77% of SMBs use AI without a formalized policy — an avoidable risk
Your employees use ChatGPT, Copilot or Midjourney daily, but 77% of French SMBs have no written AI usage policy. Without a framework, risks accumulate: data leaks, erroneous content published, GDPR non-compliance. Yet an effective AI usage policy fits in 3 to 5 pages and can be drafted in one week. It is based on a clear table of what is authorized, supervised and forbidden, tailored to your business.
The problem
Generative AI was adopted in companies spontaneously, without waiting for directives. Employees discovered ChatGPT, found it useful, and integrated it into their daily work. This "bottom-up" adoption is healthy in its momentum, but dangerous without a framework.
The concrete problems we observe among our SMB clients:
- Use of unsecured tools: 58% of employees use the free version of ChatGPT for professional tasks, without knowing that the data entered may be used to train the model.
- No data classification: no one knows which data can or cannot be entered into an AI tool. An accountant copies and pastes a balance sheet into ChatGPT to generate a summary; a salesperson enters their customer list to prepare a campaign.
- No validation process: AI-generated content is sent to customers or published without review. Hallucinations (false figures, non-existent sources) end up in sales proposals or reports.
- Anxiety-inducing legal uncertainty: management knows it must "do something" but doesn't know where to start. The result: either a total ban (loss of competitiveness) or a hands-off approach (risk-taking).
The challenge is not to slow innovation but to channel it. A well-designed AI usage policy is an accelerator, not a brake: it gives employees the confidence to use AI more widely and better.
The AI solution
Our AI usage policy template rests on three essential components, tested and validated with more than 30 SMBs and mid-market companies.
Allowed / supervised / forbidden table
The heart of the policy: a simple table that classifies uses into three categories. Green (allowed): brainstorming, drafting, general information research, translation of public content. Orange (supervised): drafting customer documents (mandatory validation), aggregated data analysis, marketing visual generation. Red (forbidden): entering personal data, unpublished financial data, industrial secrets, automatic decision-making without supervision.
Governance rules
Who validates what? The responsibilities table defines: the AI lead (tool management and monitoring), the process for requesting access to a new AI tool, the validation circuit for generated content according to its criticality, the incident reporting procedures, and the sanctions in case of non-compliance. These rules integrate into the existing internal regulations.
Approved tools kit
The list of AI tools authorized in the company, with for each: the required version (free vs. enterprise), the authorized uses, the limits, and the level of confidentiality guaranteed. Example: ChatGPT Enterprise (authorized for all supervised uses), Midjourney (authorized for marketing only), GitHub Copilot (authorized for the dev team with mandatory code review).
Implementation
Here is the three-step action plan to draft and deploy your AI usage policy in one week.
Flash usage audit (days 1-2)
Send an anonymous 5-minute survey to all employees: which AI tools do you use? how often? for what tasks? what data do you enter? Complement it with 3-4 interviews with key managers. The goal is to get a realistic snapshot of current practices, not an exhaustive inventory.
Collaborative drafting (days 3-4)
Bring together the working group (executive management, CIO, DPO, 1-2 business reps) for a 3-hour session. Start from our template and adapt it: classify your specific uses in the green/orange/red table, choose the approved tools, define the validation processes. The final document is 3 to 5 pages maximum — conciseness is the key to adoption.
Rollout and training (days 5-7)
Present the policy at a 30-minute plenary meeting. Distribute a one-page summary sheet (the allowed/forbidden table) that each employee can post at their workstation. Organize 1-hour training sessions per department to address specific cases. Create a dedicated channel (Slack, Teams) for questions. Schedule a first review at 3 months.
Results
Frequently asked questions
Is an AI usage policy mandatory for SMBs?
Not yet mandatory in the strict sense, but strongly recommended. The European AI Act has imposed AI literacy obligations since February 2025, which implies documenting usage and training employees. In addition, the GDPR requires documenting any processing of personal data, including via AI tools. A formalized policy protects you in the event of an audit.
Who should draft the AI usage policy?
Ideally, a working group bringing together executive management (strategic validation), the CIO or IT manager (technical feasibility and security), the DPO or legal manager (GDPR and AI Act compliance), and one or two business representatives (usability and acceptance). In SMBs, this often comes down to 3-4 people working in 2-3 sessions of 2 hours.
How often should the AI policy be updated?
At least once a year, or as soon as a significant event occurs: new regulatory text, security incident, adoption of a new AI tool, change of business activity. In practice, AI technologies evolve so fast that a semi-annual review is more prudent in the first year.
How do you enforce the AI usage policy?
Three complementary levers: training (raising awareness about the why, not just the what), technical controls (an enterprise proxy that blocks unauthorized tools, DLP to detect data leaks), and integration into existing processes (including AI rules in the internal regulations and annual reviews).
For technical profiles
Comparison of enterprise AI control and governance tools:
| Criterion | Microsoft Purview + Copilot | Custom AI proxy (LiteLLM / Helicone) | Manual policy alone |
|---|---|---|---|
| Tool access control | Native (Azure AD) | Via centralized proxy | Declarative only |
| DLP (data leak prevention) | Integrated (auto detection) | Custom (regex, NER) | No |
| Request logging | Complete + compliance | Complete + analytics | No |
| Monthly cost (50 users) | 600 – 1,500 euros | 100 – 500 euros | 0 euros |
| Deployment complexity | Medium (MS ecosystem) | High (DevOps skills) | Low |
| Multi-model | OpenAI + Azure only | All models | All models |
| Suitable for | SMBs already on Microsoft 365 | Mid-market with a DevOps team | First step, any SMB |
Recommendation: start with a manual policy deployed in 1 week (step 1), then add an AI proxy such as LiteLLM or Helicone as soon as you have 20+ active AI users (step 2). The Microsoft Purview suite is relevant if you are already in the Microsoft 365 E5 ecosystem.