Travers SmithAI literacy requirement: national supervision and enforcement from 2 August 2026; proportionality and record-keeping

Related reading

Working through a governance question like this one?

Talk to the practice