You Adopted AI Before You Wrote Any Rules for It. The Rules Just Showed Up Anyway.
77% of small businesses use AI daily, most with no policy. Now compliance deadlines are arriving from outside. A plain one-page framework you can write this week.
Most small businesses did not decide to adopt AI. It happened one subscription at a time.
Someone on your team started drafting emails with a chatbot. Someone else fed a client list into a tool to clean it up. The bookkeeper found something that categorizes receipts. No meeting, no policy, no decision. Just a slow drift into depending on tools nobody signed off on.
The numbers say this is nearly universal. A 2026 Intuit report drawing on more than 34,000 surveys found 77 percent of small and mid-sized businesses use AI daily. A separate BlackFog study put 49 percent of employees on unapproved AI tools, and 58 percent of those on free versions with weak data controls. So half your people may be using tools you never approved, on the tier least protective of your data.
For a while that was a quiet risk. This month it stopped being quiet, because the rules you never wrote started arriving from outside.
The deadlines that just landed on your calendar
Two of them matter right now.
Starting August 2, 2026, the transparency obligations in Article 50 of the EU AI Act take effect. As Sidley's privacy team lays out, people must be told when they are interacting with an AI system, and AI-generated or manipulated content must be disclosed and marked. If you think that is a European problem, check who visits your site and who buys from you. The Act reaches conduct that touches EU users, not just EU companies.
Closer to home, the FTC opened a comment period, running through July 31, on a proposed statement about accuracy in AI systems, per the same Forbes reporting. That is early-stage, but it signals where the federal floor is heading. And 47 states have already passed laws touching AI-generated media, each with its own standard. If you operate across state lines, you are already living under a patchwork.
We are not raising this to alarm you. We are raising it because the first real compliance test for most small businesses will not come from a regulator. It will come from a customer's procurement team asking a simple question: what AI do you use, and what happens to our data inside it. When a client asks that, "we don't really have a policy" is the wrong answer to give out loud.
Why a ban is the wrong instinct
The reflex, when you realize this is happening, is to shut it down. Do not.
A ban does not stop the usage. It drives it underground, onto personal phones and personal accounts, exactly where you have the least visibility and the least control. The businesses in real trouble are not the ones whose staff use AI. They are the ones whose staff use it invisibly, pasting client information into a free tool that trains on whatever it receives.
The goal is not zero AI. It is AI you can see.
The one page that solves most of this
You do not need a compliance department. You need a single page, written in plain language, that everyone actually reads. Here is the shape of it.
Which tools are approved, and who can use them. Name the specific tools. Point people to the paid, data-protected tiers, not the free ones. Ambiguity is what sends people to whatever they found on their own.
What never goes into an AI tool. Client financial data, personal information, anything covered by a contract or an NDA. Make this concrete with your own examples, not abstract categories, so a new hire knows the line without asking.
When you disclose. If AI wrote something a customer reads, or a customer is talking to a bot, say so. This is where the EU transparency rule and plain honesty happen to point the same direction. Write it once and you satisfy both.
Where a human checks the work. Name the moments that require a person to review before anything ships to a client. AI drafts. People approve. That order does not change.
What you are spending. Once a month, look at the subscriptions and ask whether each one is earning its keep. Shadow tools are also shadow costs.
Start by asking your team what they already use, with amnesty, no blame. You will learn more in that one conversation than in a month of guessing, and the people who actually use the tools will write you a better policy than you could write alone. Then revisit it quarterly, because the tools will not sit still.
The part nobody tells you
That one page does more than keep you out of trouble. It becomes a sales asset.
When a bigger customer runs a vendor security review, and more of them do every quarter, you hand over your policy and answer in a day what your competitor cannot answer in a week. The business that governs its AI does not just carry less risk. It closes faster, because it looks like the grown-up in the room.
You adopted AI faster than you wrote the rules. Almost everyone did. The move now is not to feel behind. It is to spend one afternoon writing the page, before a customer, a regulator, or a data leak writes it for you.
If you want a second set of eyes on that page before it goes to your team, that is a conversation we are glad to have.
Join the conversation
Straight talk welcome. Comments are moderated, no pitches, no spam.
Comments load once the Hyvor Talk Website ID is set in
article.html.