Do You Need an AI Use Policy?
If anyone on your team is already using ChatGPT or a similar AI tool for work, and on most teams somebody already is, then yes, you need a short written AI use policy, now rather than after something goes wrong. This is not because AI itself is dangerous. It is because client information, employee information, and your firm's name are all riding on how that tool gets used, and right now nobody has actually agreed on the rules.
I work with small business owners and law firm owners on exactly this kind of foundation work, the policies and procedures that quietly prevent expensive problems. AI use is the newest item on that list, and it is moving fast enough that waiting on it is its own risk.
Your Team Is Already Using AI, With or Without Your Say
Walk around most offices right now and you will find someone using AI for something. A paralegal getting a first draft of a client letter. Someone cleaning up marketing copy. Someone, in more law firms than owners want to admit, getting help on actual client work.
None of that happened because you announced an AI initiative. It happened because the tools are free, fast, and sitting right there in a browser tab. The question is not whether AI is in your business. It already is. The question is whether anyone is steering it.
Why No Policy Is Actually a Business Risk
A policy vacuum feels harmless until it is not. Three places it actually bites.
Client Confidentiality
Whatever gets typed into a public AI tool can end up stored, reviewed, or used to train that tool, depending on the product and its settings. A well meaning employee who pastes a client email, a contract, or a case detail into a free AI tool to clean it up may have just handed sensitive information to a third party outside your control. For a law firm, that stacks a confidentiality problem on top of a data problem.
Data Security
This is the same conversation as passwords and locked screens, just with a newer tool. Every place employee or client data can travel is a place you are responsible for protecting, and an ungoverned AI tool is one more door nobody thought to lock. If you have not put basic habits in place yet, our small business data security checklist covers the fundamentals.
A Wrong Answer Going Out Under Your Name
AI tools write confidently even when they are wrong. They can invent a case citation, misstate a number, or draft something that sounds right but is not, and if nobody reviews it before it goes out, it goes out under your name and your license. A marketing post with a made up statistic is embarrassing. A client email or legal document with a fabricated fact is a different problem entirely.
None of this means AI is off limits. The informal, anything goes approach most small businesses are running today is the actual risk, not the tool itself.
States Are Starting to Write Rules for This
This part of the picture is genuinely moving fast, so here is where things actually stand, not where they used to.
Colorado passed one of the country's first broad AI laws in 2024, then spent much of 2026 rewriting it. Colorado Senate Bill 26 189, adopted in May 2026, repealed that law and replaced it with a scaled back version. It drops the heaviest requirements, formal risk management programs and impact assessments, and instead sets practical duties for businesses using automated decision technology in employment, housing, credit, and insurance decisions: notice before the technology is used on someone, disclosure of certain adverse outcomes, a right to correct inaccurate data, and human review on request. Compliance is not required until January 1, 2027, and the state is still writing the detailed rules, which shows how unsettled even Colorado's own law remains.
Illinois took a narrower, employment focused approach. Amendments to the Illinois Human Rights Act under House Bill 3773 took effect January 1, 2026, requiring employers who use AI in hiring, promotion, and similar decisions to notify employees and applicants, describing the tool and how to ask questions or request an accommodation.
California's Civil Rights Council finalized its own regulations on automated decision systems in employment, effective October 1, 2025, expecting employers who use AI in hiring or other employment decisions to test for bias and keep records of how the tool was used.
Three states, three approaches, one shared worry: AI shaping decisions about real people without enough oversight. Other states are debating similar bills, and this list will keep changing. This is general business operations education, not legal advice about any specific state's law. Confirm current requirements for where you operate with your own attorney rather than relying on any single article, including this one.
What Belongs in a Simple Internal AI Use Policy
You do not need a legal team or a fifteen page document. A working policy fits on one or two pages and covers a short list of decisions.
1. Which AI tools are approved for use at work, and which are off limits.
2. What can never be typed into an AI tool: client information, employee information, financial data, anything covered by confidentiality, ever.
3. Who reviews AI assisted work before it reaches a client, a patient, or the public, especially anything carrying your firm's name.
4. Whether your business uses AI in any employment decision, and if so, what notice you owe employees or applicants under the rules that apply where you operate.
5. What records you keep of how AI tools are used, particularly around hiring or other employment decisions.
6. Who owns the policy and when it gets reviewed. Given how fast this area is changing, quarterly is not too often.
Write it in plain language, put it where your team will actually read it, and walk through it out loud once rather than emailing a document nobody opens.
For Law Firm Owners, There's One More Layer
An internal AI use policy covers the business side: your data, your employees, your operations. It does not cover the separate professional responsibility questions that come with using AI in actual legal work, competence, confidentiality, billing, and supervision duties that most state bars are actively addressing right now. Those rules vary by state and change often, so confirm the current bar guidance for AI use in legal work with your own bar association and counsel before your firm relies on AI for anything client facing. If trust account compliance is also on your worry list, our companion site for law firm trust accounting is a good next stop.
Frequently asked questions
Do these state AI laws apply to my small business?
It depends on where you operate and whether you use AI in hiring or other employment decisions. Coverage varies by state and is still developing, so confirm with your attorney rather than assuming either way.
What is the single biggest risk of having no AI policy at all?
Not knowing what already left the building. Without a policy, you cannot know what client, employee, or financial information has already been typed into a public AI tool, or what unreviewed AI content has already gone out under your name.
Can my employees use ChatGPT for client work at all?
Many businesses allow it for drafting and first passes, as long as no confidential information is entered and a person reviews the output before it goes anywhere. Where the line sits is your call, but it needs to be a decision, written down, not a default nobody chose.
How long does an AI use policy need to be?
Long enough to answer the checklist above, usually one to two pages. A short policy your team actually reads beats a long one that sits in a drawer.
Are there special AI rules for attorneys beyond the general business rules?
Yes. Most state bars are issuing or considering guidance on AI use in legal work, covering competence, confidentiality, and billing, on top of the general business rules. Check with your state bar and your own counsel for what currently applies to your practice.
A Note From Nettie
I am not the person to tell you what your state's AI law requires or what your bar expects of AI use in legal work. That is a conversation for your attorney. What I can help with is the business side: a clear, written policy so your team knows the rules, your data stays where it belongs, and nothing goes out under your name that you have not reviewed. That kind of foundation work sits at the center of the operational consulting I do with small business and law firm owners, and it is far easier to build before something goes wrong than after. If you want a hand putting a real AI use policy in place, reach out through our contact page and we will get you a straightforward starting point.
About the author
Nettie Roos is the owner of Rebel Patriot Business Services, a bookkeeper and business consultant who works with small business and law firm owners on their books, operations, and the systems that let them run the business instead of the business running them. She is not an attorney or a CPA. This article is general business operations education, not legal advice. Rules on AI regulation vary by state and change often, so confirm current requirements, and any bar specific rules for AI use in legal work, with your own attorney.










