Small Business AI Policy Toolkit
A fill-in-the-blank workbook that takes a non-technical owner or manager from 'we have no AI rules' to a finished, adopted, staff-acknowledged AI Acceptable-Use Policy — in an afternoon.
Description
Your team is already using AI — most of them started without anyone saying it was okay, and now client data, contracts, and credentials are quietly flowing into tools you don't control ('shadow AI'). Meanwhile your cyber-insurance renewal, your clients' security questionnaires, and your own liability all ask the same question: do you have a written AI policy your staff actually follow? This isn't another blank template. It's a guided seven-step workbook: you answer plain-language prompts about your business and come out with six real artifacts — a shadow-AI inventory, a memorable four-tier data-classification rule, a living approved-tools register, a finished AI Acceptable-Use Policy assembled from your own answers, an employee one-pager plus acknowledgment form, and a training/rollout/incident process so it actually gets adopted. It's model-agnostic (works with ChatGPT, Copilot, Gemini, or Claude), and honest about its limits: it's a practical framework, not legal advice, and it flags every legal, insurance, and sector-specific decision as [CONFIRM] for you to resolve with counsel and your broker.
What's included
- README.md — overview, who it's for, what you finish with, and the honesty/legal note
- 00-start-here.md — the 2026 shadow-AI + cyber-insurance context, how to use the workbook, and the legal disclaimer (53 lines)
- 01-ai-inventory-worksheet.md — Step 1: find shadow AI blamelessly, inventory every tool, and the 'what has already gone in?' reckoning (79 lines)
- 02-data-classification.md — Step 2: the four-tier data rule, a map-your-own-data worksheet, and the 'does this tool train on our inputs?' question (80 lines)
- 03-approved-tools-register.md — Step 3: vetting questions, the register template, and a lightweight request-a-tool path (79 lines)
- 04-policy-builder-worksheet.md — Step 4: eleven prompts that assemble into every section of your policy (153 lines)
- 05-employee-one-pager.md — Step 5: the one-page do/don't card and the acknowledgment form (75 lines)
- 06-training-and-rollout.md — Step 6: a 30-minute team-training script, rollout checklist, and quarterly review (86 lines)
- 07-incident-and-exception-process.md — Step 7: what to do when something goes wrong, plus a documented exception process (113 lines)
- ai-policy-master-template.md — the assembled, copy-paste AI Acceptable-Use Policy skeleton (12 sections) + a short solo/freelancer version (65 lines)
Delivery
Instant download after Stripe checkout. File: nightforge-small-business-ai-policy-toolkit.zip